URL:

https://www.footem.site

Full analysis: https://app.any.run/tasks/bf39975d-49ed-4178-8b62-571578f61f5a
Verdict: Malicious activity
Analysis date: October 29, 2021, 17:57:06
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

A8C6E4FDBE1F37ED48318FBBD1721F4C

SHA1:

4C664F836A450CE9A9E737FE5D928DA895BF47B4

SHA256:

10E687A5916A52C42B6461A494492399784C12D410DCD4E5D09A3CCA1453CEDD

SSDEEP:

3:N8DSLWK/LWV:2OLWK/iV

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads Microsoft Outlook installation path

      • iexplore.exe (PID: 1536)
  • INFO

    • Checks supported languages

      • iexplore.exe (PID: 2464)
      • iexplore.exe (PID: 1536)
    • Changes internet zones settings

      • iexplore.exe (PID: 2464)
    • Reads the computer name

      • iexplore.exe (PID: 2464)
      • iexplore.exe (PID: 1536)
    • Checks Windows Trust Settings

      • iexplore.exe (PID: 1536)
      • iexplore.exe (PID: 2464)
    • Application launched itself

      • iexplore.exe (PID: 2464)
    • Changes settings of System certificates

      • iexplore.exe (PID: 2464)
    • Reads internet explorer settings

      • iexplore.exe (PID: 1536)
    • Reads settings of System Certificates

      • iexplore.exe (PID: 2464)
      • iexplore.exe (PID: 1536)
    • Creates files in the user directory

      • iexplore.exe (PID: 1536)
    • Adds / modifies Windows certificates

      • iexplore.exe (PID: 2464)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
36
Monitored processes
2
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
1536"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2464 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2464"C:\Program Files\Internet Explorer\iexplore.exe" "https://www.footem.site"C:\Program Files\Internet Explorer\iexplore.exe
Explorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
Total events
18 037
Read events
17 922
Write events
113
Delete events
2

Modification events

(PID) Process:(2464) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
1
(PID) Process:(2464) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchLowDateTime
Value:
(PID) Process:(2464) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30919918
(PID) Process:(2464) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateLowDateTime
Value:
(PID) Process:(2464) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30919918
(PID) Process:(2464) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(2464) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(2464) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(2464) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(2464) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
0
Suspicious files
23
Text files
17
Unknown types
20

