URL:

https://www.maybank2u.com.my/home/m2u/common/login.do

Full analysis: https://app.any.run/tasks/47ccba56-ce5f-406f-9ed2-283d2980a8ab
Verdict: Malicious activity
Analysis date: February 20, 2020, 06:39:54
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

6F8C15AFF2460DA6C8613016148ECCDA

SHA1:

36CAFE624A226BB4744C3A6E92B49646D2ABDFA4

SHA256:

675E17A8284F9521100FE66DA952359C7566099681D6044E667BDFD21B01670F

SSDEEP:

3:N8DSLt6XacaQAKGtEn:2OLCHAde

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Changes internet zones settings

      • iexplore.exe (PID: 3000)
    • Application launched itself

      • iexplore.exe (PID: 3000)
    • Reads internet explorer settings

      • iexplore.exe (PID: 952)
    • Reads Internet Cache Settings

      • iexplore.exe (PID: 3000)
      • iexplore.exe (PID: 952)
    • Dropped object may contain Bitcoin addresses

      • iexplore.exe (PID: 952)
    • Creates files in the user directory

      • iexplore.exe (PID: 952)
    • Reads settings of System Certificates

      • iexplore.exe (PID: 952)
      • iexplore.exe (PID: 3000)
    • Adds / modifies Windows certificates

      • iexplore.exe (PID: 3000)
    • Changes settings of System certificates

      • iexplore.exe (PID: 3000)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
36
Monitored processes
2
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe

Process information

PID
CMD
Path
Indicators
Parent process
952"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3000 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
3000"C:\Program Files\Internet Explorer\iexplore.exe" https://www.maybank2u.com.my/home/m2u/common/login.doC:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
Total events
8 734
Read events
852
Write events
5 864
Delete events
2 018

Modification events

(PID) Process:(3000) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateLowDateTime
Value:
2849416116
(PID) Process:(3000) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30795704
(PID) Process:(3000) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(3000) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3000) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3000) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(3000) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(3000) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
46000000A1000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
(PID) Process:(3000) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(3000) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
Executable files
0
Suspicious files
63
Text files
625
Unknown types
71

