analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
download:

l.php

Full analysis: https://app.any.run/tasks/0bb84e18-da71-4897-a219-3d2adf785d3c
Verdict: Malicious activity
Analysis date: August 25, 2019, 21:12:34
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: text/html
File info: HTML document, UTF-8 Unicode text, with very long lines
MD5:

4F043AA9FDABEA728F796E4BE50282A2

SHA1:

0FBBF219CD471E23433197358C57EA1A5A76900F

SHA256:

7814FEE07A82DF798EDB82CD0591E9E95234FD0E8516DBD40989E69375479049

SSDEEP:

1536:H+jMl6kB4CRD6r0wK/tL3FBACscYd7s9KlzDgBEFLzicMpoJgFz5:H2S/BLAb7sUDLFLzizB

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Starts Internet Explorer

      • rundll32.exe (PID: 2872)
    • Executed via COM

      • FlashUtil32_26_0_0_131_ActiveX.exe (PID: 3848)
  • INFO

    • Changes internet zones settings

      • iexplore.exe (PID: 3020)
      • iexplore.exe (PID: 1264)
    • Application launched itself

      • iexplore.exe (PID: 1264)
      • iexplore.exe (PID: 3020)
    • Reads internet explorer settings

      • iexplore.exe (PID: 3964)
    • Reads Internet Cache Settings

      • iexplore.exe (PID: 3552)
      • iexplore.exe (PID: 3964)
    • Reads settings of System Certificates

      • iexplore.exe (PID: 1264)
      • iexplore.exe (PID: 3964)
    • Creates files in the user directory

      • iexplore.exe (PID: 3964)
      • FlashUtil32_26_0_0_131_ActiveX.exe (PID: 3848)
    • Changes settings of System certificates

      • iexplore.exe (PID: 1264)
    • Dropped object may contain Bitcoin addresses

      • iexplore.exe (PID: 3964)
    • Adds / modifies Windows certificates

      • iexplore.exe (PID: 1264)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.html | HyperText Markup Language (100)

EXIF

HTML

Title: Link geblokkeerd
msapplicationTask: name=Vrienden;action-uri=/?sk=fr;icon-uri=/images/icons/app/friends.ico
msapplicationWindow: width=1230;height=700
msapplicationStarturl: /
msapplicationTooltip: Bezoek facebook om op de hoogte te blijven van je vrienden
applicationName: Facebook
referrer: default
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
39
Monitored processes
6
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start rundll32.exe no specs iexplore.exe iexplore.exe iexplore.exe iexplore.exe no specs flashutil32_26_0_0_131_activex.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2872"C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\AppData\Local\Temp\l.phpC:\Windows\system32\rundll32.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
1264"C:\Program Files\Internet Explorer\iexplore.exe" -nohomeC:\Program Files\Internet Explorer\iexplore.exe
rundll32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
3020"C:\Program Files\Internet Explorer\iexplore.exe" -nohomeC:\Program Files\Internet Explorer\iexplore.exe
rundll32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
3964"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:1264 CREDAT:71937C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
3552"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3020 CREDAT:71937C:\Program Files\Internet Explorer\iexplore.exeiexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
3848C:\Windows\system32\Macromed\Flash\FlashUtil32_26_0_0_131_ActiveX.exe -EmbeddingC:\Windows\system32\Macromed\Flash\FlashUtil32_26_0_0_131_ActiveX.exesvchost.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
MEDIUM
Description:
Adobe® Flash® Player Installer/Uninstaller 26.0 r0
Version:
26,0,0,131
Total events
813
Read events
677
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
5
Text files
131
Unknown types
18

