URL:

adavanced-ip-scaner.com

Full analysis: https://app.any.run/tasks/6bee3ebc-e901-44dd-84da-4108bd1bbb05
Verdict: Malicious activity
Analysis date: November 23, 2023, 20:25:31
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

6F5C7DE0D4DE65187898CA52F6829763

SHA1:

855F629DA90DB127DC5C752FE4C75D2458B8AB47

SHA256:

9FB7C9BCC35E54C3426D41CA9E9C50CB546B904BB851694E3ABF5310BCB9F154

SSDEEP:

3:oE2GA5IWHYdI:oE2G3W4K

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Checks supported languages

      • wmpnscfg.exe (PID: 3752)
    • Reads the computer name

      • wmpnscfg.exe (PID: 3752)
    • Application launched itself

      • iexplore.exe (PID: 3428)
    • Reads the machine GUID from the registry

      • wmpnscfg.exe (PID: 3752)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 3752)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
38
Monitored processes
3
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3216"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3428 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
3428"C:\Program Files\Internet Explorer\iexplore.exe" "adavanced-ip-scaner.com"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
3752"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ole32.dll
Total events
19 110
Read events
19 042
Write events
63
Delete events
5

Modification events

(PID) Process:(3428) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
0
(PID) Process:(3428) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30847387
(PID) Process:(3428) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30847437
(PID) Process:(3428) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3428) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3428) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(3428) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3428) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3428) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3428) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
0
Suspicious files
23
Text files
28
Unknown types
0

