URL:

abcdefghijklmnopqrstuvwxyz.org

Full analysis: https://app.any.run/tasks/a19996f8-12bd-445b-9457-bb1b83e51679
Verdict: Malicious activity
Analysis date: December 01, 2023, 18:53:15
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

F3077D88BE237FE9EA6EEB9CDC6BF440

SHA1:

A84AC29B3E0E45A51A42F876CE37823ED166F8D8

SHA256:

98F96D2B8F9A9624EBC1AA73F7524A700F4D8F604B98C1273596D4ECC1710B95

SSDEEP:

3:u+6LO5SfLDn:u+6LO5Sff

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Manual execution by a user

      • wmpnscfg.exe (PID: 2184)
    • Application launched itself

      • iexplore.exe (PID: 844)
    • Reads the computer name

      • wmpnscfg.exe (PID: 2184)
    • Checks supported languages

      • wmpnscfg.exe (PID: 2184)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
40
Monitored processes
3
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
844"C:\Program Files\Internet Explorer\iexplore.exe" "abcdefghijklmnopqrstuvwxyz.org"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2184"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
3976"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:844 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
Total events
24 005
Read events
23 905
Write events
100
Delete events
0

Modification events

(PID) Process:(844) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
0
(PID) Process:(844) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30847387
(PID) Process:(844) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30847437
(PID) Process:(844) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(844) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(844) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(844) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(844) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(844) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(844) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
0
Suspicious files
92
Text files
160
Unknown types
0

