| URL: | http://www65.zippyshare.com/v/t3NZSFs7/file.html |
| Full analysis: | https://app.any.run/tasks/a90f6083-a2a3-4344-8be5-31ee14d87494 |
| Verdict: | Malicious activity |
| Analysis date: | February 08, 2024, 16:24:43 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MD5: | 065E5305E41D1D608B30F9A042493623 |
| SHA1: | 0E119F03184D3EA54866852300283B7530A52A4B |
| SHA256: | AA3714F3A84620A63A9C041CDB8EB1B88DDAADB058F6845883D8436624EF9872 |
| SSDEEP: | 3:N1KJSgAwGKjKwAgWJ:CcgAwGjPRJ |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1652 | "C:\Program Files\Internet Explorer\iexplore.exe" "http://www65.zippyshare.com/v/t3NZSFs7/file.html" | C:\Program Files\Internet Explorer\iexplore.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| 3484 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:1652 CREDAT:267521 /prefetch:2 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| (PID) Process: | (1652) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPDaysSinceLastAutoMigration |
Value: 0 | |||
| (PID) Process: | (1652) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPLastLaunchHighDateTime |
Value: 30847387 | |||
| (PID) Process: | (1652) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager |
| Operation: | write | Name: | NextCheckForUpdateHighDateTime |
Value: 30847437 | |||
| (PID) Process: | (1652) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (1652) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (1652) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main |
| Operation: | write | Name: | CompatibilityFlags |
Value: 0 | |||
| (PID) Process: | (1652) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (1652) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (1652) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (1652) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3484 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\font-awesome.v2[1].css | text | |
MD5:183540CD2E86C4FB48612AB38F94D28E | SHA256:1EA4DFE698AF85B8C0BE2BEA33995932214934666BF103846330A3ED3FDA3CE0 | |||
| 3484 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\protonmail[1].svg | image | |
MD5:FC5B1E8B92DD09734CA7C9D91E89DB93 | SHA256:27BD40ED5364A90D5510D1C58F45EEA1961C7A45920E191CAF9745D10BD29C9A | |||
| 3484 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\zippyshare[1].png | image | |
MD5:CEA2AED34D001DD66EDCC4C4B7A45FC5 | SHA256:937C3F209A5021B01AEB088C45950122A5C7255D73E0E5E21A135CB00B39A0BD | |||
| 3484 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\nord[1].png | image | |
MD5:E155603B54B07FF3CF31860D4DE6145E | SHA256:C813CBCE890D359206479362718A5F859D9EEAA741DE995E3D8E4DE64E06E473 | |||
| 3484 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\main.v2[1].css | text | |
MD5:7FE82702862DA49A6966E470F7BBC68E | SHA256:36802D82179FC146D9947A26C1DDD41F1AEA4FC2F962BDB4FE83E4D42D01781A | |||
| 3484 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\E5HLTQZC.htm | html | |
MD5:1CADD881ADB79E401ABFB1746539B52C | SHA256:20E0AC8E3D9D2DBDE3A0D91AF899FAFA66BF602E2C1908BEDDC6155A2EC23D8E | |||
| 3484 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\modernizr.v2[1].js | html | |
MD5:F3F01A645CF37CC013F9657561552C20 | SHA256:0C290F0AB1DFB5BBAA65A49E47045F2E7FEB474A928D69420332C75FB719E75E | |||
| 3484 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\protondrive[1].svg | image | |
MD5:704D9EF7F6B6A5A521BEB656E3A00DB0 | SHA256:4B914C853D6102E29FC2E6B5537B8862F86FD987D656E97350645CEDF054A7B7 | |||
| 3484 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\pcloud[1].png | image | |
MD5:4EE78C171F01CF88F8886B4EC2D8996F | SHA256:3648F994C51F630DA14FFAADAB18943C48144A9A5D6D9F5920390D67AB23E1D1 | |||
| 3484 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\protonvpn[1].svg | image | |
