URL:

https://gdzjq.flndluver.com/c/da57dc555e50572d?s1=32298&s2=1352729&j1=1

Full analysis: https://app.any.run/tasks/5bd8ba59-0f3f-4d90-8839-52cb7c027c3f
Verdict: Malicious activity
Analysis date: January 26, 2022, 17:39:38
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

6986306A70B3E68398E26A0D9C03C4EC

SHA1:

D3C0BFD2644A3E83C863E3777AE241E782E678E6

SHA256:

24ACC99933DAE027C239280E09241D10CC651F12F89B1C89579FBB56A2D8064B

SSDEEP:

3:N8gnUVYWLGT6VqAYhWHcgIoUcUYU:2gjHTCeW8tl5

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads Microsoft Outlook installation path

      • iexplore.exe (PID: 736)
  • INFO

    • Checks supported languages

      • iexplore.exe (PID: 3628)
      • iexplore.exe (PID: 736)
    • Reads the computer name

      • iexplore.exe (PID: 3628)
      • iexplore.exe (PID: 736)
    • Changes internet zones settings

      • iexplore.exe (PID: 3628)
    • Reads settings of System Certificates

      • iexplore.exe (PID: 736)
      • iexplore.exe (PID: 3628)
    • Application launched itself

      • iexplore.exe (PID: 3628)
    • Changes settings of System certificates

      • iexplore.exe (PID: 3628)
    • Adds / modifies Windows certificates

      • iexplore.exe (PID: 3628)
    • Reads internet explorer settings

      • iexplore.exe (PID: 736)
    • Creates files in the user directory

      • iexplore.exe (PID: 736)
    • Checks Windows Trust Settings

      • iexplore.exe (PID: 3628)
      • iexplore.exe (PID: 736)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
38
Monitored processes
2
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe

Process information

PID
CMD
Path
Indicators
Parent process
736"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3628 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
3628"C:\Program Files\Internet Explorer\iexplore.exe" "https://gdzjq.flndluver.com/c/da57dc555e50572d?s1=32298&s2=1352729&j1=1"C:\Program Files\Internet Explorer\iexplore.exe
Explorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
Total events
17 242
Read events
17 116
Write events
124
Delete events
2

Modification events

(PID) Process:(3628) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
1
(PID) Process:(3628) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchLowDateTime
Value:
(PID) Process:(3628) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30937819
(PID) Process:(3628) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateLowDateTime
Value:
(PID) Process:(3628) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30937819
(PID) Process:(3628) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(3628) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3628) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3628) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(3628) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
0
Suspicious files
31
Text files
79
Unknown types
27

