analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
URL:

http://hongwoniu.com.cn/wp-content/rooftop.php?to=andrei.gorin&message=bef3192a9f6f14563683235615431

Full analysis: https://app.any.run/tasks/d05c0749-cb82-4bb9-b29e-1e647e5e09c8
Verdict: Malicious activity
Analysis date: September 19, 2019, 06:24:17
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

173131F7E9C902E6A079988003F888A5

SHA1:

C419A5E328001135C57F93A64BDA9D48EF8AF45A

SHA256:

56825D831C17621EAB007167489B802AFF03B2CA1A733F44B7A77408AB71C974

SSDEEP:

3:N1KWK2SuyKh+mIfAQ1R+11ZMLoPWFXuTOXzT:CWCKNIfAqC1yEPCuTOX/

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Creates files in the user directory

      • iexplore.exe (PID: 3548)
      • iexplore.exe (PID: 4064)
      • iexplore.exe (PID: 2352)
    • Changes internet zones settings

      • iexplore.exe (PID: 3548)
    • Reads Internet Cache Settings

      • iexplore.exe (PID: 4064)
      • iexplore.exe (PID: 3548)
      • iexplore.exe (PID: 2352)
    • Application launched itself

      • iexplore.exe (PID: 3548)
    • Reads internet explorer settings

      • iexplore.exe (PID: 4064)
      • iexplore.exe (PID: 2352)
    • Adds / modifies Windows certificates

      • iexplore.exe (PID: 3548)
    • Reads settings of System Certificates

      • iexplore.exe (PID: 3548)
    • Changes settings of System certificates

      • iexplore.exe (PID: 3548)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
39
Monitored processes
3
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe iexplore.exe

Process information

PID
CMD
Path
Indicators
Parent process
3548"C:\Program Files\Internet Explorer\iexplore.exe" "http://hongwoniu.com.cn/wp-content/rooftop.php?to=andrei.gorin&message=bef3192a9f6f14563683235615431"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
4064"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3548 CREDAT:71937C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2352"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3548 CREDAT:6405C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
799
Read events
640
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
1
Text files
55
Unknown types
11

