analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
URL:

https://tgb.qq.com/en/games/pubg.html

Full analysis: https://app.any.run/tasks/8f5b7bcb-b483-4622-a782-b5a9ef5e1b96
Verdict: Malicious activity
Analysis date: August 06, 2019, 11:35:16
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

4A524E1800501A7EB4EE98D8AE953EDC

SHA1:

8082B01BA4B66CFB695F504E03846E3F296A9CAF

SHA256:

8CC3521D1CC0CC75F2009C0092CDDECCF83451728E4209F84C3B29548C13DDE2

SSDEEP:

3:N8KHLUULm+CEzjLUJ:2KrUN+HjUJ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executed via COM

      • FlashUtil32_26_0_0_131_ActiveX.exe (PID: 2812)
  • INFO

    • Reads Internet Cache Settings

      • iexplore.exe (PID: 3220)
    • Creates files in the user directory

      • FlashUtil32_26_0_0_131_ActiveX.exe (PID: 2812)
      • iexplore.exe (PID: 3220)
    • Reads internet explorer settings

      • iexplore.exe (PID: 3220)
    • Changes internet zones settings

      • iexplore.exe (PID: 3668)
    • Reads settings of System Certificates

      • iexplore.exe (PID: 3668)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
36
Monitored processes
3
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe flashutil32_26_0_0_131_activex.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3668"C:\Program Files\Internet Explorer\iexplore.exe" -nohomeC:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
3220"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3668 CREDAT:71937C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
2812C:\Windows\system32\Macromed\Flash\FlashUtil32_26_0_0_131_ActiveX.exe -EmbeddingC:\Windows\system32\Macromed\Flash\FlashUtil32_26_0_0_131_ActiveX.exesvchost.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
MEDIUM
Description:
Adobe® Flash® Player Installer/Uninstaller 26.0 r0
Version:
26,0,0,131
Total events
399
Read events
341
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
0
Text files
28
Unknown types
5

Dropped files

PID
Process
Filename
Type
3668iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\favicon[1].ico
MD5:
SHA256:
3668iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
MD5:
SHA256:
3220iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ42X24Y\pubg[1].htm
MD5:
SHA256:
3220iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQ42X24Y\js[1]text
MD5:E43FE1A8CFE71807687FA2F1582CEA9E
SHA256:39C72750D4A35F5282D6313C95077BDEDFA0010CD545D1A51C1EF283183066FC
3220iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\TVTYXXX4\f[1].txttext
MD5:88700F7DC3BDA8972337A322350D274F
SHA256:83340E7ED8EAC7619D3B24951A12BFB72B56FDCFA7818EC2A74EDC4C5B111811
3220iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\EK9WHA97\js[1]text
MD5:F932723344AAFAEEFB6B21D13BE33FF3
SHA256:181710C623A68FB211AEE9CF39DB0DDFF0B38EB8025052B799F42BC6907DEF26
3220iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\History\Low\History.IE5\index.datdat
MD5:9BD902FE0F3AFBD0C112BE5031A2150E
SHA256:31F0C9976218CE3F1EEA43CFB4693D349CD0E26D6D27BE27FA3FEA40654DA628
3220iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\EK9WHA97\logo_new[1].pngimage
MD5:FB11BC667335500C253FF2B46A5FCD5B
SHA256:1AA5A58CF0F217AC661A3CC7F89B6E56ED4B8053D0F02D7D1C76239A598552C3
3220iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\TVTYXXX4\bg-back-36ef3e001c[1].pngimage
MD5:36EF3E001CC8201BD9E3C3033D57C538
SHA256:1A6FA6AE9CE687830C97627A8E498A1F420966C9B1BFE6E8F4B27CB5928BF3B7
3220iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\index.datdat
MD5:1C619DBF6AFA5AC8399DB10DDEE3563F
SHA256:A3E95264013BD490E792D3948BC9AE57B0CB5CB2B99DCA978CC40F3C990D79DD
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
20
DNS requests
14
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3668
iexplore.exe
GET
200
204.79.197.200:80
http://www.bing.com/favicon.ico
US
image
237 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3220
iexplore.exe
172.217.22.98:443
googleads.g.doubleclick.net
Google Inc.
US
whitelisted
3668
iexplore.exe
204.79.197.200:80
www.bing.com
Microsoft Corporation
US
whitelisted
3220
iexplore.exe
172.217.16.206:443
www.google-analytics.com
Google Inc.
US
whitelisted
203.205.158.60:443
pc1.gtimg.com
Tencent Building, Kejizhongyi Avenue
CN
suspicious
216.58.208.34:443
www.googleadservices.com
Google Inc.
US
whitelisted
3220
iexplore.exe
203.205.158.61:443
pc1.gtimg.com
Tencent Building, Kejizhongyi Avenue
CN
suspicious
3220
iexplore.exe
203.205.158.56:443
pingjs.qq.com
Tencent Building, Kejizhongyi Avenue
CN
unknown
3220
iexplore.exe
172.217.18.104:443
www.googletagmanager.com
Google Inc.
US
suspicious
3220
iexplore.exe
203.205.128.169:443
tgb.qq.com
Tencent Building, Kejizhongyi Avenue
CN
unknown
3220
iexplore.exe
203.205.128.168:443
tgb.qq.com
Tencent Building, Kejizhongyi Avenue
CN
unknown

DNS requests

Domain
IP
Reputation
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
tgb.qq.com
  • 203.205.128.168
  • 203.205.128.169
unknown
www.googletagmanager.com
  • 172.217.18.104
whitelisted
pc1.gtimg.com
  • 203.205.158.61
  • 203.205.138.73
  • 203.205.158.60
  • 203.205.138.231
  • 203.205.138.74
  • 203.205.158.50
  • 203.205.158.62
whitelisted
s.pc.qq.com
  • 203.205.158.60
  • 203.205.138.231
  • 203.205.138.74
  • 203.205.158.50
  • 203.205.158.62
  • 203.205.158.61
  • 203.205.138.73
whitelisted
www.google-analytics.com
  • 172.217.16.206
whitelisted
www.googleadservices.com
  • 216.58.208.34
whitelisted
googleads.g.doubleclick.net
  • 172.217.22.98
whitelisted
report.syzs.qq.com
  • 203.205.128.169
  • 203.205.128.168
whitelisted
pingjs.qq.com
  • 203.205.158.56
  • 203.205.138.71
  • 203.205.158.35
  • 203.205.158.55
  • 203.205.158.54
  • 203.205.158.34
  • 203.205.158.53
whitelisted

Threats

No threats detected
No debug info