URL:

bounceme.net

Full analysis: https://app.any.run/tasks/4c7e67f1-31a4-4a97-ba18-8aa6307e79cb
Verdict: Malicious activity
Analysis date: October 06, 2023, 02:42:11
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

E22144F9D5B844776AE9E426D9C92646

SHA1:

28F3B06F09722A1BEE06DFA17DA2F414D1B13E46

SHA256:

A8A913C35813E9DF032D70777C303F9328219BF5060B458B7B0418007A2DEC63

SSDEEP:

3:fGAIEARn:fXIpR

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Application launched itself

      • iexplore.exe (PID: 3236)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
38
Monitored processes
3
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe iexplore.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2332"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3236 CREDAT:4003084 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exeiexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
c:\windows\system32\version.dll
2372"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3236 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
3236"C:\Program Files\Internet Explorer\iexplore.exe" "bounceme.net"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\sechost.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
Total events
21 256
Read events
21 142
Write events
114
Delete events
0

Modification events

(PID) Process:(3236) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
0
(PID) Process:(3236) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30847387
(PID) Process:(3236) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30847437
(PID) Process:(3236) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3236) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3236) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(3236) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3236) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3236) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3236) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
0
Suspicious files
48
Text files
55
Unknown types
0

Dropped files

PID
Process
Filename
Type
2372iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\shortstar[1].csstext
MD5:6E7BAF35807D234B8E10A7D48180E011
SHA256:254F244B5C5117240E87F7E5AA4978CEDA2D8E2C1128CA5CD18CB152E34A8436
2372iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\7X3KK4KL.txttext
MD5:D80CF30EC315B74634EF0E48684696AA
SHA256:4BDB34265A28DB44A28687B97439712184CEDC3A16C2DF432A1EBB5CE4594884
2372iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\ZYZM1W7V.txttext
MD5:6402076C829A86C057A9866D047294FA
SHA256:8788B4415F768B0731636A99BDE0C4A99ACD92E255E21470AA63A639EAA70401
2372iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\1ZJV41P6.txttext
MD5:6EDAF2DB04F455702D3E014DF6D5F918
SHA256:1547EE3A0616573386379EC18FEFDEA0E46E6618FECD339B9FDC7D375D530BB1
2372iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157compressed
MD5:1BFE591A4FE3D91B03CDF26EAACD8F89
SHA256:9CF94355051BF0F4A45724CA20D1CC02F76371B963AB7D1E38BD8997737B13D8
2372iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\shortstar[1].jstext
MD5:7A2742B2AB51E715F098C2434130BA03
SHA256:8293F6115A8E203DFAEF91D10165640642753AAC67891B12A10973AF5B538555
2372iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\6xKydSBYKcSV-LCoeQqfX1RYOo3ik4zwlxdo[1].woffbinary
MD5:3BCC787B94E90E45DCE32670AD2F3845
SHA256:D40268EACF4E3F34EC8272B42364310EEF19D0B5067AA7F6D8B3C11A23A25243
2372iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\logo-grey[1].pngimage
MD5:9B0EE274D3E0546FE2D5515C182E874F
