| URL: | http://ptyptossen.com/LYW/quines.php?l=klyc9.bod |
| Full analysis: | https://app.any.run/tasks/da3a0114-42b8-4ab2-999b-4cce76b3934a |
| Verdict: | Malicious activity |
| Threats: | Ursnif is a banking Trojan that usually infects corporate victims. It is based on an old malware but was substantially updated over the years and became quite powerful. Today Ursnif is one of the most widely spread banking Trojans in the world. |
| Analysis date: | December 15, 2018, 01:56:49 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MD5: | B23671B80ED3CAB2BA96EA8CF9FEFC97 |
| SHA1: | 6B8A250947A3E5E904EE48631A4D37959EF32C8E |
| SHA256: | 33C164DA39EC736D6D8EC578E5991D41D9CB11B383471F28A34DFD18F0BAD373 |
| SSDEEP: | 3:N1KORnmOKISZ0MVHaJ1qHKB:CORmOKI/MC1qHKB |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2684 | "C:\Program Files\Internet Explorer\iexplore.exe" -nohome | C:\Program Files\Internet Explorer\iexplore.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Exit code: 0 Version: 8.00.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2828 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2684 CREDAT:71937 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Exit code: 0 Version: 8.00.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 4072 | C:\Windows\system32\Macromed\Flash\FlashUtil32_26_0_0_131_ActiveX.exe -Embedding | C:\Windows\system32\Macromed\Flash\FlashUtil32_26_0_0_131_ActiveX.exe | — | svchost.exe | |||||||||||
User: admin Company: Adobe Systems Incorporated Integrity Level: MEDIUM Description: Adobe® Flash® Player Installer/Uninstaller 26.0 r0 Exit code: 0 Version: 26,0,0,131 Modules
| |||||||||||||||
| (PID) Process: | (2684) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main |
| Operation: | write | Name: | CompatibilityFlags |
Value: 0 | |||
| (PID) Process: | (2684) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (2684) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
| (PID) Process: | (2684) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones |
| Operation: | write | Name: | SecuritySafe |
Value: 1 | |||
| (PID) Process: | (2684) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (2684) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
| Operation: | write | Name: | SavedLegacySettings |
Value: 4600000069000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2684) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Recovery\Active |
| Operation: | write | Name: | {B5524AAF-000C-11E9-91D7-5254004A04AF} |
Value: 0 | |||
| (PID) Process: | (2684) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore |
| Operation: | write | Name: | Type |
Value: 4 | |||
| (PID) Process: | (2684) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore |
| Operation: | write | Name: | Count |
Value: 3 | |||
| (PID) Process: | (2684) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore |
| Operation: | write | Name: | Time |
Value: E2070C0006000F000100390000005203 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2684 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9ZEWH8D\favicon[1].ico | — | |
MD5:— | SHA256:— | |||
| 2684 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico | — | |
MD5:— | SHA256:— | |||
| 2828 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OCDM6JB6\quines[1].htm | html | |
MD5:— | SHA256:— | |||
| 2828 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PP6KS563\f[1].txt | html | |
MD5:— | SHA256:— | |||
| 2828 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PP6KS563\hm[1].js | text | |
MD5:— | SHA256:— | |||
| 2828 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OCDM6JB6\tj[1].js | html | |
MD5:— | SHA256:— | |||
| 2828 | iexplore.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\admin@hm.baidu[1].txt | text | |
MD5:— | SHA256:— | |||
| 2828 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\index.dat | dat | |
MD5:— | SHA256:— | |||
| 2828 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\History\Low\History.IE5\MSHist012018121520181216\index.dat | dat | |
MD5:— | SHA256:— | |||
| 2828 | iexplore.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\admin@baidu[1].txt | text | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2828 | iexplore.exe | GET | 200 | 183.131.207.78:80 | http://ia.51.la/go1?id=19703923&rt=1544839039615&rl=1280*720&lang=en-us&ct=unknow&pf=1&ins=1&vd=1&ce=1&cd=32&ds=&ing=1&ekc=&sid=1544839039615&tt=404%2520Not%2520Found&kw=&cu=http%253A%252F%252Fptyptossen.com%252FLYW%252Fquines.php%253Fl%253Dklyc9.bod&pu= | CN | — | — | whitelisted |
2828 | iexplore.exe | GET | 302 | 111.206.37.189:80 | http://api.share.baidu.com/s.gif?l=http://ptyptossen.com/LYW/quines.php?l=klyc9.bod | CN | — | — | whitelisted |
2828 | iexplore.exe | GET | 200 | 104.201.20.75:80 | http://ptyptossen.com/LYW/quines.php?l=klyc9.bod | US | html | 2.39 Kb | malicious |
2828 | iexplore.exe | GET | 200 | 104.201.20.75:80 | http://ptyptossen.com/tj.js | US | html | 102 b | malicious |
2828 | iexplore.exe | GET | 200 | 222.186.57.120:88 | http://web.xixigmail.com:88/a/105.js | CN | text | 1.27 Kb | unknown |
2828 | iexplore.exe | GET | 200 | 103.235.46.39:80 | http://www.baidu.com/search/error.html | HK | html | 4.75 Kb | whitelisted |
2828 | iexplore.exe | GET | 200 | 111.206.37.189:80 | http://push.zhanzhang.baidu.com/push.js | CN | text | 227 b | whitelisted |
2684 | iexplore.exe | GET | 200 | 204.79.197.200:80 | http://www.bing.com/favicon.ico | US | image | 237 b | whitelisted |
2684 | iexplore.exe | GET | 200 | 104.201.20.75:80 | http://ptyptossen.com/favicon.ico | US | — | — | malicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2684 | iexplore.exe | 204.79.197.200:80 | www.bing.com | Microsoft Corporation | US | whitelisted |
2828 | iexplore.exe | 104.201.20.75:80 | ptyptossen.com | eSited Solutions | US | malicious |
2828 | iexplore.exe | 111.206.37.189:80 | push.zhanzhang.baidu.com | China Unicom Beijing Province Network | CN | malicious |
2828 | iexplore.exe | 220.243.212.50:443 | js.users.51.la | QUANTIL, INC | CN | unknown |
2828 | iexplore.exe | 222.186.57.120:88 | web.xixigmail.com | AS Number for CHINANET jiangsu province backbone | CN | unknown |
2828 | iexplore.exe | 183.131.207.78:80 | ia.51.la | DaLi | CN | suspicious |
2684 | iexplore.exe | 104.201.20.75:80 | ptyptossen.com | eSited Solutions | US | malicious |
2828 | iexplore.exe | 103.235.46.39:80 | www.baidu.com | Beijing Baidu Netcom Science and Technology Co., Ltd. | HK | unknown |
2828 | iexplore.exe | 103.235.46.191:443 | hm.baidu.com | Beijing Baidu Netcom Science and Technology Co., Ltd. | HK | suspicious |
Domain | IP | Reputation |
|---|---|---|
www.bing.com |
| whitelisted |
ptyptossen.com |
| malicious |
push.zhanzhang.baidu.com |
| whitelisted |
hm.baidu.com |
| whitelisted |
js.users.51.la |
| whitelisted |
ia.51.la |
| whitelisted |
web.xixigmail.com |
| unknown |
api.share.baidu.com |
| whitelisted |
www.baidu.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2828 | iexplore.exe | A Network Trojan was detected | SC TROJAN_DOWNLOADER Trojan-Downloader MacroLoader MSOffice |
2828 | iexplore.exe | A Network Trojan was detected | SC TROJAN_DOWNLOADER Trojan-Downloader MacroLoader MSOffice |