| URL: | bounceme.net |
| Full analysis: | https://app.any.run/tasks/4c7e67f1-31a4-4a97-ba18-8aa6307e79cb |
| Verdict: | Malicious activity |
| Analysis date: | October 06, 2023, 02:42:11 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MD5: | E22144F9D5B844776AE9E426D9C92646 |
| SHA1: | 28F3B06F09722A1BEE06DFA17DA2F414D1B13E46 |
| SHA256: | A8A913C35813E9DF032D70777C303F9328219BF5060B458B7B0418007A2DEC63 |
| SSDEEP: | 3:fGAIEARn:fXIpR |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2332 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3236 CREDAT:4003084 /prefetch:2 | C:\Program Files\Internet Explorer\iexplore.exe | — | iexplore.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| 2372 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3236 CREDAT:267521 /prefetch:2 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| 3236 | "C:\Program Files\Internet Explorer\iexplore.exe" "bounceme.net" | C:\Program Files\Internet Explorer\iexplore.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| (PID) Process: | (3236) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPDaysSinceLastAutoMigration |
Value: 0 | |||
| (PID) Process: | (3236) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPLastLaunchHighDateTime |
Value: 30847387 | |||
| (PID) Process: | (3236) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager |
| Operation: | write | Name: | NextCheckForUpdateHighDateTime |
Value: 30847437 | |||
| (PID) Process: | (3236) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (3236) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (3236) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main |
| Operation: | write | Name: | CompatibilityFlags |
Value: 0 | |||
| (PID) Process: | (3236) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (3236) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (3236) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (3236) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2372 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\shortstar[1].css | text | |
MD5:6E7BAF35807D234B8E10A7D48180E011 | SHA256:254F244B5C5117240E87F7E5AA4978CEDA2D8E2C1128CA5CD18CB152E34A8436 | |||
| 2372 | iexplore.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\7X3KK4KL.txt | text | |
MD5:D80CF30EC315B74634EF0E48684696AA | SHA256:4BDB34265A28DB44A28687B97439712184CEDC3A16C2DF432A1EBB5CE4594884 | |||
| 2372 | iexplore.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\ZYZM1W7V.txt | text | |
MD5:6402076C829A86C057A9866D047294FA | SHA256:8788B4415F768B0731636A99BDE0C4A99ACD92E255E21470AA63A639EAA70401 | |||
| 2372 | iexplore.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\1ZJV41P6.txt | text | |
MD5:6EDAF2DB04F455702D3E014DF6D5F918 | SHA256:1547EE3A0616573386379EC18FEFDEA0E46E6618FECD339B9FDC7D375D530BB1 | |||
| 2372 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157 | compressed | |
MD5:1BFE591A4FE3D91B03CDF26EAACD8F89 | SHA256:9CF94355051BF0F4A45724CA20D1CC02F76371B963AB7D1E38BD8997737B13D8 | |||
| 2372 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\shortstar[1].js | text | |
MD5:7A2742B2AB51E715F098C2434130BA03 | SHA256:8293F6115A8E203DFAEF91D10165640642753AAC67891B12A10973AF5B538555 | |||
| 2372 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\6xKydSBYKcSV-LCoeQqfX1RYOo3ik4zwlxdo[1].woff | binary | |
MD5:3BCC787B94E90E45DCE32670AD2F3845 | SHA256:D40268EACF4E3F34EC8272B42364310EEF19D0B5067AA7F6D8B3C11A23A25243 | |||
| 2372 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\logo-grey[1].png | image | |