SHA256:BEACEB10412E96FB56E91B8451872257F3D3D741C66FF7ED59B5180BA6A25ECF
2372iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\6xK3dSBYKcSV-LCoeQqfX1RYOo3qOK7j[1].woffbinary
MD5:9347E153F350E24BAF7EB7015BDBEFC2
SHA256:69491B82A23A2C945E2B8D04DA984A3F8E4C944BE5200720332246B20C525B73
2372iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\69E9XDNT.htmhtml
MD5:7D27D7D9E2B3AC9AE6C9BC90F371B66D
SHA256:47DEA45E661A2C55C5BC27AD5E0B967B16A9FC856C18CF2D264C32723723A543
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
46
TCP/UDP connections
78
DNS requests
32
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2372
iexplore.exe
GET
301
158.247.7.206:80
http://bounceme.net/
unknown
unknown
2372
iexplore.exe
GET
301
142.251.141.46:80
http://translate.google.com/translate_a/element.js?cb=googleTranslateElementInit
unknown
unknown
2372
iexplore.exe
GET
200
143.204.205.209:80
http://d2qr50rz2oof04.cloudfront.net/assets/build/js/shortstar.js?id=69a8b5de39938f0f29d6
unknown
text
73.1 Kb
unknown
2372
iexplore.exe
GET
200
143.204.205.209:80
http://d2qr50rz2oof04.cloudfront.net/assets/img/logo/logo-grey.png
unknown
image
1.52 Kb
unknown
2372
iexplore.exe
GET
200
143.204.205.209:80
http://d2qr50rz2oof04.cloudfront.net/assets/build/css/shortstar.css?id=6e7baf35807d234b8e10
unknown
text
113 Kb
unknown
2372
iexplore.exe
GET
200
158.247.7.206:80
http://freeddns.noip.com/?d=bounceme.net&u=Ym91bmNlbWUubmV0Lw==
unknown
html
11.7 Kb
unknown
2372
iexplore.exe
GET
200
172.217.169.130:80
http://www.googleadservices.com/pagead/conversion.js
unknown
text
18.7 Kb
unknown
2372
iexplore.exe
GET
200
209.197.3.8:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?a133c2cc88d50dba
unknown
compressed
4.66 Kb
unknown
2372
iexplore.exe
GET
200
209.197.3.8:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?70b557c706e6a566
unknown
compressed
4.66 Kb
unknown
2372
iexplore.exe
GET
200
142.250.187.131:80
http://fonts.gstatic.com/s/opensans/v36/memSYaGs126MiZpBA-UvWbX2vVnXBbObj2OVZyOOSr4dVJWUgsiH0B4gaVQ.woff
unknown
binary
22.4 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2372
iexplore.exe
158.247.7.206:80
bounceme.net
NOIP-VITAL
US
unknown
2372
iexplore.exe
143.204.205.209:80
d2qr50rz2oof04.cloudfront.net
AMAZON-02
US
unknown
2372
iexplore.exe
172.217.169.130:80
www.googleadservices.com
GOOGLE
US
unknown
2372
iexplore.exe
142.251.141.46:80
translate.google.com
GOOGLE
US
unknown
2372
iexplore.exe
172.217.17.104:443
www.googletagmanager.com
GOOGLE
US
whitelisted
2372
iexplore.exe
142.250.187.170:80
fonts.googleapis.com
GOOGLE
US
whitelisted
2372
iexplore.exe
142.251.141.46:443
translate.google.com
GOOGLE
US
unknown
2372
iexplore.exe
142.251.140.78:443
www.google-analytics.com
GOOGLE
US
unknown
2372
iexplore.exe
172.217.17.104:80
www.googletagmanager.com
GOOGLE
US
whitelisted
2372
iexplore.exe
142.250.187.131:80
fonts.gstatic.com
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
bounceme.net
  • 158.247.7.206
unknown
freeddns.noip.com
  • 158.247.7.206
malicious
d2qr50rz2oof04.cloudfront.net
  • 143.204.205.209
  • 143.204.205.79
  • 143.204.205.83
  • 143.204.205.223
unknown
www.googleadservices.com
  • 172.217.169.130
whitelisted
translate.google.com
  • 142.251.141.46
whitelisted
www.googletagmanager.com
  • 172.217.17.104
whitelisted
fonts.googleapis.com
  • 142.250.187.170
whitelisted
www.google-analytics.com
  • 142.251.140.78
whitelisted
fonts.gstatic.com
  • 142.250.187.131
whitelisted
ctldl.windowsupdate.com
  • 209.197.3.8
whitelisted

Threats

Found threats are available for the paid subscriptions
1 ETPRO signatures available at the full report
No debug info