| URL: | netu.ac |
| Full analysis: | https://app.any.run/tasks/920ed123-dd49-47dd-a214-aa1c45a4efe0 |
| Verdict: | Malicious activity |
| Analysis date: | November 29, 2023, 12:31:22 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MD5: | F0CD98B88797C9DCF53A5300F09FDF4F |
| SHA1: | C6830522C105DFCDC679E2226A27677989A2B391 |
| SHA256: | 905E6FA192B3974981B9FBD8934DB04BA44B2D858145BD87D6A4EE1B0F882DCA |
| SSDEEP: | 3:ZEG:6G |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 856 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=3120 --field-trial-handle=1148,i,9661135575059679172,9348381418983653968,131072 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 952 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=quarantine.mojom.Quarantine --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=4480 --field-trial-handle=1148,i,9661135575059679172,9348381418983653968,131072 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 1248 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=8 --mojo-platform-channel-handle=2236 --field-trial-handle=1148,i,9661135575059679172,9348381418983653968,131072 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 1808 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=10 --mojo-platform-channel-handle=3456 --field-trial-handle=1148,i,9661135575059679172,9348381418983653968,131072 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 1820 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3388 --field-trial-handle=1148,i,9661135575059679172,9348381418983653968,131072 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 1884 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=15 --mojo-platform-channel-handle=3704 --field-trial-handle=1148,i,9661135575059679172,9348381418983653968,131072 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 1928 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=13 --mojo-platform-channel-handle=2164 --field-trial-handle=1148,i,9661135575059679172,9348381418983653968,131072 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 2324 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=4244 --field-trial-handle=1148,i,9661135575059679172,9348381418983653968,131072 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 2724 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=2420 --field-trial-handle=1148,i,9661135575059679172,9348381418983653968,131072 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 2848 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3004 CREDAT:267521 /prefetch:2 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| (PID) Process: | (3004) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPDaysSinceLastAutoMigration |
Value: 0 | |||
| (PID) Process: | (3004) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPLastLaunchHighDateTime |
Value: 30847387 | |||
| (PID) Process: | (3004) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager |
| Operation: | write | Name: | NextCheckForUpdateHighDateTime |
Value: 30847437 | |||
| (PID) Process: | (3004) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (3004) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (3004) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main |
| Operation: | write | Name: | CompatibilityFlags |
Value: 0 | |||
| (PID) Process: | (3004) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (3004) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
| Operation: | write | Name: | SavedLegacySettings |
Value: 4600000059010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3004) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (3004) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2848 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\ZA7GEZLK.htm | html | |
MD5:2D7086068AD8B5B339327045BB36AD3C | SHA256:CEC9D8F1D36DE06215D42D5873BF40D8CA59D38EB3F544CC7672B639D4AECEBA | |||
| 2848 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157 | compressed | |
MD5:1BFE591A4FE3D91B03CDF26EAACD8F89 | SHA256:9CF94355051BF0F4A45724CA20D1CC02F76371B963AB7D1E38BD8997737B13D8 | |||
| 2848 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157 | binary | |
