URL:

18stream.com

Full analysis: https://app.any.run/tasks/9d8954c2-e6d9-4edb-849e-82f8c7ff0517
Verdict: Malicious activity
Analysis date: January 07, 2024, 17:06:48
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

593E700BC1F25103BEEF9779C5E898E9

SHA1:

44AB6FF2875D8BF9E389C2C58DB7BF3969B19315

SHA256:

E2203F91E49A348EEA44B62B0C306C0163589D9DA66CFD2AF49040B3CE65EE9C

SSDEEP:

3:EWR7:EWd

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Application launched itself

      • iexplore.exe (PID: 2036)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
35
Monitored processes
2
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe

Process information

PID
CMD
Path
Indicators
Parent process
2036"C:\Program Files\Internet Explorer\iexplore.exe" "18stream.com"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2204"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2036 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
Total events
14 720
Read events
14 662
Write events
56
Delete events
2

Modification events

(PID) Process:(2036) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
0
(PID) Process:(2036) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30847387
(PID) Process:(2036) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30847437
(PID) Process:(2036) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(2036) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(2036) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(2036) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2036) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2036) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2036) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
0
Suspicious files
18
Text files
19
Unknown types
0

Dropped files

PID
Process
Filename
Type
2204iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\jquery-ui.min[1].csstext
MD5:938109D2B5F9778C8D9EEC5884ED0A64
SHA256:54DC71796BFBF1F069559DDC33C2E8992EFEC541F621797A849D442A69822696
2204iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\jquery.ui.touch-punch.min[1].jstext
MD5:D78EC54003324D4EE10CF2CF22FC7C7E
SHA256:AC47C332D3055F634A100A799AD11E559D5B23189DD79A9B800D18F1797D074C
2204iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\sale_form[1].jstext
MD5:64F809E06446647E192FCE8D1EC34E09
SHA256:F52CBD664986AD7ED6E71C448E2D31D1A16463E4D9B7BCA0C6BE278649CCC4F3
2204iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\eModal.min[1].jstext
MD5:12DC1E020FCB41CEA5346E7DA0C6D1D9
SHA256:2048951EAB7E2FEF25C5FF1A027565DF6276127847E3940D3687B1491D4236D7
2204iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\CO2ZQRAV.htmhtml
MD5:E4E3E59BBF7FB774E190CFED89D0C255
SHA256:792A6337D464714E94204625177A6A0CA549B3EA057B7C83B346C95A9142FFDE
2204iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\logo[1].svgimage
MD5:39714C739B7B145F7453F0CD18EF12EC
SHA256:0CE9E099125464652B7B98BC935028F2DFBC957F97B36263C4967EDBB3841D34
2204iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\jquery.min[1].jstext
MD5:E6C2415C0ACE414E5153670314CE99A9
SHA256:D8F9AFBF492E4C139E9D2BCB9BA6EF7C14921EB509FB703BC7A3F911B774EFF8
2204iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\bootstrap.min[1].csstext
MD5:EC3BB52A00E176A7181D454DFFAEA219
SHA256:F75E846CC83BD11432F4B1E21A45F31BC85283D11D372F7B19ACCD1BF6A2635C
2036iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\EAF8AA29A62AB29E614331747385D816_F9E4DC0B9D5C777357D7DB8DEF51118Abinary
MD5:2D1084E3CFC8F603FA39CA7FD428F7D4
SHA256:2EC78237C66320CF226ED2C9AA6FE4C6963761BA5C621B4A61F68C7C87EC7E80
2204iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506compressed
MD5:AC05D27423A85ADC1622C714F2CB6184
SHA256:C6456E12E5E53287A547AF4103E0397CB9697E466CF75844312DC296D43D144D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
21
TCP/UDP connections
29
DNS requests
15
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2204
iexplore.exe
GET
200
192.64.151.240:80
http://18stream.com/
unknown
html
3.93 Kb
unknown
2204
iexplore.exe
GET
200
192.64.151.240:80
http://18stream.com/public/bootstrap/3.3.7/css/bootstrap.min.css
unknown
text
118 Kb
unknown
2204
iexplore.exe
GET
200
192.64.151.240:80
http://18stream.com/public/ajax/libs/jqueryui/1.13.2/themes/base/jquery-ui.min.css
unknown
text
30.0 Kb
unknown
2204
iexplore.exe
GET
200
185.53.178.30:80
http://c.parkingcrew.net/scripts/sale_form.js
unknown
text
761 b
unknown
2204
iexplore.exe
GET
200
192.64.151.240:80
http://18stream.com/public/ajax/libs/jquery/3.7.0/jquery.min.js
unknown
text
85.4 Kb
unknown
2204
iexplore.exe
GET
200
192.64.151.240:80
http://18stream.com/public/npm/@rwap/jquery-ui-touch-punch@1.0.11/jquery.ui.touch-punch.min.js
unknown
text
2.72 Kb
unknown
2204
iexplore.exe
GET
200
192.64.151.240:80
http://18stream.com/public/ajax/libs/eModal/1.2.69/eModal.min.js
unknown
text
6.00 Kb
unknown
2204
iexplore.exe
GET
200
192.64.151.240:80
http://18stream.com/public/ajax/libs/jqueryui/1.13.2/jquery-ui.min.js
unknown
text
249 Kb
unknown
2204
iexplore.exe
GET
200
192.64.151.240:80
http://18stream.com/public/bootstrap/3.3.7/js/bootstrap.min.js
unknown
text
36.1 Kb
unknown
2204
iexplore.exe
GET
200
192.64.151.240:80
http://18stream.com/public/logo.svg
unknown
image
7.47 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
2204
iexplore.exe
192.64.151.240:80
18stream.com
TP
US
unknown
2204
iexplore.exe
185.53.178.30:80
c.parkingcrew.net
Team Internet AG
DE
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
2204
iexplore.exe
208.91.196.46:80
ifdnzact.com
CONFLUENCE-NETWORK-INC
VG
unknown
2036
iexplore.exe
104.126.37.51:443
www.bing.com
Akamai International B.V.
DE
unknown
2036
iexplore.exe
87.248.205.0:80
ctldl.windowsupdate.com
LLNW
US
unknown
2204
iexplore.exe
192.64.151.249:443
chatbox.computer.com
TP
US
unknown
2036
iexplore.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
18stream.com
  • 192.64.151.240
malicious
c.parkingcrew.net
  • 185.53.178.30
whitelisted
ifdnzact.com
  • 208.91.196.46
malicious
api.bing.com
  • 13.107.5.80
whitelisted
www.bing.com
  • 104.126.37.51
  • 104.126.37.42
  • 104.126.37.40
  • 104.126.37.43
  • 104.126.37.34
  • 104.126.37.41
  • 104.126.37.48
  • 104.126.37.35
  • 104.126.37.57
whitelisted
ctldl.windowsupdate.com
  • 87.248.205.0
whitelisted
chatbox.computer.com
  • 192.64.151.249
unknown
ocsp.digicert.com
  • 192.229.221.95
whitelisted
x1.c.lencr.org
  • 69.192.161.44
whitelisted
www.googletagmanager.com
  • 216.58.206.40
whitelisted

Threats

No threats detected
No debug info