URL:

https://www.getdrip.com

Full analysis: https://app.any.run/tasks/ae09a8f6-60a7-4a67-9d60-ebc44229e654
Verdict: Malicious activity
Analysis date: September 19, 2023, 21:29:08
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

358B4A7F8D14B708657167202BC539C7

SHA1:

BD32B56CD367D4314B7114D531771C2B7163645D

SHA256:

DA07CFF30BDF0F5E69CD93964EA383DCF4A010C10158280F6F00321C677086FE

SSDEEP:

3:N8DSLoVLdI:2OL5

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Application launched itself

      • iexplore.exe (PID: 3652)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
37
Monitored processes
2
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe

Process information

PID
CMD
Path
Indicators
Parent process
720"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3652 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\sechost.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
3652"C:\Program Files\Internet Explorer\iexplore.exe" "https://www.getdrip.com"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
Total events
25 707
Read events
25 475
Write events
232
Delete events
0

Modification events

(PID) Process:(3652) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
0
(PID) Process:(3652) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30847387
(PID) Process:(3652) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30847437
(PID) Process:(3652) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3652) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3652) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(3652) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3652) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3652) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3652) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
0
Suspicious files
62
Text files
143
Unknown types
0

Dropped files

PID
Process
Filename
Type
3652iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6BADA8974A10C4BD62CC921D13E43B18_711ED44619924BA6DC33E69F97E7FF63der
MD5:68D552D4AE17863339FF74F721958A10
SHA256:7CC4F4A6ABF536D5FFA836A180FF0B9BE04C1CD01B752715DD3A2E693EDF5518
720iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\75CA58072B9926F763A91F0CC2798706_056B48C93C4964C2E64C0A8958238656binary
MD5:D4FEE3DDC420F1DA8B15C160FBDD2925
SHA256:43F2F07F57CE4B3DB43F9FFE1F09B807FB613D8802CD472EBF75E7C99CF2898E
720iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B66240B0F6C84BD4857ABA60CF5CE4A0_5043E0F5DF723415C9EECC201C838A62binary
MD5:B9054E5C39DD7746B3529FC894C6CF35
SHA256:6446B9EAFE213BE581BD21AAEDE7A6617A990837330F6D8BF789A153B7EA2394
3652iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6BADA8974A10C4BD62CC921D13E43B18_711ED44619924BA6DC33E69F97E7FF63binary
MD5:8E8B1AC8A49F9DE90C16BB29FB2EC56B
SHA256:749703F3C98D95F8FE3F7698E7945824E3D031FB67D738FFB181E098951B0E98
720iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\BAD725C80F9E10846F35D039A996E4A8_88B6AE015495C1ECC395D19C1DD02894binary
MD5:7CC9B90153CE0D11D4FD8A6A389019F3
SHA256:357F3D24A8705635F4A1DFFC9B551553B9922EB939B60FBCA4AE3E116EF96BE6
720iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\CAF4703619713E3F18D8A9D5D88D6288_F2DAF19C1F776537105D08FC8D978464binary
MD5:FBFF54BC2EACB90563473A87BE3408D4
SHA256:42F679123FF8966E936204FCB37F4917E5439996A2CE1978F75135B984997134
720iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\F53EB4E574DE32C870452087D92DBEBB_3C3A56E06D3837B2D69F84FDC8E6F80Dbinary
MD5:0CE844FD168339BF446585941C23D2AD
SHA256:BC38F704D90AF48E5971D88EADD38487A9B70A0DFBD5B68EE3D871019B58AE77
3652iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\favicon[1].icoimage
MD5:DA597791BE3B6E732F0BC8B20E38EE62
SHA256:5B2C34B3C4E8DD898B664DBA6C3786E2FF9869EFF55D673AA48361F11325ED07
3652iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.icoimage
MD5:DA597791BE3B6E732F0BC8B20E38EE62
