analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
URL:

https://wertyuiuytrewqerty.wixsite.com

Full analysis: https://app.any.run/tasks/dd103d06-ac80-4a9d-ba7a-c6c63bb04f2c
Verdict: Malicious activity
Analysis date: June 12, 2019, 07:45:44
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

12C6F2B8A0DAB5F274F0A8D83FAD43BC

SHA1:

BF9A27C7E80C0241CC7F033A948F937431472FC1

SHA256:

093D246EF9A4F113BC451D6ABD2F197847DFA91DDD2D80095A8817FB232EECF4

SSDEEP:

3:N8RBbgXAnyg/dlA2:2rgQnDda2

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Application launched itself

      • iexplore.exe (PID: 2996)
    • Reads internet explorer settings

      • iexplore.exe (PID: 3544)
    • Reads Internet Cache Settings

      • iexplore.exe (PID: 3544)
    • Changes internet zones settings

      • iexplore.exe (PID: 2996)
    • Creates files in the user directory

      • iexplore.exe (PID: 3544)
    • Dropped object may contain Bitcoin addresses

      • iexplore.exe (PID: 3544)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
34
Monitored processes
2
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe

Process information

PID
CMD
Path
Indicators
Parent process
2996"C:\Program Files\Internet Explorer\iexplore.exe" https://wertyuiuytrewqerty.wixsite.comC:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
3544"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2996 CREDAT:71937C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Total events
342
Read events
297
Write events
45
Delete events
0

Modification events

(PID) Process:(2996) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(2996) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(2996) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(2996) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones
Operation:writeName:SecuritySafe
Value:
1
(PID) Process:(2996) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(2996) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000006E000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
(PID) Process:(2996) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Recovery\Active
Operation:writeName:{1DF912A3-8CE6-11E9-B3B3-5254004A04AF}
Value:
0
(PID) Process:(2996) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Type
Value:
4
(PID) Process:(2996) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Count
Value:
1
(PID) Process:(2996) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Time
Value:
E307060003000C0007002D003B00E302
Executable files
0
Suspicious files
0
Text files
17
Unknown types
30

Dropped files

PID
Process
Filename
Type
2996iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H6QNMHE9\favicon[1].ico
MD5:
SHA256:
2996iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
MD5:
SHA256:
3544iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\History\Low\History.IE5\index.datdat
MD5:5267D57650C9263305D46EFE54810EA9
SHA256:F6A6AC9BAAB0E16074EF1AB73D315996E8063C4ADC3C88B5E96AAF579576D726
3544iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\CAFWZP2M\88fcd49a-13c7-4d0c-86b1-ad1e258bd75d[1].eoteot
MD5:9376DACDE003E1A98E9688B5CF617688
SHA256:0E943B8B94E52CAABA37EB5D09E21B2A177C17BAB8DF1C859CA6BF7CD6B57F5B
3544iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\CAFWZP2M\58a5cbff-d570-4c18-a5e3-60868dc07ae8[1].eoteot
MD5:776B77342FF1DDB8CB886A26F5FD679A
SHA256:473CA4A5624413FBF482FB780145BD3B081049D28C16A2451B76E2A20DCE326B
3544iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\index.datdat
MD5:9816A6371DCD243B8406FDA675790B64
SHA256:BB6B8015F8AC4780C3732CF276D8AC4FE0A776FAA4EFDE265AEF4FF9516548AD
3544iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\desktop.iniini
MD5:4A3DEB274BB5F0212C2419D3D8D08612
SHA256:2842973D15A14323E08598BE1DFB87E54BF88A76BE8C7BC94C56B079446EDF38
3544iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\CAFWZP2M\56be84de-9d60-4089-8df0-0ea6ec786b84[1].eoteot
MD5:301347FD6432E7A617A09891EF8975D0
SHA256:11850D5A61482FCFD84B5461D011DC9A644B93DACB9680832FC3EDE741001593
2996iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H6QNMHE9\favicon[1].pngimage
MD5:9FB559A691078558E77D6848202F6541
SHA256:6D8A01DC7647BC218D003B58FE04049E24A9359900B7E0CEBAE76EDF85B8B914
3544iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\XDHVUPNQ\07fe0fec-b63f-4963-8ee1-535528b67fdb[1].eoteot
MD5:D4820EB00D7F44435676403105C5D877
SHA256:0E5D20118C0F283AFA97F350D3CEF05EEB4575E33E123015B61EF6E47F7E35D4
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
10
DNS requests
5
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2996
iexplore.exe
GET
200
204.79.197.200:80
http://www.bing.com/favicon.ico
US
image
237 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
204.79.197.200:80
www.bing.com
Microsoft Corporation
US
whitelisted
3544
iexplore.exe
35.246.6.109:443
wertyuiuytrewqerty.wixsite.com
US
malicious
3544
iexplore.exe
185.230.60.179:443
www.wix.com
suspicious
3544
iexplore.exe
216.58.206.10:443
ajax.googleapis.com
Google Inc.
US
whitelisted
3544
iexplore.exe
130.211.46.196:443
static.parastorage.com
Google Inc.
US
whitelisted

DNS requests

Domain
IP
Reputation
wertyuiuytrewqerty.wixsite.com
  • 35.246.6.109
malicious
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
static.parastorage.com
  • 130.211.46.196
shared
ajax.googleapis.com
  • 216.58.206.10
  • 216.58.207.42
  • 216.58.207.74
  • 172.217.16.138
  • 172.217.22.42
  • 216.58.210.10
  • 172.217.16.202
  • 172.217.18.106
  • 216.58.205.234
  • 172.217.21.234
  • 172.217.18.170
  • 172.217.23.138
whitelisted
www.wix.com
  • 185.230.60.179
whitelisted

Threats

No threats detected
No debug info