URL:

sb.scorecardresearch.com

Full analysis: https://app.any.run/tasks/b670e9d5-d4b9-4b86-9ef1-777912c143bb
Verdict: Malicious activity
Analysis date: October 05, 2023, 21:54:09
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

0F32C08932A94494278DC96A1D4D2F7F

SHA1:

6F0CA09CDC147FB0066345014E5AD1D684FDACB1

SHA256:

6F62302CF04D24CF01BB6C7570B30259C8AA985291D8F46C954B706894A02E5C

SSDEEP:

3:3aRA+v:KRp

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • msdt.exe (PID: 3632)
    • Process uses IPCONFIG to discover network configuration

      • sdiagnhost.exe (PID: 3472)
    • Reads the Internet Settings

      • sdiagnhost.exe (PID: 3472)
      • msdt.exe (PID: 3632)
    • Uses ROUTE.EXE to obtain the routing table information

      • sdiagnhost.exe (PID: 3472)
    • Reads settings of System Certificates

      • msdt.exe (PID: 3632)
    • Reads Microsoft Outlook installation path

      • msdt.exe (PID: 3632)
    • Reads Internet Explorer settings

      • msdt.exe (PID: 3632)
  • INFO

    • Create files in a temporary directory

      • msdt.exe (PID: 3632)
      • sdiagnhost.exe (PID: 3472)
      • makecab.exe (PID: 2972)
    • Reads security settings of Internet Explorer

      • msdt.exe (PID: 3632)
      • sdiagnhost.exe (PID: 3472)
    • Drops the executable file immediately after the start

      • msdt.exe (PID: 3632)
    • Creates files or folders in the user directory

      • msdt.exe (PID: 3632)
    • Application launched itself

      • iexplore.exe (PID: 292)
    • Checks proxy server information

      • msdt.exe (PID: 3632)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
44
Monitored processes
7
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe msdt.exe no specs sdiagnhost.exe no specs ipconfig.exe no specs route.exe no specs makecab.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
292"C:\Program Files\Internet Explorer\iexplore.exe" "sb.scorecardresearch.com"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2972"C:\Windows\system32\makecab.exe" /f NetworkConfiguration.ddfC:\Windows\System32\makecab.exesdiagnhost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft® Cabinet Maker
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\makecab.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3388"C:\Windows\system32\ipconfig.exe" /allC:\Windows\System32\ipconfig.exesdiagnhost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
IP Configuration Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ipconfig.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\ws2_32.dll
3456"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:292 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
3472C:\Windows\System32\sdiagnhost.exe -EmbeddingC:\Windows\System32\sdiagnhost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Scripted Diagnostics Native Host
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sdiagnhost.exe
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\ole32.dll
3632 -modal 786850 -skip TRUE -path C:\Windows\diagnostics\system\networking -af C:\Users\admin\AppData\Local\Temp\NDF9D54.tmp -ep NetworkDiagnosticsWebC:\Windows\System32\msdt.exeiexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Diagnostics Troubleshooting Wizard
Exit code:
2
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msdt.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3984"C:\Windows\system32\ROUTE.EXE" printC:\Windows\System32\ROUTE.EXEsdiagnhost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
TCP/IP Route Command
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\route.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
Total events
20 687
Read events
20 570
Write events
117
Delete events
0

Modification events

(PID) Process:(292) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
0
(PID) Process:(292) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30847387
(PID) Process:(292) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30847437
(PID) Process:(292) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(292) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(292) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(292) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(292) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(292) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(292) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
2
Suspicious files
61
Text files
71
Unknown types
0

