URL:

sourl.cn

Full analysis: https://app.any.run/tasks/22dcca31-3f1c-4e6a-ba69-3c6268fbd926
Verdict: Malicious activity
Analysis date: December 22, 2023, 17:33:27
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

0AD71D97C3BE43F799C857E77CAE7B83

SHA1:

A91532E3873F3D358EF5F178EEC13AABD2B29DB1

SHA256:

433650EB9CD20FFF652CF6E3B15DAD1F8406713238C0EC8CF1D077DACC47301F

SSDEEP:

3:ZL:1

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Application launched itself

      • iexplore.exe (PID: 128)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
36
Monitored processes
2
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe

Process information

PID
CMD
Path
Indicators
Parent process
128"C:\Program Files\Internet Explorer\iexplore.exe" "sourl.cn"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
296"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:128 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
Total events
21 841
Read events
21 767
Write events
72
Delete events
2

Modification events

(PID) Process:(128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
0
(PID) Process:(128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30847387
(PID) Process:(128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30847437
(PID) Process:(128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
0
Suspicious files
19
Text files
11
Unknown types
0

Dropped files

PID
Process
Filename
Type
296iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\BSUQWGDI.htmhtml
MD5:36E297AB1FB0B65D0B7359FCF106EE54
SHA256:249BD8F7B07D28044B8C8D021915054B112B47E89B5C59F75A9DBF86AFECC102
296iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B2FAF7692FD9FFBD64EDE317E42334BA_BE25D0FE540174A4A87E2295C663329Dbinary
MD5:607DB781939E787809BF111718FE9F07
SHA256:55B9E77F785E67BCC38D8F3A20BA39EFDB6E9FCD33D2D87180A0AA76B99F153D
296iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:E7532E32E15CDA474B7FB82961731A58
SHA256:07905E29F5CBCFC58A2279BE856FAA30F7FE6B418C811B9872DF5699D8F2E6EE
296iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B2FAF7692FD9FFBD64EDE317E42334BA_BE25D0FE540174A4A87E2295C663329Dbinary
MD5:9420482CC5A0BD1F6A7B0A6EDD54E672
SHA256:1A2AB9560F400DE62144FF24E7EAA7F9FC1512FE01695CD373FBF445E5D20B3A
296iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\3390319[1].pngimage
MD5:5362E3A1FBA2D744E1504D64396C4884
SHA256:6F1D37547A9157A99715DFAD5E73868FBDC658B73A9565FE4EBBD906B31BF99B
296iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B427D15CDE663F35297ADFBAAA93283Fbinary
MD5:9AE1B490ADCD6994D7E047D16E1454BC
SHA256:C92B352D412DF4800B90D19FD8C99E30635BFECE60FC18421D5C0AE6B61F8913
296iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\d7d28e7[1].pngimage
MD5:CFC3A8B2B8CD4B1A9A7CFFEFD3DCC81D
SHA256:1E3D5C9D5BD36B6B80D91E32B0A37504A136B39064D8794E0DF8C7087A59F38D
296iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\1B1F4BA66CDBFEC85A20E11BF729AF23_AA85F8F9DAFF33153B5AEC2E983B94B6binary
MD5:5CF4265FA7129B1D308973C5541D7293
SHA256:762DE61F03AF7AD4BA9E58D548E70AA29EC31CAB0F837185769DAA0398FA5744
296iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\1B1F4BA66CDBFEC85A20E11BF729AF23_AA85F8F9DAFF33153B5AEC2E983B94B6binary
MD5:56CAB9F89ED0953288096CA1B5A7D7E1
SHA256:D376B5280F88DD62FA2EBC73ED5B879644DC20D62FFCD4DFA6F91BBAD6255313
296iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\68FAF71AF355126BCA00CE2E73CC7374_A2C4C6E5B37C3E3A5010D0A651ED0037binary
MD5:74B9ECEC0F6456249841F1A778FAFE96
