analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
URL:

https://aka.ms/ghei36

Full analysis: https://app.any.run/tasks/9e024e0f-e5bf-44db-be10-dcff1ee1f463
Verdict: Malicious activity
Analysis date: May 15, 2019, 10:05:38
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

974AAAD878FA48270600B9E62219DFB0

SHA1:

046EC6E02A2637DBB195FA8791677862CCF59964

SHA256:

0AA364B6ACD0058D238823A417376B9F4683B84C7E31395F7C2E94AD62C3A830

SSDEEP:

3:N8O8WKC/Un:2O8Nrn

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Application launched itself

      • iexplore.exe (PID: 1740)
    • Creates files in the user directory

      • iexplore.exe (PID: 3632)
      • iexplore.exe (PID: 1740)
    • Changes internet zones settings

      • iexplore.exe (PID: 1740)
    • Reads internet explorer settings

      • iexplore.exe (PID: 3632)
    • Reads Internet Cache Settings

      • iexplore.exe (PID: 3632)
      • iexplore.exe (PID: 1740)
    • Reads settings of System Certificates

      • iexplore.exe (PID: 1740)
    • Adds / modifies Windows certificates

      • iexplore.exe (PID: 1740)
    • Changes settings of System certificates

      • iexplore.exe (PID: 1740)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
34
Monitored processes
2
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe

Process information

PID
CMD
Path
Indicators
Parent process
1740"C:\Program Files\Internet Explorer\iexplore.exe" -nohomeC:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
3632"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:1740 CREDAT:71937C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Total events
430
Read events
350
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
0
Text files
20
Unknown types
11

Dropped files

PID
Process
Filename
Type
1740iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H6QNMHE9\favicon[1].ico
MD5:
SHA256:
1740iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
MD5:
SHA256:
3632iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\G9SN5V3G\mobile[1].txt
MD5:
SHA256:
3632iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\History\Low\History.IE5\index.datdat
MD5:CF4A6ECDA4CE9D2C06671EB55D1E9790
SHA256:B8CD76DA576BDB0E4D57B60356ACC4716553854EDAFF602E053D9235C71E338A
3632iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\index.datdat
MD5:B3AEB30BBA6C0E33A7D95F19533D4E80
SHA256:4A4CDA7CABE761BCB572A3BA7A37EF5EF1B3F0566D6588AFF75D1217A90CEF67
3632iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\G9SN5V3G\mobile[1].htmhtml
MD5:CED155A04EFC0AE777CD0167AF346314
SHA256:4143B59F008B1DD3DB3C61B22ACD1C2CBC4AC78A2577D4400D6B51BE98AB71DD
3632iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\9VHTRR1T\mshpicons-regular-webfont[1].eoteot
MD5:FD28E58DED2F9730DF34EC11DC56659B
SHA256:139B21E1C5B6E4358D4D986755A9150EAC63075E375E02FB154DA4603C4D257F
3632iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ASBG7VTF\l2-sms-page[1].csstext
MD5:CCA5E894FE7B8D05FA0B3546D933CBC0
SHA256:2F0ECC0A814CB89BE1DABAD4E5533D16730E5C0B2EA342D4FBB5D234BF631C72
3632iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\MSIMGSIZ.DATsmt
MD5:B54402589B87CE309884D89C438F8819
SHA256:ED1D5E3CE43F36D80722810F997C195B89ECCAE9D0DEFB5EEF3636A6DC92BB3D
3632iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\G9SN5V3G\l2-sms-page[1].jstext
MD5:33199D135F348647196D911945DA3885
SHA256:7E485923BEB3C4DEF1AD0FE0A9FAE4FF249F74DBBF96CB513E31CADD0EB7965F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
19
DNS requests
6
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1740
iexplore.exe
GET
200
204.79.197.200:80
http://www.bing.com/favicon.ico
US
image
237 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1740
iexplore.exe
204.79.197.200:80
www.bing.com
Microsoft Corporation
US
whitelisted
3632
iexplore.exe
152.199.19.161:443
ol.azureedge.net
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
3632
iexplore.exe
13.107.246.10:443
assets.outlook.com
Microsoft Corporation
US
whitelisted
3632
iexplore.exe
23.66.21.99:443
aka.ms
Akamai Technologies, Inc.
NL
whitelisted
3632
iexplore.exe
23.102.191.170:443
w2.outlook.com
Microsoft Corporation
US
whitelisted
1740
iexplore.exe
23.102.191.170:443
w2.outlook.com
Microsoft Corporation
US
whitelisted
3632
iexplore.exe
185.151.204.6:443
app.adjust.com
datapath.io GmbH
DE
unknown

DNS requests

Domain
IP
Reputation
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
aka.ms
  • 23.66.21.99
whitelisted
app.adjust.com
  • 185.151.204.6
  • 185.151.204.14
  • 185.151.204.7
  • 185.151.204.12
whitelisted
w2.outlook.com
  • 23.102.191.170
whitelisted
assets.outlook.com
  • 13.107.246.10
whitelisted
ol.azureedge.net
  • 152.199.19.161
whitelisted

Threats

No threats detected
No debug info