URL:

pornhub.com

Full analysis: https://app.any.run/tasks/f3ea6c01-ec17-40cd-9c4c-9573f5332806
Verdict: Malicious activity
Analysis date: April 11, 2024, 18:25:54
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

B27193CE8E78D1C0AA8018F1ADF3692B

SHA1:

5E1F4F7BAF524CADB03DBBFFDE68DC8C1EF253E3

SHA256:

F451A0CE975DBD22A62BD8204A25038BA485AC621A6F2FE2C605D7F3025C7A29

SSDEEP:

3:4NS2:A3

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Application launched itself

      • iexplore.exe (PID: 3992)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
39
Monitored processes
2
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe

Process information

PID
CMD
Path
Indicators
Parent process
2580"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3992 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
3992"C:\Program Files\Internet Explorer\iexplore.exe" "pornhub.com"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
Total events
27 248
Read events
26 878
Write events
178
Delete events
192

Modification events

(PID) Process:(3992) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
1
(PID) Process:(3992) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchLowDateTime
Value:
(PID) Process:(3992) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
31099965
(PID) Process:(3992) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateLowDateTime
Value:
(PID) Process:(3992) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
31099965
(PID) Process:(3992) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(3992) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3992) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3992) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(3992) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
0
Suspicious files
26
Text files
287
Unknown types
25

Dropped files

PID
Process
Filename
Type
2580iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:
SHA256:
2580iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\26C212D9399727259664BDFCA073966E_A60A47F328D1536988B0DFE88D6D301Fder
MD5:
SHA256:
2580iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\26C212D9399727259664BDFCA073966E_A60A47F328D1536988B0DFE88D6D301Fbinary
MD5:
SHA256:
2580iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B1C7267527E2135ED2C5C2AE13A93217_7C467C3BFC77B0282FB30FDE34666973der
MD5:
SHA256:
2580iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B1C7267527E2135ED2C5C2AE13A93217_7C467C3BFC77B0282FB30FDE34666973binary
MD5:
SHA256:
2580iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\BHEU5Y8V.txttext
MD5:
SHA256:
2580iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\XTH45033.txttext
MD5:
SHA256:
2580iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\EVWBIM0L.txttext
MD5:
SHA256:
2580iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\46WHWCRF.txttext
MD5:
SHA256:
2580iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\88NKBRAV.txttext
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
31
TCP/UDP connections
100
DNS requests
40
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2580
iexplore.exe
GET
304
88.221.110.121:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?92967c53a8c0ec29
unknown
2580
iexplore.exe
GET
301
66.254.114.41:80
http://pornhub.com/
unknown
2580
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAwiVBgdbf36ZuJk48F6SLw%3D
unknown
2580
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS%2Fm8vvceKzm40ZSHrPx1iFNU%2BPAgQUiiPrnmvX%2BTdd%2BW0hOXaaoWfeEKgCEA%2FN%2Bw%2BLlAVpJfASRkC5P3k%3D
unknown
2580
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAsA6S1NbXMfyjBZx8seGIY%3D
unknown
2580
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAz1vQYrVgL0erhQLCPM8GY%3D
unknown
2580
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS%2Fm8vvceKzm40ZSHrPx1iFNU%2BPAgQUiiPrnmvX%2BTdd%2BW0hOXaaoWfeEKgCEAbtQuDQ0c3gzpS%2Bx4P2Z9I%3D
unknown
2580
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSnxLiz3Fu1WB6n1%2FE6xWn1b0jXiQQUdIWAwGbH3zfez70pN6oDHb7tzRcCEAvTPwVJejdJm7x7948EZoA%3D
unknown
2580
iexplore.exe
GET
200
92.123.17.153:80
http://x1.c.lencr.org/
unknown
2580
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSnxLiz3Fu1WB6n1%2FE6xWn1b0jXiQQUdIWAwGbH3zfez70pN6oDHb7tzRcCEATrBUr1SwE1nf8fA%2BNKVx0%3D
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
unknown
2580
iexplore.exe
66.254.114.41:80
pornhub.com
REFLECTED
US
unknown
2580
iexplore.exe
66.254.114.41:443
pornhub.com
REFLECTED
US
unknown
2580
iexplore.exe
88.221.110.121:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
2580
iexplore.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
unknown
2580
iexplore.exe
66.254.114.156:443
cdn1-smallimg.phncdn.com
REFLECTED
US
unknown
2580
iexplore.exe
66.254.122.22:443
ei.phncdn.com
REFLECTED
US
unknown
2580
iexplore.exe
66.254.122.20:443
ei.phncdn.com
REFLECTED
US
unknown

DNS requests

Domain
IP
Reputation
pornhub.com
  • 66.254.114.41
unknown
ctldl.windowsupdate.com
  • 88.221.110.121
  • 88.221.110.64
  • 88.221.110.96
  • 2.16.100.168
  • 2.16.100.177
  • 88.221.110.106
  • 199.232.210.172
  • 199.232.214.172
unknown
ocsp.digicert.com
  • 192.229.221.95
unknown
www.pornhub.com
  • 66.254.114.41
unknown
www.pornhub.org
  • 66.254.114.41
unknown
ei.phncdn.com
  • 66.254.122.22
  • 66.254.122.17
  • 66.254.122.20
  • 66.254.122.19
  • 66.254.122.16
  • 66.254.122.23
  • 66.254.122.18
  • 66.254.122.21
unknown
static.trafficjunky.com
  • 66.254.122.23
  • 66.254.122.20
  • 66.254.122.19
  • 66.254.122.21
  • 66.254.122.16
  • 66.254.122.22
  • 66.254.122.17
  • 66.254.122.18
unknown
cdn1-smallimg.phncdn.com
  • 66.254.114.156
unknown
media.trafficjunky.net
  • 66.254.122.20
  • 66.254.122.19
  • 66.254.122.18
  • 66.254.122.22
  • 66.254.122.16
  • 66.254.122.21
  • 66.254.122.17
  • 66.254.122.23
unknown
x1.c.lencr.org
  • 92.123.17.153
unknown

Threats

PID
Process
Class
Message
Not Suspicious Traffic
INFO [ANY.RUN] Global content delivery network (unpkg .com)
No debug info