URL:

https://url.3u.com/zmAJjyaa

Full analysis: https://app.any.run/tasks/4e766fa8-fabe-4e35-b715-47f7579fdf99
Verdict: Malicious activity
Analysis date: December 17, 2023, 21:18:34
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

F9E9A82A89017A3C5FEDA89DF60209D2

SHA1:

CB4E76C4927F35271B1E1B4A034DA9FD7356408C

SHA256:

71B068CF63EEBA6D3AB6D7DD326C550482E26E8A270A1C3C2B12F4EE4A88D3E5

SSDEEP:

3:N8UiZGc:2US

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • 3uTools_v3.07.016_Setup_x86.exe (PID: 2624)
  • SUSPICIOUS

    • Drops 7-zip archiver for unpacking

      • 3uTools_v3.07.016_Setup_x86.exe (PID: 2624)
    • The process creates files with name similar to system file names

      • 3uTools_v3.07.016_Setup_x86.exe (PID: 2624)
    • Process drops legitimate windows executable

      • 3uTools_v3.07.016_Setup_x86.exe (PID: 2624)
    • The process drops C-runtime libraries

      • 3uTools_v3.07.016_Setup_x86.exe (PID: 2624)
    • Reads the Internet Settings

      • 3uTools_v3.07.016_Setup_x86.exe (PID: 2624)
    • Process requests binary or script from the Internet

      • 3uTools.exe (PID: 2404)
    • Reads settings of System Certificates

      • 3uTools.exe (PID: 2404)
  • INFO

    • Checks supported languages

      • 3uTools_v3.07.016_Setup_x86.exe (PID: 2624)
      • 3uTools.exe (PID: 2404)
      • 3uViewer.exe (PID: 3076)
      • 3uViewer.exe (PID: 884)
      • updater.exe (PID: 2788)
    • The process uses the downloaded file

      • iexplore.exe (PID: 128)
    • Reads the computer name

      • 3uTools_v3.07.016_Setup_x86.exe (PID: 2624)
      • 3uTools.exe (PID: 2404)
    • Application launched itself

      • iexplore.exe (PID: 128)
    • Drops the executable file immediately after the start

      • iexplore.exe (PID: 2032)
    • Creates files in the program directory

      • 3uTools_v3.07.016_Setup_x86.exe (PID: 2624)
      • 3uTools.exe (PID: 2404)
      • updater.exe (PID: 2788)
    • Create files in a temporary directory

      • 3uTools_v3.07.016_Setup_x86.exe (PID: 2624)
      • 3uTools.exe (PID: 2404)
    • Process checks computer location settings

      • 3uTools.exe (PID: 2404)
    • Reads the machine GUID from the registry

      • 3uTools.exe (PID: 2404)
    • Creates files or folders in the user directory

      • 3uTools.exe (PID: 2404)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
48
Monitored processes
8
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe 3utools_v3.07.016_setup_x86.exe no specs 3utools_v3.07.016_setup_x86.exe 3utools.exe updater.exe no specs 3uviewer.exe no specs 3uviewer.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
128"C:\Program Files\Internet Explorer\iexplore.exe" "https://url.3u.com/zmAJjyaa"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
1
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
8843uViewer.exe /reg 1C:\Program Files\3uToolsV3\x86\3uViewer.exe3uTools.exe
User:
admin
Company:
Shenzhen Aidapu Network Technology Co.,Ltd.
Integrity Level:
HIGH
Description:
Image Viewer
Exit code:
0
Version:
1.0.3.0
Modules
Images
c:\program files\3utoolsv3\x86\3uviewer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1636"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\3uTools_v3.07.016_Setup_x86.exe" C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\3uTools_v3.07.016_Setup_x86.exeiexplore.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\po2hn1x2\3utools_v3.07.016_setup_x86.exe
c:\windows\system32\ntdll.dll
2032"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:128 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2404"C:\Program Files\3uToolsV3\x86\3uTools.exe" C:\Program Files\3uToolsV3\x86\3uTools.exe
3uTools_v3.07.016_Setup_x86.exe
User:
admin
Company:
Shenzhen Aidapu Network Technology Co.,Ltd.
Integrity Level:
HIGH
Description:
3uTools
Exit code:
0
Version:
3.07.016.0
Modules
Images
c:\program files\3utoolsv3\x86\3utools.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\3utoolsv3\x86\qt5svg.dll
c:\program files\3utoolsv3\x86\qt5widgets.dll
c:\program files\3utoolsv3\x86\qt5gui.dll
c:\windows\system32\d3d11.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\dxgi.dll
2624"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\3uTools_v3.07.016_Setup_x86.exe" C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\3uTools_v3.07.016_Setup_x86.exe
iexplore.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\po2hn1x2\3utools_v3.07.016_setup_x86.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2788"C:\Program Files\3uToolsV3\x86\updater.exe" /backgroundC:\Program Files\3uToolsV3\x86\updater.exe3uTools.exe
User:
admin
Company:
Shenzhen Aidapu Network Technology Co.,Ltd.
Integrity Level:
HIGH
Exit code:
0
Version:
2.5.3.12
Modules
Images
c:\program files\3utoolsv3\x86\updater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
30763uViewer.exe /reg 2C:\Program Files\3uToolsV3\x86\3uViewer.exe3uTools.exe
User:
admin
Company:
Shenzhen Aidapu Network Technology Co.,Ltd.
Integrity Level:
HIGH
Description:
Image Viewer
Exit code:
0
Version:
1.0.3.0
Modules
Images
c:\program files\3utoolsv3\x86\3uviewer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
Total events
23 686
Read events
23 589
Write events
92
Delete events
5

