| URL: | getfile.dokpub.com |
| Full analysis: | https://app.any.run/tasks/8c880cc2-78b8-4caa-800e-3bfc5debac39 |
| Verdict: | Malicious activity |
| Analysis date: | February 13, 2024, 12:08:21 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MD5: | 0A6FE0BBEFF675C21A7CB339542AD14E |
| SHA1: | 2ABCFF428955EB20021E7AE1D1C465FD7255A321 |
| SHA256: | DEE344E992B8C78146CBCE94CBED4F9F7C6F50496A64F2B3FFE1DD3EBD693A46 |
| SSDEEP: | 3:TB4GT:yGT |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 3668 | "C:\Program Files\Internet Explorer\iexplore.exe" "getfile.dokpub.com" | C:\Program Files\Internet Explorer\iexplore.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| 3972 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3668 CREDAT:267521 /prefetch:2 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| (PID) Process: | (3668) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPDaysSinceLastAutoMigration |
Value: 1 | |||
| (PID) Process: | (3668) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPLastLaunchLowDateTime |
Value: | |||
| (PID) Process: | (3668) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPLastLaunchHighDateTime |
Value: 31088245 | |||
| (PID) Process: | (3668) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager |
| Operation: | write | Name: | NextCheckForUpdateLowDateTime |
Value: | |||
| (PID) Process: | (3668) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager |
| Operation: | write | Name: | NextCheckForUpdateHighDateTime |
Value: 31088245 | |||
| (PID) Process: | (3668) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (3668) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (3668) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (3668) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main |
| Operation: | write | Name: | CompatibilityFlags |
Value: 0 | |||
| (PID) Process: | (3668) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3972 | iexplore.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\7JONOM7H.txt | text | |
MD5:47451BD3C42DEE0E7949BCDCF666985E | SHA256:07469A90745FC7D2262E523722BA77D6F08B7E4DC6D0E4609981DCBCA6C28B21 | |||
| 3972 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\81B9B36F9ABC4DA631A4713EE66FAEC6_54E4CEBDB015BBB5A9EA8D3BFB187ABC | der | |
MD5:29F073BEFC3223BCFECE3467617F4D0B | SHA256:740CBA1672FAD2A1AAED060C91C7CDB9488A7B2232E18E2670A86D4F7D890D60 | |||
| 3972 | iexplore.exe | C:\Users\admin\AppData\Local\Temp\Low\CabF126.tmp | compressed | |
MD5:AC05D27423A85ADC1622C714F2CB6184 | SHA256:C6456E12E5E53287A547AF4103E0397CB9697E466CF75844312DC296D43D144D | |||
| 3972 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506 | compressed | |
MD5:AC05D27423A85ADC1622C714F2CB6184 | SHA256:C6456E12E5E53287A547AF4103E0397CB9697E466CF75844312DC296D43D144D | |||
| 3972 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751 | binary | |
MD5:8D6D147510ED71FDB16001C5F6DDCF1D | SHA256:D130A9052DEB0341AF809D773C5CFDA919E95DBC2D4587006005341E83C1C79A | |||
| 3972 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\0DA515F703BB9B49479E8697ADB0B955_7DAD5545724AA2C98C55095F428499FB | der | |
MD5:339C7D3E69F1ACB8E2B72AEF8463A122 | SHA256:97BC26A3A2DFC8895A5070BECCEC46ABE3176E7243E65A9A5F7E8139ADF2837D | |||
| 3972 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\0DA515F703BB9B49479E8697ADB0B955_7DAD5545724AA2C98C55095F428499FB | binary | |
MD5:62FCC2FD5B28B97AE88F4609D321BF7A | SHA256:C33B5B0AA888B26F336DDA5B5F9C0F12CDC02F6403590AC7CF812E67EBB39CCC | |||
| 3972 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\81B9B36F9ABC4DA631A4713EE66FAEC6_D391C1D03A63B66863342F8A4B64298F | binary | |
MD5:B445DF85B8886F0A643020C09C0C30AC | SHA256:CB73A7163DDD6E87D072AD3A03CE6586544E9A768857EDAA9967946DA393DE5B | |||
