analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
URL:

https://lucidbrands.com

Full analysis: https://app.any.run/tasks/bc15603b-3d04-4a3a-90b9-7181e9e90cdd
Verdict: Malicious activity
Analysis date: January 24, 2022, 19:32:22
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

272FBDC0884034E0810BA08DC01FDB8E

SHA1:

43A898EB190FFDB74E46BBE973EAC86ED7E1AF5A

SHA256:

31455155A9DEE3DC34DF6B1DAFC675567FD274570E90146F7953F9D03A76CE14

SSDEEP:

3:N8QGpBqI:2QGyI

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads Microsoft Outlook installation path

      • iexplore.exe (PID: 3860)
  • INFO

    • Reads the computer name

      • iexplore.exe (PID: 1252)
      • iexplore.exe (PID: 3860)
    • Reads settings of System Certificates

      • iexplore.exe (PID: 3860)
      • iexplore.exe (PID: 1252)
    • Checks supported languages

      • iexplore.exe (PID: 1252)
      • iexplore.exe (PID: 3860)
    • Application launched itself

      • iexplore.exe (PID: 1252)
    • Changes internet zones settings

      • iexplore.exe (PID: 1252)
    • Checks Windows Trust Settings

      • iexplore.exe (PID: 3860)
      • iexplore.exe (PID: 1252)
    • Reads internet explorer settings

      • iexplore.exe (PID: 3860)
    • Dropped object may contain Bitcoin addresses

      • iexplore.exe (PID: 3860)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
37
Monitored processes
2
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe

Process information

PID
CMD
Path
Indicators
Parent process
1252"C:\Program Files\Internet Explorer\iexplore.exe" "https://lucidbrands.com"C:\Program Files\Internet Explorer\iexplore.exe
Explorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
3860"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:1252 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Total events
11 588
Read events
11 471
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
16
Text files
22
Unknown types
17

Dropped files

PID
Process
Filename
Type
3860iexplore.exeC:\Users\admin\AppData\Local\Temp\Low\TarF551.tmpcat
MD5:D99661D0893A52A0700B8AE68457351A
SHA256:BDD5111162A6FA25682E18FA74E37E676D49CAFCB5B7207E98E5256D1EF0D003
3860iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:66595050570B2685EC38BC7451F7007A
SHA256:DF7E18123750F3A6857D916D784FC5D904E347409F130640DA0318741E1141B4
3860iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751binary
MD5:48CCCD64930608CDA54BE4343487F7C8
SHA256:36EFAEC9F03AA69DD442CA24AF973BE45AA0FD0F4F88F64D6AA401D3C82CDA1B
3860iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506binary
MD5:929C4EB841EB697759E6593379839E94
SHA256:D0FA6571AC0235646FD520FAA67E7EDCDE6C889279AF08767F35F44A7A6E8232
3860iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157compressed
MD5:F7DCB24540769805E5BB30D193944DCE
SHA256:6B88C6AC55BBD6FEA0EBE5A760D1AD2CFCE251C59D0151A1400701CB927E36EA
1252iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6BADA8974A10C4BD62CC921D13E43B18_711ED44619924BA6DC33E69F97E7FF63binary
MD5:5013475DD3F08EDC81A6D6FDC8248EE1
SHA256:4684080F6B99233E8D8E22EA124F96560811B2DA453A0298E3D167581D11A55F
1252iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6BADA8974A10C4BD62CC921D13E43B18_711ED44619924BA6DC33E69F97E7FF63der
MD5:FC990EAA7247546FB67C18916A4CAC9B
SHA256:294F5BE9159C87842AD3173FE7CDA168C9F2010C6D428085A8AC30EF436CA993
3860iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\BAD725C80F9E10846F35D039A996E4A8_88B6AE015495C1ECC395D19C1DD02894der
MD5:E9953511B806D96C85112D07C44DE02A
SHA256:86008864D275A5005CDEE88B0DF9E38009AB1F28E731673403DDCD89078A381B
3860iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B66240B0F6C84BD4857ABA60CF5CE4A0_5043E0F5DF723415C9EECC201C838A62der
MD5:949CEC434DD48DBFECFC8A1A8D055B7F
SHA256:8B5B70DC721BE51D2D326069F158A3D0A820036F5EA0E0FA09E476C00A36D530
1252iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\favicon[1].icoimage
MD5:DA597791BE3B6E732F0BC8B20E38EE62
SHA256:5B2C34B3C4E8DD898B664DBA6C3786E2FF9869EFF55D673AA48361F11325ED07
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
11
TCP/UDP connections
56
DNS requests
21
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3860
iexplore.exe
GET
200
18.66.242.62:80
http://ocsp.rootg2.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBSIfaREXmfqfJR3TkMYnD7O5MhzEgQUnF8A36oB1zArOIiiuG1KnPIRkYMCEwZ%2FlEoqJ83z%2BsKuKwH5CO65xMY%3D
US
der
1.51 Kb
whitelisted
3860
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAbY2QTVWENG9oovp1QifsQ%3D
US
der
471 b
whitelisted
3860
iexplore.exe
GET
200
13.107.4.50:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?b2261f61964f64d3
US
compressed
59.9 Kb
whitelisted
3860
iexplore.exe
GET
200
104.89.32.83:80
http://x1.c.lencr.org/
NL
der
717 b
whitelisted
3860
iexplore.exe
GET
200
104.18.20.226:80
http://ocsp2.globalsign.com/rootr3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT1nGh%2FJBjWKnkPdZIzB1bqhelHBwQUj%2FBLf6guRSSuTVD6Y5qL3uLdG7wCEHophRq39F1meVBmQbb%2F1x0%3D
US
der
1.40 Kb
whitelisted
3860
iexplore.exe
GET
200
18.66.242.228:80
http://o.ss2.us//MEowSDBGMEQwQjAJBgUrDgMCGgUABBSLwZ6EW5gdYc9UaSEaaLjjETNtkAQUv1%2B30c7dH4b0W1Ws3NcQwg6piOcCCQCnDkpMNIK3fw%3D%3D
US
der
1.70 Kb
whitelisted
3860
iexplore.exe
GET
200
18.66.242.62:80
http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwZ%2FlFeFh%2Bisd96yUzJbvJmLVg0%3D
US
der
1.39 Kb
shared
1252
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
der
471 b
whitelisted
1252
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA8Ull8gIGmZT9XHrHiJQeI%3D
US
der
1.47 Kb
whitelisted
3860
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAH9o%2BtuynXIiEOLckvPvJE%3D
US
der
471 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3860
iexplore.exe
104.89.32.83:80
x1.c.lencr.org
Akamai Technologies, Inc.
NL
suspicious
1252
iexplore.exe
13.107.22.200:443
www.bing.com
Microsoft Corporation
US
whitelisted
1252
iexplore.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
3860
iexplore.exe
151.101.192.119:443
lucidbrands.com
Fastly
US
malicious
3860
iexplore.exe
13.107.4.50:80
ctldl.windowsupdate.com
Microsoft Corporation
US
whitelisted
3860
iexplore.exe
92.123.225.18:443
use.typekit.net
Akamai International B.V.
malicious
3860
iexplore.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
3860
iexplore.exe
18.66.242.62:80
ocsp.rootg2.amazontrust.com
Massachusetts Institute of Technology
US
whitelisted
3860
iexplore.exe
108.157.4.27:443
pro2-bar-s3-cdn-cf3.myportfolio.com
US
unknown
3860
iexplore.exe
108.157.4.29:443
pro2-bar-s3-cdn-cf3.myportfolio.com
US
suspicious

DNS requests

Domain
IP
Reputation
lucidbrands.com
  • 151.101.192.119
malicious
ctldl.windowsupdate.com
  • 13.107.4.50
whitelisted
api.bing.com
  • 13.107.13.80
whitelisted
www.bing.com
  • 13.107.22.200
  • 131.253.33.200
whitelisted
x1.c.lencr.org
  • 104.89.32.83
whitelisted
ocsp.digicert.com
  • 93.184.220.29
whitelisted
pro2-bar-s3-cdn-cf3.myportfolio.com
  • 108.157.4.29
  • 108.157.4.27
  • 108.157.4.78
  • 108.157.4.62
whitelisted
use.typekit.net
  • 92.123.225.18
  • 92.123.225.10
  • 92.123.225.40
  • 92.123.225.9
  • 92.123.225.73
whitelisted
pro2-bar-s3-cdn-cf1.myportfolio.com
  • 108.157.4.78
  • 108.157.4.27
  • 108.157.4.62
  • 108.157.4.29
whitelisted
pro2-bar-s3-cdn-cf5.myportfolio.com
  • 108.157.4.62
  • 108.157.4.27
  • 108.157.4.29
  • 108.157.4.78
suspicious

Threats

No threats detected
No debug info