URL:

free-porn.com

Full analysis: https://app.any.run/tasks/16d8c4e6-e6fc-4fc9-9054-056499ef243e
Verdict: Malicious activity
Analysis date: January 20, 2024, 01:56:36
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
opendir
Indicators:
MD5:

C441F3DC6121A5D40996B1C49F1DD38C

SHA1:

9F9EE2C3FCDE5F69E8732A89AA76D15FB2524D75

SHA256:

9730CEB21875B35F8D4B980E4FBEAFED60B6A57B37854093237919C1C1409A45

SSDEEP:

3:5IRT:AT

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Application launched itself

      • iexplore.exe (PID: 1404)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
37
Monitored processes
3
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe iexplore.exe

Process information

PID
CMD
Path
Indicators
Parent process
1404"C:\Program Files\Internet Explorer\iexplore.exe" "free-porn.com"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2080"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:1404 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2308"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:1404 CREDAT:3609865 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
Total events
25 073
Read events
24 989
Write events
78
Delete events
6

Modification events

(PID) Process:(1404) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
0
(PID) Process:(1404) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30847387
(PID) Process:(1404) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30847437
(PID) Process:(1404) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(1404) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(1404) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(1404) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(1404) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(1404) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(1404) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
0
Suspicious files
43
Text files
104
Unknown types
0

Dropped files

PID
Process
Filename
Type
2080iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\main[1].csstext
MD5:D0E945A0D39F1F3E85BE193E39CCBAD7
SHA256:E2ECF1777D8AFD862235CAEE75D72476B265832D9F6D020BF9DE42312C669BBF
2080iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\bg-commit1[1].jpgimage
MD5:25FAD649FAD13B2D9A25237A22D9CC29
SHA256:3476779EA97D05C5F07F25F461E3359481F82B8842F719245BB878F622893F99
2080iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\access_button[1].pngimage
MD5:0E870E4026BF6F8D7C0A98192DDEBC5B
SHA256:D8B04F14E1D3E96D155596AF61D74F273C1104D7083EF74EA89A63EE380C4F24
2080iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\downloadpass_lg[1].jpgimage
MD5:00A8A9D60F6C9A03686843F3F4813E4E
SHA256:22107639653F9342824EDF790027EDC05DC6F41C445683BDDD2F307C00334F20
2080iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\add_button[1].gifimage
MD5:FF0F211F81EE17C2C0DDFCB140B9396A
SHA256:C8F1D4F7153E0384E4CDB4CB6A3A648AB09AC9C41F407FBF8BD7E5EB84663C8B
2080iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\CO2ZQRAV.htmhtml
MD5:64DF8AF4C2F97E3B572D816BC4002EFF
SHA256:4C720C29D56F30B00A3C32AFEAE03502325E5E45EFEE67ED2DF9DF5AC286FE2A
2080iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\megasitepass_lg[1].jpgimage
MD5:DD765B6895A0F16A92F73EEDD14B3E51
SHA256:474FD249DBA759BCA2504C7AB0ACA26F4B0FB0FDC357B5DA5E1135E5F43A05BE
2080iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\5[1].gifimage
MD5:822B3BE405E81258FBEF4EE2C9F00C0C
SHA256:87C9BDA991525C3E78A6206584541E705C561743D90DF2EEE0C554B4F120F233
2080iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\ethnicpass_lg[1].jpgimage
MD5:A4AA1454FFC5FBFF855DD8695975181B
SHA256:F1EFD7CA8E8CE225BE704F4AAA2897CEE06EB9CF1008ABC9128F1A84E19004AC
2080iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\sexbook[1].htmhtml
MD5:1D7E105F6929FA04F2EC0E8CC2BF18D3
SHA256:9E5FE1FC9FB5E65DBB0AF3BC4FCD3443A2DBF812BCD75F2BF7B17C3D7524B8FE
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
85
TCP/UDP connections
65
DNS requests
28
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2080
iexplore.exe
GET
200
66.115.166.42:80
http://free-porn.com/
unknown
html
34.7 Kb
unknown
2080
iexplore.exe
GET
200
66.115.166.42:80
http://free-porn.com/images/add_button.gif
unknown
image
1.03 Kb
unknown
2080
iexplore.exe
GET
301
13.49.232.30:80
http://www.freetube.com/sexbook.js
unknown
html
169 b
unknown
2080
iexplore.exe
GET
200
66.115.166.42:80
http://free-porn.com/images/5.gif
unknown
image
326 b
unknown
2080
iexplore.exe
GET
200
66.115.166.42:80
http://free-porn.com/main.css
unknown
text
4.24 Kb
unknown
2080
iexplore.exe
GET
200
66.115.166.42:80
http://free-porn.com/images/bg-commit1.jpg
unknown
image
5.54 Kb
unknown
2080
iexplore.exe
GET
200
66.115.166.42:80
http://free-porn.com/images/thumbs/downloadpass_lg.jpg
unknown
image
16.1 Kb
unknown
2080
iexplore.exe
GET
200
66.115.166.42:80
http://free-porn.com/images/bg-commit2.jpg
unknown
image
35.6 Kb
unknown
2080
iexplore.exe
GET
200
66.115.166.42:80
http://free-porn.com/images/thumbs/ethnicpass_lg.jpg
unknown
image
16.8 Kb
unknown
2080
iexplore.exe
GET
200
66.115.166.42:80
http://free-porn.com/images/access_button.png
unknown
image
9.27 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
2080
iexplore.exe
66.115.166.42:80
free-porn.com
PERFORMIVE
US
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
2080
iexplore.exe
13.49.232.30:80
www.freetube.com
AMAZON-02
SE
unknown
2080
iexplore.exe
52.210.20.76:443
lushchat.com
AMAZON-02
IE
shared
2080
iexplore.exe
93.184.221.240:80
ctldl.windowsupdate.com
EDGECAST
GB
whitelisted
2080
iexplore.exe
207.246.147.249:80
www.camlive.com
ATG-11608
US
unknown
2080
iexplore.exe
207.246.147.249:443
www.camlive.com
ATG-11608
US
unknown
2080
iexplore.exe
23.192.153.142:80
x1.c.lencr.org
AKAMAI-AS
GB
unknown

DNS requests

Domain
IP
Reputation
free-porn.com
  • 66.115.166.42
malicious
www.freetube.com
  • 13.49.232.30
unknown
www.camlive.com
  • 207.246.147.249
  • 207.246.147.192
  • 207.246.147.191
  • 207.246.147.250
unknown
lushchat.com
  • 52.210.20.76
unknown
ctldl.windowsupdate.com
  • 93.184.221.240
whitelisted
x1.c.lencr.org
  • 23.192.153.142
whitelisted
r3.o.lencr.org
  • 2.16.241.15
  • 2.16.241.8
shared
textad.xxxmatch.com
  • 104.18.41.205
  • 172.64.146.51
unknown
www.google-analytics.com
  • 142.250.184.206
whitelisted
ocsp.pki.goog
  • 142.250.74.195
whitelisted

Threats

No threats detected
No debug info