analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
URL:

https://mbledu-my.sharepoint.com:443/:b:/g/personal/kfouke_mbl_edu/EedlE3CQ4E1Il-c8BmyPnX4BaVVHKoUsHXWyc83erpKuDQ?e=4%3a2PuLYb&at=9

Full analysis: https://app.any.run/tasks/854c7ab6-4427-4d56-bbd7-bf76122425e2
Verdict: Malicious activity
Analysis date: January 17, 2020, 16:58:12
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

8E7DB08B8E0043B18814203B6932F471

SHA1:

D29A7D73253DD528260573CAD91DCF95E188AC59

SHA256:

31C99CDF4C00E5724E7E2F00E331A56BEA49D43D385363C3AED63EE2A735ED80

SSDEEP:

3:N8nQ19QArLnuhKqGSOWbAMEQGGtLLajPPcuQeYRKBcn:2CQAfuhVbHTLajH4eRqn

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Reads internet explorer settings

      • iexplore.exe (PID: 2128)
    • Reads Internet Cache Settings

      • iexplore.exe (PID: 3180)
      • iexplore.exe (PID: 2128)
    • Changes internet zones settings

      • iexplore.exe (PID: 3180)
    • Creates files in the user directory

      • iexplore.exe (PID: 2128)
    • Reads settings of System Certificates

      • iexplore.exe (PID: 3180)
    • Changes settings of System certificates

      • iexplore.exe (PID: 3180)
    • Adds / modifies Windows certificates

      • iexplore.exe (PID: 3180)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
35
Monitored processes
2
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe

Process information

PID
CMD
Path
Indicators
Parent process
3180"C:\Program Files\Internet Explorer\iexplore.exe" "https://mbledu-my.sharepoint.com:443/:b:/g/personal/kfouke_mbl_edu/EedlE3CQ4E1Il-c8BmyPnX4BaVVHKoUsHXWyc83erpKuDQ?e=4%3a2PuLYb&at=9"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
2128"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3180 CREDAT:71937C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Total events
452
Read events
369
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
0
Text files
27
Unknown types
7

Dropped files

PID
Process
Filename
Type
3180iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\favicon[1].ico
MD5:
SHA256:
3180iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
MD5:
SHA256:
2128iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\JJS54OWQ\onedrive[1].aspx
MD5:
SHA256:
2128iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\JJS54OWQ\start[1].aspx
MD5:
SHA256:
2128iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\index.datdat
MD5:A31FE841913B8E4120FFD5436E26F35B
SHA256:F8532B9AE2A9735C01277261854D5C74231B6B332B0E06012F19B10184C595C4
2128iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txttext
MD5:2DF9501777012678F97BC9C6C7136DEF
SHA256:357E744716F7196AADE917F0FE2C82EFBB74F9500273808DD8138206A2FDE9AD
2128iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\JJS54OWQ\start[1].htmhtml
MD5:A556557E59EBCB5C2A9AD9CF18923344
SHA256:6117950A206685660E1B39B6CA104693409C5FC8457A31644FB8597797030FEB
2128iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\History\Low\History.IE5\index.datdat
MD5:7C2D6812D3C1B156AE73611A31BBA03B
SHA256:18099D890E800348DB68367AE4808DECD83703767D4125DA76F68654268B8B34
2128iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txttext
MD5:27244B3BEBB1B00CD21BAD9A61E41066
SHA256:16C2BA6D99937998BB5EDE66A7297256F071D33362643B08AB93551090B48DB7
2128iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\JJS54OWQ\onedrive[1].htmhtml
MD5:29ECFCF2BF12D34D2247D2286123AA1E
SHA256:261F2F363B7AC796AD0F44801EA7C6DD573EC5828EE21A0D311DEC92EE58ECCE
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
13
DNS requests
3
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3180
iexplore.exe
GET
200
204.79.197.200:80
http://www.bing.com/favicon.ico
US
image
237 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3180
iexplore.exe
13.107.136.9:443
mbledu-my.sharepoint.com
Microsoft Corporation
US
whitelisted
2128
iexplore.exe
13.107.136.9:443
mbledu-my.sharepoint.com
Microsoft Corporation
US
whitelisted
3180
iexplore.exe
204.79.197.200:80
www.bing.com
Microsoft Corporation
US
whitelisted
2128
iexplore.exe
95.100.130.58:443
static.sharepointonline.com
Akamai Technologies, Inc.
unknown

DNS requests

Domain
IP
Reputation
mbledu-my.sharepoint.com
  • 13.107.136.9
suspicious
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
static.sharepointonline.com
  • 95.100.130.58
whitelisted

Threats

No threats detected
No debug info