URL:

sourl.cn

Full analysis: https://app.any.run/tasks/22dcca31-3f1c-4e6a-ba69-3c6268fbd926
Verdict: Malicious activity
Analysis date: December 22, 2023, 17:33:27
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

0AD71D97C3BE43F799C857E77CAE7B83

SHA1:

A91532E3873F3D358EF5F178EEC13AABD2B29DB1

SHA256:

433650EB9CD20FFF652CF6E3B15DAD1F8406713238C0EC8CF1D077DACC47301F

SSDEEP:

3:ZL:1

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Application launched itself

      • iexplore.exe (PID: 128)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
36
Monitored processes
2
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe

Process information

PID
CMD
Path
Indicators
Parent process
128"C:\Program Files\Internet Explorer\iexplore.exe" "sourl.cn"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
296"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:128 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
Total events
21 841
Read events
21 767
Write events
72
Delete events
2

Modification events

(PID) Process:(128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
0
(PID) Process:(128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30847387
(PID) Process:(128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30847437
(PID) Process:(128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
0
Suspicious files
19
Text files
11
Unknown types
0

Dropped files

PID
Process
Filename
Type
296iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B427D15CDE663F35297ADFBAAA93283Fbinary
MD5:9AE1B490ADCD6994D7E047D16E1454BC
SHA256:C92B352D412DF4800B90D19FD8C99E30635BFECE60FC18421D5C0AE6B61F8913
296iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\3390319[1].pngimage
MD5:5362E3A1FBA2D744E1504D64396C4884
SHA256:6F1D37547A9157A99715DFAD5E73868FBDC658B73A9565FE4EBBD906B31BF99B
296iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\d7d28e7[1].pngimage
MD5:CFC3A8B2B8CD4B1A9A7CFFEFD3DCC81D
SHA256:1E3D5C9D5BD36B6B80D91E32B0A37504A136B39064D8794E0DF8C7087A59F38D
296iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\1B1F4BA66CDBFEC85A20E11BF729AF23_AA85F8F9DAFF33153B5AEC2E983B94B6binary
MD5:56CAB9F89ED0953288096CA1B5A7D7E1
SHA256:D376B5280F88DD62FA2EBC73ED5B879644DC20D62FFCD4DFA6F91BBAD6255313
296iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\68FAF71AF355126BCA00CE2E73CC7374_A2C4C6E5B37C3E3A5010D0A651ED0037binary
MD5:74B9ECEC0F6456249841F1A778FAFE96
SHA256:3377B586E38C949F2C5326B85239099B76D263442ADD26C88E86C76C98160F43
296iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\iHPTn23xJS7DxTNW[1].pngimage
MD5:87A6966D8FEA09B1A4A4362398A3BE46
SHA256:9441F4BD65E0157EEF1D875673CC642CCB7BEC12FB1D047C41110A07D30967F9
296iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\1B1F4BA66CDBFEC85A20E11BF729AF23_AA85F8F9DAFF33153B5AEC2E983B94B6binary
MD5:5CF4265FA7129B1D308973C5541D7293
SHA256:762DE61F03AF7AD4BA9E58D548E70AA29EC31CAB0F837185769DAA0398FA5744
296iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B427D15CDE663F35297ADFBAAA93283Fbinary
MD5:E83F7D0554508C97A761DE6182207D90
SHA256:9C82B4896D73904AA84E3104E9638730B62C103B7AFE4DBDE1338893CBB9375A
296iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157compressed
MD5:1BFE591A4FE3D91B03CDF26EAACD8F89
SHA256:9CF94355051BF0F4A45724CA20D1CC02F76371B963AB7D1E38BD8997737B13D8
296iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B2FAF7692FD9FFBD64EDE317E42334BA_BE25D0FE540174A4A87E2295C663329Dbinary
MD5:9420482CC5A0BD1F6A7B0A6EDD54E672
