URL:

https://gamefabrique.com

Full analysis: https://app.any.run/tasks/52d5d3e3-1490-4de1-b942-cdf8cf6228f0
Verdict: Malicious activity
Analysis date: June 12, 2022, 05:36:32
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

776F49F8C74591E829C97D4EF4854895

SHA1:

4CDD0F02A5C8C2549BA7EA55C6C5078ACD681F00

SHA256:

9DFEE4B847E05C3E1753E1EB41C1BE7A995BFC82A106807D65EFEB43AA20DF2D

SSDEEP:

3:N8l0XMUhGT:22XMPT

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops executable file immediately after starts

      • iexplore.exe (PID: 3236)
      • iexplore.exe (PID: 2840)
      • Pokemon Fire Red_zeNhR-1.exe (PID: 2036)
    • Application was dropped or rewritten from another process

      • Pokemon Fire Red_zeNhR-1.exe (PID: 2036)
  • SUSPICIOUS

    • Reads Microsoft Outlook installation path

      • iexplore.exe (PID: 3236)
    • Executable content was dropped or overwritten

      • iexplore.exe (PID: 3236)
      • Pokemon Fire Red_zeNhR-1.exe (PID: 2036)
      • iexplore.exe (PID: 2840)
    • Drops a file with a compile date too recent

      • iexplore.exe (PID: 3236)
      • iexplore.exe (PID: 2840)
      • Pokemon Fire Red_zeNhR-1.exe (PID: 2036)
    • Checks supported languages

      • Pokemon Fire Red_zeNhR-1.exe (PID: 2036)
      • Pokemon Fire Red_zeNhR-1.tmp (PID: 2760)
    • Reads the computer name

      • Pokemon Fire Red_zeNhR-1.tmp (PID: 2760)
  • INFO

    • Application launched itself

      • iexplore.exe (PID: 2840)
    • Checks supported languages

      • iexplore.exe (PID: 2840)
      • iexplore.exe (PID: 3236)
    • Reads the computer name

      • iexplore.exe (PID: 2840)
      • iexplore.exe (PID: 3236)
    • Changes internet zones settings

      • iexplore.exe (PID: 2840)
    • Checks Windows Trust Settings

      • iexplore.exe (PID: 3236)
      • iexplore.exe (PID: 2840)
    • Reads settings of System Certificates

      • iexplore.exe (PID: 3236)
      • iexplore.exe (PID: 2840)
    • Creates files in the user directory

      • iexplore.exe (PID: 3236)
    • Reads internet explorer settings

      • iexplore.exe (PID: 3236)
    • Adds / modifies Windows certificates

      • iexplore.exe (PID: 2840)
    • Changes settings of System certificates

      • iexplore.exe (PID: 2840)
    • Modifies the phishing filter of IE

      • iexplore.exe (PID: 2840)
    • Application was dropped or rewritten from another process

      • Pokemon Fire Red_zeNhR-1.tmp (PID: 2760)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
38
Monitored processes
4
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe pokemon fire red_zenhr-1.exe pokemon fire red_zenhr-1.tmp no specs

Process information

PID
CMD
Path
Indicators
Parent process
2036"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\Pokemon Fire Red_zeNhR-1.exe" C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\Pokemon Fire Red_zeNhR-1.exe
iexplore.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
AKSIUM AUDIT, OOO Download Manager
Exit code:
0
Version:
3.334.90
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\6z2bcoul\pokemon fire red_zenhr-1.exe
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\shlwapi.dll
2760"C:\Users\admin\AppData\Local\Temp\is-GJTFL.tmp\Pokemon Fire Red_zeNhR-1.tmp" /SL5="$501E2,13628241,797696,C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\Pokemon Fire Red_zeNhR-1.exe" C:\Users\admin\AppData\Local\Temp\is-GJTFL.tmp\Pokemon Fire Red_zeNhR-1.tmpPokemon Fire Red_zeNhR-1.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\appdata\local\temp\is-gjtfl.tmp\pokemon fire red_zenhr-1.tmp
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2840"C:\Program Files\Internet Explorer\iexplore.exe" "https://gamefabrique.com"C:\Program Files\Internet Explorer\iexplore.exe
Explorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
3236"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2840 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
Total events
13 106
Read events
12 960
Write events
138
Delete events
8

Modification events

(PID) Process:(2840) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
1
(PID) Process:(2840) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchLowDateTime
Value:
(PID) Process:(2840) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30965278
(PID) Process:(2840) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateLowDateTime
Value:
(PID) Process:(2840) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30965278
(PID) Process:(2840) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(2840) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(2840) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(2840) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(2840) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
4
Suspicious files
18
Text files
157
Unknown types
15

