URL:

https://url11.mailanyone.net/scanner?m=1rXEY1-00043S-64&d=4%7Cmail%2F14%2F1707199200%2F1rXEY1-00043S-64%7Cin11c%7C57e1b682%7C13224752%7C7272187%7C65C1CB9DD840C610A63C8F1E00EDD223&o=%2Fphtl%3A%2Fctsefouiar-dl%2F.pfpomiscbbfsifye%2Fac5gxhnzattj7sd5rtowzsqmrg3suapo7shntvhws5mud3quz5cemfq.kal%23iahma%40llstiumbrpgrpoies.ne&s=H0Ivyhl7AeX86N3_b9RLriMS6A0

Full analysis: https://app.any.run/tasks/2368190d-a07e-4d84-9290-ea45f3459c4d
Verdict: Malicious activity
Analysis date: February 06, 2024, 08:22:29
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

B7B59A0831130B884349096A10A09321

SHA1:

DDD600A06EE3269CE176D137F129A630C26EA81C

SHA256:

F593981760977AB336529C278797D698697BA7C20C6DAAA0FD3CC00BB7C71487

SSDEEP:

6:2Uh4TH2B6hynbdZi7J4oEyjRO6xJy3pgL1yWSGaIMRaJNSYPJyeRe6mIAI:2UUWB6hiPgDEyjROdp610G1DTxyeRedq

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Application launched itself

      • iexplore.exe (PID: 752)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
39
Monitored processes
2
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe

Process information

PID
CMD
Path
Indicators
Parent process
752"C:\Program Files\Internet Explorer\iexplore.exe" "https://url11.mailanyone.net/scanner?m=1rXEY1-00043S-64&d=4%7Cmail%2F14%2F1707199200%2F1rXEY1-00043S-64%7Cin11c%7C57e1b682%7C13224752%7C7272187%7C65C1CB9DD840C610A63C8F1E00EDD223&o=%2Fphtl%3A%2Fctsefouiar-dl%2F.pfpomiscbbfsifye%2Fac5gxhnzattj7sd5rtowzsqmrg3suapo7shntvhws5mud3quz5cemfq.kal%23iahma%40llstiumbrpgrpoies.ne&s=H0Ivyhl7AeX86N3_b9RLriMS6A0"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2416"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:752 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
Total events
17 451
Read events
17 372
Write events
73
Delete events
6

Modification events

(PID) Process:(752) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
0
(PID) Process:(752) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30847387
(PID) Process:(752) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30847437
(PID) Process:(752) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(752) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(752) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(752) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(752) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(752) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(752) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
0
Suspicious files
20
Text files
18
Unknown types
1

Dropped files

PID
Process
Filename
Type
2416iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EAbinary
MD5:C9D531935898486D7DFCB48A2F91029C
SHA256:990D03BBB6185C11DCA47515DB414A25E49A585F99004BBF2F003A11FD0C9D4F
2416iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\main.2768b4bf.chunk[1].csstext
MD5:5ED8A5EC7C2F3373DAB40F406BE4E1E6
SHA256:E3526F688F0037EB9818B78E5096B7ED43AEC8D0A9A1CBEA6C7FEA39D812291D
2416iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:07A7025E76E8E589FD0AADB075F64C93
SHA256:DD4AFA01C9A7746A89611C2FBEB8EB4E1BE131A9DA797FEF4BFB894651B1AF0E
2416iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EAder
MD5:A0B63D315B1A6D763785D33E2B012991
SHA256:46D505297E9E4D9E7C53422EA4EF00F7428782E779BF5F8830D862C81F144C26
2416iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\CAF4703619713E3F18D8A9D5D88D6288_F2DAF19C1F776537105D08FC8D978464der
MD5:8202A1CD02E7D69597995CABBE881A12
SHA256:58F381C3A0A0ACE6321DA22E40BD44A597BD98B9C9390AB9258426B5CF75A7A5
2416iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\CAF4703619713E3F18D8A9D5D88D6288_F2DAF19C1F776537105D08FC8D978464binary
MD5:B211461E657E81958028D1D0FB96BC4E
SHA256:F6D1A4F5F8CB12EA04B23EA144614CF98190674DEB3B27AB772C7B0AA4A1F35F
2416iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\VAS25P0M.txttext
MD5:54E958C49529A0467EFAA5D584AC2622
SHA256:1306CD0F7992300CC89B48AE192285272484BD839D5A3250B91DF447F29E1B14
2416iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\scanner[1].htmhtml
MD5:CAB6057F3FB0BD14FDB154C9636F2ACD
SHA256:48CC5FBCA021072CF7BE4F476DDF522623AA9ABF483623E1722A92F074644324
2416iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\2.fde2ca04.chunk[1].jstext
MD5:FED72784CBCB19D9375B283B432D7B3B
SHA256:A9DBEF011641348EC3C7A812DD3EB4871E6C971A66870630D8641C56DE39AF69
2416iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\3.51e54426.chunk[1].jstext
MD5:A5AF6842BF26FC8A4BCB71E4FA55C0CA
SHA256:22F86A3F92002829B79768B323C877434B256A0B49C10CF370EA22B3B9336B36
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
12
TCP/UDP connections
29
DNS requests
15
Threats
3