SHA256:3377B586E38C949F2C5326B85239099B76D263442ADD26C88E86C76C98160F43
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
18
TCP/UDP connections
33
DNS requests
17
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
296
iexplore.exe
GET
200
119.188.210.162:80
http://sourl.cn/
unknown
html
4.30 Kb
unknown
296
iexplore.exe
GET
200
184.24.77.202:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?da7d239c2d634b3e
unknown
compressed
4.66 Kb
unknown
296
iexplore.exe
GET
200
184.24.77.202:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?b9cb2e4cef5cf09c
unknown
compressed
4.66 Kb
unknown
296
iexplore.exe
GET
200
184.24.77.202:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?0ff45b802431ef22
unknown
compressed
4.66 Kb
unknown
296
iexplore.exe
GET
200
184.24.77.202:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?b71d3251e987e393
unknown
compressed
4.66 Kb
unknown
296
iexplore.exe
GET
200
184.24.77.202:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?c95ff0e62e19a3db
unknown
compressed
4.66 Kb
unknown
296
iexplore.exe
GET
200
172.64.149.23:80
http://ocsp.comodoca.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEQCyDO1VLjGgvzQ6dSh0O%2Bmr
unknown
binary
1.42 Kb
unknown
296
iexplore.exe
GET
200
119.36.90.164:80
http://ocsp.trust-provider.cn/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBQDhvjmfMdSVsHZ9u52p9jqu3rd8gQUXzp8ERB%2BDGdxYdyLo7UAA2f1VxwCEQDd2Svz76hsiIa2%2FRrRJMx5
unknown
binary
600 b
unknown
296
iexplore.exe
GET
200
2.17.100.200:80
http://subca.ocsp-certum.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBR5iK7tYk9tqQEoeQhZNkKcAol9bgQUjEPEy22YwaechGnr30oNYJY6w%2FsCEQCTkoVAAWVxX5R%2FKI%2FvyZso
unknown
binary
1.50 Kb
unknown
296
iexplore.exe
GET
200
119.36.90.164:80
http://ocsp.trust-provider.cn/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQDhvjmfMdSVsHZ9u52p9jqu3rd8gQUXzp8ERB%2BDGdxYdyLo7UAA2f1VxwCEF1%2FNuV4UtqmC9LHEM7%2FKoU%3D
unknown
binary
599 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
296
iexplore.exe
119.188.210.162:80
sourl.cn
CHINA UNICOM China169 Backbone
CN
unknown
296
iexplore.exe
104.166.169.130:443
static.interval.im
ZEN-ECN
US
unknown
296
iexplore.exe
104.166.169.132:443
static.interval.im
ZEN-ECN
US
unknown
296
iexplore.exe
59.110.117.5:443
program.xinchacha.com
Hangzhou Alibaba Advertising Co.,Ltd.
CN
unknown
296
iexplore.exe
184.24.77.202:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
296
iexplore.exe
172.64.149.23:80
ocsp.comodoca.com
CLOUDFLARENET
US
unknown
296
iexplore.exe
119.36.90.164:80
ocsp.trust-provider.cn
CHINA UNICOM China169 Backbone
CN
unknown

DNS requests

Domain
IP
Reputation
sourl.cn
  • 119.188.210.162
unknown
static.interval.im
  • 104.166.169.130
  • 104.166.169.132
  • 23.90.190.178
  • 128.1.77.226
unknown
cdn.docsmall.com
  • 104.166.169.132
  • 23.90.190.178
  • 128.1.77.226
  • 104.166.169.130
unknown
program.xinchacha.com
  • 59.110.117.5
unknown
ctldl.windowsupdate.com
  • 184.24.77.202
  • 184.24.77.194
whitelisted
ocsp.comodoca.com
  • 172.64.149.23
  • 104.18.38.233
whitelisted
ocsp.trust-provider.cn
  • 119.36.90.164
  • 36.143.236.7
  • 36.248.38.100
  • 111.13.153.152
  • 111.48.138.18
  • 111.206.23.199
  • 112.50.95.96
  • 117.27.246.96
malicious
subca.ocsp-certum.com
  • 2.17.100.200
  • 2.17.100.234
whitelisted
xinchacha2ov.ocsp-certum.com
  • 2.17.100.200
  • 2.17.100.234
unknown
api.bing.com
  • 13.107.5.80
whitelisted

Threats

No threats detected
No debug info