Dropped files

PID
Process
Filename
Type
3216iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\css[1].txttext
MD5:62600796A34616876FBC42189343F891
SHA256:0CB2602F766E34B3A1CFE4AEC0ACE43D8D8197ABB402FBB325A2C7820F99C5D2
3216iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\2UIUUB6R.htmhtml
MD5:3CD152C12DE52AD330B19C9F1D1CC20D
SHA256:735A2736E5ECD1AA402B1BB699DDD411169CFBADF5551D4760C42FCE1951D6CD
3216iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\jquery.min.js[1].jstext
MD5:05E51B1DB558320F1939F9789CCF5C8F
SHA256:702B9E051E82B32038FFDB33A4F7EB5F7B38F4CF6F514E4182D8898F4EB0B7FB
3216iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\LPZ0EN3G.txttext
MD5:5313697D2E114C03D9C2A0B528BDA3EC
SHA256:10FA67C44D68EDCF1B04C905D0DB979E101CEE3766E963DE04931620E5BB283F
3216iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\events.js[1].jstext
MD5:7ADE2EFFC6BF7674F3536FA6CB0D9C5F
SHA256:5F0205AD6A1BD86DC9512A5C0B8C3A73A181F47B699C409831065E0E27BD098F
3216iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\main.js[1].jstext
MD5:5A6616725DBF004BF36FAC584F8DC5C2
SHA256:3335D313057D6276A4393D1B8FCDA03BEC87A8DB03FDC6DD9776DC4750A59CAD
3216iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\ses.js[1].jstext
MD5:8500F6C2B19837C19CDC41A518019127
SHA256:3581BE3B1A77CC782D61CD31EE842E090B84C89456E839BA8BFA1A182F70E718
3216iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\styles[1].csstext
MD5:EE16B415E4AA26915BFAA1DF888C4DC9
SHA256:7B8A4564B7FAC348829EB37FC0D7A885C795450402F1209291F315453783E914
3216iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\MGBV26OW.txttext
MD5:628A27FB0D9451D0C9C4A5B7854B3255
SHA256:2C95659EFC11C1CF7456E62DED630E6B21AB2625B1B194DA9EA2697F8BF38A6A
3216iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\ERQE86U7.txttext
MD5:795AC0AEA44CA45C3B5ACC36B739D28A
SHA256:399B5D3F8A01595182F6CE7EBCED3707A58FBFED7B123A4CBE7559FDF9CCD3E7
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
34
TCP/UDP connections
41
DNS requests
16
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3216
iexplore.exe
GET
200
185.11.61.65:80
http://adavanced-ip-scaner.com/
unknown
html
4.02 Kb
unknown
3216
iexplore.exe
GET
200
185.11.61.65:80
http://adavanced-ip-scaner.com/index_files/styles.css
unknown
text
2.23 Kb
unknown
3216
iexplore.exe
GET
200
185.11.61.65:80
http://adavanced-ip-scaner.com/index_files/css
unknown
text
729 b
unknown
3216
iexplore.exe
GET
200
185.11.61.65:80
http://adavanced-ip-scaner.com/index_files/js
unknown
text
271 Kb
unknown
3216
iexplore.exe
GET
200
185.11.61.65:80
http://adavanced-ip-scaner.com/index_files/jquery.min.js.%D0%91%D0%B5%D0%B7%20%D0%BD%D0%B0%D0%B7%D0%B2%D0%B0%D0%BD%D0%B8%D1%8F
unknown
text
29.5 Kb
unknown
3216
iexplore.exe
GET
200
185.11.61.65:80
http://adavanced-ip-scaner.com/index_files/main.png
unknown
image
22.7 Kb
unknown
3216
iexplore.exe
GET
200
185.11.61.65:80
http://adavanced-ip-scaner.com/index_files/it_pro_preferred_light_horizontal.png
unknown
image
9.14 Kb
unknown
3216
iexplore.exe
GET
200
185.11.61.65:80
http://adavanced-ip-scaner.com/index_files/color.js.%D0%91%D0%B5%D0%B7%20%D0%BD%D0%B0%D0%B7%D0%B2%D0%B0%D0%BD%D0%B8%D1%8F
unknown
text
576 b
unknown
3216
iexplore.exe
GET
200
185.11.61.65:80
http://adavanced-ip-scaner.com/index_files/modal.js.%D0%91%D0%B5%D0%B7%20%D0%BD%D0%B0%D0%B7%D0%B2%D0%B0%D0%BD%D0%B8%D1%8F
unknown
text
1.16 Kb
unknown
3216
iexplore.exe
GET
200
185.11.61.65:80
http://adavanced-ip-scaner.com/index_files/main.js.%D0%91%D0%B5%D0%B7%20%D0%BD%D0%B0%D0%B7%D0%B2%D0%B0%D0%BD%D0%B8%D1%8F
unknown
text
264 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
unknown
3216
iexplore.exe
185.11.61.65:80
adavanced-ip-scaner.com
Chang Way Technologies Co. Limited
RU
malicious
3216
iexplore.exe
172.217.16.202:80
ajax.googleapis.com
GOOGLE
US
whitelisted
3216
iexplore.exe
188.40.30.100:443
www.advanced-ip-scanner.com
Hetzner Online GmbH
DE
unknown
4
System
192.168.100.255:138
whitelisted
3216
iexplore.exe
172.217.16.142:443
www.google-analytics.com
GOOGLE
US
whitelisted
2588
svchost.exe
239.255.255.250:1900
whitelisted
3216
iexplore.exe
87.248.205.0:80
ctldl.windowsupdate.com
LLNW
US
unknown
3216
iexplore.exe
67.26.81.254:80
ctldl.windowsupdate.com
LEVEL3
US
unknown

DNS requests

Domain
IP
Reputation
adavanced-ip-scaner.com
  • 185.11.61.65
unknown
ajax.googleapis.com
  • 172.217.16.202
whitelisted
www.advanced-ip-scanner.com
  • 188.40.30.100
shared
www.google-analytics.com
  • 172.217.16.142
whitelisted
ctldl.windowsupdate.com
  • 87.248.205.0
  • 67.26.81.254
  • 67.27.233.126
  • 67.27.158.254
  • 8.248.149.254
  • 67.27.157.254
whitelisted
ocsp.pki.goog
  • 142.250.186.163
whitelisted
x1.c.lencr.org
  • 23.60.200.134
whitelisted
api.bing.com
  • 13.107.5.80
whitelisted
www.bing.com
  • 13.107.21.200
  • 204.79.197.200
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted

Threats

No threats detected
No debug info