URL:

http://5e62.personplain.top/bb?Z3oA

Full analysis: https://app.any.run/tasks/f94bf79e-488b-48bb-b6c9-befe0d150c70
Verdict: Malicious activity
Analysis date: March 19, 2024, 13:21:11
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

954D4D3B0B87511BAA02F84272F5868A

SHA1:

BE9734563D8B1DD59E564766FD662AC0578329F4

SHA256:

351D81F429F967A3B7490FCDA843F2EB898822D086396B63B984A89327B3B933

SSDEEP:

3:N1K0vqdtLL0cHSk:C0itLLuk

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • msdt.exe (PID: 1728)
    • Reads settings of System Certificates

      • msdt.exe (PID: 1728)
    • Reads the Internet Settings

      • sdiagnhost.exe (PID: 3556)
  • INFO

    • Checks supported languages

      • wmpnscfg.exe (PID: 3028)
    • Reads the computer name

      • wmpnscfg.exe (PID: 3028)
    • Application launched itself

      • iexplore.exe (PID: 3936)
    • Create files in a temporary directory

      • msdt.exe (PID: 1728)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 3028)
    • Drops the executable file immediately after the start

      • msdt.exe (PID: 1728)
    • Reads security settings of Internet Explorer

      • msdt.exe (PID: 1728)
      • sdiagnhost.exe (PID: 3556)
    • Reads the software policy settings

      • msdt.exe (PID: 1728)
    • Creates files or folders in the user directory

      • msdt.exe (PID: 1728)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
46
Monitored processes
5
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe wmpnscfg.exe no specs msdt.exe no specs sdiagnhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1728 -modal 1114548 -skip TRUE -path C:\Windows\diagnostics\system\networking -af C:\Users\admin\AppData\Local\Temp\NDF8F60.tmp -ep NetworkDiagnosticsWebC:\Windows\System32\msdt.exeiexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Diagnostics Troubleshooting Wizard
Exit code:
4294967295
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msdt.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2572"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3936 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
3028"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
3556C:\Windows\System32\sdiagnhost.exe -EmbeddingC:\Windows\System32\sdiagnhost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Scripted Diagnostics Native Host
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\sdiagnhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
3936"C:\Program Files\Internet Explorer\iexplore.exe" "http://5e62.personplain.top/bb?Z3oA"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
Total events
22 451
Read events
22 155
Write events
176
Delete events
120

Modification events

(PID) Process:(3936) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
1
(PID) Process:(3936) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchLowDateTime
Value:
(PID) Process:(3936) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
31095296
(PID) Process:(3936) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateLowDateTime
Value:
(PID) Process:(3936) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
31095296
(PID) Process:(3936) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(3936) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3936) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3936) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(3936) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
2
Suspicious files
24
Text files
216
Unknown types
11

