| URL: | whyers.io |
| Full analysis: | https://app.any.run/tasks/3ad78e98-4a8b-414e-bcaa-f9d99c2abf5a |
| Verdict: | Malicious activity |
| Threats: | Mallox is a ransomware strain that emerged in 2021, known for its ability to encrypt files and target database servers using vulnerabilities like RDP. Often distributed through phishing campaigns and exploiting exposed SQL servers, it locks victims' data and demands a ransom. Mallox operates as a Ransomware-as-a-Service (RaaS), making it accessible to affiliates who use it to conduct attacks. |
| Analysis date: | April 13, 2024, 21:54:05 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MD5: | 950F1A8E2BDED946D95A1319A42EF221 |
| SHA1: | 244D0582C894EBEE9B712252AAD53486FB956EE5 |
| SHA256: | 537DA1C34FD82F5B6F68CE42BD08FBB65414A39A495ED30F8E4475A27CC03ED7 |
| SSDEEP: | 3:jKKn:jR |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 480 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --mojo-platform-channel-handle=3648 --field-trial-handle=1348,i,8603895658676592411,8031679348240524251,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 492 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --use-gl=angle --use-angle=swiftshader-webgl --mojo-platform-channel-handle=1492 --field-trial-handle=1348,i,8603895658676592411,8031679348240524251,131072 /prefetch:2 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 109.0.1518.115 Modules
| |||||||||||||||
| 712 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=8 --mojo-platform-channel-handle=1500 --field-trial-handle=1348,i,8603895658676592411,8031679348240524251,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 109.0.1518.115 Modules
| |||||||||||||||
| 924 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=4088 --field-trial-handle=1348,i,8603895658676592411,8031679348240524251,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 984 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=4040 --field-trial-handle=1348,i,8603895658676592411,8031679348240524251,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 992 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3944 --field-trial-handle=1348,i,8603895658676592411,8031679348240524251,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1824 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1228 --field-trial-handle=1348,i,8603895658676592411,8031679348240524251,131072 /prefetch:2 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1972 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1396 --field-trial-handle=1348,i,8603895658676592411,8031679348240524251,131072 /prefetch:3 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | msedge.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1992 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --first-renderer-process --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=2196 --field-trial-handle=1348,i,8603895658676592411,8031679348240524251,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 109.0.1518.115 Modules
| |||||||||||||||
| 2364 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=1640 --field-trial-handle=1348,i,8603895658676592411,8031679348240524251,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 109.0.1518.115 Modules
| |||||||||||||||
| (PID) Process: | (3992) msedge.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
| (PID) Process: | (3992) msedge.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | state |
Value: 2 | |||
| (PID) Process: | (3992) msedge.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Edge\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: | |||
| (PID) Process: | (3992) msedge.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Edge\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: 01000000 | |||
| (PID) Process: | (3992) msedge.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | state |
Value: 1 | |||
| (PID) Process: | (3992) msedge.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\EdgeUpdate\ClientState\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062} |
| Operation: | write | Name: | dr |
Value: 1 | |||
| (PID) Process: | (3992) msedge.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Edge\StabilityMetrics |
| Operation: | write | Name: | user_experience_metrics.stability.exited_cleanly |
Value: 0 | |||
| (PID) Process: | (3992) msedge.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault |
| Operation: | write | Name: | S-1-5-21-1302019708-1500728564-335382590-1000 |
Value: EC6A4DB697742F00 | |||
| (PID) Process: | (3992) msedge.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\FirstNotDefault |
| Operation: | delete value | Name: | S-1-5-21-1302019708-1500728564-335382590-1000 |
Value: | |||
| (PID) Process: | (3992) msedge.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Edge |
| Operation: | write | Name: | UsageStatsInSample |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3992 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad\settings.dat | binary | |
MD5:— | SHA256:— | |||
| 4008 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\CrashpadMetrics.pma | binary | |
MD5:— | SHA256:— | |||
| 3992 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Variations | binary | |
MD5:— | SHA256:— | |||
| 3992 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\70f98b21-b797-4f88-a968-95b912acbb12.tmp | — | |
MD5:— | SHA256:— | |||
| 3992 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Local State~RF181f79.TMP | text | |
MD5:— | SHA256:— | |||
| 3992 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Local State | text | |
MD5:— | SHA256:— | |||
| 3992 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Last Version | text | |
MD5:— | SHA256:— | |||
| 3992 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\Site Characteristics Database\LOG.old~RF181fc8.TMP | text | |
MD5:— | SHA256:— | |||
| 3992 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\Site Characteristics Database\LOG.old | text | |
MD5:— | SHA256:— | |||
| 3992 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF181fc8.TMP | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1972 | msedge.exe | GET | 302 | 72.52.178.23:80 | http://whyers.io/ | unknown | — | — | unknown |
1972 | msedge.exe | GET | 200 | 76.223.26.96:80 | http://ww12.whyers.io/?usid=18&utid=25512485029 | unknown | — | — | unknown |
1972 | msedge.exe | GET | 200 | 67.225.218.50:80 | http://parking.parklogic.com/page/enhance.js?pcId=12&domain=whyers.io | unknown | — | — | unknown |
1972 | msedge.exe | GET | 200 | 76.223.26.96:80 | http://ww12.whyers.io/track.php?domain=whyers.io&toggle=browserjs&uid=MTcxMzA0NTI1My45NzM1OmQ3MjQ1YjU5ZmViMDJiOTAwOTA2NjcxOTM5ZGM1YmRhYWNkZWZhYWRmZDE1OTUyYzA4NGNiMzIyM2U2MjBjYWM6NjYxYWZmMDVlZGFiNg%3D%3D | unknown | — | — | unknown |
1972 | msedge.exe | GET | 200 | 67.225.218.50:80 | http://parking.parklogic.com/page/scribe.php?pcId=12&domain=whyers.io&pId=1055&usid=18&utid=25512485029&query=null&domainJs=ww12.whyers.io&path=/&ss=true&lp=1 | unknown | — | — | unknown |
1972 | msedge.exe | GET | 201 | 76.223.26.96:80 | http://ww12.whyers.io/ls.php?t=661aff05&token=af70d757e9edd1c9bed0bb64ac951c734245a974 | unknown | — | — | unknown |
1972 | msedge.exe | GET | 200 | 18.239.102.57:80 | http://d38psrni17bvxu.cloudfront.net/themes/cleanPeppermintBlack_657d9013/img/arrows.png | unknown | — | — | unknown |
1972 | msedge.exe | GET | 200 | 76.223.26.96:80 | http://ww12.whyers.io/favicon.ico | unknown | — | — | unknown |
1972 | msedge.exe | GET | 200 | 76.223.26.96:80 | http://ww12.whyers.io/track.php?domain=whyers.io&caf=1&toggle=answercheck&answer=yes&uid=MTcxMzA0NTI1My45NzM1OmQ3MjQ1YjU5ZmViMDJiOTAwOTA2NjcxOTM5ZGM1YmRhYWNkZWZhYWRmZDE1OTUyYzA4NGNiMzIyM2U2MjBjYWM6NjYxYWZmMDVlZGFiNg%3D%3D | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
3992 | msedge.exe | 239.255.255.250:1900 | — | — | — | unknown |
1972 | msedge.exe | 13.107.21.239:443 | edge.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
1972 | msedge.exe | 13.107.42.16:443 | config.edge.skype.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
1972 | msedge.exe | 72.52.178.23:80 | whyers.io | LIQUIDWEB | US | unknown |
1972 | msedge.exe | 76.223.26.96:80 | ww12.whyers.io | AMAZON-02 | US | unknown |
1972 | msedge.exe | 67.225.218.50:80 | parking.parklogic.com | LIQUIDWEB | US | unknown |
1972 | msedge.exe | 142.250.185.110:443 | www.adsensecustomsearchads.com | — | — | whitelisted |
Domain | IP | Reputation |
|---|---|---|
config.edge.skype.com |
| whitelisted |
whyers.io |
| unknown |
edge.microsoft.com |
| whitelisted |
ww12.whyers.io |
| unknown |
parking.parklogic.com |
| unknown |
www.google.com |
| whitelisted |
d38psrni17bvxu.cloudfront.net |
| unknown |
www.afternic.com |
| whitelisted |
www.adsensecustomsearchads.com |
| whitelisted |
partner.googleadservices.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
1972 | msedge.exe | A Network Trojan was detected | ET MALWARE Mallox Ransomware CnC Domain (whyers .io) in DNS Lookup |
1972 | msedge.exe | A Network Trojan was detected | ET MALWARE Mallox Ransomware CnC Domain (whyers .io) in DNS Lookup |
1972 | msedge.exe | A Network Trojan was detected | ET MALWARE Mallox Ransomware CnC Domain (whyers .io) in DNS Lookup |
1972 | msedge.exe | A Network Trojan was detected | ET MALWARE Mallox Ransomware CnC Domain (whyers .io) in DNS Lookup |