URL:

sourl.cn

Full analysis: https://app.any.run/tasks/22dcca31-3f1c-4e6a-ba69-3c6268fbd926
Verdict: Malicious activity
Analysis date: December 22, 2023, 17:33:27
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

0AD71D97C3BE43F799C857E77CAE7B83

SHA1:

A91532E3873F3D358EF5F178EEC13AABD2B29DB1

SHA256:

433650EB9CD20FFF652CF6E3B15DAD1F8406713238C0EC8CF1D077DACC47301F

SSDEEP:

3:ZL:1

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Application launched itself

      • iexplore.exe (PID: 128)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
36
Monitored processes
2
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe

Process information

PID
CMD
Path
Indicators
Parent process
128"C:\Program Files\Internet Explorer\iexplore.exe" "sourl.cn"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
296"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:128 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
Total events
21 841
Read events
21 767
Write events
72
Delete events
2

Modification events

(PID) Process:(128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
0
(PID) Process:(128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30847387
(PID) Process:(128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30847437
(PID) Process:(128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
0
Suspicious files
19
Text files
11
Unknown types
0

Dropped files

PID
Process
Filename
Type
296iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B427D15CDE663F35297ADFBAAA93283Fbinary
MD5:9AE1B490ADCD6994D7E047D16E1454BC
SHA256:C92B352D412DF4800B90D19FD8C99E30635BFECE60FC18421D5C0AE6B61F8913
296iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157compressed
MD5:1BFE591A4FE3D91B03CDF26EAACD8F89
SHA256:9CF94355051BF0F4A45724CA20D1CC02F76371B963AB7D1E38BD8997737B13D8
296iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B2FAF7692FD9FFBD64EDE317E42334BA_BE25D0FE540174A4A87E2295C663329Dbinary
MD5:607DB781939E787809BF111718FE9F07
SHA256:55B9E77F785E67BCC38D8F3A20BA39EFDB6E9FCD33D2D87180A0AA76B99F153D
296iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\BSUQWGDI.htmhtml
MD5:36E297AB1FB0B65D0B7359FCF106EE54
SHA256:249BD8F7B07D28044B8C8D021915054B112B47E89B5C59F75A9DBF86AFECC102
296iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B2FAF7692FD9FFBD64EDE317E42334BA_BE25D0FE540174A4A87E2295C663329Dbinary
MD5:9420482CC5A0BD1F6A7B0A6EDD54E672
SHA256:1A2AB9560F400DE62144FF24E7EAA7F9FC1512FE01695CD373FBF445E5D20B3A
296iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\1B1F4BA66CDBFEC85A20E11BF729AF23_AA85F8F9DAFF33153B5AEC2E983B94B6binary
MD5:56CAB9F89ED0953288096CA1B5A7D7E1
SHA256:D376B5280F88DD62FA2EBC73ED5B879644DC20D62FFCD4DFA6F91BBAD6255313
296iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\d7d28e7[1].pngimage
MD5:CFC3A8B2B8CD4B1A9A7CFFEFD3DCC81D
SHA256:1E3D5C9D5BD36B6B80D91E32B0A37504A136B39064D8794E0DF8C7087A59F38D
296iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B427D15CDE663F35297ADFBAAA93283Fbinary
MD5:E83F7D0554508C97A761DE6182207D90
SHA256:9C82B4896D73904AA84E3104E9638730B62C103B7AFE4DBDE1338893CBB9375A
296iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\50D83FCD808EF23206F7ED2D967A02A5binary
MD5:368986BC55FB5F2312F3D0349FDE62C2
SHA256:307C5EE18497255EE9AB6A8C3A23E511736D03B4AFD91BC665790B86AEB32165
296iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\50D83FCD808EF23206F7ED2D967A02A5binary
MD5:116D0943C58A6B32E5A82AA0BC697732
