URL:

archive.org

Full analysis: https://app.any.run/tasks/6f4f9ffc-6516-440d-b88f-6e772b25eb9b
Verdict: Malicious activity
Analysis date: January 03, 2024, 18:35:43
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
opendir
Indicators:
MD5:

3660D3164B7BF9624969267EC54288D3

SHA1:

6D1C224ADE33223178BF7BC2D30F4E605C1A4302

SHA256:

B83974D09BEF2F6E3513026FC9F2A92A0C5EF8C97E86C060AB7B61889A7B309A

SSDEEP:

3:+aKXC:+xXC

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Application launched itself

      • iexplore.exe (PID: 2036)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
36
Monitored processes
2
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe

Process information

PID
CMD
Path
Indicators
Parent process
2036"C:\Program Files\Internet Explorer\iexplore.exe" "archive.org"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2204"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2036 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
Total events
22 166
Read events
22 091
Write events
73
Delete events
2

Modification events

(PID) Process:(2036) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
0
(PID) Process:(2036) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30847387
(PID) Process:(2036) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30847437
(PID) Process:(2036) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(2036) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(2036) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(2036) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2036) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2036) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2036) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
0
Suspicious files
14
Text files
85
Unknown types
0

Dropped files

PID
Process
Filename
Type
2204iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\223DE96EE265046957A660ED7C9DD9E7_EFF9B9BA98DEAA773F261FA85A0B1771binary
MD5:01BBAEF8FD6271B10FE37376BC55EF17
SHA256:E78013DAEB2F4DE3B102240283ABA1AA7B681011DC7C021E2D25153181867EC4
2204iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\223DE96EE265046957A660ED7C9DD9E7_EFF9B9BA98DEAA773F261FA85A0B1771der
MD5:9C07FE7D435AE9F50A41057AEA3B65DA
SHA256:B355125F70F148B31CCC47CA791CC9DAEAA87B31C548C371C56B29F847675368
2204iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\book-lend[1].pngimage
MD5:23E6AA5AB152C3767E32664EE1139E17
SHA256:C0074EFFABE2450A2617CA965A4067BFD96E4F5E3FE0366B56E34FE0B243300D
2204iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:C5FB4065E31E7FC06867C96B79635A6B
SHA256:A4255647AA8E2AF332A7A55A7A726E3FD07C1B4C8C31711E0DFC59F9563952A8
2204iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\librivoxaudio[1].jpgimage
MD5:54F08CCDFBEE6E25EF9B520DA764FBAB
SHA256:3FA57A28226F48EB0FC258789949E80E5F7F66F2E8F2A4983CA0D9A6CA7AB251
2204iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\widgetOL[1].pngimage
MD5:3F422331B6DB980D51D63DC24B66CB6E
SHA256:7411FAF158712BB4F8ACCEBC394734AD3EE29AC33BA3E64237C2704C0D477473
2204iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\web.0b09e7de6b3c58366582f2f53c672cfd[1].svgimage
MD5:F077BAB444AEEFE1C684A83B7A8DB20F
SHA256:BD88582D8E4DD80FB86EEF013862DDC0164BFC87DCFBE986F75EB0858F4F6624
2204iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\index.34c417fd1d63[1].csstext
MD5:34C417FD1D634C81D22EE138AD2E2CEA
SHA256:79EA0F5DCD5558CCCEC196A159B6D05BE0F5E6163E9873006D423357A20DC3D4
2204iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\tv.1a3d4b51378ef7aedcaa3cd2a0a8fe8b[1].svgimage
MD5:B2D928860F4B2519742A247FE0BEE4E6
SHA256:47DA4B25675FE7B79E37403593F32D92968C25E1E0A13F9BF7EF58BA616FC45C
2204iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\clevelandart[1].jpgimage
MD5:751305A65865EA485BAD328C37C9A53C
SHA256:69FCE9A899CA9F337E0B531D2E91B258B41A388B221380E148DBFA0A69B68760
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
17
TCP/UDP connections
33
DNS requests
11
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2204
iexplore.exe
GET
200
184.24.77.199:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?47f35deae42e081d
unknown
compressed
4.66 Kb
unknown
2204
iexplore.exe
GET
200
207.241.224.2:80
http://archive.org/
unknown
compressed
37.7 Kb
unknown
2204
iexplore.exe
GET
200
184.24.77.199:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?31f7b821c08f5ff0
unknown
compressed
4.66 Kb
unknown
2204
iexplore.exe
GET
200
184.24.77.199:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?2169a3e6a7f6c6aa
unknown
compressed
4.66 Kb
unknown
2204
iexplore.exe
GET
200
192.124.249.24:80
http://ocsp.godaddy.com//MEIwQDA%2BMDwwOjAJBgUrDgMCGgUABBQdI2%2BOBkuXH93foRUj4a7lAr4rGwQUOpqFBxBnKLbv9r0FQW4gwZTaD94CAQc%3D
unknown
binary
2.01 Kb
unknown
2036
iexplore.exe
GET
304
184.24.77.199:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?111b88f027149bc7
unknown
unknown
2036
iexplore.exe
GET
304
184.24.77.199:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?56a48ccbaf965781
unknown
unknown
2204
iexplore.exe
GET
200
184.24.77.199:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?45a9dd4385f2d15b
unknown
compressed
4.66 Kb
unknown
2204
iexplore.exe
GET
200
184.24.77.199:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?b91080394e982349
unknown
compressed
4.66 Kb
unknown
2204
iexplore.exe
GET
200
192.124.249.24:80
http://ocsp.godaddy.com//MEQwQjBAMD4wPDAJBgUrDgMCGgUABBTkIInKBAzXkF0Qh0pel3lfHJ9GPAQU0sSw0pHUTBFxs2HLPaH%2B3ahq1OMCAxvnFQ%3D%3D
unknown
binary
1.98 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
2204
iexplore.exe
207.241.224.2:80
archive.org
INTERNET-ARCHIVE
US
malicious
2204
iexplore.exe
207.241.224.2:443
archive.org
INTERNET-ARCHIVE
US
malicious
2204
iexplore.exe
184.24.77.199:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
2204
iexplore.exe
192.124.249.24:80
ocsp.godaddy.com
SUCURI-SEC
US
unknown
2036
iexplore.exe
207.241.224.2:80
archive.org
INTERNET-ARCHIVE
US
malicious
2036
iexplore.exe
104.126.37.171:443
www.bing.com
Akamai International B.V.
DE
unknown
2036
iexplore.exe
184.24.77.199:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
2036
iexplore.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
archive.org
  • 207.241.224.2
whitelisted
ctldl.windowsupdate.com
  • 184.24.77.199
  • 184.24.77.205
  • 184.24.77.191
whitelisted
ocsp.godaddy.com
  • 192.124.249.24
  • 192.124.249.22
  • 192.124.249.41
  • 192.124.249.36
  • 192.124.249.23
whitelisted
api.bing.com
  • 13.107.5.80
whitelisted
www.bing.com
  • 104.126.37.171
  • 104.126.37.129
  • 104.126.37.178
  • 104.126.37.185
  • 104.126.37.177
  • 104.126.37.128
  • 104.126.37.170
  • 104.126.37.176
  • 104.126.37.130
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
iecvlist.microsoft.com
  • 152.199.19.161
whitelisted
r20swj13mr.microsoft.com
  • 152.199.19.161
whitelisted
ia801206.us.archive.org
  • 207.241.228.26
unknown

Threats

No threats detected
No debug info