MD5:1A0ADAE4BB8679A210D0CC637139A8FF | SHA256:D32DF21C983133C2021716FAD05312B96BAE4C84AB8E28FDACF2BB19102688A0 | |||
| 2848 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\font-awesome.min[1].css | text | |
MD5:4FBD15CB6047AF93373F4F895639C8BF | SHA256:DDD92F10AD162C7449EFF0ACAF40598C05B1111739587EDB75E5326B6697C5D5 | |||
| 2848 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\D0E1C4B6144E7ECAB3F020E4A19EFC29_B5F77004C894173A10E3A199871D2D90 | binary | |
MD5:BD979F9BC12BACF1DD2496757C3D6948 | SHA256:FEB4BA74351572E4ACEFED1FB67FC04F67404707F8C0239D6DFF7C2BA5870045 | |||
| 2848 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\D0E1C4B6144E7ECAB3F020E4A19EFC29_B5F77004C894173A10E3A199871D2D90 | binary | |
MD5:CE4C1D45D49BBB504D97F2EEAB04091D | SHA256:689C82704F6E0D5475B44C4E72FC06FA7C02BEE6C5C21C95092798AB50B2FA2C | |||
| 2848 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6BADA8974A10C4BD62CC921D13E43B18_28DEA62A0AE77228DD387E155AD0BA27 | binary | |
MD5:1D7ACFE5301E1F91FAA0CE1ABBD6CB5B | SHA256:48D9ADA5008B11AD9B047B9A0B5A515919DFFF10CEB7233CB52547FC60A6F222 | |||
| 2848 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\swfobject[1].js | text | |
MD5:892A543F3ABB54E8EC1ADA55BE3B0649 | SHA256:8677971B119CCDB82AF697FF0E08F218490D15116F221D44301F1CC8797E67D4 | |||
| 2848 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6BADA8974A10C4BD62CC921D13E43B18_28DEA62A0AE77228DD387E155AD0BA27 | binary | |
MD5:524FC9607301885F18C58B0E89378B33 | SHA256:0E04E8A7C29800FF44A27C35DE55F7183E353175AEBD8069A66F30964D86431B | |||
| 2848 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EA | binary | |
MD5:2B82797352ACC9EC793E780162F105EE | SHA256:888F78341FD34F2F70C81613BC15B9497789AC9CEAA831D080F2C716A1D850B7 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2848 | iexplore.exe | GET | 200 | 190.115.19.71:80 | http://netu.ac/ | unknown | html | 30.2 Kb | unknown |
2848 | iexplore.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEAo3h2ReX7SMIk79G%2B0UDDw%3D | unknown | binary | 1.47 Kb | unknown |
2848 | iexplore.exe | GET | — | 190.115.19.71:80 | http://netu.ac/styles/cbv2new/theme/counter.css? | unknown | — | — | unknown |
2848 | iexplore.exe | GET | — | 190.115.19.71:80 | http://netu.ac/styles/cbv2new/theme/bootstrap.css?17 | unknown | — | — | unknown |
2848 | iexplore.exe | GET | — | 216.58.206.34:80 | http://pagead2.googlesyndication.com/pagead/js/adsbygoogle.js | unknown | — | — | unknown |
2848 | iexplore.exe | GET | — | 190.115.19.71:80 | http://netu.ac/styles/cbv2new/theme/main.css?232 | unknown | — | — | unknown |
2848 | iexplore.exe | GET | — | 190.115.19.71:80 | http://netu.ac/styles/cbv2new/theme/animate.css?56 | unknown | — | — | unknown |
2848 | iexplore.exe | GET | 200 | 104.18.10.207:80 | http://maxcdn.bootstrapcdn.com/font-awesome/4.5.0/css/font-awesome.min.css | unknown | text | 6.72 Kb | unknown |
2848 | iexplore.exe | GET | 200 | 142.250.181.234:80 | http://ajax.googleapis.com/ajax/libs/swfobject/2.2/swfobject.js | unknown | text | 3.88 Kb | unknown |
2848 | iexplore.exe | GET | 200 | 23.53.40.35:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?ee508b6a43ac39ca | unknown | compressed | 4.66 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2848 | iexplore.exe | 190.115.19.71:80 | netu.ac | DDOS-GUARD CORP. | BZ | unknown |
2848 | iexplore.exe | 216.58.206.34:80 | pagead2.googlesyndication.com | GOOGLE | US | unknown |
2848 | iexplore.exe | 104.18.10.207:80 | maxcdn.bootstrapcdn.com | CLOUDFLARENET | — | unknown |
2848 | iexplore.exe | 190.115.19.71:443 | netu.ac | DDOS-GUARD CORP. | BZ | unknown |
2848 | iexplore.exe | 142.250.181.234:443 | ajax.googleapis.com | GOOGLE | US | whitelisted |
2848 | iexplore.exe | 142.250.181.234:80 | ajax.googleapis.com | GOOGLE | US | whitelisted |
2848 | iexplore.exe | 142.250.185.99:443 | www.recaptcha.net | GOOGLE | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
netu.ac |
| unknown |
maxcdn.bootstrapcdn.com |
| whitelisted |
pagead2.googlesyndication.com |
| whitelisted |
hqq.tv |
| whitelisted |
waaw.tv |
| whitelisted |
yandexcdn.com |
| unknown |
waaw1.tv |
| unknown |
ajax.googleapis.com |
| whitelisted |
www.recaptcha.net |
| whitelisted |
cdnjs.cloudflare.com |
| whitelisted |