analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
URL:

http://www.sports-stream.site/ch/ch46.html

Full analysis: https://app.any.run/tasks/f698a776-aec1-4625-9620-0236e0c532d8
Verdict: Malicious activity
Analysis date: April 01, 2023, 19:03:11
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

EF22594B3B0AC7DFF95AF195AF91FBF9

SHA1:

965F7AE655187FBA38425CAE16556C1AE1168164

SHA256:

A0A95F0A0E0EDE6128FEBA4B66F96ADEA8C5857E354B8D916D00968A141BEA04

SSDEEP:

3:N1KJS4geOdNPBQ:Cc4geOdNpQ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Application launched itself

      • iexplore.exe (PID: 2824)
    • The process uses the downloaded file

      • FlashUtil32_32_0_0_453_ActiveX.exe (PID: 2916)
    • Create files in a temporary directory

      • iexplore.exe (PID: 3112)
      • iexplore.exe (PID: 2824)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
39
Monitored processes
3
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe flashutil32_32_0_0_453_activex.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2824"C:\Program Files\Internet Explorer\iexplore.exe" "http://www.sports-stream.site/ch/ch46.html"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\version.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
3112"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2824 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2916C:\Windows\system32\Macromed\Flash\FlashUtil32_32_0_0_453_ActiveX.exe -EmbeddingC:\Windows\System32\Macromed\Flash\FlashUtil32_32_0_0_453_ActiveX.exesvchost.exe
User:
admin
Company:
Adobe
Integrity Level:
MEDIUM
Description:
Adobe® Flash® Player Installer/Uninstaller 32.0 r0
Version:
32,0,0,453
Modules
Images
c:\windows\system32\macromed\flash\flashutil32_32_0_0_453_activex.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
Total events
50 372
Read events
50 184
Write events
188
Delete events
0

Modification events

(PID) Process:(2824) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
0
(PID) Process:(2824) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30847387
(PID) Process:(2824) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30847437
(PID) Process:(2824) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(2824) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(2824) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(2824) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2824) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2824) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2824) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
0
Suspicious files
38
Text files
88
Unknown types
28

Dropped files

PID
Process
Filename
Type
3112iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\12RNNQV0.txttext
MD5:3DC54058FEF66B4889A473CCE5B63DD7
SHA256:CC47383B4C43C06921420B015708F912FA98566302A76908CF252CDD7AE21103
3112iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\spsch[1].htmhtml
MD5:9ECF56A655E39BD39903029B5842C83B
SHA256:84065EA62952B565B0625C4CEB6597A1310CB7503F05CC21A511B37CA61F9A17
3112iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\P6IHA0EM.txttext
MD5:8A08F61ACFE894BE8D2CC2BC2618A731
SHA256:6C7F9DA324E2935DD68372C3019E4A317CE43537188691C09F6F463542BE33AA
3112iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\XT2JDRBY.txttext
MD5:F0332B3FE74798FDF9F6D17EF749C463
SHA256:E33D92F1EFF858580E14449B9A7D3B2DF916745685D2B8E4DA1FEEA4F19A2330
3112iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\ch46[1].htmhtml
MD5:31B2A66FD1A8FD8D1BCE58477024BDB0
SHA256:34DB60EA0CE9778D80741AA7FBC9CE57C16EB1CD0F63BBE42580F7E797018FD3
3112iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\RWG57QIW.txttext
MD5:8DA75CA831FD1A84E235C468E4071DA2
SHA256:2DFF8DD3971919630DD0967281157A3BCBA470A8D2C5C6F093A6332654E533E0
3112iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\IPJK3YPD.txttext
MD5:529984A30EC7A9FBC3485037DF765483
SHA256:C55AE58D98A82B5560904DEB0EB8B6A799DA7993FA8EB5C267E888463CAAE999
3112iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\LOK9HE5H.txttext
MD5:59E425C01F04E3ABE602630CA59149E4
SHA256:6BD946C60C9EE56AD8AECA15D49E7ED4B20856F773E188F4B702F5DF72EEFE7C
3112iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\UV9BB4BD.txttext
MD5:6D96A378B688D2D012B812A3D06D6E1A
SHA256:250D06555C3D300DDC19CBEDA1AC0E1DDC505054FE76BA237EADE070A8C9DA63
3112iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\X46O4J3M.txttext
MD5:F3E3A2796E6158413AD2FE545021A328
SHA256:0DFCFFEE051372F96F8472B1A808F5EAAFAD68C90367076AFA81044EB253C160
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
26
TCP/UDP connections
60
DNS requests
28
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3112
iexplore.exe
GET
200
188.114.96.3:80
http://www.sports-stream.site/ch/ch46.html
US
html
651 b
malicious
3112
iexplore.exe
GET
200
188.114.96.3:80
http://www.sports-stream.site/ads/ads-stream1.html
US
html
333 b
malicious
3112
iexplore.exe
GET
200
172.217.18.99:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
US
der
1.41 Kb
whitelisted
3112
iexplore.exe
GET
200
209.197.3.8:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?2950ec1e9c6a4d62
US
compressed
61.1 Kb
whitelisted
3112
iexplore.exe
GET
200
172.67.204.65:80
http://acacdn.com/script/ut.js?cb=1680375797270
US
text
23.9 Kb
suspicious
3112
iexplore.exe
GET
200
172.67.204.65:80
http://acacdn.com/script/suv4.js
US
text
33.0 Kb
suspicious
3112
iexplore.exe
GET
200
172.64.155.188:80
http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEH1bUSa0droR23QWC7xTDac%3D
US
der
2.18 Kb
whitelisted
3112
iexplore.exe
GET
200
188.114.96.3:80
http://www.sports-stream.site/ch/spsch.php?ch=superfotball
US
html
21.1 Kb
malicious
3112
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEAo3h2ReX7SMIk79G%2B0UDDw%3D
US
der
1.47 Kb
whitelisted
3112
iexplore.exe
GET
200
209.197.3.8:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?7b71663a87bf802e
US
compressed
4.70 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3112
iexplore.exe
188.114.96.3:80
www.sports-stream.site
CLOUDFLARENET
NL
malicious
3112
iexplore.exe
172.67.204.65:80
acacdn.com
CLOUDFLARENET
US
malicious
3112
iexplore.exe
172.67.145.158:443
coolcast2.com
CLOUDFLARENET
US
malicious
3112
iexplore.exe
46.105.201.240:80
s10.histats.com
OVH SAS
FR
suspicious
3112
iexplore.exe
149.56.240.31:443
s4.histats.com
OVH SAS
CA
unknown
3112
iexplore.exe
156.146.33.18:443
www.blockadsnot.com
Datacamp Limited
DE
suspicious
3112
iexplore.exe
209.197.3.8:80
ctldl.windowsupdate.com
STACKPATH-CDN
US
whitelisted
3112
iexplore.exe
172.217.16.138:443
ajax.googleapis.com
GOOGLE
US
whitelisted
3112
iexplore.exe
172.217.18.99:80
ocsp.pki.goog
GOOGLE
US
whitelisted
3112
iexplore.exe
104.18.10.207:443
maxcdn.bootstrapcdn.com
CLOUDFLARENET
suspicious

DNS requests

Domain
IP
Reputation
www.sports-stream.site
  • 188.114.96.3
  • 188.114.97.3
malicious
s10.histats.com
  • 46.105.201.240
whitelisted
acacdn.com
  • 172.67.204.65
  • 104.21.85.95
suspicious
www.blockadsnot.com
  • 156.146.33.18
  • 195.181.170.18
  • 156.146.33.26
  • 195.181.174.7
  • 185.59.220.17
suspicious
coolcast2.com
  • 172.67.145.158
  • 104.21.87.189
malicious
s4.histats.com
  • 149.56.240.31
  • 149.56.240.127
  • 149.56.240.132
  • 149.56.240.128
  • 149.56.240.129
  • 54.39.128.117
  • 149.56.240.130
  • 149.56.240.131
  • 54.39.128.162
  • 149.56.240.27
  • 54.39.156.32
whitelisted
ctldl.windowsupdate.com
  • 209.197.3.8
whitelisted
ocsp.pki.goog
  • 172.217.18.99
whitelisted
ajax.googleapis.com
  • 172.217.16.138
whitelisted
maxcdn.bootstrapcdn.com
  • 104.18.10.207
  • 104.18.11.207
whitelisted

Threats

PID
Process
Class
Message
3112
iexplore.exe
Misc activity
ET HUNTING [TW] Likely Javascript-Obfuscator Usage Observed M1
No debug info