File name:

myie.zip

Full analysis: https://app.any.run/tasks/6085e226-0b7d-42a5-884c-ee84628dbd9b
Verdict: Malicious activity
Analysis date: March 10, 2024, 13:02:26
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract, compression method=store
MD5:

C1971BA634BCEB355C2135713EE059BA

SHA1:

E250C408C491D9FA4D5918F627EBD3EDE6CD8C0F

SHA256:

2CB627ECF70F7D3C36800D59F9E186DE8EBEF915935E39232D4B4FDC838DC545

SSDEEP:

49152:iqgqbT9bpBt36U/12YtRE+SLYrFHUROng4YGj/aoUxqyoIjiHoLj2mKu:iCHd53H/1HRlrFHSOngah0LoIJLj2bu

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • MyIE.exe (PID: 2328)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • MyIE.exe (PID: 2328)
    • Reads the Internet Settings

      • MyIE.exe (PID: 2328)
    • Starts SC.EXE for service management

      • MyIE.exe (PID: 2328)
    • Get information on the list of running processes

      • MyIE.exe (PID: 2328)
    • Executable content was dropped or overwritten

      • MyIE.exe (PID: 2328)
    • Executes as Windows Service

      • tasklist.exe (PID: 4008)
    • Reads Microsoft Outlook installation path

      • MyIE.exe (PID: 2328)
    • Reads Internet Explorer settings

      • MyIE.exe (PID: 2328)
    • Checks Windows Trust Settings

      • MyIE.exe (PID: 2328)
    • Reads settings of System Certificates

      • MyIE.exe (PID: 2328)
    • Adds/modifies Windows certificates

      • MyIE.exe (PID: 2328)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3668)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 3668)
    • Manual execution by a user

      • MyIE.exe (PID: 2920)
      • MyIE.exe (PID: 2328)
    • Checks supported languages

      • MyIE.exe (PID: 2328)
      • tasklist.exe (PID: 864)
      • tasklist.exe (PID: 4008)
    • Reads the computer name

      • MyIE.exe (PID: 2328)
      • tasklist.exe (PID: 864)
      • tasklist.exe (PID: 4008)
    • Create files in a temporary directory

      • MyIE.exe (PID: 2328)
    • Reads the machine GUID from the registry

      • MyIE.exe (PID: 2328)
    • Checks proxy server information

      • MyIE.exe (PID: 2328)
    • Creates files or folders in the user directory

      • MyIE.exe (PID: 2328)
    • Reads the software policy settings

      • MyIE.exe (PID: 2328)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2017:11:26 13:27:46
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: Skin/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
46
Monitored processes
6
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe myie.exe no specs myie.exe tasklist.exe sc.exe no specs tasklist.exe

Process information

PID
CMD
Path
Indicators
Parent process
120sc start tasklistC:\Windows\System32\sc.exeMyIE.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
A tool to aid in developing services for WindowsNT
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\sc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
864"C:\Windows\tasklist.exe" -installC:\Windows\tasklist.exe
MyIE.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\windows\tasklist.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2328"C:\Users\admin\AppData\Local\Temp\myie\MyIE.exe" C:\Users\admin\AppData\Local\Temp\myie\MyIE.exe
explorer.exe
User:
admin
Company:
5huawei
Integrity Level:
HIGH
Description:
MyIE Web Browser
Exit code:
0
Version:
1, 0, 0, 0
Modules
Images
c:\users\admin\appdata\local\temp\myie\myie.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winmm.dll
2920"C:\Users\admin\AppData\Local\Temp\myie\MyIE.exe" C:\Users\admin\AppData\Local\Temp\myie\MyIE.exeexplorer.exe
User:
admin
Company:
5huawei
Integrity Level:
MEDIUM
Description:
MyIE Web Browser
Exit code:
3221226540
Version:
1, 0, 0, 0
Modules
Images
c:\users\admin\appdata\local\temp\myie\myie.exe
c:\windows\system32\ntdll.dll
3668"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\myie.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
4008C:\Windows\tasklist.exeC:\Windows\tasklist.exe
services.exe
User:
SYSTEM
Integrity Level:
SYSTEM
Exit code:
0
Modules
Images
c:\windows\tasklist.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
Total events
20 563
Read events
20 476
Write events
72
Delete events
15

Modification events

(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3668) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\myie.zip
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
3
Suspicious files
24
Text files
341
Unknown types
19

