URL:

adavanced-ip-scaner.com

Full analysis: https://app.any.run/tasks/6bee3ebc-e901-44dd-84da-4108bd1bbb05
Verdict: Malicious activity
Analysis date: November 23, 2023, 20:25:31
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

6F5C7DE0D4DE65187898CA52F6829763

SHA1:

855F629DA90DB127DC5C752FE4C75D2458B8AB47

SHA256:

9FB7C9BCC35E54C3426D41CA9E9C50CB546B904BB851694E3ABF5310BCB9F154

SSDEEP:

3:oE2GA5IWHYdI:oE2G3W4K

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Checks supported languages

      • wmpnscfg.exe (PID: 3752)
    • Application launched itself

      • iexplore.exe (PID: 3428)
    • Reads the computer name

      • wmpnscfg.exe (PID: 3752)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 3752)
    • Reads the machine GUID from the registry

      • wmpnscfg.exe (PID: 3752)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
38
Monitored processes
3
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3216"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3428 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
3428"C:\Program Files\Internet Explorer\iexplore.exe" "adavanced-ip-scaner.com"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
3752"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ole32.dll
Total events
19 110
Read events
19 042
Write events
63
Delete events
5

Modification events

(PID) Process:(3428) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
0
(PID) Process:(3428) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30847387
(PID) Process:(3428) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30847437
(PID) Process:(3428) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3428) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3428) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(3428) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3428) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3428) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3428) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
0
Suspicious files
23
Text files
28
Unknown types
0

