analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
download:

index.html

Full analysis: https://app.any.run/tasks/85f05bf8-b3df-4b16-ba73-ce0c103b64c6
Verdict: Malicious activity
Analysis date: October 09, 2019, 15:23:29
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: text/html
File info: HTML document, UTF-8 Unicode text, with very long lines, with CRLF, LF line terminators
MD5:

0B1B083478AB5A254ADA8220FC40BF7F

SHA1:

45AAAD91FB62DDFC3EBF8E81C367A0062C624720

SHA256:

8D6B97818346F631B952BBDBFADA7583D6CB1158FC41C8BF7BB1622E52A35679

SSDEEP:

3072:mA79YVAmGSXyfRcu4z47WYBDKQuB/DV7mq4T:kDVOT

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Application launched itself

      • iexplore.exe (PID: 2808)
    • Reads internet explorer settings

      • iexplore.exe (PID: 3348)
    • Changes internet zones settings

      • iexplore.exe (PID: 2808)
    • Creates files in the user directory

      • iexplore.exe (PID: 3348)
    • Reads settings of System Certificates

      • iexplore.exe (PID: 3348)
    • Adds / modifies Windows certificates

      • iexplore.exe (PID: 3348)
    • Changes settings of System certificates

      • iexplore.exe (PID: 3348)
    • Reads Internet Cache Settings

      • iexplore.exe (PID: 3348)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rdf | Resource Description Framework (54.4)
.htm/html | HyperText Markup Language with DOCTYPE (36.7)
.html | HyperText Markup Language (8.8)

EXIF

HTML

viewport: width=device-width
HandheldFriendly:
MobileOptimized: width
Title: Agence de Presse Régionale |
Generator: Drupal 7 (https://www.drupal.org)
Description: L'information numérique relayée en temps réel
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
34
Monitored processes
2
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe

Process information

PID
CMD
Path
Indicators
Parent process
2808"C:\Program Files\Internet Explorer\iexplore.exe" C:\Users\admin\AppData\Local\Temp\index.htmlC:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
3348"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2808 CREDAT:79873C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Total events
496
Read events
401
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
0
Text files
150
Unknown types
8

Dropped files

PID
Process
Filename
Type
2808iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\favicon[1].ico
MD5:
SHA256:
2808iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
MD5:
SHA256:
3348iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0488CJO\back[1].csstext
MD5:1ACCC4C18A0DB1D13C64F698F446FC6E
SHA256:D7A94DE9A313A1BB3B0E77BCE79EBD8DB48436673A76E0BF736B38D2573A4B24
3348iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGRR2OYX\user[1].csstext
MD5:1162BEC186856E63A6CA207B04282816
SHA256:63EEB9BAF46A801BCCB55EF3C1A60610E820D57F90814480A393A0EC8EDB36A3
3348iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0488CJO\twocol_bricks[1].csstext
MD5:B10797F3C35D6A4AD9B99B1FEB45A6A9
SHA256:2F77CEF824F0E2D2A204E5671C85DF2F42DD21F4B38E34928D1EA2CB73FC1DF4
3348iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\simplenews[1].csstext
MD5:CECF8A979B52A6ADE1F7AFFAE0A81519
SHA256:48D16CD2D84FE46B21632D8E12EFC6C79DB489BD49C08EF2789FEB50E493D08F
3348iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGRR2OYX\views_slideshow_cycle[1].csstext
MD5:76107C5BC1149BDD7EC020CC76351CAF
SHA256:E7311DC0EA90CCC94A5AB723864B2AF07487D6EE1497E4AD8AC6CBA9BCBB977F
3348iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0488CJO\search[1].csstext
MD5:648EC873B4B9E80880653FBAE1F5B235
SHA256:50F8D8E45F6742713A156C9FCF1B20D7C8C2DBDDC7C649B76EE377775C6C4B83
3348iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H6QNMHE9\ctools[1].csstext
MD5:0C78B9B65520315A2FB697DB36BB453E
SHA256:C1247C6C6E2FA2A3B02F04886DEAC34F46CCEF66483B1C64C1347E6B95E158B9
3348iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\jquery.once[1].jstext
MD5:CCEEBAD9BBB56917E310D1A7369F267B
SHA256:1430F42C0D760BA8E05BB3762480502E541F654FEC5739EE40625AB22DC38C4F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
70
DNS requests
6
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3348
iexplore.exe
GET
200
81.4.122.193:80
http://track.positiverefreshment.org/s_code.js?cid=220&v=24eca7c911f5e102e2ba
NL
text
140 b
malicious
2808
iexplore.exe
GET
200
13.107.21.200:80
http://www.bing.com/favicon.ico
US
image
237 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2808
iexplore.exe
204.79.197.200:80
www.bing.com
Microsoft Corporation
US
whitelisted
3348
iexplore.exe
51.68.186.148:443
apr-news.fr
GB
unknown
2808
iexplore.exe
13.107.21.200:80
www.bing.com
Microsoft Corporation
US
whitelisted
51.68.186.148:443
apr-news.fr
GB
unknown
4
System
185.60.216.19:445
connect.facebook.net
Facebook, Inc.
IE
whitelisted
4
System
185.60.216.19:139
connect.facebook.net
Facebook, Inc.
IE
whitelisted
3348
iexplore.exe
172.217.18.110:443
www.google-analytics.com
Google Inc.
US
whitelisted
3348
iexplore.exe
81.4.122.193:80
track.positiverefreshment.org
RouteLabel V.O.F.
NL
malicious

DNS requests

Domain
IP
Reputation
apr-news.fr
  • 51.68.186.148
unknown
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
track.positiverefreshment.org
  • 81.4.122.193
unknown
www.google-analytics.com
  • 172.217.18.110
whitelisted
connect.facebook.net
  • 185.60.216.19
whitelisted

Threats

No threats detected
No debug info