analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
URL:

https://mht.focus-staging.com/?y=c3RlcGhhbmllLmtlbXB0b25AYWJlcmRlZW5zdGFuZGFyZC5jb20=

Full analysis: https://app.any.run/tasks/e22a0a0c-8c3d-4010-897d-d868b3109be6
Verdict: Malicious activity
Analysis date: April 25, 2019, 08:46:58
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

CC4FF95998BACF530EB2B4FE7E3565E5

SHA1:

7CE2950D37FBE4C01723A8F249C3FBB1A1A84A4D

SHA256:

8F77A824BC177D6923457BE0AB5E9E33AF8CE2AF74DE713A209E0D0059D70980

SSDEEP:

3:N863lFEPL9PNNQp2ntnka+O/XVYn:263lFEPLJf8AxX+OfVY

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Creates files in the user directory

      • iexplore.exe (PID: 3064)
      • iexplore.exe (PID: 2808)
    • Application launched itself

      • iexplore.exe (PID: 2808)
    • Reads internet explorer settings

      • iexplore.exe (PID: 3064)
    • Reads Internet Cache Settings

      • iexplore.exe (PID: 3064)
    • Changes internet zones settings

      • iexplore.exe (PID: 2808)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
33
Monitored processes
2
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe

Process information

PID
CMD
Path
Indicators
Parent process
2808"C:\Program Files\Internet Explorer\iexplore.exe" -nohomeC:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
3064"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2808 CREDAT:71937C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Total events
382
Read events
322
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
0
Text files
106
Unknown types
7

Dropped files

PID
Process
Filename
Type
2808iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H6QNMHE9\favicon[1].ico
MD5:
SHA256:
2808iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
MD5:
SHA256:
3064iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\V3TGKDHE\yourtabsservices_su[1].txt
MD5:
SHA256:
3064iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\JZ9PKHDR\cart_icon[1].gifimage
MD5:9F71DE7FCE37A1B2975D13C88C0EF69B
SHA256:B83B3B63EEA898B5AF29E58C750E67534A5D765F41656F8BC44D3D8811D21643
3064iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\index.datdat
MD5:A3594AC840C699677EAE968BAF785F71
SHA256:3EE3049C864322B111FBE8B9109033BE9811A3128125BD936E7FF74692817017
3064iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\History\Low\History.IE5\index.datdat
MD5:5718C0A05CDD794FDA3537A3D790D74B
SHA256:FCF1E76D28008D8A446D1B3F7E0A4B7CE3028942EA69291E7B989A1B67B0925A
3064iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IC2E3CFN\language_ES[1].pngimage
MD5:CC7941103B6A0C9D4ADBB13D08836AB5
SHA256:6E08BC6727BDFC04C644D70DDBB99C1F7FBEE506C3C86206BD6A9E1478144598
3064iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\09CWKV1Q\language_DE[1].pngimage
MD5:8BCDF5D2C5A9E203748981888AC12828
SHA256:08546E5E47A58546B72B071BAABDB1B3FD88F15DF622CB067D96AA47751CA063
3064iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\09CWKV1Q\search_go[1].pngimage
MD5:BBBC5FBF7E839303DD3DC014C523C2AD
SHA256:C45046A3A576E31A861BD26DF5F39C578888BE953E70CDF6912919A4E6046481
3064iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\JZ9PKHDR\top-line_bg[1].gifimage
MD5:C5C24FAC21F3A862FBB232715BE009A3
SHA256:29E0AF4617B97C23734C4BD36053A92A469AA3D8D31F55B3CA12280B6E3DEB7C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
101
TCP/UDP connections
103
DNS requests
4
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3064
iexplore.exe
GET
200
95.110.232.65:80
http://yourtabsservices.su/images/cp/top-line_bg.gif
IT
image
49 b
suspicious
3064
iexplore.exe
GET
200
95.110.232.65:80
http://yourtabsservices.su/images/cp/cart_icon.gif
IT
image
1.30 Kb
suspicious
3064
iexplore.exe
GET
200
95.110.232.65:80
http://yourtabsservices.su/images/cp/language_FR.png
IT
image
1.33 Kb
suspicious
3064
iexplore.exe
GET
200
95.110.232.65:80
http://yourtabsservices.su/images/cp/m_delivery.gif
IT
image
2.18 Kb
suspicious
3064
iexplore.exe
GET
404
95.110.232.65:80
http://yourtabsservices.su/4dbf543acc91450a1b2f98b3b37efbe17041.gif?1556182302
IT
html
571 b
suspicious
3064
iexplore.exe
GET
200
95.110.232.65:80
http://yourtabsservices.su/
IT
html
13.8 Kb
suspicious
3064
iexplore.exe
GET
200
95.110.232.65:80
http://yourtabsservices.su/images/cp/bgl_we_ship_worldwide.png
IT
image
47.0 Kb
suspicious
3064
iexplore.exe
GET
200
95.110.232.65:80
http://yourtabsservices.su/images/cp/language_DE.png
IT
image
1.28 Kb
suspicious
3064
iexplore.exe
GET
200
95.110.232.65:80
http://yourtabsservices.su/images/cp/search_go.png
IT
image
5.30 Kb
suspicious
3064
iexplore.exe
GET
404
95.110.232.65:80
http://yourtabsservices.su/5fad3a54bee341a7a61deec5c10cd69c1d60.gif?1556182303
IT
html
571 b
suspicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2808
iexplore.exe
204.79.197.200:80
www.bing.com
Microsoft Corporation
US
whitelisted
3064
iexplore.exe
95.110.232.65:80
yourtabsservices.su
Aruba S.p.A.
IT
suspicious
3064
iexplore.exe
34.213.1.157:443
mht.focus-staging.com
Amazon.com, Inc.
US
unknown
3064
iexplore.exe
93.125.99.87:443
www.mebel-brw.by
Republican Unitary Telecommunication Enterprise Beltelecom
BY
unknown
95.110.232.65:80
yourtabsservices.su
Aruba S.p.A.
IT
suspicious
2808
iexplore.exe
95.110.232.65:80
yourtabsservices.su
Aruba S.p.A.
IT
suspicious

