URL:

http://yourube.com

Full analysis: https://app.any.run/tasks/e738987c-df13-4a88-a156-81de45b0a89a
Verdict: Malicious activity
Analysis date: May 24, 2021, 00:58:54
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
evasion
Indicators:
MD5:

A8DCDA057524D3F828424EDF78657E01

SHA1:

C04AB797D53ABDAB560CA3083F1BA7A1366F898D

SHA256:

E94008A7FE60DEFB5E039DDB930F3EA71FA8DA0786320539707C05BF6B042A0E

SSDEEP:

3:N1KHsHAyTn:CMHJT

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Checks for external IP

      • opera.exe (PID: 2552)
  • INFO

    • Creates files in the user directory

      • opera.exe (PID: 2552)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
37
Monitored processes
1
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start opera.exe

Process information

PID
CMD
Path
Indicators
Parent process
2552"C:\Program Files\Opera\opera.exe" "http://yourube.com"C:\Program Files\Opera\opera.exe
explorer.exe
User:
admin
Company:
Opera Software
Integrity Level:
MEDIUM
Description:
Opera Internet Browser
Exit code:
0
Version:
1748
Modules
Images
c:\program files\opera\opera.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\psapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\rpcrt4.dll
Total events
302
Read events
241
Write events
61
Delete events
0

Modification events

(PID) Process:(2552) opera.exeKey:HKEY_CURRENT_USER\Software\Opera Software
Operation:writeName:Last CommandLine v2
Value:
C:\Program Files\Opera\opera.exe "http://yourube.com"
(PID) Process:(2552) opera.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2552) opera.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E
Operation:writeName:@"%windir%\System32\ie4uinit.exe",-732
Value:
Finds and displays information and Web sites on the Internet.
Executable files
0
Suspicious files
76
Text files
80
Unknown types
36

Dropped files

PID
Process
Filename
Type
2552opera.exeC:\Users\admin\AppData\Roaming\Opera\Opera\sessions\opr822A.tmp
MD5:
SHA256:
2552opera.exeC:\Users\admin\AppData\Roaming\Opera\Opera\opr822B.tmp
MD5:
SHA256:
2552opera.exeC:\Users\admin\AppData\Roaming\Opera\Opera\opr8289.tmp
MD5:
SHA256:
2552opera.exeC:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr00001.tmp
MD5:
SHA256:
2552opera.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\KN2FGCTLHXBJ3JUS99IA.temp
MD5:
SHA256:
2552opera.exeC:\Users\admin\AppData\Roaming\Opera\Opera\sessions\opr9538.tmp
MD5:
SHA256:
2552opera.exeC:\Users\admin\AppData\Roaming\Opera\Opera\opssl6.datbinary
MD5:
SHA256:
2552opera.exeC:\Users\admin\AppData\Roaming\Opera\Opera\sessions\oprBE1D.tmp
MD5:
SHA256:
2552opera.exeC:\Users\admin\AppData\Roaming\Opera\Opera\tasks.xmlxml
MD5:
SHA256:
2552opera.exeC:\Users\admin\AppData\Roaming\Opera\Opera\operaprefs.initext
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
50
TCP/UDP connections
111
DNS requests
51
Threats
8