SHA256:1A2AB9560F400DE62144FF24E7EAA7F9FC1512FE01695CD373FBF445E5D20B3A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
18
TCP/UDP connections
33
DNS requests
17
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
296
iexplore.exe
GET
200
119.188.210.162:80
http://sourl.cn/
unknown
html
4.30 Kb
unknown
296
iexplore.exe
GET
200
184.24.77.202:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?c95ff0e62e19a3db
unknown
compressed
4.66 Kb
unknown
296
iexplore.exe
GET
200
184.24.77.202:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?b71d3251e987e393
unknown
compressed
4.66 Kb
unknown
296
iexplore.exe
GET
200
184.24.77.202:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?b9cb2e4cef5cf09c
unknown
compressed
4.66 Kb
unknown
296
iexplore.exe
GET
200
119.36.90.164:80
http://ocsp.trust-provider.cn/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBQDhvjmfMdSVsHZ9u52p9jqu3rd8gQUXzp8ERB%2BDGdxYdyLo7UAA2f1VxwCEQDd2Svz76hsiIa2%2FRrRJMx5
unknown
binary
600 b
unknown
296
iexplore.exe
GET
200
2.17.100.200:80
http://subca.ocsp-certum.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTYOkzrrCGQj08njZXbUQQpkoUmuQQUCHbNywf%2FJPbFze27kLzihDdGdfcCEQDyRAgtq6kNpYxy6fKak0Cu
unknown
binary
1.54 Kb
unknown
296
iexplore.exe
GET
200
119.36.90.164:80
http://ocsp.trust-provider.cn/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQDhvjmfMdSVsHZ9u52p9jqu3rd8gQUXzp8ERB%2BDGdxYdyLo7UAA2f1VxwCEF1%2FNuV4UtqmC9LHEM7%2FKoU%3D
unknown
binary
599 b
unknown
296
iexplore.exe
GET
200
2.17.100.200:80
http://xinchacha2ov.ocsp-certum.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBROEINLkjAkTWwp1OV6PhKtnRlGWwQU%2BqDLwsddgbUgkgcgC7Y7cDsJDlUCEHqnxF0gie6HhRXKamm24O0%3D
unknown
binary
1.52 Kb
unknown
128
iexplore.exe
GET
304
184.24.77.202:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?3459b2d391457a37
unknown
unknown
296
iexplore.exe
GET
200
2.17.100.200:80
http://subca.ocsp-certum.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBR5iK7tYk9tqQEoeQhZNkKcAol9bgQUjEPEy22YwaechGnr30oNYJY6w%2FsCEQCTkoVAAWVxX5R%2FKI%2FvyZso
unknown
binary
1.50 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
296
iexplore.exe
119.188.210.162:80
sourl.cn
CHINA UNICOM China169 Backbone
CN
unknown
296
iexplore.exe
104.166.169.130:443
static.interval.im
ZEN-ECN
US
unknown
296
iexplore.exe
104.166.169.132:443
static.interval.im
ZEN-ECN
US
unknown
296
iexplore.exe
59.110.117.5:443
program.xinchacha.com
Hangzhou Alibaba Advertising Co.,Ltd.
CN
unknown
296
iexplore.exe
184.24.77.202:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
296
iexplore.exe
172.64.149.23:80
ocsp.comodoca.com
CLOUDFLARENET
US
unknown
296
iexplore.exe
119.36.90.164:80
ocsp.trust-provider.cn
CHINA UNICOM China169 Backbone
CN
unknown

DNS requests

Domain
IP
Reputation
sourl.cn
  • 119.188.210.162
unknown
static.interval.im
  • 104.166.169.130
  • 104.166.169.132
  • 23.90.190.178
  • 128.1.77.226
unknown
cdn.docsmall.com
  • 104.166.169.132
  • 23.90.190.178
  • 128.1.77.226
  • 104.166.169.130
unknown
program.xinchacha.com
  • 59.110.117.5
unknown
ctldl.windowsupdate.com
  • 184.24.77.202
  • 184.24.77.194
whitelisted
ocsp.comodoca.com
  • 172.64.149.23
  • 104.18.38.233
whitelisted
ocsp.trust-provider.cn
  • 119.36.90.164
  • 36.143.236.7
  • 36.248.38.100
  • 111.13.153.152
  • 111.48.138.18
  • 111.206.23.199
  • 112.50.95.96
  • 117.27.246.96
malicious
subca.ocsp-certum.com
  • 2.17.100.200
  • 2.17.100.234
whitelisted
xinchacha2ov.ocsp-certum.com
  • 2.17.100.200
  • 2.17.100.234
unknown
api.bing.com
  • 13.107.5.80
whitelisted

Threats

No threats detected
No debug info