Dropped files

PID
Process
Filename
Type
2840iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6BADA8974A10C4BD62CC921D13E43B18_711ED44619924BA6DC33E69F97E7FF63der
MD5:2E2994B4DA72235815B11DE21A431A92
SHA256:5E1EB70EEBF0DB9E7B826878BFD0DC5A0E4D55D949B9E848C5D759479D88556F
3236iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\07CEF2F654E3ED6050FFC9B6EB844250_3431D4C539FB2CFCB781821E9902850Dder
MD5:A26978D9F2615325FB2B045C080C9657
SHA256:F8539E0108A07604E84E1981C07A6DE12589661720624376F0A6DC3A3616535E
3236iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\1D39E0AFEA82782B1A14DA16A97A132Abinary
MD5:07560F0D7067D904571CEE4A0C4A5C2F
SHA256:8949A598D8689EA6EA504F51E6FFAAE6D06D5E1028F1A930470782C51112A387
3236iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\07CEF2F654E3ED6050FFC9B6EB844250_3431D4C539FB2CFCB781821E9902850Dbinary
MD5:BF89BE8B029F930414868D4C0E00E5A3
SHA256:E37657F6E32444FAE752B181357BF37C6FB56AA230B8AB6A89A86A63187CD98F
3236iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B2FAF7692FD9FFBD64EDE317E42334BA_D7393C8F62BDE4D4CB606228BC7A711Eder
MD5:2EAC94298F927B399D52F5180A6B1BB8
SHA256:D683738C25F5D44D35C2458C7893DC5B6A98861158FC40493CE3621EEB172A27
3236iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\1D39E0AFEA82782B1A14DA16A97A132Ader
MD5:5AF3930D3E78408140A861924ED9ECFC
SHA256:F9531C27AA433742AF581F9FE42EE1FD343E2EB0F85C81EEF33985529AB2AA75
2840iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:C0C5FBCCC38C3B047A9922185C40B33B
SHA256:5EEEACA61A509BC2094D661B7813D909682E7B6CF6FF15DA878DE0E66426B5C3
3236iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B2FAF7692FD9FFBD64EDE317E42334BA_D7393C8F62BDE4D4CB606228BC7A711Ebinary
MD5:8B4C6C435272C9D77BC8E43C0F9B5A3D
SHA256:DA0E076A47208AB5DF777F888BA391D859F86B217F1F9404E86E2AE1CCE4D312
2840iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157compressed
MD5:F7DCB24540769805E5BB30D193944DCE
SHA256:6B88C6AC55BBD6FEA0EBE5A760D1AD2CFCE251C59D0151A1400701CB927E36EA
2840iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6BADA8974A10C4BD62CC921D13E43B18_711ED44619924BA6DC33E69F97E7FF63binary
MD5:5D1DE7BB09F1B36D92D98ED257F9D260
SHA256:0DF2517AD22D7AF0009EBCD1DF7C74A468AA1C75AE4DC9991BF83BEF2BADDCA5
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
15
TCP/UDP connections
53
DNS requests
21
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2840
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA8Ull8gIGmZT9XHrHiJQeI%3D
US
der
1.47 Kb
whitelisted
3236
iexplore.exe
GET
200
104.18.32.68:80
http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEDlyRDr5IrdR19NsEN0xNZU%3D
US
der
471 b
whitelisted
3236
iexplore.exe
GET
200
172.64.155.188:80
http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEH1bUSa0droR23QWC7xTDac%3D
US
der
727 b
whitelisted
3236
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEAo3h2ReX7SMIk79G%2B0UDDw%3D
US
der
1.47 Kb
whitelisted
2840
iexplore.exe
GET
200
23.216.77.69:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?b751281f24805fcb
US
compressed
4.70 Kb
whitelisted
3236
iexplore.exe
GET
200
104.18.32.68:80
http://ocsp.sectigo.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRDC9IOTxN6GmyRjyTl2n4yTUczyAQUjYxexFStiuF36Zv5mwXhuAGNYeECEFvpIdipAmSWNYK8bGOA3aQ%3D
US
der
471 b
whitelisted
3236
iexplore.exe
GET
200
142.250.184.195:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
US
der
1.41 Kb
whitelisted
3236
iexplore.exe
GET
200
142.250.184.195:80
http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFNZazTHGPUBUGY%3D
US
der
724 b
whitelisted
2840
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
der
471 b
whitelisted
3236
iexplore.exe
GET
200
142.250.184.195:80
http://ocsp.pki.goog/gts1c3/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEQDi15VM0BYOewq4TUp6IjEK
US
der
472 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3236
iexplore.exe
104.18.32.68:80
ocsp.comodoca.com
Cloudflare Inc
US
suspicious
3236
iexplore.exe
172.64.155.188:80
ocsp.comodoca.com
US
suspicious
3236
iexplore.exe
89.248.171.137:443
gamefabrique.com
Quasi Networks LTD.
SC
suspicious
3236
iexplore.exe
142.250.186.142:443
www.google-analytics.com
Google Inc.
US
whitelisted
142.250.186.142:443
www.google-analytics.com
Google Inc.
US
whitelisted
3236
iexplore.exe
104.18.10.207:443
stackpath.bootstrapcdn.com
Cloudflare Inc
US
suspicious
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
3236
iexplore.exe
142.250.184.195:80
ocsp.pki.goog
Google Inc.
US
whitelisted
2840
iexplore.exe
13.107.21.200:443
www.bing.com
Microsoft Corporation
US
whitelisted
3236
iexplore.exe
74.125.140.157:443
stats.g.doubleclick.net
Google Inc.
US
whitelisted

DNS requests

Domain
IP
Reputation
gamefabrique.com
  • 89.248.171.137
whitelisted
api.bing.com
  • 13.107.5.80
whitelisted
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
ctldl.windowsupdate.com
  • 23.216.77.69
  • 23.216.77.80
whitelisted
ocsp.digicert.com
  • 93.184.220.29
whitelisted
ocsp.comodoca.com
  • 104.18.32.68
  • 172.64.155.188
whitelisted
ocsp.usertrust.com
  • 172.64.155.188
  • 104.18.32.68
whitelisted
ocsp.sectigo.com
  • 104.18.32.68
  • 172.64.155.188
whitelisted
ajax.googleapis.com
  • 172.217.16.138
whitelisted
stackpath.bootstrapcdn.com
  • 104.18.10.207
  • 104.18.11.207
whitelisted

Threats

No threats detected
No debug info