URL:

http://static1.1.sqspcdn.com/static/f/633774/21553624/1357400446143/Spanish+Accents+CapsLock+setup.exe

Full analysis: https://app.any.run/tasks/bf53cd8f-8805-47a9-adb8-a34c766c0902
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: March 10, 2020, 17:52:22
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
loader
Indicators:
MD5:

D51CFE3671F51F5D0ABEA223E238BDF7

SHA1:

3D9C4E424DBA56763AA52E6C83F48ABC47A88567

SHA256:

5B49C5158C4973C47E6B9F6E0CD34B158E4389A360EB01F81800E833CDD23BDB

SSDEEP:

3:N1KNRwULlPs9LGTNRBGKUWWaDbRuvOkVvOmLRWJ88OdkA:Cp4yBRsHOcWmLwJ0kA

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Downloads executable files from the Internet

      • iexplore.exe (PID: 3888)
    • Application was dropped or rewritten from another process

      • Spanish Accents CapsLock setup.exe (PID: 1156)
      • Spanish Accents CapsLock setup.exe (PID: 2868)
      • Spanish Accents CapsLock.exe (PID: 2856)
      • Spanish Accents CapsLock.exe (PID: 3708)
      • Spanish Accents CapsLock.exe (PID: 1888)
    • Writes to a start menu file

      • Spanish Accents CapsLock setup.tmp (PID: 3180)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • iexplore.exe (PID: 3888)
      • Spanish Accents CapsLock setup.tmp (PID: 3180)
      • Spanish Accents CapsLock setup.exe (PID: 1156)
      • iexplore.exe (PID: 1740)
      • Spanish Accents CapsLock setup.exe (PID: 2868)
    • Reads Windows owner or organization settings

      • Spanish Accents CapsLock setup.tmp (PID: 3180)
    • Reads the Windows organization settings

      • Spanish Accents CapsLock setup.tmp (PID: 3180)
    • Creates files in the user directory

      • Spanish Accents CapsLock setup.tmp (PID: 3180)
  • INFO

    • Application launched itself

      • iexplore.exe (PID: 1740)
    • Changes internet zones settings

      • iexplore.exe (PID: 1740)
    • Reads Internet Cache Settings

      • iexplore.exe (PID: 3888)
      • iexplore.exe (PID: 1740)
    • Application was dropped or rewritten from another process

      • Spanish Accents CapsLock setup.tmp (PID: 3180)
      • Spanish Accents CapsLock setup.tmp (PID: 3036)
    • Modifies the phishing filter of IE

      • iexplore.exe (PID: 1740)
    • Creates files in the program directory

      • Spanish Accents CapsLock setup.tmp (PID: 3180)
    • Loads dropped or rewritten executable

      • Spanish Accents CapsLock setup.tmp (PID: 3180)
    • Creates a software uninstall entry

      • Spanish Accents CapsLock setup.tmp (PID: 3180)
    • Manual execution by user

      • Spanish Accents CapsLock.exe (PID: 3708)
      • WINWORD.EXE (PID: 3364)
      • Spanish Accents CapsLock.exe (PID: 1888)
    • Creates files in the user directory

      • WINWORD.EXE (PID: 3364)
    • Reads Microsoft Office registry keys

      • WINWORD.EXE (PID: 3364)
    • Reads settings of System Certificates

      • iexplore.exe (PID: 1740)
    • Adds / modifies Windows certificates

      • iexplore.exe (PID: 1740)
    • Changes settings of System certificates

      • iexplore.exe (PID: 1740)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
48
Monitored processes
10
Malicious processes
4
Suspicious processes
3

