| URL: | 18stream.com |
| Full analysis: | https://app.any.run/tasks/9d8954c2-e6d9-4edb-849e-82f8c7ff0517 |
| Verdict: | Malicious activity |
| Analysis date: | January 07, 2024, 17:06:48 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MD5: | 593E700BC1F25103BEEF9779C5E898E9 |
| SHA1: | 44AB6FF2875D8BF9E389C2C58DB7BF3969B19315 |
| SHA256: | E2203F91E49A348EEA44B62B0C306C0163589D9DA66CFD2AF49040B3CE65EE9C |
| SSDEEP: | 3:EWR7:EWd |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2036 | "C:\Program Files\Internet Explorer\iexplore.exe" "18stream.com" | C:\Program Files\Internet Explorer\iexplore.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| 2204 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2036 CREDAT:267521 /prefetch:2 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| (PID) Process: | (2036) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPDaysSinceLastAutoMigration |
Value: 0 | |||
| (PID) Process: | (2036) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPLastLaunchHighDateTime |
Value: 30847387 | |||
| (PID) Process: | (2036) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager |
| Operation: | write | Name: | NextCheckForUpdateHighDateTime |
Value: 30847437 | |||
| (PID) Process: | (2036) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (2036) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (2036) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main |
| Operation: | write | Name: | CompatibilityFlags |
Value: 0 | |||
| (PID) Process: | (2036) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2036) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2036) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2036) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2204 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\sale_form[1].js | text | |
MD5:64F809E06446647E192FCE8D1EC34E09 | SHA256:F52CBD664986AD7ED6E71C448E2D31D1A16463E4D9B7BCA0C6BE278649CCC4F3 | |||
| 2204 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\jquery.ui.touch-punch.min[1].js | text | |
MD5:D78EC54003324D4EE10CF2CF22FC7C7E | SHA256:AC47C332D3055F634A100A799AD11E559D5B23189DD79A9B800D18F1797D074C | |||
| 2204 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\logo[1].svg | image | |
MD5:39714C739B7B145F7453F0CD18EF12EC | SHA256:0CE9E099125464652B7B98BC935028F2DFBC957F97B36263C4967EDBB3841D34 | |||
| 2204 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\eModal.min[1].js | text | |
MD5:12DC1E020FCB41CEA5346E7DA0C6D1D9 | SHA256:2048951EAB7E2FEF25C5FF1A027565DF6276127847E3940D3687B1491D4236D7 | |||
| 2204 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\jquery-ui.min[1].css | text | |
MD5:938109D2B5F9778C8D9EEC5884ED0A64 | SHA256:54DC71796BFBF1F069559DDC33C2E8992EFEC541F621797A849D442A69822696 | |||
| 2204 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\bootstrap.min[1].js | text | |
MD5:5869C96CC8F19086AEE625D670D741F9 | SHA256:53964478A7C634E8DAD34ECC303DD8048D00DCE4993906DE1BACF67F663486EF | |||
| 2204 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\jquery.min[1].js | text | |
MD5:E6C2415C0ACE414E5153670314CE99A9 | SHA256:D8F9AFBF492E4C139E9D2BCB9BA6EF7C14921EB509FB703BC7A3F911B774EFF8 | |||
| 2204 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\CO2ZQRAV.htm | html | |
MD5:E4E3E59BBF7FB774E190CFED89D0C255 | SHA256:792A6337D464714E94204625177A6A0CA549B3EA057B7C83B346C95A9142FFDE | |||
| 2036 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\EAF8AA29A62AB29E614331747385D816_F9E4DC0B9D5C777357D7DB8DEF51118A | binary | |
MD5:2D1084E3CFC8F603FA39CA7FD428F7D4 | SHA256:2EC78237C66320CF226ED2C9AA6FE4C6963761BA5C621B4A61F68C7C87EC7E80 | |||
| 2036 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157 | binary | |
MD5:027EC81F542CAB56E82E62838245B900 | SHA256:0301F7D6EAED0D3A7C44972DC84E0AA25CE396DC5DCB4C777DEB959F8F384C8D | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2204 | iexplore.exe | GET | 200 | 192.64.151.240:80 | http://18stream.com/ | unknown | html | 3.93 Kb | unknown |
2204 | iexplore.exe | GET | 200 | 192.64.151.240:80 | http://18stream.com/public/bootstrap/3.3.7/css/bootstrap.min.css | unknown | text | 118 Kb | unknown |
2204 | iexplore.exe | GET | 200 | 192.64.151.240:80 | http://18stream.com/public/ajax/libs/jqueryui/1.13.2/themes/base/jquery-ui.min.css | unknown | text | 30.0 Kb | unknown |
2204 | iexplore.exe | GET | 200 | 185.53.178.30:80 | http://c.parkingcrew.net/scripts/sale_form.js | unknown | text | 761 b | unknown |
2204 | iexplore.exe | GET | 200 | 192.64.151.240:80 | http://18stream.com/public/ajax/libs/jquery/3.7.0/jquery.min.js | unknown | text | 85.4 Kb | unknown |
2204 | iexplore.exe | GET | 200 | 192.64.151.240:80 | http://18stream.com/public/npm/@rwap/jquery-ui-touch-punch@1.0.11/jquery.ui.touch-punch.min.js | unknown | text | 2.72 Kb | unknown |
2204 | iexplore.exe | GET | 200 | 192.64.151.240:80 | http://18stream.com/public/ajax/libs/eModal/1.2.69/eModal.min.js | unknown | text | 6.00 Kb | unknown |
2204 | iexplore.exe | GET | 200 | 192.64.151.240:80 | http://18stream.com/public/ajax/libs/jqueryui/1.13.2/jquery-ui.min.js | unknown | text | 249 Kb | unknown |
2204 | iexplore.exe | GET | 200 | 192.64.151.240:80 | http://18stream.com/public/bootstrap/3.3.7/js/bootstrap.min.js | unknown | text | 36.1 Kb | unknown |
2204 | iexplore.exe | GET | 200 | 192.64.151.240:80 | http://18stream.com/public/logo.svg | unknown | image | 7.47 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2204 | iexplore.exe | 192.64.151.240:80 | 18stream.com | TP | US | unknown |
2204 | iexplore.exe | 185.53.178.30:80 | c.parkingcrew.net | Team Internet AG | DE | unknown |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2204 | iexplore.exe | 208.91.196.46:80 | ifdnzact.com | CONFLUENCE-NETWORK-INC | VG | unknown |
2036 | iexplore.exe | 104.126.37.51:443 | www.bing.com | Akamai International B.V. | DE | unknown |
2036 | iexplore.exe | 87.248.205.0:80 | ctldl.windowsupdate.com | LLNW | US | unknown |
2204 | iexplore.exe | 192.64.151.249:443 | chatbox.computer.com | TP | US | unknown |
2036 | iexplore.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
18stream.com |
| malicious |
c.parkingcrew.net |
| whitelisted |
ifdnzact.com |
| malicious |
api.bing.com |
| whitelisted |
www.bing.com |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
chatbox.computer.com |
| unknown |
ocsp.digicert.com |
| whitelisted |
x1.c.lencr.org |
| whitelisted |
www.googletagmanager.com |
| whitelisted |