| URL: | ifdnzact.com |
| Full analysis: | https://app.any.run/tasks/17794579-d8df-4cb7-9c75-13d1d524aba3 |
| Verdict: | Malicious activity |
| Analysis date: | January 11, 2024, 21:15:57 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MD5: | 05A7A0C0CDBF02AF5ABA4CDF990613A8 |
| SHA1: | C8F5F93C65A11DBF75DF465F8FB42A7656611DDF |
| SHA256: | B3A58BB7888FCC5EB5D8F99889FF2230FF151542AE38304098351C0FAB1DB2EE |
| SSDEEP: | 3:CBTRZI:CXZI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 116 | "C:\Program Files\Internet Explorer\iexplore.exe" "ifdnzact.com" | C:\Program Files\Internet Explorer\iexplore.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| 324 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:116 CREDAT:267521 /prefetch:2 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| (PID) Process: | (116) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPDaysSinceLastAutoMigration |
Value: 0 | |||
| (PID) Process: | (116) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPLastLaunchHighDateTime |
Value: 30847387 | |||
| (PID) Process: | (116) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager |
| Operation: | write | Name: | NextCheckForUpdateHighDateTime |
Value: 30847437 | |||
| (PID) Process: | (116) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (116) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (116) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main |
| Operation: | write | Name: | CompatibilityFlags |
Value: 0 | |||
| (PID) Process: | (116) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (116) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (116) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (116) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 324 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\min[1].js | text | |
MD5:C16C3A4C0FAD29106F34D00E89F6886E | SHA256:097786D677A859B7BC87E285377B083B76D66A2FC2832A16BCD50B0E99DF77FF | |||
| 324 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\montserrat-regular[1].eot | binary | |
MD5:F6215401E6AAE823823C97578C0E132E | SHA256:0B32375761DF803FD122DE37B123251BB4997F14EF68E9E520289FC49B41FB00 | |||
| 324 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\px[1].js | text | |
MD5:F84F931C0DD37448E03F0DABF4E4CA9F | SHA256:5C1D5FD46A88611C31ECBB8FFC1142A7E74EC7FB7D72BD3891131C880EF3F584 | |||
| 324 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\arrrow[1].png | image | |
MD5:80D42C82A6C37DA90210FD60A2F36128 | SHA256:A1626E2D9160A0890A0A8D6E3AF9E7095D68A24F9FB5AC8A166000C9A2581E10 | |||
| 116 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\EAF8AA29A62AB29E614331747385D816_F9E4DC0B9D5C777357D7DB8DEF51118A | binary | |
MD5:C4451446E8A99D89213EF097D9FB2D3F | SHA256:717D3FEFBE0BBF344A96D5B74534886A5FCD6113767562796017F458BBC4B13C | |||
| 324 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\bg1[1].png | image | |
MD5:825CCD29AC102FCADAF92B2343D5917B | SHA256:0878FB2875C0AD852DE8FB3E8F443AFDF3064890F1443B3FECCC274382F913CD | |||
| 116 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157 | binary | |
MD5:5E33146017FE52E4CBBF4D35D81E813A | SHA256:8EF808F2E94FEF7FAEFA94DAF09C020FF586318644FC849A492822DB8AA368F1 | |||
| 324 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\montserrat-bold[1].eot | binary | |
