URL:

https://cricfree.live/livetv/bt3.php

Full analysis: https://app.any.run/tasks/fbf11a19-3d03-41df-af5e-315d5498de5d
Verdict: Malicious activity
Analysis date: November 21, 2021, 13:29:47
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

266FE171EFA512C7B8DA81703F759225

SHA1:

5BA3E4B2CBD610A1F7951EBB09B3D99EE53AE309

SHA256:

92F09205C5BBEAB0A068C9A92DA92B0D7FDB00FE2FB199C9F18C4D7066B6DA54

SSDEEP:

3:N8KjQA9Mc0EMV:2KZ9sEMV

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads the computer name

      • FlashUtil32_32_0_0_453_ActiveX.exe (PID: 3468)
    • Checks supported languages

      • FlashUtil32_32_0_0_453_ActiveX.exe (PID: 3468)
    • Reads Microsoft Outlook installation path

      • iexplore.exe (PID: 1588)
    • Executed via COM

      • FlashUtil32_32_0_0_453_ActiveX.exe (PID: 3468)
    • Creates files in the user directory

      • FlashUtil32_32_0_0_453_ActiveX.exe (PID: 3468)
  • INFO

    • Checks supported languages

      • iexplore.exe (PID: 3004)
      • iexplore.exe (PID: 1588)
    • Reads the computer name

      • iexplore.exe (PID: 3004)
      • iexplore.exe (PID: 1588)
    • Reads settings of System Certificates

      • iexplore.exe (PID: 1588)
      • iexplore.exe (PID: 3004)
    • Changes internet zones settings

      • iexplore.exe (PID: 3004)
    • Reads CPU info

      • iexplore.exe (PID: 1588)
    • Application launched itself

      • iexplore.exe (PID: 3004)
    • Reads internet explorer settings

      • iexplore.exe (PID: 1588)
    • Checks Windows Trust Settings

      • iexplore.exe (PID: 3004)
      • iexplore.exe (PID: 1588)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
37
Monitored processes
3
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe flashutil32_32_0_0_453_activex.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1588"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3004 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
3004"C:\Program Files\Internet Explorer\iexplore.exe" "https://cricfree.live/livetv/bt3.php"C:\Program Files\Internet Explorer\iexplore.exe
Explorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
c:\windows\system32\rpcrt4.dll
3468C:\Windows\system32\Macromed\Flash\FlashUtil32_32_0_0_453_ActiveX.exe -EmbeddingC:\Windows\system32\Macromed\Flash\FlashUtil32_32_0_0_453_ActiveX.exesvchost.exe
User:
admin
Company:
Adobe
Integrity Level:
MEDIUM
Description:
Adobe� Flash� Player Installer/Uninstaller 32.0 r0
Exit code:
0
Version:
32,0,0,453
Modules
Images
c:\windows\system32\macromed\flash\flashutil32_32_0_0_453_activex.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
Total events
25 999
Read events
25 800
Write events
199
Delete events
0

Modification events

(PID) Process:(3004) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
1
(PID) Process:(3004) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchLowDateTime
Value:
(PID) Process:(3004) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30924507
(PID) Process:(3004) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateLowDateTime
Value:
(PID) Process:(3004) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30924507
(PID) Process:(3004) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(3004) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3004) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3004) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(3004) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
0
Suspicious files
32
Text files
106
Unknown types
68