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2416
iexplore.exe
GET
304
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?f324de6a56943962
GB
unknown
2416
iexplore.exe
GET
200
142.250.181.227:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
US
binary
1.41 Kb
unknown
2416
iexplore.exe
GET
200
142.250.181.227:80
http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFCjJ1PwkYAi7fE%3D
US
binary
724 b
unknown
752
iexplore.exe
GET
304
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?2f21ede4db813e6d
GB
unknown
2416
iexplore.exe
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?47ea4fcd4323d6fd
GB
compressed
65.2 Kb
unknown
2416
iexplore.exe
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?73ca38dd750672c1
GB
compressed
65.2 Kb
unknown
2416
iexplore.exe
GET
200
2.23.197.184:80
http://x1.c.lencr.org/
GB
binary
717 b
unknown
2416
iexplore.exe
GET
304
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?26bc83074cde97bc
GB
unknown
752
iexplore.exe
GET
304
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?36150233369f924a
GB
unknown
752
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAzlnDD9eoNTLi0BRrMy%2BWU%3D
US
binary
313 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
2416
iexplore.exe
172.64.149.52:443
url11.mailanyone.net
CLOUDFLARENET
US
unknown
2416
iexplore.exe
93.184.221.240:80
ctldl.windowsupdate.com
EDGECAST
GB
whitelisted
2416
iexplore.exe
142.250.181.227:80
ocsp.pki.goog
GOOGLE
US
whitelisted
752
iexplore.exe
172.64.149.52:443
url11.mailanyone.net
CLOUDFLARENET
US
unknown
752
iexplore.exe
93.184.221.240:80
ctldl.windowsupdate.com
EDGECAST
GB
whitelisted
2416
iexplore.exe
151.101.2.133:443
spa.tclcdn.com
FASTLY
US
unknown
752
iexplore.exe
184.86.251.18:443
www.bing.com
Akamai International B.V.
DE
unknown

DNS requests

Domain
IP
Reputation
url11.mailanyone.net
  • 172.64.149.52
  • 104.18.38.204
unknown
ctldl.windowsupdate.com
  • 93.184.221.240
whitelisted
ocsp.pki.goog
  • 142.250.181.227
whitelisted
api.bing.com
  • 13.107.5.80
whitelisted
www.bing.com
  • 184.86.251.18
  • 184.86.251.15
  • 184.86.251.16
  • 184.86.251.19
  • 184.86.251.22
  • 184.86.251.20
  • 184.86.251.21
  • 184.86.251.24
  • 184.86.251.23
whitelisted
spa.tclcdn.com
  • 151.101.2.133
  • 151.101.66.133
  • 151.101.130.133
  • 151.101.194.133
unknown
ocsp.digicert.com
  • 192.229.221.95
whitelisted
x1.c.lencr.org
  • 2.23.197.184
whitelisted
cloudflare-ipfs.com
  • 104.17.96.13
  • 104.17.64.14
malicious
x2.c.lencr.org
  • 69.192.161.44
whitelisted

Threats

PID
Process
Class
Message
1080
svchost.exe
Misc activity
ET INFO Peer to Peer File Sharing Service in DNS Lookup (cloudflare-ipfs .com)
2416
iexplore.exe
Misc activity
ET INFO Peer to Peer File Sharing Service Domain in TLS SNI (cloudflare-ipfs .com)
2416
iexplore.exe
Misc activity
ET INFO Peer to Peer File Sharing Service Domain in TLS SNI (cloudflare-ipfs .com)
No debug info