SHA256:A0EF518A6E1653EB72777C6D235F9C716C4009D372C1B3466BDDBF9DFF8A2DE8
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
18
TCP/UDP connections
33
DNS requests
17
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
296
iexplore.exe
GET
200
119.188.210.162:80
http://sourl.cn/
CN
html
4.30 Kb
unknown
296
iexplore.exe
GET
200
184.24.77.202:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?da7d239c2d634b3e
DE
compressed
4.66 Kb
unknown
296
iexplore.exe
GET
200
184.24.77.202:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?b71d3251e987e393
DE
compressed
4.66 Kb
unknown
296
iexplore.exe
GET
200
184.24.77.202:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?b9cb2e4cef5cf09c
DE
compressed
4.66 Kb
unknown
296
iexplore.exe
GET
200
184.24.77.202:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?c95ff0e62e19a3db
DE
compressed
4.66 Kb
unknown
296
iexplore.exe
GET
200
172.64.149.23:80
http://ocsp.comodoca.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEQCyDO1VLjGgvzQ6dSh0O%2Bmr
US
binary
1.42 Kb
unknown
296
iexplore.exe
GET
200
119.36.90.164:80
http://ocsp.trust-provider.cn/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBQDhvjmfMdSVsHZ9u52p9jqu3rd8gQUXzp8ERB%2BDGdxYdyLo7UAA2f1VxwCEQDd2Svz76hsiIa2%2FRrRJMx5
CN
binary
600 b
unknown
296
iexplore.exe
GET
200
119.36.90.164:80
http://ocsp.trust-provider.cn/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQDhvjmfMdSVsHZ9u52p9jqu3rd8gQUXzp8ERB%2BDGdxYdyLo7UAA2f1VxwCEF1%2FNuV4UtqmC9LHEM7%2FKoU%3D
CN
binary
599 b
unknown
296
iexplore.exe
GET
200
2.17.100.200:80
http://subca.ocsp-certum.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBR5iK7tYk9tqQEoeQhZNkKcAol9bgQUjEPEy22YwaechGnr30oNYJY6w%2FsCEQCTkoVAAWVxX5R%2FKI%2FvyZso
DE
binary
1.50 Kb
unknown
296
iexplore.exe
GET
200
2.17.100.200:80
http://subca.ocsp-certum.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTYOkzrrCGQj08njZXbUQQpkoUmuQQUCHbNywf%2FJPbFze27kLzihDdGdfcCEQDyRAgtq6kNpYxy6fKak0Cu
DE
binary
1.54 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
296
iexplore.exe
119.188.210.162:80
sourl.cn
CHINA UNICOM China169 Backbone
CN
unknown
296
iexplore.exe
104.166.169.130:443
static.interval.im
ZEN-ECN
US
unknown
296
iexplore.exe
104.166.169.132:443
static.interval.im
ZEN-ECN
US
unknown
296
iexplore.exe
59.110.117.5:443
program.xinchacha.com
Hangzhou Alibaba Advertising Co.,Ltd.
CN
unknown
296
iexplore.exe
184.24.77.202:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
296
iexplore.exe
172.64.149.23:80
ocsp.comodoca.com
CLOUDFLARENET
US
unknown
296
iexplore.exe
119.36.90.164:80
ocsp.trust-provider.cn
CHINA UNICOM China169 Backbone
CN
unknown

DNS requests

Domain
IP
Reputation
sourl.cn
  • 119.188.210.162
unknown
static.interval.im
  • 104.166.169.130
  • 104.166.169.132
  • 23.90.190.178
  • 128.1.77.226
unknown
cdn.docsmall.com
  • 104.166.169.132
  • 23.90.190.178
  • 128.1.77.226
  • 104.166.169.130
unknown
program.xinchacha.com
  • 59.110.117.5
unknown
ctldl.windowsupdate.com
  • 184.24.77.202
  • 184.24.77.194
whitelisted
ocsp.comodoca.com
  • 172.64.149.23
  • 104.18.38.233
whitelisted
ocsp.trust-provider.cn
  • 119.36.90.164
  • 36.143.236.7
  • 36.248.38.100
  • 111.13.153.152
  • 111.48.138.18
  • 111.206.23.199
  • 112.50.95.96
  • 117.27.246.96
malicious
subca.ocsp-certum.com
  • 2.17.100.200
  • 2.17.100.234
whitelisted
xinchacha2ov.ocsp-certum.com
  • 2.17.100.200
  • 2.17.100.234
unknown
api.bing.com
  • 13.107.5.80
whitelisted

Threats

No threats detected
No debug info