Behavior graph

Click at the process to see the details
drop and start start drop and start drop and start iexplore.exe iexplore.exe spanish accents capslock setup.exe spanish accents capslock setup.tmp no specs spanish accents capslock setup.exe spanish accents capslock setup.tmp spanish accents capslock.exe no specs winword.exe no specs spanish accents capslock.exe no specs spanish accents capslock.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1156"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\Spanish Accents CapsLock setup.exe" C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\Spanish Accents CapsLock setup.exe
iexplore.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Spanish Accents CapsLock Setup
Exit code:
0
Version:
2.0
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\b6qgx7lp\spanish accents capslock setup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1740"C:\Program Files\Internet Explorer\iexplore.exe" http://static1.1.sqspcdn.com/static/f/633774/21553624/1357400446143/Spanish+Accents+CapsLock+setup.exeC:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
1
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
1888"C:\Program Files\Spanish Accents CapsLock\Spanish Accents CapsLock.exe" C:\Program Files\Spanish Accents CapsLock\Spanish Accents CapsLock.exeexplorer.exe
User:
admin
Company:
One Hour Programming
Integrity Level:
MEDIUM
Description:
Spanish Accents CapsLock
Exit code:
0
Version:
2.0.0.0
Modules
Images
c:\program files\spanish accents capslock\spanish accents capslock.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\gdi32.dll
2856"C:\Program Files\Spanish Accents CapsLock\Spanish Accents CapsLock.exe"C:\Program Files\Spanish Accents CapsLock\Spanish Accents CapsLock.exeSpanish Accents CapsLock setup.tmp
User:
admin
Company:
One Hour Programming
Integrity Level:
MEDIUM
Description:
Spanish Accents CapsLock
Exit code:
0
Version:
2.0.0.0
Modules
Images
c:\program files\spanish accents capslock\spanish accents capslock.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\gdi32.dll
2868"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\Spanish Accents CapsLock setup.exe" /SPAWNWND=$C012C /NOTIFYWND=$7021C C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\Spanish Accents CapsLock setup.exe
Spanish Accents CapsLock setup.tmp
User:
admin
Company:
Integrity Level:
HIGH
Description:
Spanish Accents CapsLock Setup
Exit code:
0
Version:
2.0
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\b6qgx7lp\spanish accents capslock setup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3036"C:\Users\admin\AppData\Local\Temp\is-52NCG.tmp\Spanish Accents CapsLock setup.tmp" /SL5="$7021C,318290,114176,C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\Spanish Accents CapsLock setup.exe" C:\Users\admin\AppData\Local\Temp\is-52NCG.tmp\Spanish Accents CapsLock setup.tmpSpanish Accents CapsLock setup.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-52ncg.tmp\spanish accents capslock setup.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3180"C:\Users\admin\AppData\Local\Temp\is-224BN.tmp\Spanish Accents CapsLock setup.tmp" /SL5="$1B0260,318290,114176,C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\Spanish Accents CapsLock setup.exe" /SPAWNWND=$C012C /NOTIFYWND=$7021C C:\Users\admin\AppData\Local\Temp\is-224BN.tmp\Spanish Accents CapsLock setup.tmp
Spanish Accents CapsLock setup.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-224bn.tmp\spanish accents capslock setup.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3364"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\Desktop\clothingrest.rtf"C:\Program Files\Microsoft Office\Office14\WINWORD.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Word
Exit code:
0
Version:
14.0.6024.1000
Modules
Images
c:\program files\microsoft office\office14\winword.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
3708"C:\Program Files\Spanish Accents CapsLock\Spanish Accents CapsLock.exe" C:\Program Files\Spanish Accents CapsLock\Spanish Accents CapsLock.exeexplorer.exe
User:
admin
Company:
One Hour Programming
Integrity Level:
MEDIUM
Description:
Spanish Accents CapsLock
Exit code:
0
Version:
2.0.0.0
Modules
Images
c:\program files\spanish accents capslock\spanish accents capslock.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\gdi32.dll
3888"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:1740 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
Total events
10 183
Read events
2 740
Write events
5 059
Delete events
2 384

Modification events

(PID) Process:(1740) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateLowDateTime
Value:
3251036230
(PID) Process:(1740) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30799620
(PID) Process:(1740) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(1740) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(1740) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(1740) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(1740) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(1740) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
46000000A1000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
(PID) Process:(1740) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(1740) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
Executable files
7
Suspicious files
7
Text files
6
Unknown types
11

Dropped files

PID
Process
Filename
Type
3888iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\Spanish Accents CapsLock setup.exe.7fkn8kj.partial
MD5:
SHA256:
1740iexplore.exeC:\Users\admin\AppData\Local\Temp\~DFD735951FA5128E2B.TMP
MD5:
SHA256:
1740iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\Spanish Accents CapsLock setup.exe.7fkn8kj.partial:Zone.Identifier
MD5:
SHA256:
3180Spanish Accents CapsLock setup.tmpC:\Program Files\Spanish Accents CapsLock\is-6LUBR.tmp
MD5:
SHA256:
3180Spanish Accents CapsLock setup.tmpC:\Program Files\Spanish Accents CapsLock\is-S2RFV.tmp
MD5:
SHA256:
1740iexplore.exeC:\Users\admin\AppData\Local\Temp\~DFBC967B3BFEB8E0DA.TMP
MD5:
SHA256:
1740iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{ED883FB9-62F7-11EA-972D-5254004A04AF}.dat
MD5:
SHA256:
1740iexplore.exeC:\Users\admin\AppData\Local\Temp\Cab2994.tmp
MD5:
SHA256:
1740iexplore.exeC:\Users\admin\AppData\Local\Temp\Tar2995.tmp
MD5:
SHA256:
3364WINWORD.EXEC:\Users\admin\AppData\Local\Temp\CVR9389.tmp.cvr
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
8
DNS requests
6
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1740
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA8sEMlbBsCTf7jUSfg%2BhWk%3D
US
der
1.47 Kb
whitelisted
3888
iexplore.exe
GET
200
151.101.0.238:80
http://static1.1.sqspcdn.com/static/f/633774/21553624/1357400446143/Spanish+Accents+CapsLock+setup.exe
US
executable
682 Kb
whitelisted
1740
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA8sEMlbBsCTf7jUSfg%2BhWk%3D
US
der
1.47 Kb
whitelisted
1740
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA8sEMlbBsCTf7jUSfg%2BhWk%3D
US
der
1.47 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1740
iexplore.exe
152.199.19.161:443
iecvlist.microsoft.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
1740
iexplore.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
3888
iexplore.exe
151.101.0.238:80
static1.1.sqspcdn.com
Fastly
US
malicious

DNS requests

Domain
IP
Reputation
static1.1.sqspcdn.com
  • 151.101.0.238
  • 151.101.64.238
  • 151.101.128.238
  • 151.101.192.238
whitelisted
iecvlist.microsoft.com
  • 152.199.19.161
whitelisted
r20swj13mr.microsoft.com
  • 152.199.19.161
whitelisted
ocsp.digicert.com
  • 93.184.220.29
whitelisted

Threats

PID
Process
Class
Message
3888
iexplore.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
3888
iexplore.exe
Misc activity
ET INFO EXE - Served Attached HTTP
No debug info