Dropped files

PID
Process
Filename
Type
736iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506binary
MD5:55D9FE3E4BE8078E163AFEA678DDACE7
SHA256:F59FA315CF170F5757C6914A0A05CFB17406BFA45AC319DDCECCCF3B410BB22D
736iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:9D71E709C91756B6BF75AC5057622EC0
SHA256:343D002E0692B7C7211A7714EB7003F11609AC6E7DFE47607B6A6223F3BFE366
736iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157compressed
MD5:F7DCB24540769805E5BB30D193944DCE
SHA256:6B88C6AC55BBD6FEA0EBE5A760D1AD2CFCE251C59D0151A1400701CB927E36EA
736iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\103621DE9CD5414CC2538780B4B75751der
MD5:54E9306F95F32E50CCD58AF19753D929
SHA256:45F94DCEB18A8F738A26DA09CE4558995A4FE02B971882E8116FC9B59813BB72
736iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751binary
MD5:91C62E9BC4C0A6A08790488EE3E587A4
SHA256:8D9434F1ABC746AB8804189D71EE9AE7CADA8B38999FA47F18D063F2DF508DB9
3628iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6BADA8974A10C4BD62CC921D13E43B18_711ED44619924BA6DC33E69F97E7FF63der
MD5:2A8BD700D2F7431CC7401C78F2D41529
SHA256:9C4C7F33A7FBB6722F2D560AE72F87B575234D0DD86B009037A73EB539BE3FA1
3628iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6BADA8974A10C4BD62CC921D13E43B18_711ED44619924BA6DC33E69F97E7FF63binary
MD5:FE1DB6100419881A0597F70B5D6D8A96
SHA256:298E82BB4B046003E64CE4EBEDBFC00B0816F6EAF4ED8B1AC26D272E45CCA630
736iexplore.exeC:\Users\admin\AppData\Local\Temp\Low\Cab30B0.tmpcompressed
MD5:ACAEDA60C79C6BCAC925EEB3653F45E0
SHA256:6B0CECCF0103AFD89844761417C1D23ACC41F8AEBF3B7230765209B61EEE5658
736iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\EUC0KL3K.txttext
MD5:E348B77375FB92EEA540F3FA903C3F81
SHA256:DC1F9454F8338A0CDD075AB92F1FA7FAEB3D0E5049D22964D22507F6D95D0997
736iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\da57dc555e50572d[1].htmhtml
MD5:E2D243884D2B7F607F713F660465AE57
SHA256:75F6CF468A99E387D36258EC036EF984DBF6EAE00838C91B2083F3F5CB0D14D7
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
29
TCP/UDP connections
101
DNS requests
38
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
736
iexplore.exe
GET
200
8.248.143.254:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?aa801b41339d45ac
US
compressed
59.9 Kb
whitelisted
736
iexplore.exe
GET
200
8.248.143.254:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?c3386e041cbb23ba
US
compressed
4.70 Kb
whitelisted
736
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAH9o%2BtuynXIiEOLckvPvJE%3D
US
der
471 b
whitelisted
736
iexplore.exe
GET
200
23.45.105.185:80
http://x1.c.lencr.org/
NL
der
717 b
whitelisted
736
iexplore.exe
GET
200
142.250.185.99:80
http://ocsp.pki.goog/gts1c3/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEQCrvyQ4GllugQoAAAABK4Az
US
der
472 b
whitelisted
736
iexplore.exe
GET
200
142.250.185.99:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
US
der
1.41 Kb
whitelisted
3628
iexplore.exe
GET
200
2.16.186.11:80
http://r3.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRI2smg%2ByvTLU%2Fw3mjS9We3NfmzxAQUFC6zF7dYVsuuUAlA5h%2BvnYsUwsYCEgN6U5wiGEE5wpm7hpFrkiQfcA%3D%3D
unknown
der
503 b
shared
3628
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
der
471 b
whitelisted
736
iexplore.exe
GET
200
142.250.185.99:80
http://ocsp.pki.goog/gts1c3/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEQC2PrP09fGo%2BgoAAAABK3x6
US
der
472 b
whitelisted
736
iexplore.exe
GET
200
142.250.185.99:80
http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFNZazTHGPUBUGY%3D
US
der
724 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
736
iexplore.exe
172.217.23.106:443
fonts.googleapis.com
Google Inc.
US
whitelisted
736
iexplore.exe
142.250.184.200:443
www.googletagmanager.com
Google Inc.
US
suspicious
736
iexplore.exe
142.250.185.99:80
ocsp.pki.goog
Google Inc.
US
whitelisted
3628
iexplore.exe
52.19.101.114:443
gdzjq.flndluver.com
Amazon.com, Inc.
IE
malicious
3628
iexplore.exe
2.16.186.11:80
r3.o.lencr.org
Akamai International B.V.
whitelisted
736
iexplore.exe
52.19.101.114:443
gdzjq.flndluver.com
Amazon.com, Inc.
IE
malicious
736
iexplore.exe
8.248.143.254:80
ctldl.windowsupdate.com
Level 3 Communications, Inc.
US
malicious
736
iexplore.exe
2.16.186.11:80
r3.o.lencr.org
Akamai International B.V.
whitelisted
3628
iexplore.exe
13.107.22.200:443
www.bing.com
Microsoft Corporation
US
whitelisted
736
iexplore.exe
23.45.105.185:80
x1.c.lencr.org
Akamai International B.V.
NL
unknown

DNS requests

Domain
IP
Reputation
gdzjq.flndluver.com
  • 52.19.101.114
malicious
ctldl.windowsupdate.com
  • 8.248.143.254
  • 67.27.233.254
  • 67.27.159.126
  • 67.26.83.254
  • 67.27.235.254
whitelisted
x1.c.lencr.org
  • 23.45.105.185
whitelisted
r3.o.lencr.org
  • 2.16.186.11
  • 2.16.186.27
  • 2.16.186.8
  • 2.16.186.35
  • 2.16.186.10
shared
api.bing.com
  • 13.107.5.80
whitelisted
www.bing.com
  • 131.253.33.200
  • 13.107.22.200
whitelisted
ocsp.digicert.com
  • 93.184.220.29
whitelisted
cdn-bimi.akamaized.net
  • 2.16.186.80
  • 2.16.186.107
whitelisted
fonts.googleapis.com
  • 172.217.23.106
whitelisted
ocsp.pki.goog
  • 142.250.185.99
whitelisted

Threats

No threats detected
No debug info