URL:

abcdefghijklmnopqrstuvwxyz.org

Full analysis: https://app.any.run/tasks/a19996f8-12bd-445b-9457-bb1b83e51679
Verdict: Malicious activity
Analysis date: December 01, 2023, 18:53:15
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

F3077D88BE237FE9EA6EEB9CDC6BF440

SHA1:

A84AC29B3E0E45A51A42F876CE37823ED166F8D8

SHA256:

98F96D2B8F9A9624EBC1AA73F7524A700F4D8F604B98C1273596D4ECC1710B95

SSDEEP:

3:u+6LO5SfLDn:u+6LO5Sff

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Reads the computer name

      • wmpnscfg.exe (PID: 2184)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 2184)
    • Application launched itself

      • iexplore.exe (PID: 844)
    • Checks supported languages

      • wmpnscfg.exe (PID: 2184)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
40
Monitored processes
3
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
844"C:\Program Files\Internet Explorer\iexplore.exe" "abcdefghijklmnopqrstuvwxyz.org"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2184"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
3976"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:844 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
Total events
24 005
Read events
23 905
Write events
100
Delete events
0

Modification events

(PID) Process:(844) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
0
(PID) Process:(844) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30847387
(PID) Process:(844) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30847437
(PID) Process:(844) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(844) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(844) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(844) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(844) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(844) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(844) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
0
Suspicious files
92
Text files
160
Unknown types
0