MD5:9B0EE274D3E0546FE2D5515C182E874F | SHA256:BEACEB10412E96FB56E91B8451872257F3D3D741C66FF7ED59B5180BA6A25ECF | |||
| 2372 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\6xK3dSBYKcSV-LCoeQqfX1RYOo3qOK7j[1].woff | binary | |
MD5:9347E153F350E24BAF7EB7015BDBEFC2 | SHA256:69491B82A23A2C945E2B8D04DA984A3F8E4C944BE5200720332246B20C525B73 | |||
| 2372 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\69E9XDNT.htm | html | |
MD5:7D27D7D9E2B3AC9AE6C9BC90F371B66D | SHA256:47DEA45E661A2C55C5BC27AD5E0B967B16A9FC856C18CF2D264C32723723A543 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2372 | iexplore.exe | GET | 301 | 158.247.7.206:80 | http://bounceme.net/ | unknown | — | — | unknown |
2372 | iexplore.exe | GET | 301 | 142.251.141.46:80 | http://translate.google.com/translate_a/element.js?cb=googleTranslateElementInit | unknown | — | — | unknown |
2372 | iexplore.exe | GET | 200 | 143.204.205.209:80 | http://d2qr50rz2oof04.cloudfront.net/assets/build/js/shortstar.js?id=69a8b5de39938f0f29d6 | unknown | text | 73.1 Kb | unknown |
2372 | iexplore.exe | GET | 200 | 143.204.205.209:80 | http://d2qr50rz2oof04.cloudfront.net/assets/img/logo/logo-grey.png | unknown | image | 1.52 Kb | unknown |
2372 | iexplore.exe | GET | 200 | 143.204.205.209:80 | http://d2qr50rz2oof04.cloudfront.net/assets/build/css/shortstar.css?id=6e7baf35807d234b8e10 | unknown | text | 113 Kb | unknown |
2372 | iexplore.exe | GET | 200 | 158.247.7.206:80 | http://freeddns.noip.com/?d=bounceme.net&u=Ym91bmNlbWUubmV0Lw== | unknown | html | 11.7 Kb | unknown |
2372 | iexplore.exe | GET | 200 | 172.217.169.130:80 | http://www.googleadservices.com/pagead/conversion.js | unknown | text | 18.7 Kb | unknown |
2372 | iexplore.exe | GET | 200 | 209.197.3.8:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?a133c2cc88d50dba | unknown | compressed | 4.66 Kb | unknown |
2372 | iexplore.exe | GET | 200 | 209.197.3.8:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?70b557c706e6a566 | unknown | compressed | 4.66 Kb | unknown |
2372 | iexplore.exe | GET | 200 | 142.250.187.131:80 | http://fonts.gstatic.com/s/opensans/v36/memSYaGs126MiZpBA-UvWbX2vVnXBbObj2OVZyOOSr4dVJWUgsiH0B4gaVQ.woff | unknown | binary | 22.4 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2372 | iexplore.exe | 158.247.7.206:80 | bounceme.net | NOIP-VITAL | US | unknown |
2372 | iexplore.exe | 143.204.205.209:80 | d2qr50rz2oof04.cloudfront.net | AMAZON-02 | US | unknown |
2372 | iexplore.exe | 172.217.169.130:80 | www.googleadservices.com | GOOGLE | US | unknown |
2372 | iexplore.exe | 142.251.141.46:80 | translate.google.com | GOOGLE | US | unknown |
2372 | iexplore.exe | 172.217.17.104:443 | www.googletagmanager.com | GOOGLE | US | whitelisted |
2372 | iexplore.exe | 142.250.187.170:80 | fonts.googleapis.com | GOOGLE | US | whitelisted |
2372 | iexplore.exe | 142.251.141.46:443 | translate.google.com | GOOGLE | US | unknown |
2372 | iexplore.exe | 142.251.140.78:443 | www.google-analytics.com | GOOGLE | US | unknown |
2372 | iexplore.exe | 172.217.17.104:80 | www.googletagmanager.com | GOOGLE | US | whitelisted |
2372 | iexplore.exe | 142.250.187.131:80 | fonts.gstatic.com | GOOGLE | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
bounceme.net |
| unknown |
freeddns.noip.com |
| malicious |
d2qr50rz2oof04.cloudfront.net |
| unknown |
www.googleadservices.com |
| whitelisted |
translate.google.com |
| whitelisted |
www.googletagmanager.com |
| whitelisted |
fonts.googleapis.com |
| whitelisted |
www.google-analytics.com |
| whitelisted |
fonts.gstatic.com |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |