analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
URL:

https://fedex.com

Full analysis: https://app.any.run/tasks/0cb4c9b5-3c5a-4eab-bef2-1492fc027a7d
Verdict: Malicious activity
Analysis date: August 12, 2022, 20:24:02
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

8D9525A970FD0B82A0659B5CD649EF5D

SHA1:

390A6D2FBC10190F0B5C5EF918D3FE8082E75444

SHA256:

5596F377DF46B8135FA599E65F3C6DF6F7E14E816BD9CD6FC72523C647F2353F

SSDEEP:

3:N8NGT:2UT

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads Microsoft Outlook installation path

      • iexplore.exe (PID: 2484)
  • INFO

    • Reads the computer name

      • iexplore.exe (PID: 3068)
      • iexplore.exe (PID: 2484)
    • Checks supported languages

      • iexplore.exe (PID: 3068)
      • iexplore.exe (PID: 2484)
    • Reads settings of System Certificates

      • iexplore.exe (PID: 2484)
      • iexplore.exe (PID: 3068)
    • Changes settings of System certificates

      • iexplore.exe (PID: 3068)
    • Changes internet zones settings

      • iexplore.exe (PID: 3068)
    • Application launched itself

      • iexplore.exe (PID: 3068)
    • Checks Windows Trust Settings

      • iexplore.exe (PID: 2484)
      • iexplore.exe (PID: 3068)
    • Adds / modifies Windows certificates

      • iexplore.exe (PID: 3068)
    • Reads internet explorer settings

      • iexplore.exe (PID: 2484)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
37
Monitored processes
2
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe

Process information

PID
CMD
Path
Indicators
Parent process
3068"C:\Program Files\Internet Explorer\iexplore.exe" "https://fedex.com"C:\Program Files\Internet Explorer\iexplore.exe
Explorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
2484"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3068 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Total events
11 940
Read events
11 819
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
9
Text files
15
Unknown types
5

Dropped files

PID
Process
Filename
Type
2484iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\80237EE4964FC9C409AAF55BF996A292_FB287BEB63DB9E8D59A799779773B97Cder
MD5:2BFD43A87EE3F1C3155E81B5A85D054D
SHA256:B705CCE5D94A5E6356B8651A52B5FEE7439C8CA6DDEDF24127A9F74489998326
3068iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\IKBQE3QJ.txttext
MD5:E46C49DA22748F81B87CD85A34128F41
SHA256:A8D33A2C4F7DEC4FD4F519BF90A384CD04EC9DC9B473488FAD40F7B9EF4DCDA8
2484iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\DCD0D75871DDE826855F6AE0FFC4CA06_EC4F1ED693F7F8D5C4154D159AB9A069binary
MD5:328EB8C0FA77F7F5F151E90B29B4305B
SHA256:F94BAB05959171DDD1C4D6724743461CF99E34647801294FB2C9BBAAC216EC23
2484iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\1E94DJDB.htmhtml
MD5:A6912451CE5E1BD74B53BD7A1DF3963D
SHA256:69FDC8E9A67825C83A3A90FB295F5551CF41942848CA6708FC382DAEFF1F9F5C
2484iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\80237EE4964FC9C409AAF55BF996A292_FB287BEB63DB9E8D59A799779773B97Cbinary
MD5:195CFFD75851081873B396B47CCB4FEF
SHA256:488E53696BAC872ECA67742DCEE71EE64CD36749A276C5BC3135BB8C8C5D1A4F
3068iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6BADA8974A10C4BD62CC921D13E43B18_711ED44619924BA6DC33E69F97E7FF63binary
MD5:A9B649BD4411C9D8E1701A678482334D
SHA256:2100C933507871469F98B6E79893BCFCD7D7CA2AF7F2A99B0109B35744A05910
2484iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\80237EE4964FC9C409AAF55BF996A292_44B7CEC7D7846BA12D21890D7AF2D759binary
MD5:DC6FED08978D93E963CBA7F2150DD162
SHA256:749963B68BB400BF1275C607A8EA04AA6E86A34A26B363125F4DACCEF558DDF5
2484iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\DCD0D75871DDE826855F6AE0FFC4CA06_EC4F1ED693F7F8D5C4154D159AB9A069der
MD5:5074C019074922F8E05862F6042C270F
SHA256:0D689D1D4DAFE115C58F613EE55D66A95B0D10ACB302B8F86E478C69AEEBE041
2484iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\80237EE4964FC9C409AAF55BF996A292_44B7CEC7D7846BA12D21890D7AF2D759der
MD5:2151190CE23801DCA0CD3171DBEB1515
SHA256:2B0CB4F6AE9C9C1EAE1D4B3401BFFAC2FE8ED270C9FACBE9030890726337B191
3068iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\OJ6YM7QR.txttext
MD5:ABF7C25472D11A1B93ECA9BAA61CA317
SHA256:AFD6DB7A40E184DC3B37EF383BD40F74EA26CFAF44C804B12D846749B3F1AE59
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
23
DNS requests
9
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3068
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA8Ull8gIGmZT9XHrHiJQeI%3D
US
der
1.47 Kb
whitelisted
2484
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTWEwdftt6hG98BgtOX4dN8bpJVCQQUak5Qv5honVt7IHXUWQF5SGaSMgYCEA4DhuXxyUFrfMakFMOKAvU%3D
US
der
471 b
whitelisted
2484
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAhflMAthXvozBT%2FU%2B2iPio%3D
US
der
471 b
whitelisted
3068
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
der
471 b
whitelisted
2484
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAFnjx%2FviCJV2LCnDmt7siA%3D
US
der
471 b
whitelisted
3068
iexplore.exe
GET
200
67.26.137.254:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?325939f444205851
US
compressed
4.70 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3068
iexplore.exe
67.26.137.254:80
ctldl.windowsupdate.com
Level 3 Communications, Inc.
US
malicious
3068
iexplore.exe
204.79.197.200:443
www.bing.com
Microsoft Corporation
US
whitelisted
3068
iexplore.exe
152.199.19.161:443
iecvlist.microsoft.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
3068
iexplore.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
2484
iexplore.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
3068
iexplore.exe
13.107.21.200:443
www.bing.com
Microsoft Corporation
US
whitelisted
2484
iexplore.exe
204.135.8.50:443
fedex.com
FedEx International Transmission Corporation
US
unknown
204.79.197.200:443
www.bing.com
Microsoft Corporation
US
whitelisted
2484
iexplore.exe
23.6.115.82:443
www.fedex.com
Akamai International B.V.
NL
unknown
3068
iexplore.exe
23.6.115.49:443
www.fedex.com
Akamai International B.V.
NL
unknown

DNS requests

Domain
IP
Reputation
fedex.com
  • 204.135.13.175
  • 204.135.8.50
  • 204.135.8.175
  • 204.135.13.50
  • 204.135.8.155
  • 204.135.13.155
unknown
api.bing.com
  • 13.107.5.80
whitelisted
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
ctldl.windowsupdate.com
  • 67.26.137.254
  • 67.27.159.126
  • 8.248.131.254
  • 8.248.117.254
  • 8.241.78.254
whitelisted
ocsp.digicert.com
  • 93.184.220.29
whitelisted
www.fedex.com
  • 23.6.115.82
  • 23.6.115.49
whitelisted
iecvlist.microsoft.com
  • 152.199.19.161
whitelisted
r20swj13mr.microsoft.com
  • 152.199.19.161
whitelisted

Threats

No threats detected
No debug info