| URL: | free-porn.com |
| Full analysis: | https://app.any.run/tasks/16d8c4e6-e6fc-4fc9-9054-056499ef243e |
| Verdict: | Malicious activity |
| Analysis date: | January 20, 2024, 01:56:36 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MD5: | C441F3DC6121A5D40996B1C49F1DD38C |
| SHA1: | 9F9EE2C3FCDE5F69E8732A89AA76D15FB2524D75 |
| SHA256: | 9730CEB21875B35F8D4B980E4FBEAFED60B6A57B37854093237919C1C1409A45 |
| SSDEEP: | 3:5IRT:AT |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1404 | "C:\Program Files\Internet Explorer\iexplore.exe" "free-porn.com" | C:\Program Files\Internet Explorer\iexplore.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| 2080 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:1404 CREDAT:267521 /prefetch:2 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| 2308 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:1404 CREDAT:3609865 /prefetch:2 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| (PID) Process: | (1404) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPDaysSinceLastAutoMigration |
Value: 0 | |||
| (PID) Process: | (1404) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPLastLaunchHighDateTime |
Value: 30847387 | |||
| (PID) Process: | (1404) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager |
| Operation: | write | Name: | NextCheckForUpdateHighDateTime |
Value: 30847437 | |||
| (PID) Process: | (1404) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (1404) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (1404) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main |
| Operation: | write | Name: | CompatibilityFlags |
Value: 0 | |||
| (PID) Process: | (1404) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (1404) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (1404) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (1404) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2080 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\main[1].css | text | |
MD5:D0E945A0D39F1F3E85BE193E39CCBAD7 | SHA256:E2ECF1777D8AFD862235CAEE75D72476B265832D9F6D020BF9DE42312C669BBF | |||
| 2080 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\bg-commit1[1].jpg | image | |
MD5:25FAD649FAD13B2D9A25237A22D9CC29 | SHA256:3476779EA97D05C5F07F25F461E3359481F82B8842F719245BB878F622893F99 | |||
| 2080 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\access_button[1].png | image | |
MD5:0E870E4026BF6F8D7C0A98192DDEBC5B | SHA256:D8B04F14E1D3E96D155596AF61D74F273C1104D7083EF74EA89A63EE380C4F24 | |||
| 2080 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\downloadpass_lg[1].jpg | image | |
MD5:00A8A9D60F6C9A03686843F3F4813E4E | SHA256:22107639653F9342824EDF790027EDC05DC6F41C445683BDDD2F307C00334F20 | |||
| 2080 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\add_button[1].gif | image | |
MD5:FF0F211F81EE17C2C0DDFCB140B9396A | SHA256:C8F1D4F7153E0384E4CDB4CB6A3A648AB09AC9C41F407FBF8BD7E5EB84663C8B | |||
| 2080 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\CO2ZQRAV.htm | html | |
MD5:64DF8AF4C2F97E3B572D816BC4002EFF | SHA256:4C720C29D56F30B00A3C32AFEAE03502325E5E45EFEE67ED2DF9DF5AC286FE2A | |||
| 2080 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\megasitepass_lg[1].jpg | image | |
MD5:DD765B6895A0F16A92F73EEDD14B3E51 | SHA256:474FD249DBA759BCA2504C7AB0ACA26F4B0FB0FDC357B5DA5E1135E5F43A05BE | |||
| 2080 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\5[1].gif | image | |
MD5:822B3BE405E81258FBEF4EE2C9F00C0C | SHA256:87C9BDA991525C3E78A6206584541E705C561743D90DF2EEE0C554B4F120F233 | |||
| 2080 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\ethnicpass_lg[1].jpg | image | |
MD5:A4AA1454FFC5FBFF855DD8695975181B | SHA256:F1EFD7CA8E8CE225BE704F4AAA2897CEE06EB9CF1008ABC9128F1A84E19004AC | |||
| 2080 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\sexbook[1].htm | html | |
MD5:1D7E105F6929FA04F2EC0E8CC2BF18D3 | SHA256:9E5FE1FC9FB5E65DBB0AF3BC4FCD3443A2DBF812BCD75F2BF7B17C3D7524B8FE | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2080 | iexplore.exe | GET | 200 | 66.115.166.42:80 | http://free-porn.com/ | unknown | html | 34.7 Kb | unknown |
2080 | iexplore.exe | GET | 200 | 66.115.166.42:80 | http://free-porn.com/images/add_button.gif | unknown | image | 1.03 Kb | unknown |
2080 | iexplore.exe | GET | 301 | 13.49.232.30:80 | http://www.freetube.com/sexbook.js | unknown | html | 169 b | unknown |
2080 | iexplore.exe | GET | 200 | 66.115.166.42:80 | http://free-porn.com/images/5.gif | unknown | image | 326 b | unknown |
2080 | iexplore.exe | GET | 200 | 66.115.166.42:80 | http://free-porn.com/main.css | unknown | text | 4.24 Kb | unknown |
2080 | iexplore.exe | GET | 200 | 66.115.166.42:80 | http://free-porn.com/images/bg-commit1.jpg | unknown | image | 5.54 Kb | unknown |
2080 | iexplore.exe | GET | 200 | 66.115.166.42:80 | http://free-porn.com/images/thumbs/downloadpass_lg.jpg | unknown | image | 16.1 Kb | unknown |
2080 | iexplore.exe | GET | 200 | 66.115.166.42:80 | http://free-porn.com/images/bg-commit2.jpg | unknown | image | 35.6 Kb | unknown |
2080 | iexplore.exe | GET | 200 | 66.115.166.42:80 | http://free-porn.com/images/thumbs/ethnicpass_lg.jpg | unknown | image | 16.8 Kb | unknown |
2080 | iexplore.exe | GET | 200 | 66.115.166.42:80 | http://free-porn.com/images/access_button.png | unknown | image | 9.27 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2080 | iexplore.exe | 66.115.166.42:80 | free-porn.com | PERFORMIVE | US | unknown |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2080 | iexplore.exe | 13.49.232.30:80 | www.freetube.com | AMAZON-02 | SE | unknown |
2080 | iexplore.exe | 52.210.20.76:443 | lushchat.com | AMAZON-02 | IE | shared |
2080 | iexplore.exe | 93.184.221.240:80 | ctldl.windowsupdate.com | EDGECAST | GB | whitelisted |
2080 | iexplore.exe | 207.246.147.249:80 | www.camlive.com | ATG-11608 | US | unknown |
2080 | iexplore.exe | 207.246.147.249:443 | www.camlive.com | ATG-11608 | US | unknown |
2080 | iexplore.exe | 23.192.153.142:80 | x1.c.lencr.org | AKAMAI-AS | GB | unknown |
Domain | IP | Reputation |
|---|---|---|
free-porn.com |
| malicious |
www.freetube.com |
| unknown |
www.camlive.com |
| unknown |
lushchat.com |
| unknown |
ctldl.windowsupdate.com |
| whitelisted |
x1.c.lencr.org |
| whitelisted |
r3.o.lencr.org |
| shared |
textad.xxxmatch.com |
| unknown |
www.google-analytics.com |
| whitelisted |
ocsp.pki.goog |
| whitelisted |