File name:

myie.zip

Full analysis: https://app.any.run/tasks/6085e226-0b7d-42a5-884c-ee84628dbd9b
Verdict: Malicious activity
Analysis date: March 10, 2024, 13:02:26
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract, compression method=store
MD5:

C1971BA634BCEB355C2135713EE059BA

SHA1:

E250C408C491D9FA4D5918F627EBD3EDE6CD8C0F

SHA256:

2CB627ECF70F7D3C36800D59F9E186DE8EBEF915935E39232D4B4FDC838DC545

SSDEEP:

49152:iqgqbT9bpBt36U/12YtRE+SLYrFHUROng4YGj/aoUxqyoIjiHoLj2mKu:iCHd53H/1HRlrFHSOngah0LoIJLj2bu

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • MyIE.exe (PID: 2328)
  • SUSPICIOUS

    • Reads the Internet Settings

      • MyIE.exe (PID: 2328)
    • Reads security settings of Internet Explorer

      • MyIE.exe (PID: 2328)
    • Starts SC.EXE for service management

      • MyIE.exe (PID: 2328)
    • Get information on the list of running processes

      • MyIE.exe (PID: 2328)
    • Executable content was dropped or overwritten

      • MyIE.exe (PID: 2328)
    • Executes as Windows Service

      • tasklist.exe (PID: 4008)
    • Reads Microsoft Outlook installation path

      • MyIE.exe (PID: 2328)
    • Reads Internet Explorer settings

      • MyIE.exe (PID: 2328)
    • Reads settings of System Certificates

      • MyIE.exe (PID: 2328)
    • Checks Windows Trust Settings

      • MyIE.exe (PID: 2328)
    • Adds/modifies Windows certificates

      • MyIE.exe (PID: 2328)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3668)
    • Reads the computer name

      • MyIE.exe (PID: 2328)
      • tasklist.exe (PID: 864)
      • tasklist.exe (PID: 4008)
    • Checks supported languages

      • MyIE.exe (PID: 2328)
      • tasklist.exe (PID: 864)
      • tasklist.exe (PID: 4008)
    • Manual execution by a user

      • MyIE.exe (PID: 2328)
      • MyIE.exe (PID: 2920)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 3668)
    • Create files in a temporary directory

      • MyIE.exe (PID: 2328)
    • Checks proxy server information

      • MyIE.exe (PID: 2328)
    • Reads the machine GUID from the registry

      • MyIE.exe (PID: 2328)
    • Creates files or folders in the user directory

      • MyIE.exe (PID: 2328)
    • Reads the software policy settings

      • MyIE.exe (PID: 2328)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2017:11:26 13:27:46
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: Skin/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
46
Monitored processes
6
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe myie.exe no specs myie.exe tasklist.exe sc.exe no specs tasklist.exe

Process information

PID
CMD
Path
Indicators
Parent process
120sc start tasklistC:\Windows\System32\sc.exeMyIE.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
A tool to aid in developing services for WindowsNT
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\sc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
864"C:\Windows\tasklist.exe" -installC:\Windows\tasklist.exe
MyIE.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\windows\tasklist.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2328"C:\Users\admin\AppData\Local\Temp\myie\MyIE.exe" C:\Users\admin\AppData\Local\Temp\myie\MyIE.exe
explorer.exe
User:
admin
Company:
5huawei
Integrity Level:
HIGH
Description:
MyIE Web Browser
Exit code:
0
Version:
1, 0, 0, 0
Modules
Images
c:\users\admin\appdata\local\temp\myie\myie.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winmm.dll
2920"C:\Users\admin\AppData\Local\Temp\myie\MyIE.exe" C:\Users\admin\AppData\Local\Temp\myie\MyIE.exeexplorer.exe
User:
admin
Company:
5huawei
Integrity Level:
MEDIUM
Description:
MyIE Web Browser
Exit code:
3221226540
Version:
1, 0, 0, 0
Modules
Images
c:\users\admin\appdata\local\temp\myie\myie.exe
c:\windows\system32\ntdll.dll
3668"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\myie.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
4008C:\Windows\tasklist.exeC:\Windows\tasklist.exe
services.exe
User:
SYSTEM
Integrity Level:
SYSTEM
Exit code:
0
Modules
Images
c:\windows\tasklist.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
Total events
20 563
Read events
20 476
Write events
72
Delete events
15

Modification events

(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3668) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\myie.zip
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
3
Suspicious files
24
Text files
341
Unknown types
19