Dropped files

PID
Process
Filename
Type
3976iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\style[1].csstext
MD5:9DEA3A3DCF373CF8BAA0AC530C7E8A13
SHA256:00B4782F2B63A97EAD1F693C185996D6B63F5C54A2A035056D6A37630BA20B93
3976iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\UNDZSKTU.htmhtml
MD5:E8F3B68C70DB96B81D9900FA65281686
SHA256:D13BF6EA964EC1681DB5610277F4030CD20954FEE52E2E66BAB61E6E1DABCB70
3976iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\jquery-colorbox-wrapper-min[1].jstext
MD5:76E13B5F781F026C066B1DA979C8EB4A
SHA256:BEEC43018ECA5BF4EA84EAA15D6EDF0A2FBABD7A581F6A632714C902CD0C76F4
3976iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\superfish[1].csstext
MD5:C86926C2A95676CDC135A939C200F85D
SHA256:D2D8A079896945AEBB8846CDA4FF336CB98BA1A8ED19A18210A8BAD132E1A443
3976iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\genericons[1].csstext
MD5:8604C201CA1B346289D82DAF2B6C91F6
SHA256:4D5679EB4FFE764C49E2FB1386BF3EF04139E7A5A9E867DA46AA1045374D6925
3976iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\1487945772index[1].csstext
MD5:84EB3F3C0279B9863E89F357A2266EB5
SHA256:0416D7F2B9DF103A2B726E3E990D8A834FC5082E25FC396D2178B49DB4E27CA1
3976iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\reset[1].csstext
MD5:974ED0D67A331EBC7F40292D0CA0BE8B
SHA256:8BCBA11B2554A97D5B8849D14537580699F67F5A8051A1A67DDF3BFA6E4F81E0
3976iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\external-tracking.min[1].jstext
MD5:B226DCBE052220A66EE816A359296928
SHA256:5A9DCB270BA38D94FD27A5AE4C6A6D10BB6A25FE0473DF95FE4C405E82801289
3976iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\typal[1].csstext
MD5:B42834E841699BA96229D97C39CCA8BA
SHA256:B335AE2772DAEAECA1621E3A0776F6DE96015C8034E0B209ACDB4E7D81209804
3976iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\jquery.colorbox-min[1].jstext
MD5:797B440BF73457B7D0708300CECE4D1B
SHA256:2DB48B5C5707969CA6AF2D6CDA2259D58885439BC23028664DD266292BC4D9E7
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
99
TCP/UDP connections
130
DNS requests
55
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3976
iexplore.exe
GET
200
162.244.93.7:80
http://abcdefghijklmnopqrstuvwxyz.org/
unknown
compressed
4.91 Kb
unknown
3976
iexplore.exe
GET
200
162.244.93.7:80
http://abcdefghijklmnopqrstuvwxyz.org/wp-content/cache/wpfc-minified/b9f6a84ca7b2cbf5a4d700979ceac3c3/1487945790index.css
unknown
compressed
1.19 Kb
unknown
3976
iexplore.exe
GET
200
142.250.184.202:80
http://fonts.googleapis.com/css?family=PT+Sans%3A400%2C700%2C400italic&subset=latin%2Ccyrillic&ver=3.8.18
unknown
text
214 b
unknown
3976
iexplore.exe
GET
200
162.244.93.7:80
http://abcdefghijklmnopqrstuvwxyz.org/wp-content/plugins/addthis/css/output.css?ver=3.8.18
unknown
text
248 b
unknown
3976
iexplore.exe
GET
308
23.45.238.53:80
http://s7.addthis.com/js/300/addthis_widget.js
unknown
html
171 b
unknown
3976
iexplore.exe
GET
200
142.250.181.226:80
http://pagead2.googlesyndication.com/pagead/js/adsbygoogle.js
unknown
text
61.6 Kb
unknown
3976
iexplore.exe
GET
200
162.244.93.7:80
http://abcdefghijklmnopqrstuvwxyz.org/wp-content/themes/alphabet/style.css?ver=3.8.18
unknown
compressed
536 b
unknown
3976
iexplore.exe
GET
200
162.244.93.7:80
http://abcdefghijklmnopqrstuvwxyz.org/wp-content/themes/alphabet/genericons/genericons.css?ver=3.8.18
unknown
compressed
18.9 Kb
unknown
3976
iexplore.exe
GET
200
162.244.93.7:80
http://abcdefghijklmnopqrstuvwxyz.org/wp-content/themes/alphabet/superfish-css/superfish.css?ver=3.8.18
unknown
compressed
1.23 Kb
unknown
3976
iexplore.exe
GET
200
162.244.93.7:80
http://abcdefghijklmnopqrstuvwxyz.org/wp-content/themes/alphabet/superfish-css/superfish-vertical.css?ver=3.8.18
unknown
compressed
479 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3976
iexplore.exe
162.244.93.7:80
abcdefghijklmnopqrstuvwxyz.org
PONYNET
US
unknown
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
2588
svchost.exe
239.255.255.250:1900
whitelisted
3976
iexplore.exe
142.250.184.202:80
fonts.googleapis.com
GOOGLE
US
whitelisted
3976
iexplore.exe
23.45.238.53:80
s7.addthis.com
AKAMAI-AS
DE
unknown
3976
iexplore.exe
142.250.181.226:80
pagead2.googlesyndication.com
GOOGLE
US
whitelisted
3976
iexplore.exe
216.58.212.174:443
www.google-analytics.com
GOOGLE
US
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
3976
iexplore.exe
142.250.181.226:443
pagead2.googlesyndication.com
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
abcdefghijklmnopqrstuvwxyz.org
  • 162.244.93.7
unknown
fonts.googleapis.com
  • 142.250.184.202
whitelisted
pagead2.googlesyndication.com
  • 142.250.181.226
whitelisted
s7.addthis.com
  • 23.45.238.53
whitelisted
www.google-analytics.com
  • 216.58.212.174
whitelisted
fonts.gstatic.com
  • 142.250.185.131
whitelisted
googleads.g.doubleclick.net
  • 172.217.16.194
whitelisted
ctldl.windowsupdate.com
  • 184.24.77.211
  • 184.24.77.175
  • 184.24.77.198
  • 184.24.77.180
  • 184.24.77.199
  • 184.24.77.207
  • 184.24.77.172
  • 184.24.77.210
  • 184.24.77.195
  • 93.184.221.240
whitelisted
ocsp.pki.goog
  • 142.250.184.227
whitelisted
www.googletagmanager.com
  • 142.250.185.168
whitelisted

Threats

No threats detected
No debug info