DNS requests

Domain
IP
Reputation
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
mht.focus-staging.com
  • 34.213.1.157
unknown
www.mebel-brw.by
  • 93.125.99.87
unknown
yourtabsservices.su
  • 95.110.232.65
suspicious

Threats

PID
Process
Class
Message
Potentially Bad Traffic
ET DNS Query for .su TLD (Soviet Union) Often Malware Related
3064
iexplore.exe
Potentially Bad Traffic
ET POLICY HTTP Request to .su TLD (Soviet Union) Often Malware Related
3064
iexplore.exe
Potentially Bad Traffic
ET POLICY HTTP Request to .su TLD (Soviet Union) Often Malware Related
3064
iexplore.exe
Potentially Bad Traffic
ET POLICY HTTP Request to .su TLD (Soviet Union) Often Malware Related
3064
iexplore.exe
Potentially Bad Traffic
ET POLICY HTTP Request to .su TLD (Soviet Union) Often Malware Related
3064
iexplore.exe
Potentially Bad Traffic
ET POLICY HTTP Request to .su TLD (Soviet Union) Often Malware Related
3064
iexplore.exe
Potentially Bad Traffic
ET POLICY HTTP Request to .su TLD (Soviet Union) Often Malware Related
3064
iexplore.exe
Potentially Bad Traffic
ET POLICY HTTP Request to .su TLD (Soviet Union) Often Malware Related
3064
iexplore.exe
Potentially Bad Traffic
ET POLICY HTTP Request to .su TLD (Soviet Union) Often Malware Related
3064
iexplore.exe
Potentially Bad Traffic
ET POLICY HTTP Request to .su TLD (Soviet Union) Often Malware Related
No debug info