Dropped files

PID
Process
Filename
Type
3548iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\favicon[1].ico
MD5:
SHA256:
3548iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
MD5:
SHA256:
4064iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MT2IN548\rooftop[1].php
MD5:
SHA256:
4064iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\index.datdat
MD5:8D80062ABDCC7A76D05D70DA17F28AE8
SHA256:1ED664297404CC2B7C10C62FE5F3C1E7B37146D05B21E6DC19A25E04603321F9
4064iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\69254I9A\noConnect[1]image
MD5:3CB8FACCD5DE434D415AB75C17E8FD86
SHA256:6976C426E3AC66D66303C114B22B2B41109A7DE648BA55FFC3E5A53BD0DB09E7
4064iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\J2QV670D\errorPageStrings[1]text
MD5:1A0563F7FB85A678771450B131ED66FD
SHA256:EB5678DE9D8F29CA6893D4E6CA79BD5AB4F312813820FE4997B009A2B1A1654C
4064iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MT2IN548\rooftop[1].htmhtml
MD5:783E9CCD749A7C5B837BE8DCEF3CF94B
SHA256:2622DDE29CAD9B26BB9AEE79DBA733594626D49D7108D1BC4561B65F36F6C705
4064iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\69254I9A\tools[1]image
MD5:6F20BA58551E13CFD87EC059327EFFD0
SHA256:62A7038CC42C1482D70465192318F21FC1CE0F0C737CB8804137F38A1F9D680B
4064iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\69254I9A\dnserror[1]html
MD5:68E03ED57EC741A4AFBBCD11FAB1BDBE
SHA256:1FF3334C3EB27033F8F37029FD72F648EDD4551FCE85FC1F5159FEAEA1439630
4064iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PL34DL95\real-flirtpartner12_com[1].htmhtml
MD5:E7F1193747DE61C9CAD33AD9EDDCB3D1
SHA256:9E73838BCA60BA36760C55FBB45874C948985497F5069B65819B6D9D2CD52E7B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
27
TCP/UDP connections
25
DNS requests
12
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4064
iexplore.exe
GET
200
91.195.240.97:80
http://ww3.flirtsdreams.info/
DE
html
19.7 Kb
suspicious
4064
iexplore.exe
GET
200
122.114.221.128:80
http://hongwoniu.com.cn/wp-content/rooftop.php?to=andrei.gorin&message=bef3192a9f6f14563683235615431
CN
html
1.14 Kb
suspicious
4064
iexplore.exe
GET
200
91.195.240.97:80
http://ww3.flirtsdreams.info/search/tsc.php?200=MzA3NTkzMzAz&21=ODUuMTcuNzMuMTE5&681=MTU2ODg3NDM1MzFhNDcwNDkwMDVmOTY2NDNhNjQ3MGQ2ZTY2YzlhYTAz&crc=4683388f16f0e44ce6870e9a2c8702e2ffbb3fe4&cv=1
DE
compressed
19.7 Kb
suspicious
4064
iexplore.exe
GET
200
91.195.240.97:80
http://ww3.flirtsdreams.info/search/tsc.php?200=MzA3NTkzMzAz&21=ODUuMTcuNzMuMTE5&681=MTU2ODg3NDM4MWQ3YzM4M2UwYjRlMDA3NGY2NTIyYzZjZDhmZGQyYTc4&crc=7969b17fd6fe7e97e8f0e26e2060cbf557645856&cv=1
DE
compressed
19.7 Kb
suspicious
2352
iexplore.exe
GET
200
220.181.38.148:80
http://baidu.com/
CN
html
81 b
whitelisted
3548
iexplore.exe
GET
200
220.181.38.148:80
http://baidu.com/favicon.ico
CN
image
318 b
whitelisted
4064
iexplore.exe
GET
200
172.217.18.4:80
http://www.google.com/adsense/domains/caf.js
US
text
55.4 Kb
whitelisted
4064
iexplore.exe
GET
200
199.191.50.185:80
http://flirtsdreams.info/
VG
html
422 b
malicious
4064
iexplore.exe
GET
200
91.195.240.97:80
http://ww3.flirtsdreams.info/
DE
html
19.7 Kb
suspicious
2352
iexplore.exe
GET
200
103.235.46.39:80
http://www.baidu.com/img/[email protected]
HK
image
6.36 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4064
iexplore.exe
122.114.221.128:80
hongwoniu.com.cn
CHINA UNICOM China169 Backbone
CN
suspicious
4064
iexplore.exe
91.195.240.97:80
ww3.flirtsdreams.info
SEDO GmbH
DE
suspicious
3548
iexplore.exe
92.63.192.132:443
real-flirtpartner12.com
IT DeLuxe Ltd.
RU
suspicious
4064
iexplore.exe
199.191.50.185:80
flirtsdreams.info
Confluence Networks Inc
VG
malicious
4064
iexplore.exe
92.63.192.132:443
real-flirtpartner12.com
IT DeLuxe Ltd.
RU
suspicious
3548
iexplore.exe
204.79.197.200:80
www.bing.com
Microsoft Corporation
US
whitelisted
4064
iexplore.exe
92.63.192.132:80
real-flirtpartner12.com
IT DeLuxe Ltd.
RU
suspicious
4064
iexplore.exe
216.58.208.35:80
www.gstatic.com
Google Inc.
US
whitelisted
220.181.38.148:80
baidu.com
IDC, China Telecommunications Corporation
CN
malicious
2352
iexplore.exe
103.235.46.39:80
www.baidu.com
Beijing Baidu Netcom Science and Technology Co., Ltd.
HK
unknown

DNS requests

Domain
IP
Reputation
hongwoniu.com.cn
  • 122.114.221.128
suspicious
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
real-flirtpartner12.com
  • 92.63.192.132
suspicious
flirtsdreams.info
  • 199.191.50.185
malicious
ww3.flirtsdreams.info
  • 91.195.240.97
unknown
img.sedoparking.com
  • 205.234.175.175
whitelisted
www.google.com
  • 172.217.18.4
whitelisted
www.gstatic.com
  • 216.58.208.35
whitelisted
baidu.com
  • 220.181.38.148
  • 39.156.69.79
whitelisted
www.baidu.com
  • 103.235.46.39
whitelisted

Threats

Found threats are available for the paid subscriptions
1 ETPRO signatures available at the full report
No debug info