analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
URL:

http://collegeboarde.com

Full analysis: https://app.any.run/tasks/00629885-70c2-4630-b630-8df2c0ebcba0
Verdict: Malicious activity
Analysis date: March 14, 2019, 15:46:03
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
adware
Indicators:
MD5:

57815358ABD10B8292E768F21EF409CE

SHA1:

48568BF0B6DA184C059CFCEB4F736F2CC3983A9B

SHA256:

335DF884960EB6C3B53B8B199B0B30F08D2E363343A94E7647ED5D2C926D9C3F

SSDEEP:

3:N1KdKJJgJKI:CIPI

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Changes internet zones settings

      • iexplore.exe (PID: 3480)
    • Application launched itself

      • iexplore.exe (PID: 3480)
    • Reads Internet Cache Settings

      • iexplore.exe (PID: 3740)
      • iexplore.exe (PID: 3480)
    • Reads internet explorer settings

      • iexplore.exe (PID: 3740)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
33
Monitored processes
2
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe

Process information

PID
CMD
Path
Indicators
Parent process
3480"C:\Program Files\Internet Explorer\iexplore.exe" -nohomeC:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3740"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3480 CREDAT:71937C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
433
Read events
371
Write events
59
Delete events
3

Modification events

(PID) Process:(3480) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(3480) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(3480) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(3480) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones
Operation:writeName:SecuritySafe
Value:
1
(PID) Process:(3480) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(3480) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
4600000069000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
(PID) Process:(3480) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Recovery\Active
Operation:writeName:{4DB321DF-4670-11E9-BEEC-5254004A04AF}
Value:
0
(PID) Process:(3480) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Type
Value:
4
(PID) Process:(3480) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Count
Value:
3
(PID) Process:(3480) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Time
Value:
E307030004000E000F002E0012005400
Executable files
0
Suspicious files
0
Text files
14
Unknown types
2

Dropped files

PID
Process
Filename
Type
3480iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9ZEWH8D\favicon[1].ico
MD5:
SHA256:
3480iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
MD5:
SHA256:
3740iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OCDM6JB6\ww1_collegeboarde_com[1].txt
MD5:
SHA256:
3740iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BWPPCY0O\iyfsearch_com[1].txt
MD5:
SHA256:
3740iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BWPPCY0O\iyfsearch_com[1].htmhtml
MD5:8BFF908402A78DE08DB843B4218ABFE2
SHA256:8E0AF55CD32D43276CF42E25E4FD4BC21F50A191B69EF90DA972ED4429AD470A
3480iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012019031420190315\index.datdat
MD5:8557CA5225BC5F6AA6C4DB8D1EE636F7
SHA256:2E866A6CEC4D1B713F370A301B88CEA12E7A5819A313E5E663C79352536DB97D
3740iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OCDM6JB6\js3[1].jstext
MD5:DB3CACFB57BA35D3FCFDBBCF7D46BD42
SHA256:A606134E35DB97024D04789609660C94F87F660DC259D91DB5180E32787D4DAD
3740iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OCDM6JB6\ww1_collegeboarde_com[1].htmhtml
MD5:D35C4DD980C16C6AC7884E019F748E67
SHA256:BE58A85FC6CCBC918F9A16D4498FF321CF03259846259CA1B9970C1844F688F2
3740iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\U2ZG9DE0\min[1].jstext
MD5:5563332AD6AF63C9C94CEF15761BE544
SHA256:4EFEC11A42893D4DF0249174CBE5AFAE24A5734F5DED35C5E84C56BF9F473EC2
3740iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\History\Low\History.IE5\MSHist012019031420190315\index.datdat
MD5:BAD0FA122D6B2DE8E897D5F7CB1EB916
SHA256:D649339B99D97D3C9DF6D7FB4CA03AD60B1BEB52FD14302B6177F97404E3BC43
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
19
TCP/UDP connections
14
DNS requests
9
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3480
iexplore.exe
GET
200
185.53.179.29:80
http://ww1.collegeboarde.com/favicon.ico
DE
malicious
3740
iexplore.exe
GET
200
2.16.186.106:80
http://i1.cdn-image.com/__media__/js/min.js?v2.2
unknown
text
2.97 Kb
whitelisted
3740
iexplore.exe
GET
200
185.53.179.29:80
http://ww1.collegeboarde.com/?subid1=4efb8d22-4670-11e9-a40c-8d5633c0a92f
DE
html
925 b
malicious
3740
iexplore.exe
GET
200
208.91.196.46:80
http://iyfsearch.com/?dn=collegeboarde.com&pid=9PO755G95
VG
html
5.24 Kb
suspicious
3740
iexplore.exe
GET
302
89.35.39.50:80
http://collegeboarde.com/
RO
text
11 b
malicious
3740
iexplore.exe
GET
200
2.16.186.106:80
http://i4.cdn-image.com/__media__/pics/8243/bg.gif
unknown
image
4.37 Kb
whitelisted
3740
iexplore.exe
GET
200
2.16.186.106:80
http://i4.cdn-image.com/__media__/pics/8243/h_bg.gif
unknown
image
2.17 Kb
whitelisted
3740
iexplore.exe
GET
200
2.16.186.106:80
http://i4.cdn-image.com/__media__/pics/8243/lhs.gif
unknown
image
6.57 Kb
whitelisted
3740
iexplore.exe
GET
200
185.53.179.29:80
http://parkingcrew.net/assets/scripts/js3.js
DE
text
17.5 Kb
whitelisted
3740
iexplore.exe
GET
200
2.16.186.106:80
http://i2.cdn-image.com/__media__/pics/8243/bg.gif
unknown
image
4.37 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3480
iexplore.exe
204.79.197.200:80
www.bing.com
Microsoft Corporation
US
whitelisted
3740
iexplore.exe
89.35.39.50:80
collegeboarde.com
Parfumuri Femei.com SRL
RO
malicious
3480
iexplore.exe
185.53.179.29:80
ww1.collegeboarde.com
Team Internet AG
DE
malicious
3740
iexplore.exe
2.16.186.106:80
i1.cdn-image.com
Akamai International B.V.
whitelisted
3740
iexplore.exe
185.53.179.29:80
ww1.collegeboarde.com
Team Internet AG
DE
malicious
3740
iexplore.exe
2.16.186.64:80
i1.cdn-image.com
Akamai International B.V.
whitelisted
3480
iexplore.exe
208.91.196.46:80
iyfsearch.com
Confluence Networks Inc
VG
malicious
3740
iexplore.exe
208.91.196.46:80
iyfsearch.com
Confluence Networks Inc
VG
malicious

DNS requests

Domain
IP
Reputation
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
collegeboarde.com
  • 89.35.39.50
malicious
ww1.collegeboarde.com
  • 185.53.179.29
malicious
parkingcrew.net
  • 185.53.179.29
whitelisted
iyfsearch.com
  • 208.91.196.46
suspicious
i1.cdn-image.com
  • 2.16.186.106
  • 2.16.186.64
whitelisted
i3.cdn-image.com
  • 2.16.186.64
  • 2.16.186.106
whitelisted
i2.cdn-image.com
  • 2.16.186.106
  • 2.16.186.64
whitelisted
i4.cdn-image.com
  • 2.16.186.106
  • 2.16.186.64
whitelisted

Threats

PID
Process
Class
Message
3740
iexplore.exe
Misc activity
ADWARE [PTsecurity] InstantAccess
No debug info