Dropped files

PID
Process
Filename
Type
3936iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:BBED5F0EA1A6D0BEE446D00176006812
SHA256:79ADA8ACABC9BFDFA911DAD118CBA0DE3035AC783D86FB2BDF857413A88E7413
3936iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8A7891822FCFF127E4EADADE9757112Bder
MD5:085DB3C16E33F63C873CAD874CCAD2D5
SHA256:5FB6AAF940FFA862FCFEF27A441412EC4ACF93BE29FC9502616E5C8241FE5085
3936iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\9D6B3FE9E6E4067193F477ABAD990106der
MD5:EA8332102F630F9C1236CF0851266A45
SHA256:4541D9339AB605B941805E151345FBC0CA514266FAD7D4AD0A32001124624A02
3936iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.icoimage
MD5:DA597791BE3B6E732F0BC8B20E38EE62
SHA256:5B2C34B3C4E8DD898B664DBA6C3786E2FF9869EFF55D673AA48361F11325ED07
3936iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\QQ57SQG0.txttext
MD5:05A0BC36260E559596982B8005443299
SHA256:C75976EEC19889AFFD6E6250CAF8813C6DE378E29F4AFEF9BF22DAE53EDBD9D2
3936iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\9D6B3FE9E6E4067193F477ABAD990106binary
MD5:7AF3E9572987BD031276214CBD258137
SHA256:10B4F689DAABBC0A373FA2C82548D21FFCBCE3CC39051176ACDD7E31588ECF2E
3936iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8A7891822FCFF127E4EADADE9757112Bbinary
MD5:3C9E30C72D2FC8E05C8132245A983F70
SHA256:4E084F14923CA24222A4E20AAE3D84323F714F36AE2565EEF4D8D0E49B7E9F3F
3936iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\5823DF4C.txttext
MD5:83CE4319FEFFFEBAEE150BA3D464AF63
SHA256:6195F5ECBACF28A5DFB1705A9A043037D40A317B8F70FA808C1D9E57E91BACBA
3936iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\favicon[1].icoimage
MD5:DA597791BE3B6E732F0BC8B20E38EE62
SHA256:5B2C34B3C4E8DD898B664DBA6C3786E2FF9869EFF55D673AA48361F11325ED07
3936iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\NRAFX2KJ.txttext
MD5:0202CB98AADA05C23BA7C99109289A97
SHA256:C26089A6C5EE2E73C663E2F19B62C73B693F89CA938D10268B3AC549561995C9
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
13
TCP/UDP connections
129
DNS requests
41
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3936
iexplore.exe
GET
304
23.216.77.75:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?bdc5ae628aaf0bd4
unknown
unknown
2572
iexplore.exe
GET
301
81.94.156.136:80
http://5e62.personplain.top/bb?Z3oA
unknown
html
330 b
unknown
2572
iexplore.exe
GET
301
81.94.156.136:80
http://5e62.personplain.top/bb/?Z3oA
unknown
html
330 b
unknown
3936
iexplore.exe
GET
304
23.216.77.75:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?d416ea50f343b89b
unknown
unknown
3936
iexplore.exe
GET
200
192.229.221.95:80
http://crl3.digicert.com/DigiCertGlobalRootG2.crl
unknown
binary
1.14 Kb
unknown
3936
iexplore.exe
GET
200
192.229.221.95:80
http://crl3.digicert.com/DigiCertGlobalRootG3.crl
unknown
binary
863 b
unknown
2572
iexplore.exe
GET
301
81.94.156.136:80
http://5e62.personplain.top/bb/?Z3oA
unknown
unknown
1080
svchost.exe
GET
200
23.53.40.82:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?d24e253035548135
unknown
compressed
67.5 Kb
unknown
2572
iexplore.exe
GET
301
81.94.156.136:80
http://5e62.personplain.top/bb/?Z3oA
unknown
unknown
2572
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEATh56TcXPLzbcArQrhdFZ8%3D
unknown
binary
471 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2572
iexplore.exe
81.94.156.136:80
5e62.personplain.top
OOO WestCall Ltd.
RU
unknown
3936
iexplore.exe
104.126.37.171:443
www.bing.com
Akamai International B.V.
DE
unknown
3936
iexplore.exe
104.126.37.153:443
www.bing.com
Akamai International B.V.
DE
unknown
3936
iexplore.exe
23.216.77.45:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
3936
iexplore.exe
152.199.19.161:443
iecvlist.microsoft.com
EDGECAST
US
whitelisted
3936
iexplore.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
3936
iexplore.exe
104.126.37.161:443
www.bing.com
Akamai International B.V.
DE
unknown

DNS requests

Domain
IP
Reputation
5e62.personplain.top
  • 81.94.156.136
unknown
api.bing.com
  • 13.107.5.80
whitelisted
www.bing.com
  • 104.126.37.153
  • 104.126.37.162
  • 104.126.37.154
  • 104.126.37.171
  • 104.126.37.178
  • 104.126.37.155
  • 104.126.37.161
  • 104.126.37.170
  • 104.126.37.177
  • 104.126.37.130
  • 104.126.37.184
  • 104.126.37.136
  • 104.126.37.186
  • 104.126.37.129
  • 104.126.37.131
  • 104.126.37.123
  • 104.126.37.185
whitelisted
ctldl.windowsupdate.com
  • 23.216.77.45
  • 23.216.77.75
  • 23.216.77.72
  • 23.53.40.82
  • 23.53.40.11
  • 23.53.40.59
  • 23.53.40.42
  • 23.53.40.72
  • 23.53.40.65
  • 23.53.40.73
  • 23.53.40.80
  • 23.53.40.83
  • 23.32.238.218
  • 23.32.238.209
  • 23.32.238.193
  • 23.32.238.168
  • 23.32.238.240
  • 23.32.238.194
  • 23.32.238.201
  • 23.32.238.216
  • 23.32.238.232
whitelisted
iecvlist.microsoft.com
  • 152.199.19.161
whitelisted
r20swj13mr.microsoft.com
  • 152.199.19.161
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
dns.msftncsi.com
  • 131.107.255.255
shared
crl3.digicert.com
  • 192.229.221.95
whitelisted
yahoo.com
  • 74.6.143.26
  • 74.6.231.20
  • 74.6.231.21
  • 98.137.11.163
  • 98.137.11.164
  • 74.6.143.25
whitelisted

Threats

PID
Process
Class
Message
1080
svchost.exe
Potentially Bad Traffic
ET DNS Query to a *.top domain - Likely Hostile
2572
iexplore.exe
Potentially Bad Traffic
ET INFO HTTP Request to a *.top domain
2572
iexplore.exe
Potentially Bad Traffic
ET INFO HTTP Request to a *.top domain
2572
iexplore.exe
Potentially Bad Traffic
ET INFO HTTP Request to a *.top domain
No debug info