analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
URL:

https://praetoriandigital.us17.list-manage.com/track/click?u=fbf2eef5cbb7010c3dab66a8e&id=cbc9cd331e&e=1e702dff41

Full analysis: https://app.any.run/tasks/47de5f71-cc7a-4b1b-9177-da509bdc48b3
Verdict: Malicious activity
Analysis date: March 30, 2020, 16:55:54
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

2108E4AEE408C3BED359A658D10D3460

SHA1:

B91576EA87D144AE32B5047C0183575AE2D44C89

SHA256:

265FD2DDC5875132A3966416E31A3725A26C3A07B2757D9D902FB7EE4DAC5FDD

SSDEEP:

3:N8TEzBBQMLLJXCULGGRXEGcJMkNb5DzpGLTTEdABEW4jDGn:2Qi4ZCULEGcJMWUnICBA/Gn

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executed via COM

      • FlashUtil32_26_0_0_131_ActiveX.exe (PID: 3800)
  • INFO

    • Reads Internet Cache Settings

      • iexplore.exe (PID: 2524)
      • iexplore.exe (PID: 2764)
    • Application launched itself

      • iexplore.exe (PID: 2524)
    • Changes internet zones settings

      • iexplore.exe (PID: 2524)
    • Creates files in the user directory

      • iexplore.exe (PID: 2764)
      • FlashUtil32_26_0_0_131_ActiveX.exe (PID: 3800)
      • iexplore.exe (PID: 2524)
    • Reads internet explorer settings

      • iexplore.exe (PID: 2764)
    • Dropped object may contain Bitcoin addresses

      • iexplore.exe (PID: 2764)
    • Dropped object may contain TOR URL's

      • iexplore.exe (PID: 2764)
    • Reads settings of System Certificates

      • iexplore.exe (PID: 2524)
    • Changes settings of System certificates

      • iexplore.exe (PID: 2524)
    • Adds / modifies Windows certificates

      • iexplore.exe (PID: 2524)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
37
Monitored processes
3
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe flashutil32_26_0_0_131_activex.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2524"C:\Program Files\Internet Explorer\iexplore.exe" "https://praetoriandigital.us17.list-manage.com/track/click?u=fbf2eef5cbb7010c3dab66a8e&id=cbc9cd331e&e=1e702dff41"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
2764"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2524 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
3800C:\Windows\system32\Macromed\Flash\FlashUtil32_26_0_0_131_ActiveX.exe -EmbeddingC:\Windows\system32\Macromed\Flash\FlashUtil32_26_0_0_131_ActiveX.exesvchost.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
MEDIUM
Description:
Adobe® Flash® Player Installer/Uninstaller 26.0 r0
Version:
26,0,0,131
Total events
6 151
Read events
874
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
132
Text files
151
Unknown types
68

