download:

1.hta

Full analysis: https://app.any.run/tasks/31953d62-c53d-4c75-9c36-eab3a526e267
Verdict: Malicious activity
Analysis date: January 02, 2020, 03:05:55
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: text/html
File info: HTML document, ASCII text, with very long lines, with CRLF line terminators
MD5:

A9BB69FFE538AE8A10DD1B9DEA44440F

SHA1:

6F63CC6EFFAB5E193FCE31E444F8CCECB92EA590

SHA256:

5A5FBC454671DA41A78CF29C7BBAE35FFA7996DB0B614209318C45B64D1DC19F

SSDEEP:

1536:XSDv0/DzaoNmn4ooU6p0zKVMYgylPS26j:Uc/3aQp0zAMRC3O

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes settings of System certificates

      • mshta.exe (PID: 1752)
    • Changes the autorun value in the registry

      • reg.exe (PID: 2856)
  • SUSPICIOUS

    • Executed via COM

      • DllHost.exe (PID: 2496)
    • Application launched itself

      • mshta.exe (PID: 1752)
    • Creates files in the program directory

      • mshta.exe (PID: 1752)
      • mshta.exe (PID: 284)
    • Adds / modifies Windows certificates

      • mshta.exe (PID: 1752)
    • Starts MSHTA.EXE for opening HTA or HTMLS files

      • mshta.exe (PID: 1752)
    • Executable content was dropped or overwritten

      • mshta.exe (PID: 284)
    • Starts CMD.EXE for commands execution

      • mshta.exe (PID: 284)
    • Uses REG.EXE to modify Windows registry

      • cmd.exe (PID: 3588)
  • INFO

    • Reads internet explorer settings

      • mshta.exe (PID: 1752)
      • mshta.exe (PID: 284)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
40
Monitored processes
5
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start mshta.exe PhotoViewer.dll no specs mshta.exe cmd.exe no specs reg.exe

Process information

PID
CMD
Path
Indicators
Parent process
284"C:\Windows\System32\mshta.exe" "C:\ProgramData\Adobe\tmpHta.hta" C:\Windows\System32\mshta.exe
mshta.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft (R) HTML Application host
Exit code:
0
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\mshta.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\psapi.dll
1752"C:\Windows\System32\mshta.exe" "C:\Users\admin\AppData\Local\Temp\1.hta"C:\Windows\System32\mshta.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft (R) HTML Application host
Exit code:
0
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\mshta.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\psapi.dll
2496C:\Windows\system32\DllHost.exe /Processid:{76D0CB12-7604-4048-B83C-1005C7DDC503}C:\Windows\system32\DllHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
COM Surrogate
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\dllhost.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2856REG ADD "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /V "softWiz" /t REG_SZ /F /D "C:\ProgramData\Adobe\credwiz.exe"C:\Windows\system32\reg.exe
cmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Registry Console Tool
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\reg.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3588cmd /c ""C:\ProgramData\Adobe\addreg.bat" "C:\Windows\System32\cmd.exemshta.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
702
Read events
672
Write events
29
Delete events
1

Modification events

(PID) Process:(1752) mshta.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(1752) mshta.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(1752) mshta.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
Operation:writeName:{FFE2A43C-56B9-4BF5-9A79-CC6D4285608A} {00000122-0000-0000-C000-000000000046} 0xFFFF
Value:
010000000000000098DFDF9619C1D501
(PID) Process:(2496) DllHost.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Operation:writeName:Name
Value:
DllHost.exe
(PID) Process:(1752) mshta.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Operation:writeName:Name
Value:
mshta.exe
(PID) Process:(1752) mshta.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1752) mshta.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:@%SystemRoot%\system32\p2pcollab.dll,-8042
Value:
Peer to Peer Trust
(PID) Process:(1752) mshta.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:@%SystemRoot%\system32\qagentrt.dll,-10
Value:
System Health Authentication
(PID) Process:(1752) mshta.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:@%SystemRoot%\system32\dnsapi.dll,-103
Value:
Domain Name System (DNS) Server Trust
(PID) Process:(1752) mshta.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:@%SystemRoot%\System32\fveui.dll,-843
Value:
BitLocker Drive Encryption
Executable files
3
Suspicious files
0
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
1752mshta.exeC:\ProgramData\Adobe\tempfile.txt
MD5:
SHA256:
1752mshta.exeC:\ProgramData\Adobe\tmpHta.hta
MD5:
SHA256:
284mshta.exeC:\ProgramData\Adobe\DUser.dllexecutable
MD5:
SHA256:
284mshta.exeC:\ProgramData\Adobe\addreg.battext
MD5:
SHA256:
284mshta.exeC:\Users\admin\AppData\Local\Temp\MicroSoft\winms.exeexecutable
MD5:
SHA256:
1752mshta.exeC:\Users\admin\AppData\Local\Temp\Whatsapp-Image.jpgimage
MD5:
SHA256:
284mshta.exeC:\ProgramData\Adobe\credwiz.exeexecutable
MD5:15CF85C3D904A7D8650164B0B831A318
SHA256:17EABFB88A164AA95731F198BD69A7285CC7F64ACD7C289062CD3979A4A2F5BF
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
2
DNS requests
2
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1752
mshta.exe
192.185.129.21:443
fincruitconsulting.in
CyrusOne LLC
US
suspicious

DNS requests

Domain
IP
Reputation
fincruitconsulting.in
  • 192.185.129.21
suspicious
www.fincruitconsulting.in
  • 192.185.129.21
suspicious

Threats

No threats detected
No debug info