MD5:DA4B71B9F3A89BDD24BD642039382594 | SHA256:76F55B52D5BAC6061C18790CF17299773C6660CB4B45FD63923B492602BAF1D9 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3484 | iexplore.exe | GET | 302 | 145.239.9.15:80 | http://www65.zippyshare.com/v/t3NZSFs7/file.html | unknown | html | 170 b | unknown |
3484 | iexplore.exe | GET | 200 | 145.239.9.15:80 | http://www65.zippyshare.com/ | unknown | html | 4.66 Kb | unknown |
3484 | iexplore.exe | GET | — | 145.239.9.15:80 | http://www65.zippyshare.com/css/bootstrap.min.v2.css | unknown | — | — | unknown |
3484 | iexplore.exe | GET | 200 | 145.239.9.15:80 | http://www65.zippyshare.com/css/font-awesome.v2.css | unknown | text | 23.1 Kb | unknown |
3484 | iexplore.exe | GET | 200 | 145.239.9.15:80 | http://www65.zippyshare.com/css/main.v2.css | unknown | text | 1.01 Kb | unknown |
3484 | iexplore.exe | GET | 200 | 145.239.9.15:80 | http://www65.zippyshare.com/js/modernizr.v2.js | unknown | html | 14.2 Kb | unknown |
3484 | iexplore.exe | GET | — | 145.239.9.15:80 | http://www65.zippyshare.com/js/jquery.min.v2.js | unknown | — | — | unknown |
3484 | iexplore.exe | GET | 200 | 145.239.9.15:80 | http://www65.zippyshare.com/img/zippyshare.png | unknown | image | 4.06 Kb | unknown |
3484 | iexplore.exe | GET | — | 145.239.9.15:80 | http://www65.zippyshare.com/img/mega.png | unknown | — | — | unknown |
3484 | iexplore.exe | GET | 200 | 145.239.9.15:80 | http://www65.zippyshare.com/img/nord.png | unknown | image | 3.56 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
3484 | iexplore.exe | 145.239.9.15:80 | www65.zippyshare.com | OVH SAS | FR | unknown |
3484 | iexplore.exe | 142.250.186.106:443 | fonts.googleapis.com | GOOGLE | US | whitelisted |
3484 | iexplore.exe | 93.184.221.240:80 | ctldl.windowsupdate.com | EDGECAST | GB | whitelisted |
3484 | iexplore.exe | 216.58.206.35:80 | ocsp.pki.goog | GOOGLE | US | whitelisted |
3484 | iexplore.exe | 142.250.74.195:443 | fonts.gstatic.com | GOOGLE | US | whitelisted |
3484 | iexplore.exe | 192.243.59.12:80 | incarnatepicturesque.com | DataWeb Global Group B.V. | US | unknown |
3484 | iexplore.exe | 142.250.181.238:443 | www.google-analytics.com | GOOGLE | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
www65.zippyshare.com |
| unknown |
fonts.googleapis.com |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
ocsp.pki.goog |
| whitelisted |
fonts.gstatic.com |
| whitelisted |
incarnatepicturesque.com |
| unknown |
www.google-analytics.com |
| whitelisted |
stats.g.doubleclick.net |
| whitelisted |
www.google.com |
| whitelisted |
www.google.de |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
1080 | svchost.exe | Potentially Bad Traffic | ET INFO File Sharing Related Domain in DNS Lookup (zippyshare .com) |
3484 | iexplore.exe | Potentially Bad Traffic | ET INFO File Sharing Related Domain in HTTP Request (zippyshare .com) |
3484 | iexplore.exe | Potentially Bad Traffic | ET INFO File Sharing Related Domain in HTTP Request (zippyshare .com) |
3484 | iexplore.exe | Potentially Bad Traffic | ET INFO File Sharing Related Domain in HTTP Request (zippyshare .com) |
3484 | iexplore.exe | Potentially Bad Traffic | ET INFO File Sharing Related Domain in HTTP Request (zippyshare .com) |
3484 | iexplore.exe | Potentially Bad Traffic | ET INFO File Sharing Related Domain in HTTP Request (zippyshare .com) |
3484 | iexplore.exe | Potentially Bad Traffic | ET INFO File Sharing Related Domain in HTTP Request (zippyshare .com) |
3484 | iexplore.exe | Potentially Bad Traffic | ET INFO File Sharing Related Domain in HTTP Request (zippyshare .com) |
3484 | iexplore.exe | Potentially Bad Traffic | ET INFO File Sharing Related Domain in HTTP Request (zippyshare .com) |
3484 | iexplore.exe | Potentially Bad Traffic | ET INFO File Sharing Related Domain in HTTP Request (zippyshare .com) |