URL:

https://links.worldsbest.events/ls/click?upn=zDytinePaKZvresGztECCvaKxl8aootY4Bg5rRgNMMyemDMLYON6-2BWst5y4DCzqsQo-2FgftA9BPilBpjMGFWz-2Bg-3D-3Dnhyk_6UZatjlwEZJ9CtRgb5x4-2F7uB-2BIGGADjz-2FQkC75iy51HB42BBrdCTPnf-2BxHK6rR65kCrGrtbogiRtQmxOK9sbJPzyzTcpj69MYautI-2B0-2BOtCNVHNCUtgQ6Auzi-2BavOHN5aWTnSY3u-2BXEyO2jA2H9R8ZLrLPlqTEPEc3j4rpCRNQoQe8kI8ihJ90Zy72tciUw9oZFNLdufxG-2Bfsol-2B2CaZh-2BTsyggIlDeETyxkMtGuy0pCX-2BUMYlliIjhZtAodkDnQFESlGMFWoEhcotzYI9MxcItrcCjjrYZZey-2FjlKXkzg4650c64zVLfSPwKZ03dyCVJ92y-2FQaicbnX0-2FH-2F5kOweHh4Pegi-2BGANvGdY9annNGOOG0vrIIYlZm1Pt2jdTkNW

Full analysis: https://app.any.run/tasks/a4d314a3-719b-4e45-8aba-2e7903fa2a29
Verdict: Malicious activity
Analysis date: September 26, 2023, 07:57:44
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

1D3D6256EE891F073AE0E6F234E292A2

SHA1:

5A5B82D2D8DC369E67176E3890619FB9D804C94D

SHA256:

A0CE30EEBA24D68BAD53E89418440C1A072BF06BCD9ED502657C088E731E2A58

SSDEEP:

12:2Mb10wy91+kX+DF/daQE0jLVmu2/qzAdBlhJOsOJ6my61:225y9RQAL0Nmu2/nOsW1

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Application launched itself

      • iexplore.exe (PID: 3484)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
37
Monitored processes
2
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe

Process information

PID
CMD
Path
Indicators
Parent process
3484"C:\Program Files\Internet Explorer\iexplore.exe" "https://links.worldsbest.events/ls/click?upn=zDytinePaKZvresGztECCvaKxl8aootY4Bg5rRgNMMyemDMLYON6-2BWst5y4DCzqsQo-2FgftA9BPilBpjMGFWz-2Bg-3D-3Dnhyk_6UZatjlwEZJ9CtRgb5x4-2F7uB-2BIGGADjz-2FQkC75iy51HB42BBrdCTPnf-2BxHK6rR65kCrGrtbogiRtQmxOK9sbJPzyzTcpj69MYautI-2B0-2BOtCNVHNCUtgQ6Auzi-2BavOHN5aWTnSY3u-2BXEyO2jA2H9R8ZLrLPlqTEPEc3j4rpCRNQoQe8kI8ihJ90Zy72tciUw9oZFNLdufxG-2Bfsol-2B2CaZh-2BTsyggIlDeETyxkMtGuy0pCX-2BUMYlliIjhZtAodkDnQFESlGMFWoEhcotzYI9MxcItrcCjjrYZZey-2FjlKXkzg4650c64zVLfSPwKZ03dyCVJ92y-2FQaicbnX0-2FH-2F5kOweHh4Pegi-2BGANvGdY9annNGOOG0vrIIYlZm1Pt2jdTkNW"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\sechost.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
3560"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3484 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
Total events
10 725
Read events
10 667
Write events
58
Delete events
0