Dropped files

PID
Process
Filename
Type
3668WinRAR.exeC:\Users\admin\AppData\Local\Temp\myie\Skin\A-Vista\Go.bmpimage
MD5:CFD79C0AF0EA33A3087B7DA9C9979A7D
SHA256:C8FFB5A0B656912B119BF9EB52E28940584C31C9116BF2A19B51B7FF7BEA55C9
3668WinRAR.exeC:\Users\admin\AppData\Local\Temp\myie\Skin\A-Vista\BackGround.bmpimage
MD5:23E2FD444EFEA9550888400433A1B1F7
SHA256:349209528440849609768B83A021A6749276C0C91A24140EB95D535EEE638AC5
3668WinRAR.exeC:\Users\admin\AppData\Local\Temp\myie\Skin\A-Vista\MainMenu.bmpimage
MD5:D03915535A65F32EE6A5E8FB2886B41D
SHA256:21399CE014F0A5681323276F41CAF26E89752977F22BB3E715521420208C9823
3668WinRAR.exeC:\Users\admin\AppData\Local\Temp\myie\Skin\A-Vista\StatusTool.bmpimage
MD5:26DE106409E6F279A2F3FAAAEC308F0C
SHA256:5E2D75EFA4AAE9368100CFBA80B189BD533F8940E0310B0EA0883B6A47DEAAEC
3668WinRAR.exeC:\Users\admin\AppData\Local\Temp\myie\Skin\A-Vista\MainAnimIcon.bmpimage
MD5:1F97244377B29E2399DC6B32E63B1096
SHA256:9B4F58CD91894C85F217638C54A51570A83E021F644DD3CBAEAAB26EB5D3B1A4
3668WinRAR.exeC:\Users\admin\AppData\Local\Temp\myie\Skin\A-Vista\MainTool16.bmpimage
MD5:25C5A8DD10107CDC6D79F781A34EF4FF
SHA256:55147BD6EF84F6C0CC60A8C18A00CA9625A37136F8EFDEB6393FE397E3F5D5EA
3668WinRAR.exeC:\Users\admin\AppData\Local\Temp\myie\Skin\A-Vista\MainToolGray16.bmpimage
MD5:7BE4B66F156196D20A5B9E0A4CD2A496
SHA256:6BE8EB1825FA5B876E7077549F7055F65339635E0A87C809E47B8168FB150379
3668WinRAR.exeC:\Users\admin\AppData\Local\Temp\myie\Skin\A-Vista\TaskBar.bmpimage
MD5:88B8F29837A78D1D470A2D3F79E08296
SHA256:5ABBBB9C62FC592B939429DB793852301A4970A8110AFC272CCB76443D5C263E
3668WinRAR.exeC:\Users\admin\AppData\Local\Temp\myie\Skin\A-Vista\MainToolGray24.bmpimage
MD5:6D3C837E31FB7E5C3624D486839AB2D4
SHA256:AD22AD0BDF8FB0E9A1559CD3429625C2B69335E0710D0C1230ADC1A1607E0EDA
3668WinRAR.exeC:\Users\admin\AppData\Local\Temp\myie\Skin\A-Vista\SearchBar.bmpimage
MD5:EB9ED0DCEDE1468BE1F5BFBD0C3BC0FC
SHA256:4CA53E5E8554515D4D53F8238B76968037E877792A66B22B03301A3897811249
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
26
TCP/UDP connections
57
DNS requests
41
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2328
MyIE.exe
GET
302
104.108.145.69:80
http://go.microsoft.com/fwlink/?LinkId=129792
unknown
unknown
2328
MyIE.exe
GET
304
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?8bff67302df772d2
unknown
unknown
2328
MyIE.exe
GET
302
104.108.145.69:80
http://go.microsoft.com/fwlink/?LinkId=50893
unknown
unknown
2328
MyIE.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAzlnDD9eoNTLi0BRrMy%2BWU%3D
unknown
binary
312 b
unknown
2328
MyIE.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D
unknown
binary
471 b
unknown
2328
MyIE.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEA9iL28hwv9dUh9yOh1H1i0%3D
unknown
binary
471 b
unknown
2328
MyIE.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
binary
471 b
unknown
2328
MyIE.exe
GET
302
104.108.145.69:80
http://go.microsoft.com/fwlink/?LinkId=54729
unknown
unknown
2328
MyIE.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAxq6XzO1ZmDhpCgCp6lMhQ%3D
unknown
binary
471 b
unknown
2328
MyIE.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA177el9ggmWelJjG4vdGL0%3D
unknown
binary
471 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2328
MyIE.exe
104.108.145.69:80
go.microsoft.com
AKAMAI-AS
DE
unknown
2328
MyIE.exe
88.221.221.177:443
www.bing.com
Akamai International B.V.
DE
unknown
2328
MyIE.exe
93.184.221.240:80
ctldl.windowsupdate.com
EDGECAST
GB
whitelisted
2328
MyIE.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
2328
MyIE.exe
88.221.221.106:443
r.bing.com
Akamai International B.V.
DE
unknown
2328
MyIE.exe
104.107.161.181:443
www.microsoft.com
AKAMAI-AS
DE
unknown
2328
MyIE.exe
20.40.24.37:443
microsoftedgewelcome.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown

DNS requests

Domain
IP
Reputation
www.oneonsearch.com
unknown
go.microsoft.com
  • 104.108.145.69
whitelisted
www.bing.com
  • 88.221.221.177
whitelisted
ctldl.windowsupdate.com
  • 93.184.221.240
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
r.bing.com
  • 88.221.221.106
whitelisted
www.microsoft.com
  • 104.107.161.181
whitelisted
microsoftedgewelcome.microsoft.com
  • 20.40.24.37
whitelisted
ajax.aspnetcdn.com
  • 152.199.19.160
whitelisted
edgestatic.azureedge.net
  • 13.107.246.44
unknown

Threats

PID
Process
Class
Message
2328
MyIE.exe
Not Suspicious Traffic
INFO [ANY.RUN] jQuery JavaScript Library Code Loaded (code.jquery .com)
Process
Message
tasklist.exe
Running as proxy: C:\Windows\tasklist.exe - -install
tasklist.exe
tasklist is installed.
tasklist.exe
Tasklist::ServiceWorkerThread
tasklist.exe
Tasklist::ExecuteTasks
tasklist.exe
User SID: S-1-5-21-1302019708-1500728564-335382590-1000
tasklist.exe
ProgId: MSEdgeHTM
tasklist.exe
Tasklist::Main
tasklist.exe
CServiceBase::Start
tasklist.exe
Tasklist::OnStart