URL:

https://contentcrowd.docsend.com/view/k6d8wbs

Full analysis: https://app.any.run/tasks/19c05f0e-2a1e-4628-abbc-608f26b17aa3
Verdict: No threats detected
Analysis date: September 27, 2019, 12:59:45
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

9EB59763428FDAE36A406EC993143050

SHA1:

04A2E67D5F1946C644F9A0376EC6CF98396EC378

SHA256:

5FA61D8C066C08F941127A2E0214B4AC1EC24A48CB739AA596BBAFF079227395

SSDEEP:

3:N8XAgZ9BUui:2Bjg

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executed via COM

      • FlashUtil32_26_0_0_131_ActiveX.exe (PID: 3180)
  • INFO

    • Creates files in the user directory

      • iexplore.exe (PID: 2372)
      • FlashUtil32_26_0_0_131_ActiveX.exe (PID: 3180)
    • Reads internet explorer settings

      • iexplore.exe (PID: 2372)
    • Changes internet zones settings

      • iexplore.exe (PID: 2572)
    • Dropped object may contain Bitcoin addresses

      • iexplore.exe (PID: 2372)
    • Reads Internet Cache Settings

      • iexplore.exe (PID: 2372)
      • iexplore.exe (PID: 2572)
    • Reads settings of System Certificates

      • iexplore.exe (PID: 2572)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
36
Monitored processes
3
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe flashutil32_26_0_0_131_activex.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2372"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2572 CREDAT:71937C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2572"C:\Program Files\Internet Explorer\iexplore.exe" "https://contentcrowd.docsend.com/view/k6d8wbs"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3180C:\Windows\system32\Macromed\Flash\FlashUtil32_26_0_0_131_ActiveX.exe -EmbeddingC:\Windows\system32\Macromed\Flash\FlashUtil32_26_0_0_131_ActiveX.exesvchost.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
MEDIUM
Description:
Adobe® Flash® Player Installer/Uninstaller 26.0 r0
Exit code:
0
Version:
26,0,0,131
Modules
Images
c:\windows\system32\macromed\flash\flashutil32_26_0_0_131_activex.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
Total events
563
Read events
444
Write events
117
Delete events
2

Modification events

(PID) Process:(2572) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(2572) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(2572) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(2572) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones
Operation:writeName:SecuritySafe
Value:
1
(PID) Process:(2572) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(2572) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
4600000092000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
(PID) Process:(2572) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Recovery\Active
Operation:writeName:{B6BD5401-E126-11E9-A363-5254004A04AF}
Value:
0
(PID) Process:(2572) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Type
Value:
4
(PID) Process:(2572) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Count
Value:
2
(PID) Process:(2572) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Time
Value:
E307090005001B000D00000001000702
Executable files
0
Suspicious files
0
Text files
100
Unknown types
12

Dropped files

PID
Process
Filename
Type
2572iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\favicon[1].ico
MD5:
SHA256:
2572iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
MD5:
SHA256:
2372iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\admin@docsend[1].txt
MD5:
SHA256:
2372iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\GXEHHDSO\k6d8wbs[1].txt
MD5:
SHA256:
2372iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\History\Low\History.IE5\index.datdat
MD5:
SHA256:
2372iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\909739W4\presentation-6a2115bc[1].csstext
MD5:
SHA256:
2372iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\admin@docsend[2].txttext
MD5:
SHA256:
2372iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\index.datdat
MD5:
SHA256:
2372iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\index.datdat
MD5:
SHA256:
2372iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\CBF1O678\toolbar-icons-694fd537[1].pngimage
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
37
DNS requests
24
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2572
iexplore.exe
GET
200
13.107.21.200:80
http://www.bing.com/favicon.ico
US
image
237 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2372
iexplore.exe
23.23.154.32:443
contentcrowd.docsend.com
Amazon.com, Inc.
US
unknown
2572
iexplore.exe
13.107.21.200:80
www.bing.com
Microsoft Corporation
US
whitelisted
2372
iexplore.exe
172.217.22.35:443
fonts.gstatic.com
Google Inc.
US
whitelisted
2372
iexplore.exe
35.190.88.7:443
sessions.bugsnag.com
Google Inc.
US
whitelisted
2372
iexplore.exe
52.222.172.226:443
cdn.segment.com
Amazon.com, Inc.
US
unknown
2372
iexplore.exe
172.217.18.104:443
www.googletagmanager.com
Google Inc.
US
suspicious
2372
iexplore.exe
52.85.183.2:443
widget.intercom.io
Amazon.com, Inc.
US
unknown
2372
iexplore.exe
13.224.199.13:443
scripts.kissmetrics.com
US
unknown
2372
iexplore.exe
35.166.68.180:443
api.segment.io
Amazon.com, Inc.
US
unknown
2372
iexplore.exe
52.4.3.62:443
trk.kissmetrics.com
Amazon.com, Inc.
US
unknown

DNS requests

Domain
IP
Reputation
contentcrowd.docsend.com
  • 23.23.154.32
  • 54.243.74.96
  • 23.23.168.240
whitelisted
www.bing.com
  • 13.107.21.200
  • 204.79.197.200
whitelisted
d2qvtfnm75xrxf.cloudfront.net
  • 52.222.168.230
  • 52.222.168.182
  • 52.222.168.169
  • 52.222.168.47
whitelisted
html5shim.googlecode.com
  • 74.125.206.82
whitelisted
fonts.googleapis.com
  • 216.58.207.42
whitelisted
d2wy8f7a9ursnm.cloudfront.net
  • 143.204.98.5
  • 143.204.98.104
  • 143.204.98.83
  • 143.204.98.157
shared
fonts.gstatic.com
  • 172.217.22.35
whitelisted
cdn.segment.com
  • 52.222.172.226
shared
sessions.bugsnag.com
  • 35.190.88.7
shared
widget.intercom.io
  • 52.85.183.2
  • 52.85.183.202
  • 52.85.183.93
  • 52.85.183.196
shared

Threats

No threats detected
No debug info