analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
URL:

http://profile.pinyin.sogou.com/download.php?filename=configmd5.bin

Full analysis: https://app.any.run/tasks/d0b1e0a8-a3fd-4b0c-9ae5-225f55145f1b
Verdict: Malicious activity
Analysis date: January 22, 2019, 23:22:49
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
adware
sogou
Indicators:
MD5:

CAE34F2D43BCD27CBDFBABEF7087CDC9

SHA1:

CD71B24730AB4EE2FFAAD3C833FDDC870FC2CE37

SHA256:

5C538CB85FB69313AB21A1188005181B133767A349D43FE04680DF99EFB9305D

SSDEEP:

3:N1KOXY9GfeKK8KrOLWaDI8q:COXoGeKBKrOLlI8q

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Application launched itself

      • iexplore.exe (PID: 2936)
    • Creates files in the user directory

      • iexplore.exe (PID: 3060)
      • iexplore.exe (PID: 2936)
      • iexplore.exe (PID: 1208)
      • FlashUtil32_26_0_0_131_ActiveX.exe (PID: 2268)
      • iexplore.exe (PID: 3000)
    • Reads internet explorer settings

      • iexplore.exe (PID: 3060)
      • iexplore.exe (PID: 1208)
      • iexplore.exe (PID: 3000)
    • Reads Internet Cache Settings

      • iexplore.exe (PID: 2936)
      • iexplore.exe (PID: 3060)
      • iexplore.exe (PID: 1208)
      • iexplore.exe (PID: 3000)
    • Changes internet zones settings

      • iexplore.exe (PID: 2936)
    • Reads settings of System Certificates

      • iexplore.exe (PID: 2936)
    • Dropped object may contain Bitcoin addresses

      • iexplore.exe (PID: 3060)
      • iexplore.exe (PID: 1208)
    • Adds / modifies Windows certificates

      • iexplore.exe (PID: 2936)
    • Changes settings of System certificates

      • iexplore.exe (PID: 2936)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
38
Monitored processes
5
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe flashutil32_26_0_0_131_activex.exe no specs iexplore.exe iexplore.exe

Process information

PID
CMD
Path
Indicators
Parent process
2936"C:\Program Files\Internet Explorer\iexplore.exe" -nohomeC:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
3060"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2936 CREDAT:71937C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
2268C:\Windows\system32\Macromed\Flash\FlashUtil32_26_0_0_131_ActiveX.exe -EmbeddingC:\Windows\system32\Macromed\Flash\FlashUtil32_26_0_0_131_ActiveX.exesvchost.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
MEDIUM
Description:
Adobe® Flash® Player Installer/Uninstaller 26.0 r0
Version:
26,0,0,131
1208"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2936 CREDAT:203009C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
3000"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2936 CREDAT:203010C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Total events
1 197
Read events
995
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
3
Text files
217
Unknown types
47