Modification events

(PID) Process:(128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
0
(PID) Process:(128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30847387
(PID) Process:(128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30847437
(PID) Process:(128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
249
Suspicious files
265
Text files
184
Unknown types
0

Dropped files

PID
Process
Filename
Type
2032iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157compressed
MD5:1BFE591A4FE3D91B03CDF26EAACD8F89
SHA256:9CF94355051BF0F4A45724CA20D1CC02F76371B963AB7D1E38BD8997737B13D8
2032iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_C39E9DBC666D19C07EEE7CD1E11AF8BEbinary
MD5:16E7F367CA50E9A59AED7C2259AA4CEC
SHA256:C619BC085B819F99720AA0B41BA9C3A7599F42830BEEFE48096F9BAB8E7D1D1A
2032iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_C39E9DBC666D19C07EEE7CD1E11AF8BEbinary
MD5:23C7642547ECA4813C72D377187C80C0
SHA256:7E6D2785FAE4E3B7450113610912E04037F1D602A773B52CC68950490CE5A37D
2032iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\773CFF2C7835D48C4E76FE153DBA9F81_3690FC9D7760585F010DE1CBF8C9301Abinary
MD5:B33486AFC17C5C48A437C80A1D348E56
SHA256:E5573576179F2377082F1A63A7E377E4FE30EE12334975DCDF26277550F73412
2032iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\3uTools_v3.07.016_Setup_x86[1].exeexecutable
MD5:010FD08ECE1FB74DBFE6091710DA9082
SHA256:86C3AB32AD50E3B798F6E97B32B872647140002EDC7AE52E5AF288A394D32763
2032iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\773CFF2C7835D48C4E76FE153DBA9F81_3690FC9D7760585F010DE1CBF8C9301Ader
MD5:DC42D7A0F5E4AADF0D8269EBA7593606
SHA256:620DC6B96F48C23DC3C400E7AB5C3C35AC920783F67FA4BF72D8B03C0FB91A07
128iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\urlblockindex[1].binbinary
MD5:FA518E3DFAE8CA3A0E495460FD60C791
SHA256:775853600060162C4B4E5F883F9FD5A278E61C471B3EE1826396B6D129499AA7
128iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\OI2L818B.txttext
MD5:DE840F3C00EF04974C284C38A7C6F5DB
SHA256:5BDDEEC81458C257BA5E377DBD914E6646990C21142C099B7CF7D2FF8EA8D5F3
128iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\7ZRH1L7F.txttext
MD5:91066623AA2CC7C66F96E236A1B0F0B2
SHA256:2760684168EC727D38A5FA5541E083E0643AE8711CAB06FB9B20BBA63BF7930C
2032iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:D8383EDA6174F002E5794A0F57399EDC
SHA256:9D89E62F6DCD93AC4393445899B90FC2B2A0D1E7AA654299A58726C802140237
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
44
TCP/UDP connections
115
DNS requests
26
Threats
16