Dropped files

PID
Process
Filename
Type
3020iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\favicon[1].ico
MD5:
SHA256:
3020iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
MD5:
SHA256:
1264iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\favicon[1].ico
MD5:
SHA256:
1264iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
MD5:
SHA256:
3964iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\admin@bing[2].txt
MD5:
SHA256:
3964iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\N4JRGM9L\search[1].txt
MD5:
SHA256:
3964iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\History\Low\History.IE5\index.datdat
MD5:00F36BDE775CED4740F293C3DC1F3185
SHA256:EB72BD3DC4C36EEE3306F7A356D67B0FB1F498546E73249268B103AB1C2C70F2
3964iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\index.datdat
MD5:EE66035A400E77243B53E7D3E19B90D2
SHA256:BF1B2FE52DFF9C7D6CFDE7FF0A79F2EF2806FC1379DAACD787565D7CF4A2D217
3964iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\D4P4HRVR\th[1].jpgimage
MD5:B98E71A78916AF61CCFD66422F2735DD
SHA256:16E0F42A9F288F2D4696ACAC68CE21697617509A7F46DB7D842FB0A150A9DFB8
3964iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\index.datdat
MD5:AE4DF280699497BD76C181F62887DB5B
SHA256:7C847CF2DA225C39DC4657CA7D924CA9F8FCA5E11D008F0A58FA2FF203CDE516
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
89
DNS requests
29
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3964
iexplore.exe
GET
301
2.16.186.27:80
http://shell.windows.com/fileassoc/fileassoc.asp?Ext=php
unknown
whitelisted
3964
iexplore.exe
GET
200
8.248.117.254:80
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
US
compressed
56.6 Kb
whitelisted
3964
iexplore.exe
GET
302
2.19.38.59:80
http://go.microsoft.com/fwlink/?LinkId=57426&Ext=php
unknown
whitelisted
3964
iexplore.exe
GET
301
162.209.30.134:80
http://www.zend.com/en/products/studio/downloads-studio
US
html
264 b
whitelisted
1264
iexplore.exe
GET
200
204.79.197.200:80
http://www.bing.com/favicon.ico
US
image
237 b
whitelisted
3020
iexplore.exe
GET
200
204.79.197.200:80
http://www.bing.com/favicon.ico
US
image
237 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3964
iexplore.exe
204.79.197.200:443
www.bing.com
Microsoft Corporation
US
whitelisted
3020
iexplore.exe
204.79.197.200:80
www.bing.com
Microsoft Corporation
US
whitelisted
3964
iexplore.exe
2.19.38.59:80
go.microsoft.com
Akamai International B.V.
whitelisted
1264
iexplore.exe
204.79.197.200:443
www.bing.com
Microsoft Corporation
US
whitelisted
1264
iexplore.exe
204.79.197.200:80
www.bing.com
Microsoft Corporation
US
whitelisted
3964
iexplore.exe
2.16.186.27:80
shell.windows.com
Akamai International B.V.
whitelisted
3964
iexplore.exe
162.209.30.134:443
www.zend.com
Rackspace Ltd.
US
unknown
3964
iexplore.exe
172.217.16.138:443
fonts.googleapis.com
Google Inc.
US
whitelisted
3964
iexplore.exe
23.111.8.154:443
oss.maxcdn.com
netDNA
US
unknown
3964
iexplore.exe
162.209.30.134:80
www.zend.com
Rackspace Ltd.
US
unknown

DNS requests

Domain
IP
Reputation
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
go.microsoft.com
  • 2.19.38.59
whitelisted
shell.windows.com
  • 2.16.186.27
  • 2.16.186.24
whitelisted
www.zend.com
  • 162.209.30.134
whitelisted
login.live.com
  • 40.90.137.124
  • 40.90.23.153
  • 40.90.137.120
whitelisted
cdn-mktg.roguewave.com
  • 152.195.34.251
suspicious
fonts.googleapis.com
  • 172.217.16.138
whitelisted
oss.maxcdn.com
  • 23.111.8.154
whitelisted
www.googletagmanager.com
  • 172.217.16.168
whitelisted
ssl.google-analytics.com
  • 172.217.22.40
whitelisted

Threats

No threats detected
No debug info