analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
URL:

https://www28.zippyshare.com/v/WKbo2Sx9/file.html

Full analysis: https://app.any.run/tasks/78630c21-ed0c-4e76-9798-8e80bafcb9ff
Verdict: Malicious activity
Analysis date: October 14, 2021, 13:20:04
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

DE12137B5A4670C0D15597AE7C223901

SHA1:

13A32AE951BB24FEEC858BE54CA8540222F2A0A8

SHA256:

6CA41ADB34420FD86B9988B39C0B4C9DCAA500FA2B25C69E32A94BD244D19954

SSDEEP:

3:N8DSXqZGKjK9qX6cKDMJAwJ:2OXmGj9s6cYMFJ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads Microsoft Outlook installation path

      • iexplore.exe (PID: 3644)
      • iexplore.exe (PID: 632)
    • Checks supported languages

      • FlashUtil32_32_0_0_453_ActiveX.exe (PID: 3816)
      • WinRAR.exe (PID: 2992)
    • Reads the computer name

      • FlashUtil32_32_0_0_453_ActiveX.exe (PID: 3816)
      • WinRAR.exe (PID: 2992)
    • Executed via COM

      • FlashUtil32_32_0_0_453_ActiveX.exe (PID: 3816)
    • Creates files in the user directory

      • FlashUtil32_32_0_0_453_ActiveX.exe (PID: 3816)
  • INFO

    • Checks supported languages

      • iexplore.exe (PID: 1372)
      • iexplore.exe (PID: 3644)
      • iexplore.exe (PID: 632)
    • Reads the computer name

      • iexplore.exe (PID: 1372)
      • iexplore.exe (PID: 3644)
      • iexplore.exe (PID: 632)
    • Reads settings of System Certificates

      • iexplore.exe (PID: 1372)
      • iexplore.exe (PID: 3644)
      • iexplore.exe (PID: 632)
    • Reads internet explorer settings

      • iexplore.exe (PID: 3644)
      • iexplore.exe (PID: 632)
    • Changes internet zones settings

      • iexplore.exe (PID: 1372)
    • Creates files in the user directory

      • iexplore.exe (PID: 3644)
      • iexplore.exe (PID: 632)
    • Application launched itself

      • iexplore.exe (PID: 1372)
    • Checks Windows Trust Settings

      • iexplore.exe (PID: 1372)
      • iexplore.exe (PID: 3644)
      • iexplore.exe (PID: 632)
    • Modifies the phishing filter of IE

      • iexplore.exe (PID: 1372)
    • Reads CPU info

      • iexplore.exe (PID: 3644)
    • Changes settings of System certificates

      • iexplore.exe (PID: 1372)
    • Adds / modifies Windows certificates

      • iexplore.exe (PID: 1372)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
41
Monitored processes
5
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe flashutil32_32_0_0_453_activex.exe no specs winrar.exe no specs iexplore.exe

Process information

PID
CMD
Path
Indicators
Parent process
1372"C:\Program Files\Internet Explorer\iexplore.exe" "https://www28.zippyshare.com/v/WKbo2Sx9/file.html"C:\Program Files\Internet Explorer\iexplore.exe
Explorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\version.dll
c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
3644"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:1372 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
3816C:\Windows\system32\Macromed\Flash\FlashUtil32_32_0_0_453_ActiveX.exe -EmbeddingC:\Windows\system32\Macromed\Flash\FlashUtil32_32_0_0_453_ActiveX.exesvchost.exe
User:
admin
Company:
Adobe
Integrity Level:
MEDIUM
Description:
Adobe� Flash� Player Installer/Uninstaller 32.0 r0
Version:
32,0,0,453
Modules
Images
c:\windows\system32\macromed\flash\flashutil32_32_0_0_453_activex.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2992"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\The.Forest.Steamworks.Fix.V7-REVOLT.rar"C:\Program Files\WinRAR\WinRAR.exeiexplore.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
632"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:1372 CREDAT:2692396 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
Total events
28 652
Read events
28 444
Write events
204
Delete events
4

Modification events

(PID) Process:(1372) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
1
(PID) Process:(1372) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchLowDateTime
Value:
889774848
(PID) Process:(1372) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30916862
(PID) Process:(1372) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateLowDateTime
Value:
(PID) Process:(1372) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30916862
(PID) Process:(1372) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(1372) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(1372) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(1372) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(1372) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
0
Suspicious files
37
Text files
65
Unknown types
38