Dropped files

PID
Process
Filename
Type
2764iexplore.exeC:\Users\admin\AppData\Local\Temp\Low\Cab78D2.tmp
MD5:
SHA256:
2764iexplore.exeC:\Users\admin\AppData\Local\Temp\Low\Tar78D3.tmp
MD5:
SHA256:
2764iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\1UAOJV3W.txt
MD5:
SHA256:
2524iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
MD5:
SHA256:
2764iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B66240B0F6C84BD4857ABA60CF5CE4A0_5043E0F5DF723415C9EECC201C838A62der
MD5:C16307497EA332BCA45E1239426082D3
SHA256:180200666D31E572AED78CED43758F12295AF87506F8DBAEEA412F4314B5A164
2764iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\453HF2UZ.txttext
MD5:02D9B9C7609A331A4DDD66300A5471A1
SHA256:822764962F246D0EA6BD925E1E257885DD04332896A0FEC876480F92FD5F9919
2764iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\75CA58072B9926F763A91F0CC2798706_93E4B2BA79A897B3100CCB27F2D3BF4Fbinary
MD5:AE95FE7C54820ED58DBCF21228967A4A
SHA256:FEE47A48D0DD3AE76136947159C701AC620E2AA27C1A74EBBE78DEB8D7BBAA59
2764iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B66240B0F6C84BD4857ABA60CF5CE4A0_5043E0F5DF723415C9EECC201C838A62binary
MD5:5E40E1F60D991C3F7DA9BAD36E765DEF
SHA256:1907D9E8FEE900BC41FFD249BAF1F4252882D20A016249D5480CAD8E5DDE4B01
2764iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\BAD725C80F9E10846F35D039A996E4A8_88B6AE015495C1ECC395D19C1DD02894binary
MD5:D3BA97211979D5496F77B5EF0764DE55
SHA256:C1590738D9825AFE80BA692BF2777571A1AEE4B5B813C5640C5D7764C0C38030
2764iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7423F88C7F265F0DEFC08EA88C3BDE45_D975BBA8033175C8D112023D8A7A8AD6binary
MD5:E295C31A47EBF3AC0369398C626AD5E1
SHA256:EA715B4CBE693E66BBD0407D9147E4F5E58D29AB9AB940A597A43E4086BB2A4B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
58
TCP/UDP connections
153
DNS requests
63
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2764
iexplore.exe
GET
200
151.139.128.14:80
http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBR8sWZUnKvbRO5iJhat9GV793rVlAQUrb2YejS0Jvf6xCZU7wO94CTLVBoCEBPqKHBb9OztDDZjCYBhQzY%3D
US
der
471 b
whitelisted
2764
iexplore.exe
GET
200
151.139.128.14:80
http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBR8sWZUnKvbRO5iJhat9GV793rVlAQUrb2YejS0Jvf6xCZU7wO94CTLVBoCEBPqKHBb9OztDDZjCYBhQzY%3D
US
der
471 b
whitelisted
2764
iexplore.exe
GET
200
13.35.254.41:80
http://ocsp.rootg2.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBSIfaREXmfqfJR3TkMYnD7O5MhzEgQUnF8A36oB1zArOIiiuG1KnPIRkYMCEwZ%2FlEoqJ83z%2BsKuKwH5CO65xMY%3D
US
der
1.51 Kb
whitelisted
2764
iexplore.exe
GET
200
151.139.128.14:80
http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBR8sWZUnKvbRO5iJhat9GV793rVlAQUrb2YejS0Jvf6xCZU7wO94CTLVBoCEBPqKHBb9OztDDZjCYBhQzY%3D
US
der
471 b
whitelisted
2764
iexplore.exe
GET
200
13.35.254.226:80
http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwZ%2FlFeFh%2Bisd96yUzJbvJmLVg0%3D
US
der
1.39 Kb
shared
2764
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAH9o%2BtuynXIiEOLckvPvJE%3D
US
der
471 b
whitelisted
2764
iexplore.exe
GET
200
143.204.208.127:80
http://o.ss2.us//MEowSDBGMEQwQjAJBgUrDgMCGgUABBSLwZ6EW5gdYc9UaSEaaLjjETNtkAQUv1%2B30c7dH4b0W1Ws3NcQwg6piOcCCQCnDkpMNIK3fw%3D%3D
US
der
1.70 Kb
whitelisted
2764
iexplore.exe
GET
200
13.35.254.90:80
http://ocsp.sca1b.amazontrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQz9arGHWbnBV0DFzpNHz4YcTiFDQQUWaRmBlKge5WSPKOUByeWdFv5PdACEA%2FOh0raJF4ksq4i%2FXE1l60%3D
US
der
471 b
whitelisted
2764
iexplore.exe
GET
200
172.217.21.227:80
http://ocsp.pki.goog/gsr2/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBTgXIsxbvr2lBkPpoIEVRE6gHlCnAQUm%2BIHV2ccHsBqBt5ZtJot39wZhi4CDQHjtJqhjYqpgSVpULg%3D
US
der
468 b
whitelisted
2764
iexplore.exe
GET
200
104.18.21.226:80
http://ocsp.globalsign.com/rootr1/ME8wTTBLMEkwRzAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCDkbwjNvPLFRm7zMB3V80
US
der
1.49 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2764
iexplore.exe
143.204.208.127:80
o.ss2.us
US
malicious
2764
iexplore.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
2524
iexplore.exe
204.79.197.200:80
www.bing.com
Microsoft Corporation
US
whitelisted
2764
iexplore.exe
54.86.4.50:443
www.policeone.com
Amazon.com, Inc.
US
unknown
2764
iexplore.exe
13.35.254.41:80
ocsp.rootg2.amazontrust.com
US
whitelisted
2764
iexplore.exe
23.45.237.132:443
Akamai International B.V.
NL
suspicious
2764
iexplore.exe
151.101.2.217:443
js.sentry-cdn.com
Fastly
US
suspicious
2764
iexplore.exe
151.139.128.10:443
lid.cdn.lexipol.com
Highwinds Network Group, Inc.
US
malicious
2764
iexplore.exe
13.35.254.226:80
ocsp.rootg2.amazontrust.com
US
whitelisted
2764
iexplore.exe
13.35.254.90:80
ocsp.sca1b.amazontrust.com
US
whitelisted

DNS requests

Domain
IP
Reputation
praetoriandigital.us17.list-manage.com
  • 185.60.216.35
whitelisted
ocsp.digicert.com
  • 93.184.220.29
whitelisted
api.bing.com
  • 13.107.5.80
whitelisted
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
www.policeone.com
  • 54.86.4.50
  • 18.208.67.10
unknown
o.ss2.us
  • 143.204.208.127
  • 143.204.208.79
  • 143.204.208.160
  • 143.204.208.165
whitelisted
ocsp.rootg2.amazontrust.com
  • 13.35.254.41
  • 13.35.254.52
  • 13.35.254.226
  • 13.35.254.57
whitelisted
ocsp.rootca1.amazontrust.com
  • 13.35.254.226
  • 13.35.254.52
  • 13.35.254.41
  • 13.35.254.57
shared
ocsp.sca1b.amazontrust.com
  • 13.35.254.90
  • 13.35.254.113
  • 13.35.254.89
  • 13.35.254.29
whitelisted
lid.cdn.lexipol.com
  • 151.139.128.10
malicious

Threats

No threats detected
No debug info