analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
URL:

https://onlineservices-servicesenligne.cic.gc.ca/eta/exit.do;jsessionid=0A060241A986CE88C412E0B353BE5CBF?logout=true&uri=https%3A%2F%2Fthirsty-bhabha-d37e50.netlify.app/#ZGF2aWQucGFya0BjYW5hZGEuY2E=

Full analysis: https://app.any.run/tasks/649a0b7d-d144-419a-af08-116eae0706df
Verdict: Malicious activity
Analysis date: February 07, 2022, 16:16:38
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
phishing
Indicators:
MD5:

F0218207D60049D854597F57B284C2A2

SHA1:

E0576CE8B99BE2BE2A6B92E3E77874DF30A1F5DF

SHA256:

952C2407B8C3E2A3F5155BADA34744E4D6F73F7FE756898FB7AB0F10C9346A08

SSDEEP:

6:2CdMfAXcEOb0PPq/7cawBYnm2gzw6oFAoB9v+Y:2xzb0qcTmm2gxpo6Y

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads Microsoft Outlook installation path

      • iexplore.exe (PID: 2216)
  • INFO

    • Checks supported languages

      • iexplore.exe (PID: 3780)
      • iexplore.exe (PID: 2216)
    • Reads the computer name

      • iexplore.exe (PID: 3780)
      • iexplore.exe (PID: 2216)
    • Reads settings of System Certificates

      • iexplore.exe (PID: 3780)
      • iexplore.exe (PID: 2216)
    • Adds / modifies Windows certificates

      • iexplore.exe (PID: 3780)
    • Changes internet zones settings

      • iexplore.exe (PID: 3780)
    • Application launched itself

      • iexplore.exe (PID: 3780)
    • Reads internet explorer settings

      • iexplore.exe (PID: 2216)
    • Creates files in the user directory

      • iexplore.exe (PID: 3780)
    • Checks Windows Trust Settings

      • iexplore.exe (PID: 3780)
      • iexplore.exe (PID: 2216)
    • Changes settings of System certificates

      • iexplore.exe (PID: 3780)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
36
Monitored processes
2
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe

Process information

PID
CMD
Path
Indicators
Parent process
3780"C:\Program Files\Internet Explorer\iexplore.exe" "https://onlineservices-servicesenligne.cic.gc.ca/eta/exit.do;jsessionid=0A060241A986CE88C412E0B353BE5CBF?logout=true&uri=https%3A%2F%2Fthirsty-bhabha-d37e50.netlify.app/#ZGF2aWQucGFya0BjYW5hZGEuY2E="C:\Program Files\Internet Explorer\iexplore.exe
Explorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
2216"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3780 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Total events
14 931
Read events
14 805
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
11
Text files
18
Unknown types
7

