analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
URL:

http://iyfsearch.com/trf?q\=History+of+Jazz&&r\=https%3A%2F%2Fr.search.yahoo.com%2Fcbclk%2FdWU9MDE5MkQxQzRGODk0NDVCQSZ1dD0xNTQ0MDY5ODUwNDQzJnVvPTc3MjQwNzA2ODY5NzE5Jmx0PTImZXM9b2lCZUJEZ0dQUzhNUnRvLiZqZT1kOGY0NzUyNi1mOTBkLTExZTgtYTQ3Ny0wMDhjZmE1YjQ4NzQtMmI1NDAxOGViNzAwJnVpPTIwMi4yMTg

Full analysis: https://app.any.run/tasks/65419b66-bab7-426f-94ae-93fddc57433a
Verdict: Malicious activity
Analysis date: December 06, 2018, 05:03:58
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

41DA21D0E003C6DE807210DD2DD5CC83

SHA1:

E4CF9264124ABF1F6EDAE186AB6F1EA530989E7E

SHA256:

2FB17493A77D26D13C7500B2F67C96298BD9F6DFF3E31B529727F78DCA90272F

SSDEEP:

6:CfU2IzQPxj95AYq6Co+MPrKY8FIfCCao/7xU7Mzo:6es32o+MPrH8FoBdUIzo

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Changes internet zones settings

      • iexplore.exe (PID: 2948)
    • Application launched itself

      • iexplore.exe (PID: 2948)
    • Reads internet explorer settings

      • iexplore.exe (PID: 3336)
    • Reads Internet Cache Settings

      • iexplore.exe (PID: 2948)
      • iexplore.exe (PID: 3336)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
32
Monitored processes
2
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe

Process information

PID
CMD
Path
Indicators
Parent process
2948"C:\Program Files\Internet Explorer\iexplore.exe" http://iyfsearch.com/trf?q\=History+of+Jazz&&r\=https%3A%2F%2Fr.search.yahoo.com%2Fcbclk%2FdWU9MDE5MkQxQzRGODk0NDVCQSZ1dD0xNTQ0MDY5ODUwNDQzJnVvPTc3MjQwNzA2ODY5NzE5Jmx0PTImZXM9b2lCZUJEZ0dQUzhNUnRvLiZqZT1kOGY0NzUyNi1mOTBkLTExZTgtYTQ3Ny0wMDhjZmE1YjQ4NzQtMmI1NDAxOGViNzAwJnVpPTIwMi4yMTgC:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
3336"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2948 CREDAT:71937C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Total events
407
Read events
345
Write events
59
Delete events
3

Modification events

(PID) Process:(2948) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(2948) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(2948) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(2948) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones
Operation:writeName:SecuritySafe
Value:
1
(PID) Process:(2948) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(2948) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
4600000069000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
(PID) Process:(2948) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Recovery\Active
Operation:writeName:{5F9E1D63-F914-11E8-91D7-5254004A04AF}
Value:
0
(PID) Process:(2948) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Type
Value:
4
(PID) Process:(2948) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Count
Value:
3
(PID) Process:(2948) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Time
Value:
E2070C0004000600050004000E00A602
Executable files
0
Suspicious files
0
Text files
13
Unknown types
4

