| URL: | http://hao.199it.com/ |
| Full analysis: | https://app.any.run/tasks/d77ff940-31b0-488b-ac8d-b291c2d35dec |
| Verdict: | Malicious activity |
| Analysis date: | August 21, 2023, 08:26:19 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MD5: | ACFA66CA34ED60551F1F8B6FEAAEAFCA |
| SHA1: | 7A360EA0557602D091B1EDCAA353BCDCF51FFF10 |
| SHA256: | 2CD92E26A889E899E7DD089B15472BF45BBA4E84EFEB6A49FDB522DD6613DE09 |
| SSDEEP: | 3:N1KWEQUtMRt:CWktM |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2212 | C:\Windows\system32\Macromed\Flash\FlashUtil32_32_0_0_453_ActiveX.exe -Embedding | C:\Windows\System32\Macromed\Flash\FlashUtil32_32_0_0_453_ActiveX.exe | — | svchost.exe | |||||||||||
User: admin Company: Adobe Integrity Level: MEDIUM Description: Adobe® Flash® Player Installer/Uninstaller 32.0 r0 Exit code: 0 Version: 32,0,0,453 Modules
| |||||||||||||||
| 2388 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3508 CREDAT:267521 /prefetch:2 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| 2912 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3508 CREDAT:857432 /prefetch:2 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| 3408 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3508 CREDAT:2692368 /prefetch:2 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| 3508 | "C:\Program Files\Internet Explorer\iexplore.exe" "http://hao.199it.com/" | C:\Program Files\Internet Explorer\iexplore.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| (PID) Process: | (3508) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPDaysSinceLastAutoMigration |
Value: 0 | |||
| (PID) Process: | (3508) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPLastLaunchHighDateTime |
Value: 30847387 | |||
| (PID) Process: | (3508) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager |
| Operation: | write | Name: | NextCheckForUpdateHighDateTime |
Value: 30847437 | |||
| (PID) Process: | (3508) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (3508) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (3508) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main |
| Operation: | write | Name: | CompatibilityFlags |
Value: 0 | |||
| (PID) Process: | (3508) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (3508) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (3508) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (3508) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2388 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\41[1].png | image | |
MD5:A66C3EAF56DC260F3DF396ADE2207A4E | SHA256:92F3983EE868B142C8B8F1D727678389E54FECDAEB521AB774746F117B2AB3BD | |||
| 2388 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\9[1].png | image | |
MD5:ACA52FB8BC4B4F0D169EE700AB3E439B | SHA256:D371FC16901221B68E6CE16700B78C4F1F86B2D5502EB7B9C80449CCD45C44B9 | |||
| 2388 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\f[1].txt | text | |
MD5:98247C1A951A1B32A150436E57E2F9D4 | SHA256:369CED7266B0C17B8FE73D65BE613975B25DA8D1AABAA771D6D1198B4332E3DF | |||
| 2388 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\39[1].jpg | image | |
MD5:AEEFAA61E4185C23A4685BC79A458A25 | SHA256:0803EFDC86BB5C9C511DB36B9E6F12561DC296C7EE910B704A12A263B9D3CC8C | |||
| 2388 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\bootstrap[1].css | text | |
MD5:D3EE7CF54FC3CBBCB5B4D33177463784 | SHA256:B4FFBE4A9215079C8F4A67ACFA9FB4EFC62BF8DCB87570D73626BB1D8C55264F | |||
| 2388 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\3[1].png | image | |
MD5:5DDD24A5FBC5491448CAD04D5479A8B2 | SHA256:A1FC88634FCE6D5A34FFD6ACFF27140D10DD1596E36C8158F680AE559859B30D | |||