Dropped files

PID
Process
Filename
Type
952iexplore.exeC:\Users\admin\AppData\Local\Temp\Low\Cab6F9A.tmp
MD5:
SHA256:
952iexplore.exeC:\Users\admin\AppData\Local\Temp\Low\Tar6F9B.tmp
MD5:
SHA256:
952iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\EDC238BFF48A31D55A97E1E93892934B_C31B2498754E340573F1336DE607D619der
MD5:0170EA75F086F81E4E938E6E1A4657B8
SHA256:13021AD35F79246E32E615F4C755BD5F714DA7503FEF991EE1483CBDBE9BD2B3
952iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\BE8B021F9E811DFC8C8A28572A17C05A_C3E8F839857C434632DE6B1487BCD396der
MD5:F0B026D39D3ED7A1E854A59C8E01CF61
SHA256:D79E33D3789AB5E6268C85ABDC5B1879E73A61E7F24356E3F3E7C643E105F7C0
952iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\login[1].htmhtml
MD5:90F5D1C50233636BED50318CBBF315C9
SHA256:7D15A453DEECE992AF433106202262F3479170D03E23DB75A54AD1EB52498124
952iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\BSTVR2RZ.txt
MD5:
SHA256:
952iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\teamsite-style[1].csstext
MD5:2614C0429594ADC36ADDC396B7DD7614
SHA256:B015F9BB0F4EAD9395610B6E2543AE3C52FD32C4AD42C0A5F5194488188F9E4C
952iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\logo_60_white[1].pngimage
MD5:AE7B79C58EAF30B2F002217DF506A721
SHA256:06B603801E8EF3BDFDEC7FDA6A1A54DB4B5AADAE47C0386D5785F80EE63CA7B4
952iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\BE8B021F9E811DFC8C8A28572A17C05A_C3E8F839857C434632DE6B1487BCD396binary
MD5:7FFD237D9E470E2C7F92E1C049941DC2
SHA256:9B6B3A28D97AF8663E1645EA3D4690B217643B11E3E45B21C09D9036C235BA33
952iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\BE8B021F9E811DFC8C8A28572A17C05A_E14D75834C87262DB510C3528B248A7Abinary
MD5:C68E5588621A2F9D84187B7DB7870114
SHA256:2855FEDD555B8DF606A649D37A2687753B761D9DD27F7092BA208BB80C512A37
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
35
TCP/UDP connections
95
DNS requests
34
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
952
iexplore.exe
GET
200
172.217.22.67:80
http://ocsp.pki.goog/gts1o1/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBRCRjDCJxnb3nDwj%2Fxz5aZfZjgXvAQUmNH4bhDrz5vsYJ8YkBug630J%2FSsCEQDx9it%2Fyk0DxwgAAAAALC4g
US
der
472 b
whitelisted
952
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEAx5qUSwjBGVIJJhX%2BJrHYM%3D
US
der
471 b
whitelisted
952
iexplore.exe
GET
200
172.217.22.67:80
http://ocsp.pki.goog/gsr2/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBTgXIsxbvr2lBkPpoIEVRE6gHlCnAQUm%2BIHV2ccHsBqBt5ZtJot39wZhi4CDQHjtJqhjYqpgSVpULg%3D
US
der
468 b
whitelisted
952
iexplore.exe
GET
200
172.217.22.67:80
http://ocsp.pki.goog/gts1o1/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBRCRjDCJxnb3nDwj%2Fxz5aZfZjgXvAQUmNH4bhDrz5vsYJ8YkBug630J%2FSsCEQDSvQckbIyHmwgAAAAALC4h
US
der
472 b
whitelisted
952
iexplore.exe
GET
200
172.217.22.67:80
http://ocsp.pki.goog/gts1o1/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBRCRjDCJxnb3nDwj%2Fxz5aZfZjgXvAQUmNH4bhDrz5vsYJ8YkBug630J%2FSsCEQDx9it%2Fyk0DxwgAAAAALC4g
US
der
472 b
whitelisted
952
iexplore.exe
GET
200
172.217.22.67:80
http://ocsp.pki.goog/gts1o1/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBRCRjDCJxnb3nDwj%2Fxz5aZfZjgXvAQUmNH4bhDrz5vsYJ8YkBug630J%2FSsCEQDhKaVxWCYaNQgAAAAALC5%2B
US
der
472 b
whitelisted
952
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEAx5qUSwjBGVIJJhX%2BJrHYM%3D
US
der
471 b
whitelisted
952
iexplore.exe
GET
200
172.217.22.67:80
http://ocsp.pki.goog/gts1o1/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBRCRjDCJxnb3nDwj%2Fxz5aZfZjgXvAQUmNH4bhDrz5vsYJ8YkBug630J%2FSsCEQDSvQckbIyHmwgAAAAALC4h
US
der
472 b
whitelisted
952
iexplore.exe
GET
200
172.217.22.67:80
http://ocsp.pki.goog/gts1o1/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBRCRjDCJxnb3nDwj%2Fxz5aZfZjgXvAQUmNH4bhDrz5vsYJ8YkBug630J%2FSsCEQDx9it%2Fyk0DxwgAAAAALC4g
US
der
472 b
whitelisted
952
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA%2Fz5hY5qj0aEmX0H4s05bY%3D
US
der
1.47 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
952
iexplore.exe
23.45.103.188:443
www.maybank2u.com.my
Akamai International B.V.
NL
unknown
952
iexplore.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
952
iexplore.exe
172.217.22.106:443
fonts.googleapis.com
Google Inc.
US
whitelisted
952
iexplore.exe
172.217.22.67:80
ocsp.pki.goog
Google Inc.
US
whitelisted
952
iexplore.exe
172.217.18.110:443
www.google-analytics.com
Google Inc.
US
whitelisted
952
iexplore.exe
172.217.18.8:443
www.googletagmanager.com
Google Inc.
US
whitelisted
952
iexplore.exe
157.240.20.19:443
connect.facebook.net
Facebook, Inc.
US
whitelisted
952
iexplore.exe
104.17.168.114:443
maybank2u.api.useinsider.com
Cloudflare Inc
US
shared
952
iexplore.exe
172.217.18.2:443
securepubads.g.doubleclick.net
Google Inc.
US
whitelisted
952
iexplore.exe
52.222.156.44:443
tt.mbww.com
Amazon.com, Inc.
US
unknown

DNS requests

Domain
IP
Reputation
www.maybank2u.com.my
  • 23.45.103.188
suspicious
ocsp.digicert.com
  • 93.184.220.29
whitelisted
fonts.googleapis.com
  • 172.217.22.106
whitelisted
ocsp.pki.goog
  • 172.217.22.67
whitelisted
www.googletagmanager.com
  • 172.217.18.8
whitelisted
www.google-analytics.com
  • 172.217.18.110
whitelisted
securepubads.g.doubleclick.net
  • 172.217.18.2
whitelisted
connect.facebook.net
  • 157.240.20.19
whitelisted
maybank2u.api.useinsider.com
  • 104.17.168.114
  • 104.17.169.114
  • 104.17.171.114
  • 104.17.170.114
  • 104.17.167.114
unknown
tt.mbww.com
  • 52.222.156.44
whitelisted

Threats

No threats detected
No debug info