SHA256:5B2C34B3C4E8DD898B664DBA6C3786E2FF9869EFF55D673AA48361F11325ED07
720iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B66240B0F6C84BD4857ABA60CF5CE4A0_5043E0F5DF723415C9EECC201C838A62binary
MD5:771F131E6E4883315AEC66AC2F6DC3FF
SHA256:AACEDE6D1B4F30C0049ECFA6B349E33733E0AA4E7A3EF526FA6084EFB16CB414
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
31
TCP/UDP connections
103
DNS requests
46
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
720
iexplore.exe
GET
200
108.138.2.107:80
http://o.ss2.us//MEowSDBGMEQwQjAJBgUrDgMCGgUABBSLwZ6EW5gdYc9UaSEaaLjjETNtkAQUv1%2B30c7dH4b0W1Ws3NcQwg6piOcCCQCnDkpMNIK3fw%3D%3D
unknown
der
2.02 Kb
unknown
3652
iexplore.exe
GET
200
178.79.242.0:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?7033774c17e4a793
unknown
compressed
4.66 Kb
unknown
720
iexplore.exe
GET
200
13.32.98.91:80
http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwdzEkpLy9ROx7U76vGUhC06D6E%3D
unknown
der
1.39 Kb
unknown
3652
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA8Ull8gIGmZT9XHrHiJQeI%3D
unknown
der
1.47 Kb
unknown
3652
iexplore.exe
GET
200
178.79.242.0:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?80bf958c58d95605
unknown
compressed
4.66 Kb
unknown
720
iexplore.exe
GET
200
52.222.226.205:80
http://ocsp.r2m02.amazontrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRmbQtwnInkvkvr7BNFR%2BS2lTYPjAQUwDFSzVpQw4J8dHHOy%2Bmc%2BXrrguICEA7Dhfqce9Vs2vwXT43aFOs%3D
unknown
der
471 b
unknown
720
iexplore.exe
GET
200
13.32.98.91:80
http://ocsp.rootg2.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBSIfaREXmfqfJR3TkMYnD7O5MhzEgQUnF8A36oB1zArOIiiuG1KnPIRkYMCEwZ%2FlEoqJ83z%2BsKuKwH5CO65xMY%3D
unknown
der
1.51 Kb
unknown
GET
200
142.250.184.227:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
unknown
der
1.41 Kb
unknown
720
iexplore.exe
GET
200
142.250.184.227:80
http://ocsp.pki.goog/s/gts1d4/3px9rUJEoco/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSMBFDqU0NJQdZdEGU3bkhj0FoRrQQUJeIYDrJXkZQq5dRdhpCD3lOzuJICEGRTVUJg8C4fCYhEf7ONV2Q%3D
unknown
der
471 b
unknown
720
iexplore.exe
GET
200
23.212.210.158:80
http://x1.c.lencr.org/
unknown
der
717 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3284
svchost.exe
239.255.255.250:1900
whitelisted
720
iexplore.exe
54.211.183.185:443
www.getdrip.com
AMAZON-AES
US
unknown
4
System
192.168.100.255:137
whitelisted
3652
iexplore.exe
92.123.104.67:443
www.bing.com
Akamai International B.V.
DE
unknown
3652
iexplore.exe
178.79.242.0:80
ctldl.windowsupdate.com
LLNW
DE
whitelisted
3652
iexplore.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
720
iexplore.exe
108.138.2.107:80
o.ss2.us
AMAZON-02
US
whitelisted
720
iexplore.exe
13.32.98.91:80
ocsp.rootg2.amazontrust.com
AMAZON-02
US
unknown
720
iexplore.exe
52.222.226.205:80
ocsp.r2m02.amazontrust.com
AMAZON-02
US
unknown
720
iexplore.exe
199.60.103.29:443
www.drip.com
Cloudflare London, LLC
US
unknown

DNS requests

Domain
IP
Reputation
www.getdrip.com
  • 54.211.183.185
  • 52.205.189.162
  • 54.164.26.233
  • 54.210.18.233
whitelisted
api.bing.com
  • 13.107.5.80
whitelisted
www.bing.com
  • 92.123.104.67
  • 92.123.104.31
  • 92.123.104.64
  • 92.123.104.40
  • 92.123.104.7
  • 92.123.104.32
  • 92.123.104.34
  • 92.123.104.60
  • 92.123.104.49
whitelisted
ctldl.windowsupdate.com
  • 178.79.242.0
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
o.ss2.us
  • 108.138.2.107
  • 108.138.2.195
  • 108.138.2.173
  • 108.138.2.10
whitelisted
ocsp.rootg2.amazontrust.com
  • 13.32.98.91
whitelisted
ocsp.rootca1.amazontrust.com
  • 13.32.98.91
shared
ocsp.r2m02.amazontrust.com
  • 52.222.226.205
whitelisted
www.drip.com
  • 199.60.103.29
  • 199.60.103.227
unknown

Threats

PID
Process
Class
Message
720
iexplore.exe
Potential Corporate Privacy Violation
AV POLICY Observed TikTok Domain in TLS SNI (tiktok.com)
No debug info