MD5:65E03151914E450958061CBB762EEBE1 | SHA256:64C4FEBD551454BA2B82E10DAC1E18E5D5253F9C4D152F6C7E56186A5C823E4A | |||
| 116 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157 | compressed | |
MD5:1BFE591A4FE3D91B03CDF26EAACD8F89 | SHA256:9CF94355051BF0F4A45724CA20D1CC02F76371B963AB7D1E38BD8997737B13D8 | |||
| 116 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\EAF8AA29A62AB29E614331747385D816_F9E4DC0B9D5C777357D7DB8DEF51118A | der | |
MD5:3F929B3A825C6D4580113F29AF7DFD28 | SHA256:DDADBFF532D4BEBF687A2ACD0F2981A7D53A3616A998C01A5BCFD3D379E83811 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
324 | iexplore.exe | GET | 200 | 208.91.196.46:80 | http://ifdnzact.com/ | unknown | html | 1.84 Kb | unknown |
324 | iexplore.exe | GET | 200 | 208.91.196.46:80 | http://ifdnzact.com/?fp=ZS0i2VWr1AVDwYa5VsmhLfFoXr0JxqUI1WOzgOPg4xTrtCJC%2F72YmSOVbqNW5%2FBkg3fv8ypQu4OHeuZJyPQD7oyfcFkwIMgrCykjbckDsyRLyJOUmY0JlCFIzfqdEOQ0iPQH1uYg5Ww6TeisFdPDr%2B%2BjLsMasraJfcwFsS8F1jy7YLwBnVlft99vSww%2BlgjL6Py3OcSGFoJawcRKKiey%2FOSUmlUTrypXk%2BhUS7QtBEhBb0zwM60dqTQu2Hwr7YluUM%2B7bbFGkSsJ8MfunOSCHA%3D%3D&poru=syfE%2FZh%2FTuNVCeunJmMQBPxyw3AJwMHTmBK6Mk%2FjvyE%3D&_opnslfp=1& | unknown | html | 39.9 Kb | unknown |
324 | iexplore.exe | GET | 200 | 208.91.196.46:80 | http://ifdnzact.com/px.js?ch=1 | unknown | text | 346 b | unknown |
324 | iexplore.exe | GET | 200 | 208.91.196.46:80 | http://ifdnzact.com/px.js?ch=2 | unknown | text | 346 b | unknown |
324 | iexplore.exe | GET | 200 | 208.91.196.253:80 | http://i3.cdn-image.com/__media__/js/min.js?v2.3 | unknown | text | 8.24 Kb | unknown |
324 | iexplore.exe | GET | 200 | 208.91.196.253:80 | http://i3.cdn-image.com/__media__/fonts/montserrat-regular/montserrat-regular.eot | unknown | binary | 28.5 Kb | unknown |
324 | iexplore.exe | GET | 200 | 208.91.196.253:80 | http://i3.cdn-image.com/__media__/fonts/montserrat-bold/montserrat-bold.eot | unknown | binary | 29.0 Kb | unknown |
324 | iexplore.exe | GET | 200 | 208.91.196.253:80 | http://i3.cdn-image.com/__media__/pics/28905/arrrow.png | unknown | image | 283 b | unknown |
324 | iexplore.exe | GET | 200 | 208.91.196.253:80 | http://i3.cdn-image.com/__media__/pics/29590/bg1.png | unknown | image | 17.5 Kb | unknown |
116 | iexplore.exe | GET | 404 | 208.91.196.46:80 | http://ifdnzact.com/favicon.ico | unknown | text | 10 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 192.168.100.255:138 | — | — | — | unknown |
324 | iexplore.exe | 208.91.196.46:80 | ifdnzact.com | CONFLUENCE-NETWORK-INC | VG | unknown |
324 | iexplore.exe | 208.91.196.253:80 | i3.cdn-image.com | CONFLUENCE-NETWORK-INC | VG | unknown |
116 | iexplore.exe | 208.91.196.46:80 | ifdnzact.com | CONFLUENCE-NETWORK-INC | VG | unknown |
116 | iexplore.exe | 104.126.37.152:443 | www.bing.com | Akamai International B.V. | DE | unknown |
116 | iexplore.exe | 93.184.221.240:80 | ctldl.windowsupdate.com | EDGECAST | GB | whitelisted |
116 | iexplore.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
116 | iexplore.exe | 152.199.19.161:443 | r20swj13mr.microsoft.com | EDGECAST | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
ifdnzact.com |
| malicious |
i3.cdn-image.com |
| whitelisted |
api.bing.com |
| whitelisted |
www.bing.com |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
r20swj13mr.microsoft.com |
| whitelisted |
iecvlist.microsoft.com |
| whitelisted |