Dropped files

PID
Process
Filename
Type
1536iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\50GS6Y5Y.htmhtml
MD5:DD9DD40096FA64026B9E2ACF15062453
SHA256:72464D7BF9657304B98C7ADE261E5FB0AC36D048F2A060C528E3F93D20F55570
1536iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:3183A6B25F5460F4551CF9FF8D5DF1F4
SHA256:EF6A63CDC3EE16583BA2BA6F26B1A594894C14C9080B8F51EF7D66EDB7982E01
1536iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EAder
MD5:F540033A8F3AD5E7836D8C70F2363D5F
SHA256:65F1FB92D649CE22ECEE39397AFEEE7EDCFD136661434014DB301530B664A8A7
1536iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EAbinary
MD5:C0EE042DE4CBADBA9F61578153D69238
SHA256:89B73A040FA661D517C840FDD00F89829E4D9BC6BAE92942C8D5D1ED20462676
1536iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B66240B0F6C84BD4857ABA60CF5CE4A0_5043E0F5DF723415C9EECC201C838A62binary
MD5:1C4FB36F761F0C3341D0C50ECD496142
SHA256:4C3DBBA0FC2FC35FC3E8CD7CEAE52975EF70863773F3919C89560A94618FD86E
1536iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\FE124AB097D4CDA51BABAE4410CBF6B8_19EEB030CBCF94E18F1254DE862231CEbinary
MD5:5666920AD510A8424192F33C2F86829A
SHA256:8A53B87604510D143FEE4BEC2B0DBCDC40F4BF4B6B0835B7B9B7695991866658
1536iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E87CE99F124623F95572A696C80EFCAF_0ECD9E0CFEC0543FF1D78810D7E03F54binary
MD5:27EB4E97490C7BC0D74C8C08AAFCEBBE
SHA256:75161F829D2DAB538CB4D8C6803AD02DB9825BAEF9209D6B39C096B851A4B3D0
1536iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\CAF4703619713E3F18D8A9D5D88D6288_A7725538C46DE2D0088EE44974E2CEBAder
MD5:64E9B8BB98E2303717538CE259BEC57D
SHA256:76BD459EC8E467EFC3E3FB94CB21B9C77A2AA73C9D4C0F3FAF823677BE756331
1536iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E87CE99F124623F95572A696C80EFCAF_0ECD9E0CFEC0543FF1D78810D7E03F54der
MD5:BB20D47F8AFF171DA32ED135CAD81ED8
SHA256:1DC159FF740A32CE07E53E378BF2BF9E735646CA8C22F01045942CF8B16E8173
1536iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\265C0DEB29181DD1891051371C5F863A_47758FB0BCF3FFB3996C4019E0C14DF8der
MD5:ECD7A17B3D2CB690B98A377F8F58018E
SHA256:6FA1427737BC5E2D40FC477C03F1ED05990E3372BE681B0B4BA935791C2BDA5A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
21
TCP/UDP connections
60
DNS requests
28
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1536
iexplore.exe
GET
200
142.250.186.99:80
http://ocsp.pki.goog/gts1c3/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEQC13JBUTfHICAoAAAABCKzE
US
der
472 b
whitelisted
1536
iexplore.exe
GET
200
142.250.186.99:80
http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIAjrICMzZli2TN25s%3D
US
der
724 b
whitelisted
1536
iexplore.exe
GET
200
142.250.186.99:80
http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFNZazTHGPUBUGY%3D
US
der
724 b
whitelisted
1536
iexplore.exe
GET
200
142.250.186.99:80
http://ocsp.pki.goog/gts1c3/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEQCyPFgrMEz3dAoAAAABCKqc
US
der
472 b
whitelisted
1536
iexplore.exe
GET
200
142.250.186.99:80
http://ocsp.pki.goog/gts1c3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEC7Ow4J75878CgAAAAEIq18%3D
US
der
471 b
whitelisted
2464
iexplore.exe
GET
200
93.184.220.29:80
http://crl3.digicert.com/Omniroot2025.crl
US
der
7.68 Kb
whitelisted
1536
iexplore.exe
GET
200
143.204.101.177:80
http://o.ss2.us//MEowSDBGMEQwQjAJBgUrDgMCGgUABBSLwZ6EW5gdYc9UaSEaaLjjETNtkAQUv1%2B30c7dH4b0W1Ws3NcQwg6piOcCCQCnDkpMNIK3fw%3D%3D
US
der
1.70 Kb
whitelisted
1536
iexplore.exe
GET
200
2.16.186.27:80
http://r3.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRI2smg%2ByvTLU%2Fw3mjS9We3NfmzxAQUFC6zF7dYVsuuUAlA5h%2BvnYsUwsYCEgQ2CBBgMdtNKRJt1EDlb3V2Fg%3D%3D
unknown
der
503 b
shared
2464
iexplore.exe
GET
304
23.32.238.201:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?a1ecea6b4f73a521
US
whitelisted
2464
iexplore.exe
GET
304
23.32.238.201:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?4d957fec47fd02a9
US
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1536
iexplore.exe
142.250.186.83:443
Google Inc.
US
malicious
1536
iexplore.exe
93.184.221.240:80
ctldl.windowsupdate.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
1536
iexplore.exe
142.250.186.99:80
ocsp.pki.goog
Google Inc.
US
whitelisted
2464
iexplore.exe
131.253.33.200:443
www.bing.com
Microsoft Corporation
US
whitelisted
1536
iexplore.exe
185.199.109.153:443
ljii.github.io
GitHub, Inc.
NL
shared
1536
iexplore.exe
143.204.98.120:443
images.fotmob.com
US
suspicious
1536
iexplore.exe
104.21.234.230:443
raw.githack.com
Cloudflare Inc
US
suspicious
1536
iexplore.exe
142.250.184.233:443
www.blogger.com
Google Inc.
US
unknown
1536
iexplore.exe
104.16.18.94:443
cdnjs.cloudflare.com
Cloudflare Inc
US
unknown
2464
iexplore.exe
23.32.238.201:80
ctldl.windowsupdate.com
XO Communications
US
suspicious

DNS requests

Domain
IP
Reputation
www.footem.site
  • 143.204.101.177
  • 143.204.101.123
  • 143.204.101.195
  • 143.204.101.99
malicious
ctldl.windowsupdate.com
  • 93.184.221.240
  • 23.32.238.201
  • 23.32.238.178
whitelisted
ocsp.pki.goog
  • 142.250.186.99
whitelisted
api.bing.com
  • 13.107.13.80
whitelisted
www.bing.com
  • 131.253.33.200
  • 13.107.22.200
whitelisted
cdnjs.cloudflare.com
  • 104.16.18.94
  • 104.16.19.94
whitelisted
1.bp.blogspot.com
  • 142.250.185.161
whitelisted
images.fotmob.com
  • 143.204.98.120
  • 143.204.98.124
  • 143.204.98.41
  • 143.204.98.73
malicious
ljii.github.io
  • 185.199.109.153
  • 185.199.108.153
  • 185.199.111.153
  • 185.199.110.153
malicious
raw.githack.com
  • 104.21.234.230
  • 104.21.234.231
malicious

Threats

No threats detected
No debug info