URL:

http://www.picswan.com/img/share.php?id=23AE_4C8B30EA

Full analysis: https://app.any.run/tasks/8b8a1a57-9f72-433d-ab7b-f10ce2a84d99
Verdict: Malicious activity
Analysis date: January 11, 2021, 20:38:50
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

958A2C2EADA473F1B956A2C44742D5C8

SHA1:

90E208BDC7D992CC64D71B0CC8797C4CB6DBDF51

SHA256:

C2D21BD0BA3BA472D274A03EBA9098C32DBD201996ECC7EB3F018502C874DB4C

SSDEEP:

3:N1KJS4IdIKM/KWN+ALVNwMYc6mMVgk:Cc4OIKMn+u1MVh

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executed via COM

      • FlashUtil32_26_0_0_131_ActiveX.exe (PID: 2968)
  • INFO

    • Application launched itself

      • iexplore.exe (PID: 2060)
    • Reads internet explorer settings

      • iexplore.exe (PID: 1748)
      • iexplore.exe (PID: 1872)
      • iexplore.exe (PID: 2996)
      • iexplore.exe (PID: 3224)
    • Changes internet zones settings

      • iexplore.exe (PID: 2060)
    • Adds / modifies Windows certificates

      • iexplore.exe (PID: 2060)
    • Reads settings of System Certificates

      • iexplore.exe (PID: 2996)
      • iexplore.exe (PID: 2060)
      • iexplore.exe (PID: 3224)
    • Creates files in the user directory

      • iexplore.exe (PID: 1748)
      • FlashUtil32_26_0_0_131_ActiveX.exe (PID: 2968)
      • iexplore.exe (PID: 3224)
      • iexplore.exe (PID: 2996)
      • iexplore.exe (PID: 2060)
    • Changes settings of System certificates

      • iexplore.exe (PID: 2060)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
39
Monitored processes
6
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe iexplore.exe iexplore.exe iexplore.exe no specs flashutil32_26_0_0_131_activex.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1748"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2060 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
1872"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2060 CREDAT:726290 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exeiexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2060"C:\Program Files\Internet Explorer\iexplore.exe" "http://www.picswan.com/img/share.php?id=23AE_4C8B30EA"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2968C:\Windows\system32\Macromed\Flash\FlashUtil32_26_0_0_131_ActiveX.exe -EmbeddingC:\Windows\system32\Macromed\Flash\FlashUtil32_26_0_0_131_ActiveX.exesvchost.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
MEDIUM
Description:
Adobe® Flash® Player Installer/Uninstaller 26.0 r0
Exit code:
0
Version:
26,0,0,131
Modules
Images
c:\windows\system32\macromed\flash\flashutil32_26_0_0_131_activex.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2996"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2060 CREDAT:2495773 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
3224"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2060 CREDAT:1053996 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
Total events
1 963
Read events
1 537
Write events
421
Delete events
5

Modification events

(PID) Process:(2060) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateLowDateTime
Value:
3813615804
(PID) Process:(2060) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30861401
(PID) Process:(2060) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(2060) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(2060) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(2060) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(2060) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(2060) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
46000000A5000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
(PID) Process:(2060) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(2060) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
Executable files
0
Suspicious files
165
Text files
192
Unknown types
76

Dropped files

PID
Process
Filename
Type
1748iexplore.exeC:\Users\admin\AppData\Local\Temp\Low\Cab4BCD.tmp
MD5:
SHA256:
1748iexplore.exeC:\Users\admin\AppData\Local\Temp\Low\Tar4BCE.tmp
MD5:
SHA256:
2060iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
MD5:
SHA256:
1748iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\counter[1].jstext
MD5:F13B7026438F1468E8D6D0F16ABD686C
SHA256:F748867F22D4CFA4A24F9F5BACB9A8BBC10860C75D0CB37A883BB77871CA7E43
1748iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\pma[1].htmtext
MD5:B5BBEBDFFF1FB89109C1B95FB844F482
SHA256:876F81B245BDDC56705CF98E10EB213725C5D7517927F3B42A8844F5776B186F
1748iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\pub[1].jstext
MD5:52BE5DE67271D254E00B263D520D67B0
SHA256:3AD7CD17D9D176FFD1B7BB9BBC0892B44F3A8EE5C15D8343DFC5E41EF7D1EF5F
1748iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\pop[1].jstext
MD5:2BC5D246AD12BCB922C45496D628EDC8
SHA256:3FEC8B185156C30A890E1721519C9FF3D55D20CFEF3046C823CA738E7FECE924
1748iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\display[1].jstext
MD5:D1397FF04808C66AA22E05301AC313F4
SHA256:AA551D473DB1DA661175FF89A72C7B790162AC46283AA193F323A0015CF3490B
1748iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\jac[1].jstext
MD5:39D8CBD240A4C5B953B6F6B4FB7B83C2
SHA256:914BDFAC4784C1DDA0855BDED82B70439AF6E5A5A7C957E3AA1272E854117BFA
1748iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6BADA8974A10C4BD62CC921D13E43B18_28DEA62A0AE77228DD387E155AD0BA27binary
MD5:93C30963A94F20FAAB789CF4175FCEC9
SHA256:035ED8DC620F0077EDA5770A363E37EC9C939C7FCA49659DF2148032BD09B68F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
159
TCP/UDP connections
250
DNS requests
91
Threats
3