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2404
3uTools.exe
GET
200
138.113.27.176:80
http://d.updater.3u.com/3utools/configs/miscconfig/20230707u.txt
unknown
binary
735 b
unknown
128
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA177el9ggmWelJjG4vdGL0%3D
unknown
binary
471 b
unknown
2404
3uTools.exe
GET
200
138.113.27.176:80
http://d.updater.3u.com/3utools/configs/more_devices/devices_table_20231013u.txt
unknown
binary
15.6 Kb
unknown
2032
iexplore.exe
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?608cb4ab6d3f68d3
unknown
compressed
4.66 Kb
unknown
2032
iexplore.exe
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?f6bf34dbb61e71d7
unknown
compressed
4.66 Kb
unknown
2032
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAsllCLO2YEqFaBOmVKKDvo%3D
unknown
binary
471 b
unknown
2032
iexplore.exe
GET
200
192.229.221.95:80
http://status.rapidssl.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRJiUKgT2m88fZ4nxc1Lu6M%2FjvkagQUDNtsgkkPSmcKuBTuesRIUojrVjgCEA1qXQxIsG3D24I6MzQFQiw%3D
unknown
binary
471 b
unknown
128
iexplore.exe
GET
304
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?ed92cde4cb766a79
unknown
unknown
128
iexplore.exe
GET
304
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?a85e8d0c2f0a71a5
unknown
unknown
128
iexplore.exe
GET
304
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?fa4f1dfa99832483
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2032
iexplore.exe
163.171.132.42:443
url.3u.com
QUANTILNETWORKS
DE
unknown
4
System
192.168.100.255:138
whitelisted
2032
iexplore.exe
93.184.221.240:80
ctldl.windowsupdate.com
EDGECAST
GB
whitelisted
2032
iexplore.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
2032
iexplore.exe
185.23.181.28:443
dl.3u.com
Kaopu Cloud HK Limited
DE
unknown
128
iexplore.exe
152.199.19.161:443
iecvlist.microsoft.com
EDGECAST
US
whitelisted
128
iexplore.exe
93.184.221.240:80
ctldl.windowsupdate.com
EDGECAST
GB
whitelisted
1080
svchost.exe
93.184.221.240:80
ctldl.windowsupdate.com
EDGECAST
GB
whitelisted
128
iexplore.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
url.3u.com
  • 163.171.132.42
unknown
ctldl.windowsupdate.com
  • 93.184.221.240
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
status.rapidssl.com
  • 192.229.221.95
shared
dl.3u.com
  • 185.23.181.28
  • 185.23.181.26
unknown
iecvlist.microsoft.com
  • 152.199.19.161
whitelisted
r20swj13mr.microsoft.com
  • 152.199.19.161
whitelisted
ieonline.microsoft.com
  • 204.79.197.200
whitelisted
go.microsoft.com
  • 23.35.238.131
whitelisted
www.msn.com
  • 204.79.197.203
whitelisted

Threats

PID
Process
Class
Message
2404
3uTools.exe
Potentially Bad Traffic
ET HUNTING Double User-Agent (User-Agent User-Agent)
2404
3uTools.exe
Potentially Bad Traffic
ET HUNTING Double User-Agent (User-Agent User-Agent)
2404
3uTools.exe
Potentially Bad Traffic
ET HUNTING Double User-Agent (User-Agent User-Agent)
2404
3uTools.exe
Potentially Bad Traffic
ET HUNTING Double User-Agent (User-Agent User-Agent)
2404
3uTools.exe
Potentially Bad Traffic
ET HUNTING Double User-Agent (User-Agent User-Agent)
2404
3uTools.exe
Potentially Bad Traffic
ET HUNTING Double User-Agent (User-Agent User-Agent)
2404
3uTools.exe
Potentially Bad Traffic
ET HUNTING Double User-Agent (User-Agent User-Agent)
2404
3uTools.exe
Potentially Bad Traffic
ET HUNTING Double User-Agent (User-Agent User-Agent)
8 ETPRO signatures available at the full report
Process
Message
3uTools_v3.07.016_Setup_x86.exe
AdjustTokenPrivileges succed!
3uTools.exe
Failed to load opengl32sw.dll (The specified module could not be found.)
3uTools.exe
QWindowsEGLStaticContext::create: Could not initialize EGL display: error 0x3001
3uTools.exe
QWindowsEGLStaticContext::create: When using ANGLE, check if d3dcompiler_4x.dll is available
3uTools.exe
Failed to load and resolve WGL/OpenGL functions
3uTools.exe
Sandboxing disabled by user.
3uTools.exe
QWindowsEGLStaticContext::create: Could not initialize EGL display: error 0x3001
3uTools.exe
Failed to load opengl32sw.dll (The specified module could not be found.)
3uTools.exe
QWindowsEGLStaticContext::create: When using ANGLE, check if d3dcompiler_4x.dll is available
3uTools.exe
Failed to load and resolve WGL/OpenGL functions