Dropped files

PID
Process
Filename
Type
3216iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\it_pro_preferred_light_horizontal[1].pngimage
MD5:D65EE850BE7D6B3AD77527549716C950
SHA256:3EFC93ED30D1A9DC1DE6A97B150AF24178C9FB39A3A4A8C1238CD873F2E63432
3216iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\styles[1].csstext
MD5:EE16B415E4AA26915BFAA1DF888C4DC9
SHA256:7B8A4564B7FAC348829EB37FC0D7A885C795450402F1209291F315453783E914
3216iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\jquery.min[1].jstext
MD5:05E51B1DB558320F1939F9789CCF5C8F
SHA256:702B9E051E82B32038FFDB33A4F7EB5F7B38F4CF6F514E4182D8898F4EB0B7FB
3216iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\color.js[1].jstext
MD5:65916995220568CC65E4EA6CC15040B5
SHA256:4AA13066B75F51A6C876F6A79CA177BC18165E6DB2FB9F45DE09D197F66A6807
3216iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\jquery.min.js[1].jstext
MD5:05E51B1DB558320F1939F9789CCF5C8F
SHA256:702B9E051E82B32038FFDB33A4F7EB5F7B38F4CF6F514E4182D8898F4EB0B7FB
3216iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\css[1].txttext
MD5:62600796A34616876FBC42189343F891
SHA256:0CB2602F766E34B3A1CFE4AEC0ACE43D8D8197ABB402FBB325A2C7820F99C5D2
3216iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\main[1].pngimage
MD5:122B67F4CC668535365395D8FAE7835A
SHA256:6ABA5D99522AB25C810C5D2F3B548C410E34570909EF3FD8137B4D9F1C37508F
3216iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\main.js[1].jstext
MD5:5A6616725DBF004BF36FAC584F8DC5C2
SHA256:3335D313057D6276A4393D1B8FCDA03BEC87A8DB03FDC6DD9776DC4750A59CAD
3216iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\ERQE86U7.txttext
MD5:795AC0AEA44CA45C3B5ACC36B739D28A
SHA256:399B5D3F8A01595182F6CE7EBCED3707A58FBFED7B123A4CBE7559FDF9CCD3E7
3216iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\modal.js[1].jstext
MD5:62327FCA49D1A54A6CFD2CB7ED1E72B1
SHA256:0587ADFABA0F9729E1DA02671D91063C35A88771745008F64368B317C3B42B45
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
34
TCP/UDP connections
41
DNS requests
16
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3216
iexplore.exe
GET
200
185.11.61.65:80
http://adavanced-ip-scaner.com/
unknown
html
4.02 Kb
3216
iexplore.exe
GET
200
185.11.61.65:80
http://adavanced-ip-scaner.com/index_files/css
unknown
text
729 b
3216
iexplore.exe
GET
200
185.11.61.65:80
http://adavanced-ip-scaner.com/index_files/styles.css
unknown
text
2.23 Kb
3216
iexplore.exe
GET
200
185.11.61.65:80
http://adavanced-ip-scaner.com/index_files/js
unknown
text
271 Kb
3216
iexplore.exe
GET
200
185.11.61.65:80
http://adavanced-ip-scaner.com/index_files/jquery.min.js.%D0%91%D0%B5%D0%B7%20%D0%BD%D0%B0%D0%B7%D0%B2%D0%B0%D0%BD%D0%B8%D1%8F
unknown
text
29.5 Kb
3216
iexplore.exe
GET
200
185.11.61.65:80
http://adavanced-ip-scaner.com/index_files/main.png
unknown
image
22.7 Kb
3216
iexplore.exe
GET
200
185.11.61.65:80
http://adavanced-ip-scaner.com/index_files/it_pro_preferred_light_horizontal.png
unknown
image
9.14 Kb
3216
iexplore.exe
GET
200
185.11.61.65:80
http://adavanced-ip-scaner.com/index_files/color.js.%D0%91%D0%B5%D0%B7%20%D0%BD%D0%B0%D0%B7%D0%B2%D0%B0%D0%BD%D0%B8%D1%8F
unknown
text
576 b
3216
iexplore.exe
GET
200
185.11.61.65:80
http://adavanced-ip-scaner.com/index_files/modal.js.%D0%91%D0%B5%D0%B7%20%D0%BD%D0%B0%D0%B7%D0%B2%D0%B0%D0%BD%D0%B8%D1%8F
unknown
text
1.16 Kb
3216
iexplore.exe
GET
200
185.11.61.65:80
http://adavanced-ip-scaner.com/index_files/main.js.%D0%91%D0%B5%D0%B7%20%D0%BD%D0%B0%D0%B7%D0%B2%D0%B0%D0%BD%D0%B8%D1%8F
unknown
text
264 b
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
unknown
224.0.0.252:5355
unknown
3216
iexplore.exe
185.11.61.65:80
adavanced-ip-scaner.com
Chang Way Technologies Co. Limited
RU
unknown
3216
iexplore.exe
172.217.16.202:80
ajax.googleapis.com
GOOGLE
US
unknown
3216
iexplore.exe
188.40.30.100:443
www.advanced-ip-scanner.com
Hetzner Online GmbH
DE
unknown
4
System
192.168.100.255:138
unknown
3216
iexplore.exe
172.217.16.142:443
www.google-analytics.com
GOOGLE
US
unknown
2588
svchost.exe
239.255.255.250:1900
unknown
3216
iexplore.exe
87.248.205.0:80
ctldl.windowsupdate.com
LLNW
US
unknown
3216
iexplore.exe
67.26.81.254:80
ctldl.windowsupdate.com
LEVEL3
US
unknown

DNS requests

Domain
IP
Reputation
adavanced-ip-scaner.com
  • 185.11.61.65
unknown
ajax.googleapis.com
  • 172.217.16.202
unknown
www.advanced-ip-scanner.com
  • 188.40.30.100
unknown
www.google-analytics.com
  • 172.217.16.142
unknown
ctldl.windowsupdate.com
  • 87.248.205.0
  • 67.26.81.254
  • 67.27.233.126
  • 67.27.158.254
  • 8.248.149.254
  • 67.27.157.254
unknown
ocsp.pki.goog
  • 142.250.186.163
unknown
x1.c.lencr.org
  • 23.60.200.134
unknown
api.bing.com
  • 13.107.5.80
unknown
www.bing.com
  • 13.107.21.200
  • 204.79.197.200
unknown
ocsp.digicert.com
  • 192.229.221.95
unknown

Threats

No threats detected
No debug info