| URL: | http://shop04004.whehwfh.ru |
| Full analysis: | https://app.any.run/tasks/562e5296-6d66-4810-9f6f-37cfdfa977c8 |
| Verdict: | Malicious activity |
| Analysis date: | March 25, 2022, 01:44:58 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MD5: | 9805FAF853C19ACC715B798A7FA4BFE6 |
| SHA1: | 380B72E76010E1F7E0BBE497A10DEEC28AE24F39 |
| SHA256: | 25F987A328EB551D943229FA165F0D79A31D98D5C75243F55EA49CA64413F3FB |
| SSDEEP: | 3:N1KNNO7iD+:C2mD+ |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 3004 | "C:\Program Files\Internet Explorer\iexplore.exe" "http://shop04004.whehwfh.ru" | C:\Program Files\Internet Explorer\iexplore.exe | Explorer.EXE | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| 3892 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3004 CREDAT:267521 /prefetch:2 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| (PID) Process: | (3004) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPDaysSinceLastAutoMigration |
Value: 1 | |||
| (PID) Process: | (3004) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPLastLaunchLowDateTime |
Value: | |||
| (PID) Process: | (3004) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPLastLaunchHighDateTime |
Value: 30949353 | |||
| (PID) Process: | (3004) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager |
| Operation: | write | Name: | NextCheckForUpdateLowDateTime |
Value: 53360247 | |||
| (PID) Process: | (3004) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager |
| Operation: | write | Name: | NextCheckForUpdateHighDateTime |
Value: 30949354 | |||
| (PID) Process: | (3004) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (3004) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (3004) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (3004) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main |
| Operation: | write | Name: | CompatibilityFlags |
Value: 0 | |||
| (PID) Process: | (3004) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3892 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\adidasbanner1[1].jpg | image | |
MD5:— | SHA256:— | |||
| 3892 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\js-sdk-pro.min[1].js | text | |
MD5:— | SHA256:— | |||
| 3892 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\ULCAWSBV.htm | html | |
MD5:— | SHA256:— | |||
| 3892 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\angular-route.min[1].js | text | |
MD5:32149763854F6D30B9919EC9F5DA22EB | SHA256:934D99C83F663714713CD32CC77D63F6FA2A9B554036985F3EBAD054D0433649 | |||
| 3892 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\bootstrap.min[1].css | text | |
MD5:5057F321F0DC85CD8DA94A0C5F67A8F4 | SHA256:5A3D8C05785485D36EE5C94D4681E5B1D9E4B94C5BE8B5BD7B0F3168FFF1BD9A | |||
| 3892 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\style[1].css | text | |
MD5:08572F85DB707A1D252DD338F2176CD0 | SHA256:2C0D01826A626C07DE2742B47D85A9CA6514C7C989D5EDA2782E6A6FB52AF177 | |||
| 3892 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\main[1].css | text | |
MD5:91CD4C52C4ED34C57E736E44EB7D8A9C | SHA256:BBAF67EA1B0C4BB843245E57E64C42F124400D42949B560E2EACEC256094E9A6 | |||
| 3892 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\bootstrap.min[1].js | text | |
MD5:04C84852E9937B142AC73C285B895B85 | SHA256:36460E494E4C628443AFDED40B2743B5EDE9A4A76FB4F7B9EF2345CC7E59FD64 | |||
| 3892 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\jquery1.12.4.min[1].js | text | |
MD5:618538B4AB9639D444E962729A927F15 | SHA256:27D92130C0321DAD5A03760FD5AC98A3D04ED4C94D88418FE6D50DA1F7FC5CBE | |||
| 3892 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\app[1].js | text | |
MD5:563660421C2F2699297AAB7565C79774 | SHA256:6CD7A1A14A8D39718E44B1013DB9CCFCC3A343A4DD77AB6341A9198E85401CB8 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3892 | iexplore.exe | GET | — | 104.21.42.139:80 | http://shop04004.whehwfh.ru/api/bootstrap-3.3.7-dist/css/bootstrap.min.css | US | — | — | unknown |
3892 | iexplore.exe | GET | — | 104.21.42.139:80 | http://shop04004.whehwfh.ru/api/css/main.css | US | — | — | unknown |
3892 | iexplore.exe | GET | — | 104.21.42.139:80 | http://shop04004.whehwfh.ru/api/js/jquery1.12.4.min.js | US | — | — | unknown |
3892 | iexplore.exe | GET | — | 104.21.42.139:80 | http://shop04004.whehwfh.ru/api/angular/angular.min.js | US | — | — | unknown |
3892 | iexplore.exe | GET | — | 104.21.42.139:80 | http://shop04004.whehwfh.ru/api/js/app.js | US | — | — | unknown |
3892 | iexplore.exe | GET | — | 104.21.42.139:80 | http://shop04004.whehwfh.ru/images/banner/nikebanner2.png | US | — | — | unknown |
3892 | iexplore.exe | GET | — | 104.21.42.139:80 | http://shop04004.whehwfh.ru/images/banner/nikebanner1.jpg | US | — | — | unknown |
3892 | iexplore.exe | GET | — | 104.21.42.139:80 | http://shop04004.whehwfh.ru/images/banner/adidasbanner1.jpg | US | — | — | unknown |
3892 | iexplore.exe | GET | — | 104.21.42.139:80 | http://shop04004.whehwfh.ru/api/bootstrap-3.3.7-dist/fonts/glyphicons-halflings-regular.eot? | US | — | — | unknown |
3892 | iexplore.exe | GET | 200 | 104.21.42.139:80 | http://shop04004.whehwfh.ru/ | US | html | 9.16 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3892 | iexplore.exe | 104.21.42.139:80 | shop04004.whehwfh.ru | Cloudflare Inc | US | unknown |
3892 | iexplore.exe | 112.90.153.42:443 | js.users.51.la | China Unicom IP network China169 Guangdong province | CN | suspicious |
3892 | iexplore.exe | 142.250.185.174:443 | encrypted-tbn0.gstatic.com | Google Inc. | US | whitelisted |
3892 | iexplore.exe | 47.253.50.2:80 | sdk.51.la | — | US | suspicious |
3892 | iexplore.exe | 8.241.89.254:80 | ctldl.windowsupdate.com | Level 3 Communications, Inc. | US | suspicious |
3892 | iexplore.exe | 142.250.186.163:80 | ocsp.pki.goog | Google Inc. | US | whitelisted |
3004 | iexplore.exe | 104.21.42.139:80 | shop04004.whehwfh.ru | Cloudflare Inc | US | unknown |
3004 | iexplore.exe | 152.199.19.161:443 | iecvlist.microsoft.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
3892 | iexplore.exe | 183.131.207.66:80 | collect-v6.51.la | DaLi | CN | malicious |
3004 | iexplore.exe | 204.79.197.200:443 | www.bing.com | Microsoft Corporation | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
shop04004.whehwfh.ru |
| unknown |
encrypted-tbn0.gstatic.com |
| whitelisted |
js.users.51.la |
| whitelisted |
sdk.51.la |
| suspicious |
ctldl.windowsupdate.com |
| whitelisted |
ocsp.pki.goog |
| whitelisted |
api.bing.com |
| whitelisted |
www.bing.com |
| whitelisted |
ocsp.globalsign.com |
| whitelisted |
ocsp2.globalsign.com |
| whitelisted |