analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
URL:

http://dl.360safe.com/gf/KitTip/KitTipConf.cab

Full analysis: https://app.any.run/tasks/ebb43e97-49cf-4c0a-8c97-6d39f4ca1dc1
Verdict: Malicious activity
Analysis date: January 15, 2022, 03:11:52
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

5D678931A5B5D681EA7F9BF157F694BE

SHA1:

F520D85ED650C9C61CEA5B0E05D8389DE95389BF

SHA256:

15EBB2434BA2F0F2182B2B8C46A961D9A17630BDC2E81C4EB5A14C5D1F1C1680

SSDEEP:

3:N1KaJwVoLkDGRKVmMVYEH:CaJIDGRKgMrH

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads the computer name

      • WinRAR.exe (PID: 2548)
      • WinRAR.exe (PID: 3532)
      • WinRAR.exe (PID: 2620)
    • Checks supported languages

      • WinRAR.exe (PID: 2548)
      • WinRAR.exe (PID: 2620)
      • WinRAR.exe (PID: 3532)
    • Reads Microsoft Outlook installation path

      • iexplore.exe (PID: 1420)
  • INFO

    • Reads the computer name

      • iexplore.exe (PID: 1420)
      • iexplore.exe (PID: 2916)
      • explorer.exe (PID: 3804)
    • Checks supported languages

      • iexplore.exe (PID: 2916)
      • iexplore.exe (PID: 1420)
      • explorer.exe (PID: 3804)
    • Reads the date of Windows installation

      • iexplore.exe (PID: 2916)
    • Manual execution by user

      • explorer.exe (PID: 3804)
      • WinRAR.exe (PID: 3532)
      • WinRAR.exe (PID: 2620)
    • Modifies the phishing filter of IE

      • iexplore.exe (PID: 2916)
    • Checks Windows Trust Settings

      • iexplore.exe (PID: 2916)
    • Application launched itself

      • iexplore.exe (PID: 2916)
    • Changes internet zones settings

      • iexplore.exe (PID: 2916)
    • Reads settings of System Certificates

      • iexplore.exe (PID: 2916)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
41
Monitored processes
6
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe winrar.exe no specs explorer.exe no specs winrar.exe no specs winrar.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2916"C:\Program Files\Internet Explorer\iexplore.exe" "http://dl.360safe.com/gf/KitTip/KitTipConf.cab"C:\Program Files\Internet Explorer\iexplore.exe
Explorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
1420"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2916 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2548"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Downloads\KitTipConf.cab"C:\Program Files\WinRAR\WinRAR.exeiexplore.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
1
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
3804"C:\Windows\explorer.exe" C:\Windows\explorer.exeExplorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2620"C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Downloads\KitTipConf.cab" "?\"C:\Program Files\WinRAR\WinRAR.exeExplorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
1
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3532"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Downloads\KitTipConf.cab"C:\Program Files\WinRAR\WinRAR.exeExplorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
1
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
11 436
Read events
11 317
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
5
Text files
6
Unknown types
2

Dropped files

PID
Process
Filename
Type
1420iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\KitTipConf[1].cabini
MD5:633547386F45E5E9898CF33F58792259
SHA256:12DA58FA29A732D149F067E8FE4C3B7A4AA94CF98D3471036BB43BB2A59C5E8F
2916iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{E43DE4B0-75B0-11EC-A45D-12A9866C77DE}.datbinary
MD5:870B8DE216B44387FBBBECF5B74DCB25
SHA256:247384CE8763CCEB025005FD84A37E137C31985B825EE15C140C6FE925B29E84
2916iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7423F88C7F265F0DEFC08EA88C3BDE45_AA1E8580D4EBC816148CE81268683776der
MD5:ACE427D9E2E5197DA2F600C887DCFCB1
SHA256:9D985EC5E3675B2C7DED4535F7DE2CBE39934D67046E25C3D0466220FAFE9651
1420iexplore.exeC:\Users\admin\Downloads\KitTipConf.cab.hqymq2b.partialini
MD5:633547386F45E5E9898CF33F58792259
SHA256:12DA58FA29A732D149F067E8FE4C3B7A4AA94CF98D3471036BB43BB2A59C5E8F
2916iexplore.exeC:\Users\admin\AppData\Local\Temp\~DF95D474830CF4A00B.TMPgmc
MD5:3B161B44ED556C5C2D6C91DC9F483655
SHA256:B1569F3A63544AEAB90008A6F1FC1C67F6D5AD267BD1AA61452E663A4CA11385
2916iexplore.exeC:\Users\admin\Downloads\KitTipConf.cabini
MD5:633547386F45E5E9898CF33F58792259
SHA256:12DA58FA29A732D149F067E8FE4C3B7A4AA94CF98D3471036BB43BB2A59C5E8F
2916iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:1BAB64070A63DF9FF7BEB81C7878615D
SHA256:A46E7326D91127FD39288089BA026A6A23B7861920ACCE58AB6A760082EFFB8A
2916iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7423F88C7F265F0DEFC08EA88C3BDE45_AA1E8580D4EBC816148CE81268683776binary
MD5:14CAF82D3E90AC8A5C798AF808B97E81
SHA256:180CE9AAED2B5EAEB864017C9B6CA7E9ECDA69F2AE7071CE3BCD13CCA32CCD45
2916iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\urlblockindex[1].binbinary
MD5:FA518E3DFAE8CA3A0E495460FD60C791
SHA256:775853600060162C4B4E5F883F9FD5A278E61C471B3EE1826396B6D129499AA7
2916iexplore.exeC:\Users\admin\Downloads\KitTipConf.cab.hqymq2b.partial:Zone.Identifiertext
MD5:FBCCF14D504B7B2DBCB5A5BDA75BD93B
SHA256:EACD09517CE90D34BA562171D15AC40D302F0E691B439F91BE1B6406E25F5913
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
10
DNS requests
11
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1420
iexplore.exe
GET
200
104.192.108.19:80
http://dl.360safe.com/gf/KitTip/KitTipConf.cab
US
ini
6.20 Kb
whitelisted
2916
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
der
471 b
whitelisted
2916
iexplore.exe
GET
200
67.26.81.254:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?4a5439ff8c78678d
US
compressed
4.70 Kb
whitelisted
2916
iexplore.exe
GET
200
67.26.81.254:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?01211d7c205abc8e
US
compressed
4.70 Kb
whitelisted
2916
iexplore.exe
GET
200
67.26.81.254:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?b7d39a4457690e6f
US
compressed
4.70 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2916
iexplore.exe
152.199.19.161:443
iecvlist.microsoft.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
2916
iexplore.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
1420
iexplore.exe
104.192.108.19:80
dl.360safe.com
Beijing Qihu Technology Company Limited
US
suspicious
2916
iexplore.exe
67.26.81.254:80
ctldl.windowsupdate.com
Level 3 Communications, Inc.
US
suspicious

DNS requests

Domain
IP
Reputation
dl.360safe.com
  • 104.192.108.19
  • 104.192.108.20
  • 104.192.108.21
  • 104.192.108.17
whitelisted
api.bing.com
  • 13.107.5.80
whitelisted
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
iecvlist.microsoft.com
  • 152.199.19.161
whitelisted
r20swj13mr.microsoft.com
  • 152.199.19.161
whitelisted
ctldl.windowsupdate.com
  • 67.26.81.254
  • 8.241.123.126
  • 67.27.157.126
  • 67.26.137.254
  • 8.241.121.126
  • 93.184.221.240
whitelisted
ocsp.digicert.com
  • 93.184.220.29
whitelisted

Threats

No threats detected
No debug info