URL:

18stream.com

Full analysis: https://app.any.run/tasks/9d8954c2-e6d9-4edb-849e-82f8c7ff0517
Verdict: Malicious activity
Analysis date: January 07, 2024, 17:06:48
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

593E700BC1F25103BEEF9779C5E898E9

SHA1:

44AB6FF2875D8BF9E389C2C58DB7BF3969B19315

SHA256:

E2203F91E49A348EEA44B62B0C306C0163589D9DA66CFD2AF49040B3CE65EE9C

SSDEEP:

3:EWR7:EWd

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Application launched itself

      • iexplore.exe (PID: 2036)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
35
Monitored processes
2
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe

Process information

PID
CMD
Path
Indicators
Parent process
2036"C:\Program Files\Internet Explorer\iexplore.exe" "18stream.com"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2204"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2036 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
Total events
14 720
Read events
14 662
Write events
56
Delete events
2

Modification events

(PID) Process:(2036) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
0
(PID) Process:(2036) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30847387
(PID) Process:(2036) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30847437
(PID) Process:(2036) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(2036) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(2036) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(2036) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2036) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2036) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2036) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
0
Suspicious files
18
Text files
19
Unknown types
0

Dropped files

PID
Process
Filename
Type
2204iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\sale_form[1].jstext
MD5:64F809E06446647E192FCE8D1EC34E09
SHA256:F52CBD664986AD7ED6E71C448E2D31D1A16463E4D9B7BCA0C6BE278649CCC4F3
2204iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\jquery.ui.touch-punch.min[1].jstext
MD5:D78EC54003324D4EE10CF2CF22FC7C7E
SHA256:AC47C332D3055F634A100A799AD11E559D5B23189DD79A9B800D18F1797D074C
2204iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\logo[1].svgimage
MD5:39714C739B7B145F7453F0CD18EF12EC
SHA256:0CE9E099125464652B7B98BC935028F2DFBC957F97B36263C4967EDBB3841D34
2204iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\eModal.min[1].jstext
MD5:12DC1E020FCB41CEA5346E7DA0C6D1D9
SHA256:2048951EAB7E2FEF25C5FF1A027565DF6276127847E3940D3687B1491D4236D7
2204iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\jquery-ui.min[1].csstext
MD5:938109D2B5F9778C8D9EEC5884ED0A64
SHA256:54DC71796BFBF1F069559DDC33C2E8992EFEC541F621797A849D442A69822696
2204iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\bootstrap.min[1].jstext
MD5:5869C96CC8F19086AEE625D670D741F9
SHA256:53964478A7C634E8DAD34ECC303DD8048D00DCE4993906DE1BACF67F663486EF
2204iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\jquery.min[1].jstext
MD5:E6C2415C0ACE414E5153670314CE99A9
SHA256:D8F9AFBF492E4C139E9D2BCB9BA6EF7C14921EB509FB703BC7A3F911B774EFF8
2204iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\CO2ZQRAV.htmhtml
MD5:E4E3E59BBF7FB774E190CFED89D0C255
SHA256:792A6337D464714E94204625177A6A0CA549B3EA057B7C83B346C95A9142FFDE
2036iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\EAF8AA29A62AB29E614331747385D816_F9E4DC0B9D5C777357D7DB8DEF51118Abinary
MD5:2D1084E3CFC8F603FA39CA7FD428F7D4
SHA256:2EC78237C66320CF226ED2C9AA6FE4C6963761BA5C621B4A61F68C7C87EC7E80
2036iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:027EC81F542CAB56E82E62838245B900
SHA256:0301F7D6EAED0D3A7C44972DC84E0AA25CE396DC5DCB4C777DEB959F8F384C8D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
21
TCP/UDP connections
29
DNS requests
15
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2204
iexplore.exe
GET
200
192.64.151.240:80
http://18stream.com/
unknown
html
3.93 Kb
unknown
2204
iexplore.exe
GET
200
192.64.151.240:80
http://18stream.com/public/bootstrap/3.3.7/css/bootstrap.min.css
unknown
text
118 Kb
unknown
2204
iexplore.exe
GET
200
192.64.151.240:80
http://18stream.com/public/ajax/libs/jqueryui/1.13.2/themes/base/jquery-ui.min.css
unknown
text
30.0 Kb
unknown
2204
iexplore.exe
GET
200
185.53.178.30:80
http://c.parkingcrew.net/scripts/sale_form.js
unknown
text
761 b
unknown
2204
iexplore.exe
GET
200
192.64.151.240:80
http://18stream.com/public/ajax/libs/jquery/3.7.0/jquery.min.js
unknown
text
85.4 Kb
unknown
2204
iexplore.exe
GET
200
192.64.151.240:80
http://18stream.com/public/npm/@rwap/jquery-ui-touch-punch@1.0.11/jquery.ui.touch-punch.min.js
unknown
text
2.72 Kb
unknown
2204
iexplore.exe
GET
200
192.64.151.240:80
http://18stream.com/public/ajax/libs/eModal/1.2.69/eModal.min.js
unknown
text
6.00 Kb
unknown
2204
iexplore.exe
GET
200
192.64.151.240:80
http://18stream.com/public/ajax/libs/jqueryui/1.13.2/jquery-ui.min.js
unknown
text
249 Kb
unknown
2204
iexplore.exe
GET
200
192.64.151.240:80
http://18stream.com/public/bootstrap/3.3.7/js/bootstrap.min.js
unknown
text
36.1 Kb
unknown
2204
iexplore.exe
GET
200
192.64.151.240:80
http://18stream.com/public/logo.svg
unknown
image
7.47 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
2204
iexplore.exe
192.64.151.240:80
18stream.com
TP
US
unknown
2204
iexplore.exe
185.53.178.30:80
c.parkingcrew.net
Team Internet AG
DE
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
2204
iexplore.exe
208.91.196.46:80
ifdnzact.com
CONFLUENCE-NETWORK-INC
VG
unknown
2036
iexplore.exe
104.126.37.51:443
www.bing.com
Akamai International B.V.
DE
unknown
2036
iexplore.exe
87.248.205.0:80
ctldl.windowsupdate.com
LLNW
US
unknown
2204
iexplore.exe
192.64.151.249:443
chatbox.computer.com
TP
US
unknown
2036
iexplore.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
18stream.com
  • 192.64.151.240
malicious
c.parkingcrew.net
  • 185.53.178.30
whitelisted
ifdnzact.com
  • 208.91.196.46
malicious
api.bing.com
  • 13.107.5.80
whitelisted
www.bing.com
  • 104.126.37.51
  • 104.126.37.42
  • 104.126.37.40
  • 104.126.37.43
  • 104.126.37.34
  • 104.126.37.41
  • 104.126.37.48
  • 104.126.37.35
  • 104.126.37.57
whitelisted
ctldl.windowsupdate.com
  • 87.248.205.0
whitelisted
chatbox.computer.com
  • 192.64.151.249
unknown
ocsp.digicert.com
  • 192.229.221.95
whitelisted
x1.c.lencr.org
  • 69.192.161.44
whitelisted
www.googletagmanager.com
  • 216.58.206.40
whitelisted

Threats

No threats detected
No debug info