Dropped files

PID
Process
Filename
Type
2948iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9ZEWH8D\favicon[1].ico
MD5:
SHA256:
2948iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
MD5:
SHA256:
3336iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OCDM6JB6\iyfsearch_com[1].txt
MD5:
SHA256:
3336iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OCDM6JB6\iyfsearch_com[1].htmhtml
MD5:B72BC6CE3C3907EE3EE9E1F07BAF79C2
SHA256:9F4C3B896DA995C11BA227780F0F22E8A7B63CFBBF8D54EDDC05D1885CBDD6AF
3336iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OCDM6JB6\iyfsearch_com[2].htmhtml
MD5:DC9086B5F63386E8CD05A3FA71051F3B
SHA256:70CE3A93951CBED06F5E60EED5C3B30957AC51A269079BD6542F139F242F925C
3336iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PP6KS563\min[1].jstext
MD5:5563332AD6AF63C9C94CEF15761BE544
SHA256:4EFEC11A42893D4DF0249174CBE5AFAE24A5734F5DED35C5E84C56BF9F473EC2
3336iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\History\Low\History.IE5\MSHist012018120620181207\index.datdat
MD5:D72A87FC947A53CAD2EB9CDF72BC73D1
SHA256:5AADDFD8190C03623573700BFBCC1057454513025B0CA5DE565C58F556402E65
2948iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012018120620181207\index.datdat
MD5:C1A31504B30732F3D355797ED472EA50
SHA256:049A01B7BA48753355D86EADB0BBFFFE9F168BC0CFB9202D9FAB421417478874
2948iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9ZEWH8D\favicon[2].pngimage
MD5:9FB559A691078558E77D6848202F6541
SHA256:6D8A01DC7647BC218D003B58FE04049E24A9359900B7E0CEBAE76EDF85B8B914
3336iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BWPPCY0O\libg[1].pngimage
MD5:B06CC0EE3C9BE723861A2FE8F3B594E6
SHA256:3D876C43F21D31D03EEF6D5B51E9CF7D28F6B0F017239300980AF88522A173A0
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
19
TCP/UDP connections
12
DNS requests
6
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3336
iexplore.exe
GET
302
208.91.196.46:80
http://iyfsearch.com/trf?q\=History+of+Jazz&&r\=https%3A%2F%2Fr.search.yahoo.com%2Fcbclk%2FdWU9MDE5MkQxQzRGODk0NDVCQSZ1dD0xNTQ0MDY5ODUwNDQzJnVvPTc3MjQwNzA2ODY5NzE5Jmx0PTImZXM9b2lCZUJEZ0dQUzhNUnRvLiZqZT1kOGY0NzUyNi1mOTBkLTExZTgtYTQ3Ny0wMDhjZmE1YjQ4NzQtMmI1NDAxOGViNzAwJnVpPTIwMi4yMTg
VG
suspicious
3336
iexplore.exe
GET
200
208.91.196.46:80
http://iyfsearch.com/
VG
html
1.05 Kb
suspicious
3336
iexplore.exe
GET
200
208.91.196.46:80
http://iyfsearch.com/px.js?ch=1
VG
text
346 b
suspicious
2948
iexplore.exe
GET
200
204.79.197.200:80
http://www.bing.com/favicon.ico
US
image
237 b
whitelisted
3336
iexplore.exe
GET
200
2.16.186.106:80
http://i3.cdn-image.com/__media__/fonts/ubuntu-b/ubuntu-b.eot?
unknown
eot
110 Kb
whitelisted
3336
iexplore.exe
GET
200
2.16.186.106:80
http://i3.cdn-image.com/__media__/js/min.js?v2.2
unknown
text
2.97 Kb
whitelisted
3336
iexplore.exe
GET
200
208.91.196.46:80
http://iyfsearch.com/?fp=oIFYcdfMdIiGbBb7d4Knav7uC3RkehVdHPSrmEbDAFMIOg%2FXIknV%2BFrnMOH6lT5hGGKm28rZi5D%2FAC599Nh1FwNBI1n2MLZP5Sck3Am5WYy89aKRoHwiOVF70gijZM0fVufe6wKVfvrq5BKuN5EG1xtXsQEZ8AUjHDr3hCqm8QI%3D&prvtof=G1RmzAFDhkmWnLkkx50lJBzPGdA1ZYPRhkbMSZA121U%3D&poru=hc2M3of7BMGjyv6Z54lqTf%2FSuHDLS53xn6IImfEPYsAG9lytgJwn%2FS4QeKyu%2BdHb&
VG
html
6.28 Kb
suspicious
3336
iexplore.exe
GET
200
2.16.186.64:80
http://i2.cdn-image.com/__media__/pics/12471/libg.png
unknown
image
1.07 Kb
whitelisted
3336
iexplore.exe
GET
200
208.91.196.46:80
http://iyfsearch.com/px.js?ch=2
VG
text
346 b
suspicious
3336
iexplore.exe
GET
200
2.16.186.64:80
http://i1.cdn-image.com/__media__/pics/12471/search-icon.png
unknown
image
1.16 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2948
iexplore.exe
204.79.197.200:80
www.bing.com
Microsoft Corporation
US
whitelisted
3336
iexplore.exe
2.16.186.64:80
i3.cdn-image.com
Akamai International B.V.
whitelisted
3336
iexplore.exe
2.16.186.106:80
i3.cdn-image.com
Akamai International B.V.
whitelisted
208.91.196.46:80
iyfsearch.com
Confluence Networks Inc
VG
malicious
2948
iexplore.exe
208.91.196.46:80
iyfsearch.com
Confluence Networks Inc
VG
malicious
3336
iexplore.exe
208.91.196.46:80
iyfsearch.com
Confluence Networks Inc
VG
malicious

DNS requests

Domain
IP
Reputation
iyfsearch.com
  • 208.91.196.46
suspicious
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
i3.cdn-image.com
  • 2.16.186.106
  • 2.16.186.64
whitelisted
i1.cdn-image.com
  • 2.16.186.64
  • 2.16.186.106
whitelisted
i2.cdn-image.com
  • 2.16.186.64
  • 2.16.186.106
whitelisted
i4.cdn-image.com
  • 2.16.186.106
  • 2.16.186.64
whitelisted

Threats

No threats detected
No debug info