analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
URL:

http://compart.com.br/re/SFExpress/805cfsqmk43o9d4rvxn8fxbv.php?rand=13InboxLightaspxn.1774256418&fid&1252899642&fid.1&fav.1&[email protected]

Full analysis: https://app.any.run/tasks/04536a5b-d892-4a64-87eb-c5afc3e511ca
Verdict: Malicious activity
Analysis date: September 30, 2020, 14:31:18
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

346F9AA4C6AF67B540C314F0E2908992

SHA1:

4894124422FC4D6B5017D7142E1B752C24C92ADA

SHA256:

6E2F384EFC0C7B2EF33EFF3FB937B4C5241937FBB29AFCD3BB5636FDC2FA98F5

SSDEEP:

3:N1KdKIu9KL8v2j4X6KAPUzRWfxHwUSULyf/mIEfMBIOcyTDM9aYTLLIE2Q8fL6MK:CIIuZE4RAs0eUSUWf/PEfM8yTDMk+L8Q

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Reads settings of System Certificates

      • iexplore.exe (PID: 2640)
    • Reads Internet Cache Settings

      • iexplore.exe (PID: 2640)
      • iexplore.exe (PID: 2452)
    • Application launched itself

      • iexplore.exe (PID: 2640)
    • Changes internet zones settings

      • iexplore.exe (PID: 2640)
    • Reads internet explorer settings

      • iexplore.exe (PID: 2452)
    • Creates files in the user directory

      • iexplore.exe (PID: 2640)
    • Adds / modifies Windows certificates

      • iexplore.exe (PID: 2640)
    • Changes settings of System certificates

      • iexplore.exe (PID: 2640)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
36
Monitored processes
2
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe

Process information

PID
CMD
Path
Indicators
Parent process
2640"C:\Program Files\Internet Explorer\iexplore.exe" http://compart.com.br/re/SFExpress/805cfsqmk43o9d4rvxn8fxbv.php?rand=13InboxLightaspxn.1774256418&fid&1252899642&fid.1&fav.1&[email protected]C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
2452"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2640 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Total events
630
Read events
547
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
13
Text files
13
Unknown types
6

Dropped files

PID
Process
Filename
Type
2640iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
MD5:
SHA256:
2640iexplore.exeC:\Users\admin\AppData\Local\Temp\Cab9DC8.tmp
MD5:
SHA256:
2640iexplore.exeC:\Users\admin\AppData\Local\Temp\Tar9DC9.tmp
MD5:
SHA256:
2640iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Internet Explorer\VersionManager\ver9E08.tmp
MD5:
SHA256:
2640iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\W1U5ZRYO.txt
MD5:
SHA256:
2640iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\USMAI4EH.txt
MD5:
SHA256:
2640iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6BADA8974A10C4BD62CC921D13E43B18_D9817BD5013875AD517DA73475345203binary
MD5:6153A7F55D26D6E351BF8C9C842AEF11
SHA256:EBBB97FE1A500D8DF6CC5CEA41CABE05AD544AC55D3FD109C7EED1BD863BF144
2452iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\foxmail_logo[1].gifimage
MD5:54035AD8B1DB3FA773638EC7961C7313
SHA256:4B3814ADA58754DAA7E2F161375D4924B2A36583E458D860268EA6E717A465B1
2452iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\805cfsqmk43o9d4rvxn8fxbv[1].htmhtml
MD5:548A11F9473868B9D4858A68C4D26EDC
SHA256:CDAE6D06BFD441729F41CB780693E954159B005975025DC717805ABD7721FD5C
2640iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\urlblockindex[1].binbinary
MD5:FA518E3DFAE8CA3A0E495460FD60C791
SHA256:775853600060162C4B4E5F883F9FD5A278E61C471B3EE1826396B6D129499AA7
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
17
TCP/UDP connections
26
DNS requests
15
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2640
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA8sEMlbBsCTf7jUSfg%2BhWk%3D
US
der
1.47 Kb
whitelisted
2452
iexplore.exe
GET
200
179.191.121.116:80
http://compart.com.br/re/SFExpress/805cfsqmk43o9d4rvxn8fxbv.php?rand=13InboxLightaspxn.1774256418&fid&1252899642&fid.1&fav.1&[email protected]
BR
html
3.20 Kb
unknown
2640
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA8sEMlbBsCTf7jUSfg%2BhWk%3D
US
der
1.47 Kb
whitelisted
2452
iexplore.exe
GET
200
179.191.121.116:80
http://compart.com.br/re/SFExpress/images/mailenable.png
BR
image
8.92 Kb
unknown
1052
svchost.exe
GET
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEAo3h2ReX7SMIk79G%2B0UDDw%3D
US
whitelisted
2452
iexplore.exe
GET
200
179.191.121.116:80
http://compart.com.br/re/SFExpress/images/foxmail_logo.gif
BR
image
1.80 Kb
unknown
2452
iexplore.exe
GET
200
179.191.121.116:80
http://compart.com.br/re/SFExpress/images/qqmail.jpg
BR
image
32.7 Kb
unknown
2640
iexplore.exe
GET
179.191.121.116:80
http://compart.com.br/favicon.ico
BR
unknown
2452
iexplore.exe
GET
200
179.191.121.116:80
http://compart.com.br/re/SFExpress/images/outlook.png
BR
image
4.98 Kb
unknown
2452
iexplore.exe
GET
200
179.191.121.116:80
http://compart.com.br/re/SFExpress/images/SFExpress.png
BR
image
7.88 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2640
iexplore.exe
204.79.197.200:80
www.bing.com
Microsoft Corporation
US
whitelisted
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
2640
iexplore.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
2640
iexplore.exe
152.199.19.161:443
iecvlist.microsoft.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
2452
iexplore.exe
179.191.121.116:80
compart.com.br
Mundivox LTDA
BR
unknown
2640
iexplore.exe
204.79.197.200:443
www.bing.com
Microsoft Corporation
US
whitelisted
2640
iexplore.exe
203.205.136.62:80
www.sf-express.com
Tencent Building, Kejizhongyi Avenue
CN
unknown
179.191.121.116:80
compart.com.br
Mundivox LTDA
BR
unknown
2640
iexplore.exe
203.205.136.62:443
www.sf-express.com
Tencent Building, Kejizhongyi Avenue
CN
unknown
2640
iexplore.exe
47.246.43.224:80
ocsp.dcocsp.cn
US
malicious

DNS requests

Domain
IP
Reputation
compart.com.br
  • 179.191.121.116
unknown
api.bing.com
  • 13.107.13.80
whitelisted
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
iecvlist.microsoft.com
  • 152.199.19.161
whitelisted
r20swj13mr.microsoft.com
  • 152.199.19.161
whitelisted
ocsp.digicert.com
  • 93.184.220.29
whitelisted
ieonline.microsoft.com
  • 204.79.197.200
whitelisted
www.sf-express.com
  • 203.205.136.62
  • 203.205.224.59
suspicious
ocsp.dcocsp.cn
  • 47.246.43.224
  • 47.246.43.225
  • 47.246.43.226
  • 47.246.43.227
  • 47.246.43.228
  • 47.246.43.229
  • 47.246.43.230
  • 47.246.43.223
whitelisted
crl3.digicert.com
  • 93.184.220.29
whitelisted

Threats

No threats detected
No debug info