Dropped files

PID
Process
Filename
Type
2936iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9ZEWH8D\favicon[1].ico
MD5:
SHA256:
2936iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
MD5:
SHA256:
3060iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\admin@sogou[1].txt
MD5:
SHA256:
3060iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OCDM6JB6\sogou_com[1].txt
MD5:
SHA256:
3060iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\admin@sogou[2].txttext
MD5:D5C07759F31E62CBB5DB82FC503572D5
SHA256:26B7B9D22DFEA0FB47F69A0CFE45C84CB5816C0064CA592DDDCFDEB41C1E137F
3060iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txttext
MD5:E9BFC8685A37609743B0F96F475DC177
SHA256:28968B12D10C525A1F8B38B5C86EA7AB88730B5C2F8683E44B9F832054E3A8C4
3060iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\History\Low\History.IE5\MSHist012019012220190123\index.datdat
MD5:70B35BFB855EC6978DD7C4AF48C5332E
SHA256:EE7409C8523D4F1E5017AF24E69BDF49ED47E37037D4B623D0B27CC8019944F3
3060iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OCDM6JB6\sogou_com[1].htmhtml
MD5:C06DA70335A7B2900D53CEEA6074FD08
SHA256:48C770D748A9C776CFE7733289AB5A7B9305473A585BA36153149AF316966BD9
3060iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\U2ZG9DE0\profile_pinyin_sogou_com[1].htmhtml
MD5:2C443F127339E0F69BB5EF8509716453
SHA256:FF43E13F64CEE7BE3A4BFA272C08233E14EE01AD3482F2EBFF3C0A1CEB6D8078
2936iexplore.exeC:\Users\admin\AppData\Local\Temp\StructuredQuery.logtext
MD5:BD74CE3A62DE719E0A8D73BE42004150
SHA256:9FEF52402AD14DEE6AB3B34FEB7A915C1A510E2DEC02972909996669AF9C846F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
16
TCP/UDP connections
86
DNS requests
20
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3060
iexplore.exe
GET
403
49.51.130.237:80
http://profile.pinyin.sogou.com/download.php?filename=configmd5.bin
CN
malicious
1208
iexplore.exe
GET
301
203.205.128.160:80
http://baike.sogou.com/v64825136.htm?fromTitle=test%EF%BC%88Test%EF%BC%88%E6%91%94%E8%A7%92%E6%89%8B%EF%BC%89%EF%BC%89
CN
html
192 b
malicious
1208
iexplore.exe
GET
301
203.205.128.160:80
http://baike.sogou.com/v64825136.htm?fromTitle=test%EF%BC%88Test%EF%BC%88%E6%91%94%E8%A7%92%E6%89%8B%EF%BC%89%EF%BC%89
CN
html
192 b
malicious
1208
iexplore.exe
GET
301
203.205.128.160:80
http://baike.sogou.com/v64825136.htm?fromTitle=test%EF%BC%88Test%EF%BC%88%E6%91%94%E8%A7%92%E6%89%8B%EF%BC%89%EF%BC%89
CN
html
192 b
malicious
3060
iexplore.exe
GET
301
118.191.216.42:80
http://sogou.com/
CN
html
178 b
malicious
2936
iexplore.exe
GET
200
204.79.197.200:80
http://www.bing.com/favicon.ico
US
image
237 b
whitelisted
3060
iexplore.exe
GET
200
49.51.130.237:80
http://profile.pinyin.sogou.com/
CN
html
65 b
malicious
1208
iexplore.exe
GET
200
175.100.207.204:80
http://tv.sohu.com/commonfrag/vrs_flashPlayer.inc
HK
text
58 b
malicious
2936
iexplore.exe
GET
200
204.79.197.200:80
http://www.bing.com/favicon.ico
US
image
237 b
whitelisted
1208
iexplore.exe
GET
302
119.28.109.132:80
http://www.sogou.com/
CN
html
154 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2936
iexplore.exe
204.79.197.200:80
www.bing.com
Microsoft Corporation
US
whitelisted
3060
iexplore.exe
119.28.109.132:80
sogou.com
Tencent Building, Kejizhongyi Avenue
CN
malicious
3060
iexplore.exe
49.51.130.237:80
profile.pinyin.sogou.com
Tencent Building, Kejizhongyi Avenue
CN
malicious
3060
iexplore.exe
49.51.130.237:443
profile.pinyin.sogou.com
Tencent Building, Kejizhongyi Avenue
CN
malicious
2936
iexplore.exe
49.51.130.237:80
profile.pinyin.sogou.com
Tencent Building, Kejizhongyi Avenue
CN
malicious
3060
iexplore.exe
118.191.216.42:80
sogou.com
CN
malicious
3060
iexplore.exe
119.28.109.132:443
sogou.com
Tencent Building, Kejizhongyi Avenue
CN
malicious
2936
iexplore.exe
119.28.109.132:443
sogou.com
Tencent Building, Kejizhongyi Avenue
CN
malicious
3060
iexplore.exe
14.215.138.25:443
tajs.qq.com
China Telecom (Group)
CN
suspicious
3060
iexplore.exe
203.205.224.26:443
dlweb.sogoucdn.com
Tencent Building, Kejizhongyi Avenue
CN
suspicious

DNS requests

Domain
IP
Reputation
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
profile.pinyin.sogou.com
  • 49.51.130.237
malicious
sogou.com
  • 118.191.216.42
  • 118.191.216.57
  • 119.28.109.132
malicious
www.sogou.com
  • 119.28.109.132
  • 118.191.216.42
  • 118.191.216.57
whitelisted
dlweb.sogoucdn.com
  • 203.205.224.26
  • 203.205.224.16
  • 87.245.210.76
  • 203.205.224.27
  • 87.245.210.77
  • 203.205.224.14
suspicious
account.sogou.com
  • 49.51.130.237
malicious
pb6.sogou.com
  • 140.143.116.174
  • 39.97.4.240
unknown
pb.sogou.com
  • 118.191.216.57
  • 119.28.109.132
  • 118.191.216.42
unknown
tajs.qq.com
  • 14.215.138.25
whitelisted
res.iciba.com
  • 183.236.60.129
  • 124.239.226.1
  • 113.113.101.1
  • 183.146.25.1
  • 123.8.171.1
  • 61.147.122.129
  • 218.60.15.1
  • 60.221.17.1
  • 124.232.182.1
  • 60.28.125.129
  • 183.214.10.1
  • 223.112.143.1
  • 183.134.19.1
suspicious

Threats

No threats detected
No debug info