Dropped files

PID
Process
Filename
Type
1588iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B2FAF7692FD9FFBD64EDE317E42334BA_2DBE917624E9880FE0C7C5570D56E691der
MD5:72B810829D7F29893C5EAA079D730F2B
SHA256:768D7A57D7568E068ACD2E1E83F8495720DF2931C393D0342F00A98C0789C16A
1588iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\5080DC7A65DB6A5960ECD874088F3328_862BA1770B2FEE013603D2FF9ABEAFDAder
MD5:E87096B1C23FA47E0FD49FB85FE643C4
SHA256:F78E5D78523E0AE04230A6A77B964411FE8B7AE290439634C7842F087BF669F3
1588iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\5080DC7A65DB6A5960ECD874088F3328_862BA1770B2FEE013603D2FF9ABEAFDAbinary
MD5:8E8284B3434E6D8129DBBB3F3538CD46
SHA256:A724CA358BC1F90FED51A20F4F68431773DEBD393EB993DCE8F306DEE9AA9394
1588iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:798D67F297C50652CF283D35522F761C
SHA256:65DE3D2CBF6CADAD3FD093674FD1941E7E70B4CE0A14445647B8679383797350
1588iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B2FAF7692FD9FFBD64EDE317E42334BA_2DBE917624E9880FE0C7C5570D56E691binary
MD5:DDD988CF465D62E87C8F3D2400A470E5
SHA256:80523692AF49B11507698813D3BBC3F400ED488BF603D292FFB8CA77F3DB231E
1588iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\scripts[1].jstext
MD5:B963F0109C07AF961413896057A6B9FB
SHA256:7AC25EFA11CCD96A71C3A7186BD19F31B7AFAD74E3D9BBA397B4C04A01CD9B6F
1588iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\0255CEC2C51D081EFF40366512890989_D710FAF9EACFD783985ECC6094EBB3B2der
MD5:9EA2930DFC1A70651E62C87AC1C1F43D
SHA256:F244B740B55926C94ECD5DAA8EF449949B87186D0A82C8836625AB8FC40EA3D8
1588iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\styles[1].csstext
MD5:6C41F50E0D078EE9EEA29D3E10A4FAA4
SHA256:3D3FCD8F9D1CB99CCD659D15BC125095BCA2218909A16E242683AAA40832DF54
1588iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\0255CEC2C51D081EFF40366512890989_D710FAF9EACFD783985ECC6094EBB3B2binary
MD5:B7665CA8EB2BFFC525278969F2D0CD6A
SHA256:4B9EC550A6313763C15F18C05A7DE0CDE4DAFAAD5212519461D10D090B4A01DE
1588iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6BADA8974A10C4BD62CC921D13E43B18_28DEA62A0AE77228DD387E155AD0BA27binary
MD5:F3A5941B6A0FF0913B7AD3F516F17DFE
SHA256:EAE311C4DC88D3D8E4091525F5D99F6B2AED485EEFA101EBDFCC1C986DF42154
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
34
TCP/UDP connections
116
DNS requests
39
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1588
iexplore.exe
GET
200
2.16.186.81:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?edd893f4c27d18ae
unknown
compressed
4.70 Kb
whitelisted
1588
iexplore.exe
GET
200
151.139.128.14:80
http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEGfe9D7xe9riT%2FWUBgbSwIQ%3D
US
der
471 b
whitelisted
1588
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEAo3h2ReX7SMIk79G%2B0UDDw%3D
US
der
1.47 Kb
whitelisted
1588
iexplore.exe
GET
200
151.139.128.14:80
http://ocsp.comodoca.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBReAhtobFzTvhaRmVeJ38QUchY9AwQUu69%2BAj36pvE8hI6t7jiY7NkyMtQCEQDwHUvue3yjezwFZqwFlyRY
US
der
728 b
whitelisted
1588
iexplore.exe
GET
200
2.16.186.81:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?7aac6a89c08c0d36
unknown
compressed
59.9 Kb
whitelisted
1588
iexplore.exe
GET
200
151.139.128.14:80
http://ocsp.comodoca.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBSTufqHinruS%2FP9Wi1XSjRRzoTLfAQUfgNaZUFrp34K4bidCOodjh1qx2UCEQD4IXOIxN9Z04I8yLS4mqSw
US
der
472 b
whitelisted
1588
iexplore.exe
GET
200
2.16.186.81:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?22e4dc7772ef213f
unknown
compressed
59.9 Kb
whitelisted
1588
iexplore.exe
GET
200
2.16.186.81:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?f689b1cfbeda6f1d
unknown
compressed
59.9 Kb
whitelisted
1588
iexplore.exe
GET
200
2.16.186.81:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?ed3ef99e98c83e24
unknown
compressed
59.9 Kb
whitelisted
1588
iexplore.exe
GET
200
151.139.128.14:80
http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSTufqHinruS%2FP9Wi1XSjRRzoTLfAQUfgNaZUFrp34K4bidCOodjh1qx2UCEBwSLj%2BOsENok8pI5dgReV4%3D
US
der
471 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1588
iexplore.exe
142.250.185.232:443
www.googletagmanager.com
Google Inc.
US
suspicious
1588
iexplore.exe
2.16.186.16:80
r3.o.lencr.org
Akamai International B.V.
whitelisted
1588
iexplore.exe
46.105.201.240:443
s10.histats.com
OVH SAS
FR
suspicious
1588
iexplore.exe
104.21.89.248:443
www.castfree.me
Cloudflare Inc
US
suspicious
1588
iexplore.exe
142.250.74.195:80
ocsp.pki.goog
Google Inc.
US
whitelisted
1588
iexplore.exe
142.250.185.202:443
ajax.googleapis.com
Google Inc.
US
whitelisted
1588
iexplore.exe
104.18.11.207:443
maxcdn.bootstrapcdn.com
Cloudflare Inc
US
suspicious
1588
iexplore.exe
172.67.166.47:443
www.castfree.me
US
unknown
1588
iexplore.exe
185.233.186.25:443
cricfree.live
suspicious
1588
iexplore.exe
2.16.186.81:80
ctldl.windowsupdate.com
Akamai International B.V.
whitelisted

DNS requests

Domain
IP
Reputation
cricfree.live
  • 185.233.186.25
suspicious
ctldl.windowsupdate.com
  • 2.16.186.81
  • 2.16.186.56
whitelisted
ocsp.comodoca.com
  • 151.139.128.14
whitelisted
cdn.jsdelivr.net
  • 104.16.88.20
  • 104.16.87.20
  • 104.16.85.20
  • 104.16.86.20
  • 104.16.89.20
whitelisted
st.chatango.com
  • 208.93.230.18
  • 208.93.230.16
  • 208.93.230.24
  • 208.93.230.26
  • 208.93.230.22
  • 208.93.230.28
whitelisted
video.your-notice.com
  • 142.91.9.135
whitelisted
superfastcdn.com
  • 172.67.156.47
  • 104.21.48.205
unknown
ocsp.digicert.com
  • 93.184.220.29
whitelisted
cricplay2.xyz
  • 185.233.186.25
malicious
cricfree.io
  • 172.67.198.144
  • 104.21.36.187
unknown

Threats

No threats detected
No debug info