Dropped files

PID
Process
Filename
Type
292iexplore.exeC:\Users\admin\AppData\Local\Temp\StructuredQuery.logtext
MD5:9879C3C3E4F4BED9B5354D759696DBAD
SHA256:2A44CAF42969FB02A126228A1141EBAE352111F82293D9FADCE0BC5782B29539
3456iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\TP9I3OHN.htmtext
MD5:D6E3E7A5D2A2B180545FB4DFCC8E682A
SHA256:6849A407CEA12656F14F523B015F1ECB5AC136326782D48891AFECED24359DAA
292iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6BADA8974A10C4BD62CC921D13E43B18_711ED44619924BA6DC33E69F97E7FF63binary
MD5:6173305AC24653302909F5CF051578A9
SHA256:6802FCCAE6AB9B981AB20A7D12CD39F391F2331BF423C088C4E75BF6A4DC0254
292iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6BADA8974A10C4BD62CC921D13E43B18_711ED44619924BA6DC33E69F97E7FF63binary
MD5:CE0B46526AB7714DA3AC3FD91CA108D8
SHA256:7E55A0F960F6F6A64E30E5C607D650EC0889019E4DE83A93AACC2F3D477867BF
292iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157compressed
MD5:1BFE591A4FE3D91B03CDF26EAACD8F89
SHA256:9CF94355051BF0F4A45724CA20D1CC02F76371B963AB7D1E38BD8997737B13D8
3456iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\80237EE4964FC9C409AAF55BF996A292_D46D6FA25B74360E1349F9015B5CCE53binary
MD5:132A22BB7444E9AF28C42C29F7854206
SHA256:8BF2634F54DBF2FE9E53A57C38BD22AB96CB9B5489C7256F5587D495E4FB55EF
292iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\favicon[1].icoimage
MD5:DA597791BE3B6E732F0BC8B20E38EE62
SHA256:5B2C34B3C4E8DD898B664DBA6C3786E2FF9869EFF55D673AA48361F11325ED07
3456iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\RM2KK0Q8.txttext
MD5:3A17B3CED51E105B3B44F96D9785988C
SHA256:1A107EF4877A536E41273D512B670EE9261230B6EC86967AEF5DDEC3C0587D5B
3456iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\I2PIAW4R.txttext
MD5:873E80C1B894E790C22C29A85C335906
SHA256:76144CA3BAE7B1E53B90677A2B5E12D7B2A7979EE6BE031AB2527B7169CA3A38
3456iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\80237EE4964FC9C409AAF55BF996A292_D46D6FA25B74360E1349F9015B5CCE53binary
MD5:5BA2625E460378FD6AFB3C56A6EE6CFF
SHA256:C1E86B1C7551FCF158ED0C804C89539FE605C10A72FC7A0E22A7131B248561DD
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
19
TCP/UDP connections
32
DNS requests
28
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3456
iexplore.exe
GET
165.193.78.252:80
http://www.scorecardresearch.com/
unknown
unknown
3456
iexplore.exe
GET
99.84.88.43:80
http://sb.scorecardresearch.com/
unknown
unknown
3456
iexplore.exe
GET
304
99.84.88.43:80
http://sb.scorecardresearch.com/
unknown
unknown
3456
iexplore.exe
GET
304
99.84.88.43:80
http://sb.scorecardresearch.com/
unknown
unknown
3456
iexplore.exe
GET
304
99.84.88.43:80
http://sb.scorecardresearch.com/
unknown
unknown
3456
iexplore.exe
GET
304
99.84.88.43:80
http://sb.scorecardresearch.com/
unknown
unknown
292
iexplore.exe
GET
404
99.84.88.43:80
http://sb.scorecardresearch.com/favicon.ico
unknown
xml
314 b
unknown
292
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA8Ull8gIGmZT9XHrHiJQeI%3D
unknown
binary
1.47 Kb
unknown
3456
iexplore.exe
GET
200
99.84.88.43:80
http://sb.scorecardresearch.com/
unknown
text
79 b
unknown
292
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
binary
471 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
3456
iexplore.exe
99.84.88.43:80
sb.scorecardresearch.com
AMAZON-02
US
unknown
292
iexplore.exe
99.84.88.43:80
sb.scorecardresearch.com
AMAZON-02
US
unknown
2656
svchost.exe
239.255.255.250:1900
whitelisted
292
iexplore.exe
104.126.37.137:443
www.bing.com
Akamai International B.V.
DE
unknown
292
iexplore.exe
209.197.3.8:80
ctldl.windowsupdate.com
STACKPATH-CDN
US
whitelisted
292
iexplore.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
3456
iexplore.exe
13.107.5.80:443
api.bing.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3456
iexplore.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
3456
iexplore.exe
165.193.78.252:80
www.scorecardresearch.com
CENTURYLINK-LEGACY-SAVVIS
US
unknown

DNS requests

Domain
IP
Reputation
sb.scorecardresearch.com
  • 99.84.88.43
  • 99.84.88.22
  • 99.84.88.85
  • 99.84.88.4
shared
api.bing.com
  • 13.107.5.80
whitelisted
www.bing.com
  • 104.126.37.137
  • 104.126.37.171
  • 104.126.37.128
  • 104.126.37.176
  • 104.126.37.144
  • 104.126.37.163
  • 104.126.37.136
  • 104.126.37.155
  • 104.126.37.153
  • 23.53.43.115
  • 23.53.43.121
whitelisted
ctldl.windowsupdate.com
  • 209.197.3.8
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
www.scorecardresearch.com
  • 165.193.78.252
unknown
iecvlist.microsoft.com
  • 152.199.19.161
whitelisted
r20swj13mr.microsoft.com
  • 152.199.19.161
whitelisted
dns.msftncsi.com
  • 131.107.255.255
shared
ieonline.microsoft.com
  • 204.79.197.200
whitelisted

Threats

Found threats are available for the paid subscriptions
2 ETPRO signatures available at the full report
No debug info