Dropped files

PID
Process
Filename
Type
3644iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7423F88C7F265F0DEFC08EA88C3BDE45_D975BBA8033175C8D112023D8A7A8AD6binary
MD5:C4BFE9CDEC1A4A00EE9B840EF4EBA5B8
SHA256:8A3C776DBC61D8664F939A52D68B125839F8C4015CD8F898064F40E4BFEA762A
3644iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B2FAF7692FD9FFBD64EDE317E42334BA_D7393C8F62BDE4D4CB606228BC7A711Ebinary
MD5:29630F5C30639A3E12303F31F777D6ED
SHA256:D08C3697B037660E5AD5FCE63525F19D218FB0A7C9C82231B0C110428FCDAA5D
3644iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\sw[1].jstext
MD5:D2BBDC37A9EFFB0E85D055AE1BFC5A00
SHA256:4958E1EA3A29551F08C6FFC404AD0DA6EA8B96DE227C30F7211BBA6612EF9166
3644iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EAder
MD5:4EDB698D4052FCEF408116ED14BF9D03
SHA256:4B1920C84008F1B47B9587E11713C1A61B92334109F2A2278C9B75ED4DBE0BC7
1372iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:08891A7416EEB879F3F2DE6D07BA77EB
SHA256:9A26F716C75E7484AE387FAABD630DD37054D88C4D5AB4126866BFAD509A5CA4
3644iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\6Q7FYZHO.txttext
MD5:29E2D2701FF764526E73D69BB1E6056A
SHA256:A4AAE3FC353F3B8522D54BA7878D202F000F94B444BD5A4924F2800F0FF33327
3644iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\BC570EC0DE58335AFAF92FDC8E3AA330_D21CA3FA19E2494154CA1B3726B54309der
MD5:87D5130698B7E4B013B8E2E1B76E0C4B
SHA256:61249810CAAB1A53BA820ED16617739767782DF9FF56E95481CCB8C8EA0A5072
1372iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6BADA8974A10C4BD62CC921D13E43B18_1DC6D7385EA816C957BA2B715AC5C442binary
MD5:97A7DADC290C93C39DE71701B3F96161
SHA256:169E4E500C59069EA03949B0167F3ADC7D76F390D0D859D29F413E5D50710FDB
3644iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\viewjs-9c29d4e653e865831dc028fdac7e7dfff3be049e[1].csstext
MD5:888A26F04004D6F52FD5BBB5CAB8E901
SHA256:A6FF735A4F50CC9779C3B25BE4244744C915E1BFD475238E73D7FB2239150762
3644iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\ads[1].jstext
MD5:70717EDDD4B8807212F231DDDF9FB11C
SHA256:CF043C6297FFCCED765795CF0EF36F2A516C026079CDBE00CE342C6002740550
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
32
TCP/UDP connections
111
DNS requests
47
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3644
iexplore.exe
GET
200
151.139.128.14:80
http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEDlyRDr5IrdR19NsEN0xNZU%3D
US
der
471 b
whitelisted
1372
iexplore.exe
GET
200
209.197.3.8:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?bc92db3941461371
US
compressed
4.70 Kb
whitelisted
3644
iexplore.exe
GET
200
104.18.21.226:80
http://ocsp2.globalsign.com/gsalphasha2g2/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBSE1Wv4CYvTB7dm2OHrrWWWqmtnYQQU9c3VPAhQ%2BWpPOreX2laD5mnSaPcCDAQ2J002vedADHR8qQ%3D%3D
US
der
1.40 Kb
whitelisted
1372
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA%2BnRyLFPYjID1ie%2Bx%2BdSjo%3D
US
der
1.47 Kb
whitelisted
3644
iexplore.exe
GET
200
142.250.185.195:80
http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFNZazTHGPUBUGY%3D
US
der
724 b
whitelisted
3644
iexplore.exe
GET
200
143.204.101.123:80
http://o.ss2.us//MEowSDBGMEQwQjAJBgUrDgMCGgUABBSLwZ6EW5gdYc9UaSEaaLjjETNtkAQUv1%2B30c7dH4b0W1Ws3NcQwg6piOcCCQCnDkpMNIK3fw%3D%3D
US
der
1.70 Kb
whitelisted
3644
iexplore.exe
GET
200
104.18.20.226:80
http://crl.globalsign.net/root.crl
US
der
1.61 Kb
whitelisted
3644
iexplore.exe
GET
200
142.250.185.195:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
US
der
1.41 Kb
whitelisted
3644
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAH9o%2BtuynXIiEOLckvPvJE%3D
US
der
471 b
whitelisted
3644
iexplore.exe
GET
200
209.197.3.8:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?da27b9412a7b5554
US
compressed
4.70 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1372
iexplore.exe
204.79.197.200:443
www.bing.com
Microsoft Corporation
US
whitelisted
3644
iexplore.exe
209.197.3.8:80
ctldl.windowsupdate.com
Highwinds Network Group, Inc.
US
whitelisted
1372
iexplore.exe
209.197.3.8:80
ctldl.windowsupdate.com
Highwinds Network Group, Inc.
US
whitelisted
1936
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
Microsoft Corporation
GB
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
Microsoft Corporation
GB
whitelisted
3644
iexplore.exe
104.18.21.226:80
ocsp.globalsign.com
Cloudflare Inc
US
shared
3644
iexplore.exe
46.166.139.185:443
www28.zippyshare.com
NForce Entertainment B.V.
NL
unknown
104.18.20.226:80
ocsp.globalsign.com
Cloudflare Inc
US
shared
1372
iexplore.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
46.166.139.185:443
www28.zippyshare.com
NForce Entertainment B.V.
NL
unknown

DNS requests

Domain
IP
Reputation
www28.zippyshare.com
  • 46.166.139.185
suspicious
ctldl.windowsupdate.com
  • 209.197.3.8
whitelisted
api.bing.com
  • 13.107.5.80
whitelisted
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
ocsp.digicert.com
  • 93.184.220.29
whitelisted
ocsp.globalsign.com
  • 104.18.21.226
  • 104.18.20.226
whitelisted
crl.globalsign.net
  • 104.18.20.226
  • 104.18.21.226
whitelisted
ocsp2.globalsign.com
  • 104.18.21.226
  • 104.18.20.226
whitelisted
crl2.alphassl.com
  • 104.18.21.226
  • 104.18.20.226
whitelisted
settings-win.data.microsoft.com
  • 51.124.78.146
whitelisted

Threats

No threats detected
No debug info