| 3972 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\NY0CYG1G.htm | html | |
MD5:E04BEE368CDBE3BC45AF81CE5E5F2130 | SHA256:44FC61FF075FFC3669D5B78F0B79E5B4CCE6736AADCDBAA09FF5C0FD444C992A | |||
| 3972 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\66F835E41EC6A985EB9271E4A70169D7_CF44E3C99F7F4AC558EEB35244F7E046 | binary | |
MD5:55B8BEC391BDA3B36BA6B278B00BC859 | SHA256:400F3FDFEA8C414B1FF8C57A6EAC371661DBC996E319D15503BD28553736464C | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3972 | iexplore.exe | GET | 304 | 93.184.221.240:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?64db15c300a7b163 | unknown | — | — | unknown |
3972 | iexplore.exe | GET | 200 | 93.184.221.240:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?f78d505714a595e3 | unknown | compressed | 65.2 Kb | unknown |
3972 | iexplore.exe | GET | 301 | 142.132.255.217:80 | http://getfile.dokpub.com/ | unknown | — | — | unknown |
3972 | iexplore.exe | GET | 200 | 104.18.20.226:80 | http://ocsp.globalsign.com/gseccovsslca2018/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBSTMjK03nNiYoQYvu4Izyfn9OJNdAQUWHuOdSr%2BYYCqkEABrtboB0ZuP0gCDF1SAVAtbe%2BL4Z8Q4A%3D%3D | unknown | binary | 940 b | unknown |
3972 | iexplore.exe | GET | 200 | 104.18.20.226:80 | http://ocsp.globalsign.com/rootr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHUeP1PjGFkz6V8I7O6tApc%3D | unknown | binary | 1.41 Kb | unknown |
3972 | iexplore.exe | GET | 200 | 104.18.20.226:80 | http://ocsp.globalsign.com/gseccovsslca2018/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBSTMjK03nNiYoQYvu4Izyfn9OJNdAQUWHuOdSr%2BYYCqkEABrtboB0ZuP0gCDFgaqnmhz%2FKTI1ZyuA%3D%3D | unknown | binary | 939 b | unknown |
3972 | iexplore.exe | GET | 200 | 104.18.20.226:80 | http://ocsp.globalsign.com/gseccovsslca2018/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBSTMjK03nNiYoQYvu4Izyfn9OJNdAQUWHuOdSr%2BYYCqkEABrtboB0ZuP0gCDF1SAVAtbe%2BL4Z8Q4A%3D%3D | unknown | binary | 940 b | unknown |
3972 | iexplore.exe | GET | 200 | 104.18.20.226:80 | http://ocsp.globalsign.com/gseccovsslca2018/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBSTMjK03nNiYoQYvu4Izyfn9OJNdAQUWHuOdSr%2BYYCqkEABrtboB0ZuP0gCDF1SAVAtbe%2BL4Z8Q4A%3D%3D | unknown | binary | 939 b | unknown |
3972 | iexplore.exe | GET | 200 | 104.18.20.226:80 | http://ocsp.globalsign.com/gseccovsslca2018/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBSTMjK03nNiYoQYvu4Izyfn9OJNdAQUWHuOdSr%2BYYCqkEABrtboB0ZuP0gCDF1SAVAtbe%2BL4Z8Q4A%3D%3D | unknown | binary | 940 b | unknown |
3668 | iexplore.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | binary | 471 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
3972 | iexplore.exe | 142.132.255.217:80 | getfile.dokpub.com | Hetzner Online GmbH | DE | unknown |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
3972 | iexplore.exe | 142.132.255.217:443 | getfile.dokpub.com | Hetzner Online GmbH | DE | unknown |
3972 | iexplore.exe | 93.184.221.240:80 | ctldl.windowsupdate.com | EDGECAST | GB | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
3972 | iexplore.exe | 2.19.45.2:80 | x1.c.lencr.org | AKAMAI-AS | DE | whitelisted |
3972 | iexplore.exe | 77.88.55.88:443 | yandex.ru | YANDEX LLC | RU | whitelisted |
3972 | iexplore.exe | 87.250.251.119:443 | informer.yandex.ru | YANDEX LLC | RU | whitelisted |
3972 | iexplore.exe | 93.158.134.119:443 | informer.yandex.ru | YANDEX LLC | RU | whitelisted |
Domain | IP | Reputation |
|---|---|---|
getfile.dokpub.com |
| malicious |
ctldl.windowsupdate.com |
| whitelisted |
x1.c.lencr.org |
| whitelisted |
yandex.ru |
| whitelisted |
informer.yandex.ru |
| whitelisted |
mc.yandex.ru |
| whitelisted |
ocsp.globalsign.com |
| whitelisted |
ocsp2.globalsign.com |
| whitelisted |
mc.yandex.com |
| whitelisted |
api.bing.com |
| whitelisted |