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2552
opera.exe
GET
302
198.134.116.30:80
http://click.clkepd.com/click?i=AChIsRpiwZM_0
US
malicious
2552
opera.exe
GET
200
143.204.101.119:80
http://s.ss2.us/r.crl
US
der
434 b
whitelisted
2552
opera.exe
GET
200
143.204.101.118:80
http://crl.rootca1.amazontrust.com/rootca1.crl
US
der
439 b
whitelisted
2552
opera.exe
GET
200
23.39.69.41:80
http://x1.c.lencr.org/
NL
der
735 b
whitelisted
2552
opera.exe
GET
200
143.204.101.120:80
http://crl.rootg2.amazontrust.com/rootg2.crl
US
der
608 b
whitelisted
2552
opera.exe
GET
200
93.184.220.29:80
http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl
US
der
592 b
whitelisted
2552
opera.exe
GET
200
142.250.186.174:80
http://clients1.google.com/complete/search?q=yourubve&client=opera-suggest-omnibox&hl=de
US
text
143 b
whitelisted
2552
opera.exe
GET
200
142.250.186.174:80
http://clients1.google.com/complete/search?q=yourubv&client=opera-suggest-omnibox&hl=de
US
text
140 b
whitelisted
2552
opera.exe
GET
200
142.250.186.174:80
http://clients1.google.com/complete/search?q=yourube&client=opera-suggest-omnibox&hl=de
US
text
141 b
whitelisted
2552
opera.exe
GET
200
142.250.186.174:80
http://clients1.google.com/complete/search?q=yourub&client=opera-suggest-omnibox&hl=de
US
text
140 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
23.39.69.41:80
x1.c.lencr.org
Akamai Technologies, Inc.
NL
unknown
2552
opera.exe
172.67.169.50:443
platform.thatmarketwatch.com
US
suspicious
2552
opera.exe
142.250.186.174:80
clients1.google.com
Google Inc.
US
whitelisted
2552
opera.exe
18.235.67.128:80
nizephoros-pom.com
US
unknown
2552
opera.exe
18.195.174.160:443
histioned-modgerous.icu
Amazon.com, Inc.
DE
malicious
2552
opera.exe
88.80.185.92:443
bestsecretflirt.com
Linode, LLC
GB
unknown
2552
opera.exe
92.122.244.25:80
r3.o.lencr.org
GTT Communications Inc.
FR
unknown
2552
opera.exe
185.26.182.94:443
certs.opera.com
Opera Software AS
whitelisted
2552
opera.exe
192.187.111.220:80
yourube.com
DataShack, LC
US
malicious
2552
opera.exe
185.26.182.106:80
sitecheck2.opera.com
Opera Software AS
suspicious

DNS requests

Domain
IP
Reputation
yourube.com
  • 192.187.111.220
whitelisted
certs.opera.com
  • 185.26.182.94
  • 185.26.182.93
whitelisted
sitecheck2.opera.com
  • 185.26.182.106
  • 185.26.182.93
  • 185.26.182.94
  • 185.26.182.112
  • 185.26.182.111
  • 185.26.182.118
whitelisted
crl3.digicert.com
  • 93.184.220.29
whitelisted
v4.s.arclk.net
  • 34.228.5.38
  • 52.201.51.11
  • 3.226.191.120
unknown
crl.rootca1.amazontrust.com
  • 143.204.101.118
  • 143.204.101.158
  • 143.204.101.120
  • 143.204.101.50
whitelisted
s.ss2.us
  • 143.204.101.119
  • 143.204.101.111
  • 143.204.101.78
  • 143.204.101.166
whitelisted
crl.rootg2.amazontrust.com
  • 143.204.101.120
  • 143.204.101.50
  • 143.204.101.158
  • 143.204.101.118
whitelisted
ocsp.sca1b.amazontrust.com
  • 143.204.101.143
  • 143.204.101.52
  • 143.204.101.74
  • 143.204.101.188
whitelisted
click.clkepd.com
  • 198.134.116.30
malicious

Threats

PID
Process
Class
Message
2552
opera.exe
Potentially Bad Traffic
ET INFO TLS Handshake Failure
2552
opera.exe
Potentially Bad Traffic
ET INFO TLS Handshake Failure
2552
opera.exe
Potentially Bad Traffic
ET INFO TLS Handshake Failure
1052
svchost.exe
Potentially Bad Traffic
ET INFO DNS Query for Suspicious .icu Domain
2552
opera.exe
Potentially Bad Traffic
ET INFO Suspicious Domain (*.icu) in TLS SNI
2552
opera.exe
Potentially Bad Traffic
ET INFO Observed Let's Encrypt Certificate for Suspicious TLD (.icu)
1052
svchost.exe
Potential Corporate Privacy Violation
ET POLICY ipchicken .com DNS Lookup
2552
opera.exe
Potential Corporate Privacy Violation
ET POLICY External IP Lookup (ipchicken .com)
No debug info