Dropped files

PID
Process
Filename
Type
3668WinRAR.exeC:\Users\admin\AppData\Local\Temp\myie\Skin\A-Vista\TabActiveBottom.bmpimage
MD5:08BCAC3B97F257E764D3436ED5BCAFEE
SHA256:C3AC0A6317D11F6C71C0BA5A99F2A8F731AF10750AE7C1779556D375413D8EB4
3668WinRAR.exeC:\Users\admin\AppData\Local\Temp\myie\Skin\A-Vista\SystemBar.bmpimage
MD5:6D2FB7F303B37D0282E6AA9A9EB626C4
SHA256:D4973DAFE7D1D5EBF7DBF478A81C8AB3FBE84023833B1DA2943BF9E877C0DC3E
3668WinRAR.exeC:\Users\admin\AppData\Local\Temp\myie\Skin\A-Vista\TabNormal.bmpimage
MD5:EE9F2A7896D0FAE230CDEF7F2A5F559F
SHA256:D4550549BD2DE985794F4691E1BBACD0209E3CF4A734F73C7095CD999E8CE0BF
3668WinRAR.exeC:\Users\admin\AppData\Local\Temp\myie\Skin\A-Vista\TabNormalBottom.bmpimage
MD5:54D467E37343421A6728362AD441604F
SHA256:1138A14CAEBFB76A88F320B26246F8858FE21ED159D5A8E459D07853F34AFB8C
3668WinRAR.exeC:\Users\admin\AppData\Local\Temp\myie\Skin\Cartoon\FavBar.bmpimage
MD5:2CB828FD7F7DD6D93D6926B267C21BB8
SHA256:6C3B6BEB4578A57CDA72DBEAAEC0A10D3E17C20B1F84E7DED4EFBA04BA343E9A
3668WinRAR.exeC:\Users\admin\AppData\Local\Temp\myie\Skin\Cartoon\BackGround.bmpimage
MD5:6118E2E17A65B9FA3D100482F94616B7
SHA256:CEB1E17BB2857D0D8A8821664DC1345FB512AD1CAA14A794C7728366EAA5C0B3
3668WinRAR.exeC:\Users\admin\AppData\Local\Temp\myie\Skin\Cartoon\Go.bmpimage
MD5:B0C07F96832C064C95291DFF75AAA421
SHA256:49EFEA833471D3E573324AF8141B1115113D87382576F7D4805D46E574CEB894
3668WinRAR.exeC:\Users\admin\AppData\Local\Temp\myie\Skin\A-Vista\FavBar.bmpimage
MD5:A27026711C5916DCB1D1BC0F4F59C6B6
SHA256:C9E1A3B453DDAF6D8EEA98457B2578D2488B06E184D07D3DEDB21B2A73A787D3
3668WinRAR.exeC:\Users\admin\AppData\Local\Temp\myie\Skin\A-Vista\MainAnimIcon.bmpimage
MD5:1F97244377B29E2399DC6B32E63B1096
SHA256:9B4F58CD91894C85F217638C54A51570A83E021F644DD3CBAEAAB26EB5D3B1A4
3668WinRAR.exeC:\Users\admin\AppData\Local\Temp\myie\Skin\A-Vista\BackGround.bmpimage
MD5:23E2FD444EFEA9550888400433A1B1F7
SHA256:349209528440849609768B83A021A6749276C0C91A24140EB95D535EEE638AC5
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
26
TCP/UDP connections
57
DNS requests
41
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2328
MyIE.exe
GET
302
104.108.145.69:80
http://go.microsoft.com/fwlink/?LinkId=129792
unknown
unknown
2328
MyIE.exe
GET
304
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?8bff67302df772d2
unknown
unknown
2328
MyIE.exe
GET
302
104.108.145.69:80
http://go.microsoft.com/fwlink/?LinkId=50893
unknown
unknown
2328
MyIE.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAzlnDD9eoNTLi0BRrMy%2BWU%3D
unknown
binary
312 b
unknown
2328
MyIE.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEA9iL28hwv9dUh9yOh1H1i0%3D
unknown
binary
471 b
unknown
2328
MyIE.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
binary
471 b
unknown
2328
MyIE.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D
unknown
binary
471 b
unknown
2328
MyIE.exe
GET
302
104.108.145.69:80
http://go.microsoft.com/fwlink/?LinkId=54729
unknown
unknown
2328
MyIE.exe
GET
302
104.108.145.69:80
http://go.microsoft.com/fwlink/?LinkId=68927
unknown
unknown
2328
MyIE.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA177el9ggmWelJjG4vdGL0%3D
unknown
binary
471 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2328
MyIE.exe
104.108.145.69:80
go.microsoft.com
AKAMAI-AS
DE
unknown
2328
MyIE.exe
88.221.221.177:443
www.bing.com
Akamai International B.V.
DE
unknown
2328
MyIE.exe
93.184.221.240:80
ctldl.windowsupdate.com
EDGECAST
GB
whitelisted
2328
MyIE.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
2328
MyIE.exe
88.221.221.106:443
r.bing.com
Akamai International B.V.
DE
unknown
2328
MyIE.exe
104.107.161.181:443
www.microsoft.com
AKAMAI-AS
DE
unknown
2328
MyIE.exe
20.40.24.37:443
microsoftedgewelcome.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown

DNS requests

Domain
IP
Reputation
www.oneonsearch.com
unknown
go.microsoft.com
  • 104.108.145.69
whitelisted
www.bing.com
  • 88.221.221.177
whitelisted
ctldl.windowsupdate.com
  • 93.184.221.240
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
r.bing.com
  • 88.221.221.106
whitelisted
www.microsoft.com
  • 104.107.161.181
whitelisted
microsoftedgewelcome.microsoft.com
  • 20.40.24.37
whitelisted
ajax.aspnetcdn.com
  • 152.199.19.160
whitelisted
edgestatic.azureedge.net
  • 13.107.246.44
unknown

Threats

PID
Process
Class
Message
2328
MyIE.exe
Not Suspicious Traffic
INFO [ANY.RUN] jQuery JavaScript Library Code Loaded (code.jquery .com)
Process
Message
tasklist.exe
Running as proxy: C:\Windows\tasklist.exe - -install
tasklist.exe
tasklist is installed.
tasklist.exe
Tasklist::ServiceWorkerThread
tasklist.exe
Tasklist::ExecuteTasks
tasklist.exe
User SID: S-1-5-21-1302019708-1500728564-335382590-1000
tasklist.exe
ProgId: MSEdgeHTM
tasklist.exe
Tasklist::Main
tasklist.exe
CServiceBase::Start
tasklist.exe
Tasklist::OnStart