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1748
iexplore.exe
GET
200
151.139.128.11:80
http://cdn.popcash.net/pop.js
US
text
35.8 Kb
whitelisted
1748
iexplore.exe
GET
200
130.211.17.196:80
http://www.adnetworkperformance.com/a/display.php?r=453752
US
text
2.15 Kb
whitelisted
1748
iexplore.exe
GET
200
172.67.38.97:80
http://www.statcounter.com/counter/counter.js
US
text
13.8 Kb
whitelisted
1748
iexplore.exe
GET
204
130.211.17.196:80
http://www.adnetworkperformance.com/a/display.php?r=1023722
US
whitelisted
1748
iexplore.exe
GET
301
172.67.187.188:80
http://cdn.popmyads.com/pma.js
US
html
239 b
malicious
1748
iexplore.exe
GET
200
131.153.42.226:80
http://www.rips.icu/picswan.com/8qtj
US
html
1.73 Kb
suspicious
1748
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEAo3h2ReX7SMIk79G%2B0UDDw%3D
US
der
1.47 Kb
whitelisted
1748
iexplore.exe
GET
200
130.211.17.196:80
http://www.adnetworkperformance.com/ad/display.php?stamat=m%7C%2CoIid_diEqB1dQO0dEdHP3xP.3b7%2C39RpUO97DfecIw2MIckvXfoRRRRT_bX5j1nV4iCh9CI5xcWELMyqZJuXVXA4tNPTP-fO1TsGlUJHUxP_Ys8ESg%2C%2C&cbrandom=0.048916705489116974&cbtitle=Host%20your%20images%20for%20free&cbiframe=0&cbWidth=1280&cbHeight=644&cbdescription=MultiHoster%20is%20an%20easy%20image%20hosting%20solution%20for%20everyone&cbkeywords=image%20hosting%2C%20image%20hosting%20service%2C%20multiple%20image%20hosting%2C%20unlimited%20bandwidth%2C%20quick%20image%20hosting%2C%20torrent%20image%20host%2C%20file%20hosting%2C%20video%20hosting%2C%20bit%20torrent%2C%20screenshots%2C%20samples&cbref=
US
text
12.9 Kb
whitelisted
1748
iexplore.exe
GET
200
195.181.175.46:80
http://c1.popads.net/pop.js
DE
html
9.41 Kb
whitelisted
1748
iexplore.exe
GET
200
151.139.128.14:80
http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEDlyRDr5IrdR19NsEN0xNZU%3D
US
der
471 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1748
iexplore.exe
185.66.141.33:80
www.picswan.com
NForce Entertainment B.V.
NL
suspicious
1748
iexplore.exe
151.139.128.11:80
ads.juicyads.com
Highwinds Network Group, Inc.
US
malicious
1748
iexplore.exe
130.211.17.196:80
www.adnetworkperformance.com
Google Inc.
US
whitelisted
1748
iexplore.exe
172.67.38.97:80
www.statcounter.com
US
suspicious
1748
iexplore.exe
172.67.187.188:80
cdn.popmyads.com
US
unknown
1748
iexplore.exe
23.235.244.225:80
prscripts.com
SECURED SERVERS LLC
US
suspicious
1748
iexplore.exe
172.67.187.188:443
cdn.popmyads.com
US
unknown
1748
iexplore.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
1748
iexplore.exe
104.24.126.152:443
cdn.popmyads.com
Cloudflare Inc
US
shared
1748
iexplore.exe
151.139.128.14:80
ocsp.comodoca.com
Highwinds Network Group, Inc.
US
suspicious

DNS requests

Domain
IP
Reputation
www.picswan.com
  • 185.66.141.33
unknown
ads.juicyads.com
  • 151.139.128.11
whitelisted
cdn.popmyads.com
  • 172.67.187.188
  • 104.24.126.152
  • 104.24.127.152
malicious
cdn.popcash.net
  • 151.139.128.11
  • 151.139.128.10
whitelisted
www.adnetworkperformance.com
  • 130.211.17.196
unknown
www.statcounter.com
  • 172.67.38.97
  • 104.22.53.65
  • 104.22.52.65
whitelisted
prscripts.com
  • 23.235.244.225
  • 23.235.244.224
  • 131.153.42.226
  • 131.153.42.228
  • 131.153.42.227
  • 23.235.244.212
  • 23.235.244.227
  • 131.153.42.229
  • 23.235.244.226
  • 131.153.42.225
suspicious
api.bing.com
  • 13.107.5.80
whitelisted
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
ocsp.digicert.com
  • 93.184.220.29
whitelisted

Threats

PID
Process
Class
Message
1052
svchost.exe
Potentially Bad Traffic
ET INFO DNS Query for Suspicious .icu Domain
1052
svchost.exe
Potentially Bad Traffic
ET DNS Query to a *.top domain - Likely Hostile
1748
iexplore.exe
Potentially Bad Traffic
ET INFO HTTP Request to a *.top domain
No debug info