Dropped files

PID
Process
Filename
Type
3976iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\output[1].csstext
MD5:63D8BFCBB3ED6B42E38B98AF9E664832
SHA256:7C7E264F225309ED6D9BC74BE3391828E50E3B15ADD757D8209266EF3F1074A9
3976iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\UNDZSKTU.htmhtml
MD5:E8F3B68C70DB96B81D9900FA65281686
SHA256:D13BF6EA964EC1681DB5610277F4030CD20954FEE52E2E66BAB61E6E1DABCB70
3976iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\css[1].csstext
MD5:2AFF880D3863333A1F4EBFB7DEC5FDD7
SHA256:8D32F30B05EDA61266F7DE77FBAE09047BC5840DFBEA7E6A2951F2B74ECBBE3A
3976iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\superfish[1].csstext
MD5:C86926C2A95676CDC135A939C200F85D
SHA256:D2D8A079896945AEBB8846CDA4FF336CB98BA1A8ED19A18210A8BAD132E1A443
3976iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\genericons[1].csstext
MD5:8604C201CA1B346289D82DAF2B6C91F6
SHA256:4D5679EB4FFE764C49E2FB1386BF3EF04139E7A5A9E867DA46AA1045374D6925
3976iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\superfish-navbar[1].csstext
MD5:AA98D546F35DED7E8B5384F3F28D6518
SHA256:A5CA2CD1D5B3428A3FE198B20AF0764D0BF7A0FAC7BD0E3993EF67B80EB9BF6E
3976iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\1487945772index[1].csstext
MD5:1A75E2D1746B0C8658F142344AB3052D
SHA256:6F63DFC8BCD0DB85B63C5CF4369C3168C1E86C20EC7404AF8AFC37D3AAFC65F5
3976iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\external-tracking.min[1].jstext
MD5:B226DCBE052220A66EE816A359296928
SHA256:5A9DCB270BA38D94FD27A5AE4C6A6D10BB6A25FE0473DF95FE4C405E82801289
3976iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\reset[1].csstext
MD5:974ED0D67A331EBC7F40292D0CA0BE8B
SHA256:8BCBA11B2554A97D5B8849D14537580699F67F5A8051A1A67DDF3BFA6E4F81E0
3976iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\superfish.min[1].jstext
MD5:EA1E327CBBCC3B18C7AAA7BC952971C0
SHA256:A718CBA753FABBD42E5B6AE41E4BD5B7AED2062053F896D254E962B7E9E20A4C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
99
TCP/UDP connections
130
DNS requests
55
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3976
iexplore.exe
GET
200
162.244.93.7:80
http://abcdefghijklmnopqrstuvwxyz.org/wp-content/cache/wpfc-minified/b9f6a84ca7b2cbf5a4d700979ceac3c3/1487945790index.css
unknown
compressed
1.19 Kb
unknown
3976
iexplore.exe
GET
200
142.250.184.202:80
http://fonts.googleapis.com/css?family=PT+Sans%3A400%2C700%2C400italic&subset=latin%2Ccyrillic&ver=3.8.18
unknown
text
214 b
unknown
3976
iexplore.exe
GET
200
142.250.181.226:80
http://pagead2.googlesyndication.com/pagead/js/adsbygoogle.js
unknown
text
61.6 Kb
unknown
3976
iexplore.exe
GET
200
162.244.93.7:80
http://abcdefghijklmnopqrstuvwxyz.org/
unknown
compressed
4.91 Kb
unknown
3976
iexplore.exe
GET
200
162.244.93.7:80
http://abcdefghijklmnopqrstuvwxyz.org/wp-content/plugins/addthis/css/output.css?ver=3.8.18
unknown
text
248 b
unknown
3976
iexplore.exe
GET
308
23.45.238.53:80
http://s7.addthis.com/js/300/addthis_widget.js
unknown
html
171 b
unknown
3976
iexplore.exe
GET
200
162.244.93.7:80
http://abcdefghijklmnopqrstuvwxyz.org/wp-content/themes/alphabet/genericons/genericons.css?ver=3.8.18
unknown
compressed
18.9 Kb
unknown
3976
iexplore.exe
GET
200
162.244.93.7:80
http://abcdefghijklmnopqrstuvwxyz.org/wp-content/themes/alphabet/style.css?ver=3.8.18
unknown
compressed
536 b
unknown
3976
iexplore.exe
GET
200
162.244.93.7:80
http://abcdefghijklmnopqrstuvwxyz.org/wp-content/themes/alphabet/superfish-css/superfish.css?ver=3.8.18
unknown
compressed
1.23 Kb
unknown
3976
iexplore.exe
GET
200
162.244.93.7:80
http://abcdefghijklmnopqrstuvwxyz.org/wp-content/themes/alphabet/superfish-css/superfish-vertical.css?ver=3.8.18
unknown
compressed
479 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3976
iexplore.exe
162.244.93.7:80
abcdefghijklmnopqrstuvwxyz.org
PONYNET
US
unknown
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
2588
svchost.exe
239.255.255.250:1900
whitelisted
3976
iexplore.exe
142.250.184.202:80
fonts.googleapis.com
GOOGLE
US
whitelisted
3976
iexplore.exe
23.45.238.53:80
s7.addthis.com
AKAMAI-AS
DE
unknown
3976
iexplore.exe
142.250.181.226:80
pagead2.googlesyndication.com
GOOGLE
US
whitelisted
3976
iexplore.exe
216.58.212.174:443
www.google-analytics.com
GOOGLE
US
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
3976
iexplore.exe
142.250.181.226:443
pagead2.googlesyndication.com
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
abcdefghijklmnopqrstuvwxyz.org
  • 162.244.93.7
unknown
fonts.googleapis.com
  • 142.250.184.202
whitelisted
pagead2.googlesyndication.com
  • 142.250.181.226
whitelisted
s7.addthis.com
  • 23.45.238.53
whitelisted
www.google-analytics.com
  • 216.58.212.174
whitelisted
fonts.gstatic.com
  • 142.250.185.131
whitelisted
googleads.g.doubleclick.net
  • 172.217.16.194
whitelisted
ctldl.windowsupdate.com
  • 184.24.77.211
  • 184.24.77.175
  • 184.24.77.198
  • 184.24.77.180
  • 184.24.77.199
  • 184.24.77.207
  • 184.24.77.172
  • 184.24.77.210
  • 184.24.77.195
  • 93.184.221.240
whitelisted
ocsp.pki.goog
  • 142.250.184.227
whitelisted
www.googletagmanager.com
  • 142.250.185.168
whitelisted

Threats

No threats detected
No debug info