Modification events

(PID) Process:(3484) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
0
(PID) Process:(3484) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30847387
(PID) Process:(3484) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30847437
(PID) Process:(3484) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3484) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3484) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(3484) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3484) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3484) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3484) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
0
Suspicious files
11
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
3560iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B66240B0F6C84BD4857ABA60CF5CE4A0_5043E0F5DF723415C9EECC201C838A62binary
MD5:62F502EBC9FE6BC9ED608B668ABBFE4B
SHA256:542416700F0667284181CEB6ABCB28F3547234F7EC7857D535AEBC934C9076DC
3560iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\D03E46CD585BBE111C712E6577BC5F07_30CC784F59B7F895D4A163C7B8199086binary
MD5:54AC48CF2D448BE0DF979C4219F92EB1
SHA256:36654804F28876E468CF6A81803CF010DEAE890C854A4DE31C25D95F439853C3
3560iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B66240B0F6C84BD4857ABA60CF5CE4A0_5043E0F5DF723415C9EECC201C838A62binary
MD5:5FAEA27BE17FCE64A5DB626DA841016A
SHA256:38861DBDE2B1E7F00806FEE2F728D52B64DE7E9D39E649066420A5E363A65CA1
3484iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\82CB34DD3343FE727DF8890D352E0D8Fbinary
MD5:E55FC98B7ADFA60A41319DEB2B18BF32
SHA256:F655FA95F4A692799B5559A0D72CCC07E147CC315E29D06CB0AB5CD28D1AE925
3560iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157compressed
MD5:24BE8A92460B5B7A555B1DA559296958
SHA256:77A3CFE6B7EB676AF438D5DE88C7EFCB6ABCC494E0B65DA90201969E6D79B2A3
3484iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\82CB34DD3343FE727DF8890D352E0D8Fbinary
MD5:CBF8155AE28F0704EE18F241F35FA026
SHA256:464865B06F2E05779F6220302D42E77D25CE64A42A5B778140BAFF79755376B1
3560iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\75CA58072B9926F763A91F0CC2798706_B5D3A17E5BEDD2EDA793611A0A74E1E8binary
MD5:FE2D7B1EF9977141BAD57B815E73B858
SHA256:36713003601C51018F2E6B47F73468E92F21E2902EF51AAAF3BD67555BBD39F4
3560iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\BAD725C80F9E10846F35D039A996E4A8_88B6AE015495C1ECC395D19C1DD02894binary
MD5:31F777526484481EE86B677E18278EF2
SHA256:8691E3150AE575A0FF5F4C18D700E7E83537069EC810E69B962800249CD92B9F
3560iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\D03E46CD585BBE111C712E6577BC5F07_30CC784F59B7F895D4A163C7B8199086binary
MD5:1591B508D16F20D2AE0FD86B2B7FC0A7
SHA256:B5808FC90A8FB9E006F865F92B973B7D16560D96D29EAEF544A5D2BD5E3EFE92
3560iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\75CA58072B9926F763A91F0CC2798706_B5D3A17E5BEDD2EDA793611A0A74E1E8binary
MD5:43D99081BDA8C02DADD23FC4FE68DB26
SHA256:FE1AB4873443FD30D1D212A409ECEEBC9855CA35E6C613C5A88A461793A0863F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
34
DNS requests
21
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3560
iexplore.exe
GET
200
108.138.2.173:80
http://o.ss2.us//MEowSDBGMEQwQjAJBgUrDgMCGgUABBSLwZ6EW5gdYc9UaSEaaLjjETNtkAQUv1%2B30c7dH4b0W1Ws3NcQwg6piOcCCQCnDkpMNIK3fw%3D%3D
unknown
der
2.02 Kb
unknown
3560
iexplore.exe
GET
200
52.222.226.205:80
http://ocsp.r2m01.amazontrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBShdVEFnSEQ0gG5CBtzM48cPMe9XwQUgbgOY4qJEhjl%2Bjs7UJWf5uWQE4UCEAZYy71kHrkLH9do5AxZQUs%3D
unknown
der
471 b
unknown
3560
iexplore.exe
GET
200
8.248.115.254:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?6f8dc1c745099382
unknown
compressed
4.66 Kb
unknown
3560
iexplore.exe
GET
200
13.32.98.91:80
http://ocsp.rootg2.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBSIfaREXmfqfJR3TkMYnD7O5MhzEgQUnF8A36oB1zArOIiiuG1KnPIRkYMCEwZ%2FlEoqJ83z%2BsKuKwH5CO65xMY%3D
unknown
der
1.51 Kb
unknown
3560
iexplore.exe
GET
200
13.32.98.91:80
http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwdzEjgLnWaIozse2b%2BczaaODg8%3D
unknown
der
1.39 Kb
unknown
3560
iexplore.exe
GET
200
8.248.115.254:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?49361a3f17fc7612
unknown
compressed
4.66 Kb
unknown
3484
iexplore.exe
GET
200
192.229.221.95:80
http://crl3.digicert.com/Omniroot2025.crl
unknown
der
7.78 Kb
unknown
3484
iexplore.exe
GET
200
8.248.115.254:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?a320ada0b6bdda7d
unknown
compressed
4.66 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3560
iexplore.exe
18.66.97.61:443
links.worldsbest.events
US
unknown
3284
svchost.exe
239.255.255.250:1900
whitelisted
3560
iexplore.exe
8.248.149.254:80
ctldl.windowsupdate.com
LEVEL3
US
unknown
3484
iexplore.exe
104.126.37.163:443
www.bing.com
Akamai International B.V.
DE
unknown
4
System
192.168.100.255:138
whitelisted
3484
iexplore.exe
8.248.149.254:80
ctldl.windowsupdate.com
LEVEL3
US
unknown
3560
iexplore.exe
108.138.2.173:80
o.ss2.us
AMAZON-02
US
unknown
3560
iexplore.exe
13.32.98.91:80
ocsp.rootg2.amazontrust.com
AMAZON-02
US
unknown
3560
iexplore.exe
52.222.226.205:80
ocsp.r2m01.amazontrust.com
AMAZON-02
US
unknown
3560
iexplore.exe
13.224.189.126:443
rsvp.theworldsbest.events
AMAZON-02
US
whitelisted

DNS requests

Domain
IP
Reputation
links.worldsbest.events
  • 18.66.97.61
  • 18.66.97.15
  • 18.66.97.16
  • 18.66.97.114
shared
ctldl.windowsupdate.com
  • 8.248.149.254
  • 8.248.115.254
  • 8.248.143.254
  • 8.241.11.126
  • 8.241.121.254
whitelisted
api.bing.com
  • 13.107.5.80
whitelisted
www.bing.com
  • 104.126.37.131
  • 104.126.37.176
  • 104.126.37.179
  • 104.126.37.163
  • 104.126.37.130
  • 104.126.37.178
  • 104.126.37.137
  • 104.126.37.123
  • 104.126.37.177
whitelisted
o.ss2.us
  • 108.138.2.173
  • 108.138.2.107
  • 108.138.2.10
  • 108.138.2.195
whitelisted
ocsp.rootg2.amazontrust.com
  • 13.32.98.91
whitelisted
ocsp.rootca1.amazontrust.com
  • 13.32.98.91
shared
ocsp.r2m01.amazontrust.com
  • 52.222.226.205
whitelisted
rsvp.theworldsbest.events
  • 13.224.189.126
  • 13.224.189.24
  • 13.224.189.43
  • 13.224.189.48
unknown
ocsp.digicert.com
  • 192.229.221.95
whitelisted

Threats

No threats detected
No debug info