Dropped files

PID
Process
Filename
Type
2216iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7423F88C7F265F0DEFC08EA88C3BDE45_B514E3306E9B5CC22C1D3DB90570477Ader
MD5:C4B6BD73EA649B93579997329489B4D2
SHA256:942A603285E35B71180103EEA24E5F57F337D41321B391C2E7E306E45058CA1C
2216iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\5054D3D7526395AFD1BB54714B2BD386_942967496E12416BDAC019D2D44AFCA5der
MD5:652DF41DFCCCDC6488C72A929AB08F2E
SHA256:2CF1BE46321ACEABC9DE6D7ED82ED387EB03C8086F977BA4CDFAF2BD13D02AE1
2216iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B9C0457FE8FDF881D9EA458DAD3D4142_50CBEA42B0661B4C401C547997C38795der
MD5:83B31E7B66BECED16ED07AEFF2B368CF
SHA256:BFAB8745560BEE6EF97FD5831D50BDE2821E3473D307B23094C463B61A5DC5E9
3780iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:80C78481752C2EEEE727F5C88C5A6364
SHA256:DB136AE57A13A8AB59900BD7D10543B45D1C45D799D4B7781CB70F3B954B74AE
3780iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6BADA8974A10C4BD62CC921D13E43B18_711ED44619924BA6DC33E69F97E7FF63binary
MD5:CED48AE9786ADC01B87BE71D8CA0B819
SHA256:DFE54558BCD8B1154C19122715B61DA2717591D1255C302CB58C31C32F3CAAF8
2216iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\A37B8BA80004D3266CB4D93B2052DC10_9930CFFA1A8DC7DD2E91B8BAFFAF726Dder
MD5:B81496BA69C82AA82E59093F79432862
SHA256:68C962F467822A362427888C0141E0E89AB08A4259E3A54468E8C78FE72D70F5
3780iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7423F88C7F265F0DEFC08EA88C3BDE45_AA1E8580D4EBC816148CE81268683776der
MD5:B478F9B6AF8E1D07CA6A1A03F6E2E0B2
SHA256:1D1B94745CF76B32925518A4AE67327D12088E3BB59B00C2A3F353C311A62A05
3780iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6BADA8974A10C4BD62CC921D13E43B18_711ED44619924BA6DC33E69F97E7FF63der
MD5:C3982A9DF1729D8E6F87A38F2719F7CE
SHA256:6FE0AFFB7F8B266580EBD9C0E34D474586EC2E1647B56D7963B5C85188EF6F01
2216iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\5054D3D7526395AFD1BB54714B2BD386_942967496E12416BDAC019D2D44AFCA5binary
MD5:B8AC077E61D841603520DE825709376B
SHA256:5E612C0251046D2C9B16E1B91A3437728DF30181DE2FDED47AE1BBC03F8E7F0F
2216iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7423F88C7F265F0DEFC08EA88C3BDE45_B514E3306E9B5CC22C1D3DB90570477Abinary
MD5:EDFF677B27808B3EECCE58ED62118B72
SHA256:BA048154B9222041CF09FAAAF450AA09156F6B263B9C9991AF30AD30F4A1A9A2
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
10
TCP/UDP connections
37
DNS requests
23
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2216
iexplore.exe
GET
200
23.45.103.152:80
http://ocsp.entrust.net/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBTLXNCzDvBhHecWjg70iJhBW0InywQUanImetAe733nO2lR1GyNn5ASZqsCDA7pTMMAAAAAUdN3hQ%3D%3D
NL
der
1.55 Kb
whitelisted
3780
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
der
471 b
whitelisted
3780
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA8Ull8gIGmZT9XHrHiJQeI%3D
US
der
1.47 Kb
whitelisted
2216
iexplore.exe
GET
200
23.45.103.152:80
http://ocsp.entrust.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTMbSIc9rRVLC%2BHkV9a%2FvDh7s6DzAQUgqJwdN28Uz%2FPe9T3zX%2BnYMYKTL8CEF0y1RAevzbvT9DOKPWiHhs%3D
NL
der
1.55 Kb
whitelisted
2216
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQrHR6YzPN2BNbByL0VoiTIBBMAOAQUCrwIKReMpTlteg7OM8cus%2B37w3oCEAXuEb2NyWme3Nf0wkiccYA%3D
US
der
313 b
whitelisted
3780
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA177el9ggmWelJjG4vdGL0%3D
US
der
471 b
whitelisted
2216
iexplore.exe
GET
200
23.32.238.201:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?baba484557c42a26
US
compressed
4.70 Kb
whitelisted
2216
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAonX%2BcE1u7LI9XNW0saTgQ%3D
US
der
471 b
whitelisted
3780
iexplore.exe
GET
200
23.32.238.178:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?763479eeaab6eba3
US
compressed
4.70 Kb
whitelisted
3780
iexplore.exe
GET
200
23.32.238.178:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?896009c89a192b0d
US
compressed
4.70 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3780
iexplore.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
2216
iexplore.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
3780
iexplore.exe
131.253.33.200:443
www.bing.com
Microsoft Corporation
US
whitelisted
2216
iexplore.exe
23.45.103.152:80
ocsp.entrust.net
Akamai International B.V.
NL
suspicious
3780
iexplore.exe
152.199.19.161:443
iecvlist.microsoft.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
2216
iexplore.exe
23.32.238.178:80
ctldl.windowsupdate.com
XO Communications
US
suspicious
3780
iexplore.exe
23.32.238.178:80
ctldl.windowsupdate.com
XO Communications
US
suspicious
2216
iexplore.exe
23.32.238.201:80
ctldl.windowsupdate.com
XO Communications
US
suspicious
2216
iexplore.exe
3.67.255.218:443
thirsty-bhabha-d37e50.netlify.app
US
malicious
2216
iexplore.exe
167.40.16.11:443
onlineservices-servicesenligne.cic.gc.ca
CA
unknown

DNS requests

Domain
IP
Reputation
onlineservices-servicesenligne.cic.gc.ca
  • 167.40.16.11
unknown
api.bing.com
  • 13.107.13.80
  • 13.107.5.80
whitelisted
www.bing.com
  • 131.253.33.200
  • 13.107.22.200
  • 204.79.197.200
  • 13.107.21.200
whitelisted
ctldl.windowsupdate.com
  • 23.32.238.178
  • 23.32.238.201
whitelisted
ocsp.digicert.com
  • 93.184.220.29
whitelisted
ocsp.entrust.net
  • 23.45.103.152
whitelisted
thirsty-bhabha-d37e50.netlify.app
  • 3.67.255.218
  • 161.35.218.92
malicious
iecvlist.microsoft.com
  • 152.199.19.161
whitelisted
r20swj13mr.microsoft.com
  • 152.199.19.161
whitelisted
ieonline.microsoft.com
  • 204.79.197.200
whitelisted

Threats

PID
Process
Class
Message
Misc activity
ET INFO Suspicious Netlify Hosted DNS Request - Possible Phishing Landing
2216
iexplore.exe
Misc activity
ET INFO Suspicious Netlify Hosted TLS SNI Request - Possible Phishing Landing
2216
iexplore.exe
Misc activity
ET INFO Suspicious Netlify Hosted TLS SNI Request - Possible Phishing Landing
No debug info