| 2388 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\39c0e78f420fc657c8de241157017ead[1].icon | image | |
MD5:5DF1088EF40C03C783BE8A76969BCDEC | SHA256:455807D037FB1AAFB5B63B1F8015132861C13BCC52A5D16F184DB3237867C77C | |||
| 2388 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\aff4e6ca38547da9e4ba90bf190034f2[1].ico | image | |
MD5:F3418A443E7D841097C714D69EC4BCB8 | SHA256:6DA5620880159634213E197FAFCA1DDE0272153BE3E4590818533FAB8D040770 | |||
| 2388 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\54f484d8d6359d4c402692ca27562d31[1].ico | image | |
MD5:62898CE57689E0FB9AF6A77BDAFF5D8E | SHA256:8793BFAB3B21586FE08A3A768D41E9F4A7F5D1EE62504D792AF68C36526E1402 | |||
| 2388 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\10[1].png | image | |
MD5:5086CEA90433F04620BA0CB41A586F5C | SHA256:F252395CA30BCF8FE0122F32939DD5E40DAE4A26A13B8F7640B96CB0666C391A | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2388 | iexplore.exe | GET | — | 115.28.86.52:80 | http://hao.199it.com/ | CN | — | — | unknown |
2388 | iexplore.exe | GET | — | 115.28.86.52:80 | http://hao.199it.com/style/css/bootstrap-3.3.7/css/bootstrap.css | CN | — | — | unknown |
2388 | iexplore.exe | GET | — | 115.28.86.52:80 | http://hao.199it.com/style/js/jquery1.12.4.min.js | CN | — | — | unknown |
2388 | iexplore.exe | GET | — | 115.28.86.52:80 | http://hao.199it.com/upload/94575524c372300bf0e6a101de12c361.png | CN | — | — | unknown |
2388 | iexplore.exe | GET | — | 115.28.86.52:80 | http://hao.199it.com/style/images/index/31.jpg | CN | — | — | unknown |
2388 | iexplore.exe | GET | — | 115.28.86.52:80 | http://hao.199it.com/upload/54f484d8d6359d4c402692ca27562d31.ico | CN | — | — | unknown |
2388 | iexplore.exe | GET | — | 115.28.86.52:80 | http://hao.199it.com/upload/7641ed99153dd9e2ad010eea57757512.jpeg | CN | — | — | unknown |
2388 | iexplore.exe | GET | 200 | 115.28.86.52:80 | http://hao.199it.com/static/js/bootstrap.min.js | CN | compressed | 16.0 Kb | unknown |
2388 | iexplore.exe | GET | — | 115.28.86.52:80 | http://hao.199it.com/upload/49d1878cf01bbb0db68c278182409c6f.ico | CN | — | — | unknown |
2388 | iexplore.exe | GET | 200 | 43.152.26.197:80 | http://res.wx.qq.com/open/js/jweixin-1.6.0.js | DE | text | 4.19 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2388 | iexplore.exe | 43.152.26.197:80 | res.wx.qq.com | ACE | DE | unknown |
2388 | iexplore.exe | 142.250.185.98:80 | pagead2.googlesyndication.com | GOOGLE | US | shared |
3508 | iexplore.exe | 93.184.221.240:80 | ctldl.windowsupdate.com | EDGECAST | GB | whitelisted |
3508 | iexplore.exe | 2.23.209.185:443 | www.bing.com | Akamai International B.V. | GB | whitelisted |
2388 | iexplore.exe | 142.250.185.226:443 | googleads.g.doubleclick.net | GOOGLE | US | suspicious |
3508 | iexplore.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
2388 | iexplore.exe | 43.152.44.160:80 | res.wx.qq.com | ACE | DE | unknown |
2388 | iexplore.exe | 142.250.185.98:443 | pagead2.googlesyndication.com | GOOGLE | US | shared |
2388 | iexplore.exe | 103.235.46.191:443 | hm.baidu.com | Beijing Baidu Netcom Science and Technology Co., Ltd. | HK | suspicious |
2388 | iexplore.exe | 142.250.185.227:80 | ocsp.pki.goog | GOOGLE | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
hao.199it.com |
| unknown |
pagead2.googlesyndication.com |
| whitelisted |
res.wx.qq.com |
| whitelisted |
api.bing.com |
| whitelisted |
www.bing.com |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
googleads.g.doubleclick.net |
| whitelisted |
ocsp.pki.goog |
| whitelisted |
hm.baidu.com |
| whitelisted |