| URL: | archive.org |
| Full analysis: | https://app.any.run/tasks/6f4f9ffc-6516-440d-b88f-6e772b25eb9b |
| Verdict: | Malicious activity |
| Analysis date: | January 03, 2024, 18:35:43 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MD5: | 3660D3164B7BF9624969267EC54288D3 |
| SHA1: | 6D1C224ADE33223178BF7BC2D30F4E605C1A4302 |
| SHA256: | B83974D09BEF2F6E3513026FC9F2A92A0C5EF8C97E86C060AB7B61889A7B309A |
| SSDEEP: | 3:+aKXC:+xXC |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2036 | "C:\Program Files\Internet Explorer\iexplore.exe" "archive.org" | C:\Program Files\Internet Explorer\iexplore.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| 2204 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2036 CREDAT:267521 /prefetch:2 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| (PID) Process: | (2036) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPDaysSinceLastAutoMigration |
Value: 0 | |||
| (PID) Process: | (2036) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPLastLaunchHighDateTime |
Value: 30847387 | |||
| (PID) Process: | (2036) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager |
| Operation: | write | Name: | NextCheckForUpdateHighDateTime |
Value: 30847437 | |||
| (PID) Process: | (2036) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (2036) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (2036) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main |
| Operation: | write | Name: | CompatibilityFlags |
Value: 0 | |||
| (PID) Process: | (2036) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2036) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2036) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2036) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2204 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157 | compressed | |
MD5:1BFE591A4FE3D91B03CDF26EAACD8F89 | SHA256:9CF94355051BF0F4A45724CA20D1CC02F76371B963AB7D1E38BD8997737B13D8 | |||
| 2204 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157 | binary | |
MD5:C5FB4065E31E7FC06867C96B79635A6B | SHA256:A4255647AA8E2AF332A7A55A7A726E3FD07C1B4C8C31711E0DFC59F9563952A8 | |||
| 2204 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\EB2C4AB8B68FFA4B7733A9139239A396_D76DB901EE986B889F30D8CC06229E2D | der | |
MD5:4569A912C39B1AC59C672CB92E4DE6AA | SHA256:7F52D379ECDB765C21399FC40685376FECBBB6037A1110BE163D83842EA8017E | |||
| 2204 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\L29VSDD5.htm | html | |
MD5:4C3693E0CD96D82D0CE268AE318768EF | SHA256:9F512955EC35275CA4B1EB26216825BBD5107CB6019A807355D0F0DC55603588 | |||
| 2204 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\EB2C4AB8B68FFA4B7733A9139239A396_D76DB901EE986B889F30D8CC06229E2D | binary | |
MD5:D0172DB58E51FE5FDE32DA6A0C1F4E1B | SHA256:2CB11363C85128A16FAAC94E39BB8785192862B8078EF60022F059204CE81C86 | |||
| 2204 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\223DE96EE265046957A660ED7C9DD9E7_EFF9B9BA98DEAA773F261FA85A0B1771 | binary | |
MD5:01BBAEF8FD6271B10FE37376BC55EF17 | SHA256:E78013DAEB2F4DE3B102240283ABA1AA7B681011DC7C021E2D25153181867EC4 | |||
| 2204 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\book-lend[1].png | image | |
MD5:23E6AA5AB152C3767E32664EE1139E17 | SHA256:C0074EFFABE2450A2617CA965A4067BFD96E4F5E3FE0366B56E34FE0B243300D | |||
| 2204 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\internetarcade[1].jpg | image | |
MD5:6052B4DC6CFDC2EB57276B517711A997 | SHA256:CB74B2D5D82325E7BAA334263071ED477F15622E15E354D4C916D55E263C01BE | |||
| 2204 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\librivoxaudio[1].jpg | image | |
MD5:54F08CCDFBEE6E25EF9B520DA764FBAB | SHA256:3FA57A28226F48EB0FC258789949E80E5F7F66F2E8F2A4983CA0D9A6CA7AB251 | |||
| 2204 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\consolelivingroom[1].jpg | image | |
MD5:96D642DB40CE837BAD43E279B1C7CA5B | SHA256:D6684AECF1473F26943A6B2538AF9E55AE0D4A1BBEC4EAD43C8FE438582DEB19 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2204 | iexplore.exe | GET | 200 | 207.241.224.2:80 | http://archive.org/ | unknown | compressed | 37.7 Kb | unknown |
2204 | iexplore.exe | GET | 200 | 184.24.77.199:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?b58e958bd8496386 | unknown | compressed | 4.66 Kb | unknown |
2204 | iexplore.exe | GET | 200 | 184.24.77.199:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?76dd7891a48e2cd9 | unknown | compressed | 4.66 Kb | unknown |
2204 | iexplore.exe | GET | 200 | 184.24.77.199:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?0ef1d8f42f418834 | unknown | compressed | 4.66 Kb | unknown |
2204 | iexplore.exe | GET | 200 | 184.24.77.199:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?45a9dd4385f2d15b | unknown | compressed | 4.66 Kb | unknown |
2204 | iexplore.exe | GET | 200 | 184.24.77.199:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?47f35deae42e081d | unknown | compressed | 4.66 Kb | unknown |
2204 | iexplore.exe | GET | 200 | 184.24.77.199:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?31f7b821c08f5ff0 | unknown | compressed | 4.66 Kb | unknown |
2204 | iexplore.exe | GET | 200 | 184.24.77.199:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?2169a3e6a7f6c6aa | unknown | compressed | 4.66 Kb | unknown |
2204 | iexplore.exe | GET | 200 | 184.24.77.199:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?b91080394e982349 | unknown | compressed | 4.66 Kb | unknown |
2204 | iexplore.exe | GET | 200 | 192.124.249.24:80 | http://ocsp.godaddy.com//MEQwQjBAMD4wPDAJBgUrDgMCGgUABBTkIInKBAzXkF0Qh0pel3lfHJ9GPAQU0sSw0pHUTBFxs2HLPaH%2B3ahq1OMCAxvnFQ%3D%3D | unknown | binary | 1.98 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2204 | iexplore.exe | 207.241.224.2:80 | archive.org | INTERNET-ARCHIVE | US | malicious |
2204 | iexplore.exe | 207.241.224.2:443 | archive.org | INTERNET-ARCHIVE | US | malicious |
2204 | iexplore.exe | 184.24.77.199:80 | ctldl.windowsupdate.com | Akamai International B.V. | DE | unknown |
2204 | iexplore.exe | 192.124.249.24:80 | ocsp.godaddy.com | SUCURI-SEC | US | unknown |
2036 | iexplore.exe | 207.241.224.2:80 | archive.org | INTERNET-ARCHIVE | US | malicious |
2036 | iexplore.exe | 104.126.37.171:443 | www.bing.com | Akamai International B.V. | DE | unknown |
2036 | iexplore.exe | 184.24.77.199:80 | ctldl.windowsupdate.com | Akamai International B.V. | DE | unknown |
2036 | iexplore.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
archive.org |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
ocsp.godaddy.com |
| whitelisted |
api.bing.com |
| whitelisted |
www.bing.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
iecvlist.microsoft.com |
| whitelisted |
r20swj13mr.microsoft.com |
| whitelisted |
ia801206.us.archive.org |
| unknown |