analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
download:

index.html

Full analysis: https://app.any.run/tasks/4467f6a9-50f7-40ab-a984-92c447d62803
Verdict: Malicious activity
Analysis date: May 14, 2019, 23:27:40
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: text/html
File info: HTML document, ASCII text, with very long lines, with CRLF line terminators
MD5:

381E437D8D5DDA8662B9B2E875EB87E6

SHA1:

1C38EBF9AF0A2AA79E3F9E30FDAC26D685390915

SHA256:

252084A7BD43501C46E993B3626E98038F879D17C4C45EFA4D9E2A29F373F968

SSDEEP:

384:FVu336QSWB/5ce+FHZHs0GikHgt9jxhuzLGFiiGi9cWXjVvOximJoM1iKiKibiru:m3qQS4/yT1GirLX9ciGwPBzz+f0nZj

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Reads internet explorer settings

      • iexplore.exe (PID: 2792)
      • iexplore.exe (PID: 3820)
    • Reads Internet Cache Settings

      • iexplore.exe (PID: 2792)
      • iexplore.exe (PID: 2960)
      • iexplore.exe (PID: 3820)
    • Creates files in the user directory

      • iexplore.exe (PID: 2792)
      • iexplore.exe (PID: 3820)
    • Changes internet zones settings

      • iexplore.exe (PID: 2960)
    • Reads settings of System Certificates

      • iexplore.exe (PID: 2960)
    • Application launched itself

      • iexplore.exe (PID: 2960)
    • Adds / modifies Windows certificates

      • iexplore.exe (PID: 2960)
    • Changes settings of System certificates

      • iexplore.exe (PID: 2960)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

EXIF

HTML

Title: Outlook Web App
Robots: NOINDEX, NOFOLLOW
HTTPEquivXUACompatible: IE=10
ContentType: text/html; charset=UTF-8
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
37
Monitored processes
3
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe no specs iexplore.exe

Process information

PID
CMD
Path
Indicators
Parent process
2960"C:\Program Files\Internet Explorer\iexplore.exe" C:\Users\admin\AppData\Local\Temp\index.htmlC:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
2792"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2960 CREDAT:79873C:\Program Files\Internet Explorer\iexplore.exeiexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
3820"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2960 CREDAT:203009C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Total events
611
Read events
508
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
1
Text files
14
Unknown types
5

Dropped files

PID
Process
Filename
Type
2960iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H6QNMHE9\favicon[1].ico
MD5:
SHA256:
2960iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
MD5:
SHA256:
2960iexplore.exeC:\Users\admin\AppData\Local\Temp\~DF3A4B9C7E09114650.TMP
MD5:
SHA256:
2792iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012019051520190516\index.datdat
MD5:0DC61A4D849FE009CDFBB5F41FCF49BE
SHA256:FA6A0EBB96D00E6E0713C33F784B160C51D1C4FA478446E0614A3533A04254D2
2960iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{E79AB34A-769F-11E9-B63D-5254004A04AF}.datbinary
MD5:6C06BEF8DA773EDCC101B7EECFFC2CE7
SHA256:615FDFA044F02547D46F28BC87A043A8627621B51F71DB81C9DC58194B969B22
3820iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\S7GLWKHJ\owa2[1].pngimage
MD5:F2A31777571EF39A7B9E1C505BBD4B13
SHA256:5A177A608BDA3497C5AA73403883DE228D280F98A39159B884220086B4575899
3820iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\index.datdat
MD5:F7970113B47A482F411F043DA3CC4351
SHA256:19F9CE997D79A42E2BECCB816B26BC906C99D42DEDA9FF51D833EA7F4C6CA9BC
3820iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\W0PFYRIL\index[1].htmhtml
MD5:9A0365D661EDAF8C490C782ECA274BA8
SHA256:99EB2CD6FBA834768D9A0BE4CC48AD8EDDA6506355B36800EE21E619903FD61E
3820iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\History\Low\History.IE5\MSHist012019051520190516\index.datdat
MD5:81E5A5AAF7A329D65FD23EC43A1A0952
SHA256:4286FD9193F22328647A9ECE6B6596617746CD1662B5F09630A61034B9FB4A3B
3820iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\History\Low\History.IE5\index.datdat
MD5:19F44BE7254EDACF875120CE1533A933
SHA256:6F6C3E932E00B0518E51D632DA8CD97CAA9F098E2B49ED2E29C16DD67D60EAF4
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
10
DNS requests
4
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2960
iexplore.exe
GET
200
204.79.197.200:80
http://www.bing.com/favicon.ico
US
image
237 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2960
iexplore.exe
204.79.197.200:80
www.bing.com
Microsoft Corporation
US
whitelisted
2960
iexplore.exe
52.231.168.69:443
outlookmails.z32.web.core.windows.net
Microsoft Corporation
KR
unknown
3820
iexplore.exe
52.231.168.69:443
outlookmails.z32.web.core.windows.net
Microsoft Corporation
KR
unknown
3820
iexplore.exe
37.17.224.96:443
www.7short1long.de
First Colo GmbH
DE
malicious

DNS requests

Domain
IP
Reputation
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
www.7short1long.de
  • 37.17.224.96
malicious
outlookmails.z32.web.core.windows.net
  • 52.231.168.69
unknown

Threats

No threats detected
No debug info