analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
URL:

https://www.google.it

Full analysis: https://app.any.run/tasks/08574b32-4528-457c-9041-8f8728395734
Verdict: Malicious activity
Analysis date: June 19, 2019, 08:11:27
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

EA04C58C55735444B93E2C8B4E8A736A

SHA1:

E88B65E9F7906ED526386BA8658E5B8A5E9DC2A1

SHA256:

9B120553B57832ED0CB2B5580481B16BF9CD2742FE64A42A8D8202FAFF231222

SSDEEP:

3:N8DSLIQn:2OLIQn

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • reg.exe (PID: 3476)
  • SUSPICIOUS

    • Uses REG.EXE to modify Windows registry

      • Skype.exe (PID: 2156)
    • Modifies the open verb of a shell class

      • Skype.exe (PID: 2156)
    • Reads CPU info

      • Skype.exe (PID: 2156)
    • Creates files in the user directory

      • Skype.exe (PID: 2156)
      • Skype.exe (PID: 2060)
      • Skype.exe (PID: 1920)
    • Application launched itself

      • Skype.exe (PID: 2156)
      • Skype.exe (PID: 2060)
      • Skype.exe (PID: 1920)
  • INFO

    • Application launched itself

      • iexplore.exe (PID: 3320)
    • Creates files in the user directory

      • iexplore.exe (PID: 3212)
      • iexplore.exe (PID: 3320)
    • Changes internet zones settings

      • iexplore.exe (PID: 3320)
    • Reads Internet Cache Settings

      • iexplore.exe (PID: 3212)
      • iexplore.exe (PID: 3320)
    • Reads settings of System Certificates

      • iexplore.exe (PID: 3212)
      • iexplore.exe (PID: 3320)
      • Skype.exe (PID: 2156)
    • Reads internet explorer settings

      • iexplore.exe (PID: 3212)
    • Changes settings of System certificates

      • iexplore.exe (PID: 3320)
    • Adds / modifies Windows certificates

      • iexplore.exe (PID: 3320)
    • Manual execution by user

      • Skype.exe (PID: 2156)
    • Dropped object may contain Bitcoin addresses

      • Skype.exe (PID: 2156)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
49
Monitored processes
12
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe skype.exe skype.exe reg.exe skype.exe no specs reg.exe no specs skype.exe skype.exe no specs skype.exe skype.exe no specs skype.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3320"C:\Program Files\Internet Explorer\iexplore.exe" -nohomeC:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
1
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
3212"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3320 CREDAT:71937C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
2156"C:\Program Files\Microsoft\Skype for Desktop\Skype.exe" C:\Program Files\Microsoft\Skype for Desktop\Skype.exe
explorer.exe
User:
admin
Company:
Skype Technologies S.A.
Integrity Level:
MEDIUM
Description:
Skype
Version:
8.29.0.50
4076"C:\Program Files\Microsoft\Skype for Desktop\Skype.exe" --reporter-url=https://rink.hockeyapp.net/api/2/apps/a741743329d94bc08826af367733939d/crashes/upload --application-name=skype-preview "--crashes-directory=C:\Users\admin\AppData\Local\Temp\skype-preview Crashes" --v=1C:\Program Files\Microsoft\Skype for Desktop\Skype.exe
Skype.exe
User:
admin
Company:
Skype Technologies S.A.
Integrity Level:
MEDIUM
Description:
Skype
Version:
8.29.0.50
3476C:\Windows\system32\reg.exe ADD HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v "Skype for Desktop" /t REG_SZ /d "C:\Program Files\Microsoft\Skype for Desktop\Skype.exe" /fC:\Windows\system32\reg.exe
Skype.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Registry Console Tool
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
2060"C:\Program Files\Microsoft\Skype for Desktop\Skype.exe" --type=renderer --ms-disable-indexeddb-transaction-timeout --no-sandbox --service-pipe-token=EE9626C93092B95DC0162CF4DBCB0ECB --lang=en-US --app-user-model-id=Microsoft.Skype.SkypeDesktop --app-path="C:\Program Files\Microsoft\Skype for Desktop\resources\app.asar" --node-integration=false --webview-tag=true --no-sandbox --preload="C:\Program Files\Microsoft\Skype for Desktop\resources\app.asar\Preload.js" --context-id=2 --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;0,17,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;1,17,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;2,17,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;3,17,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553;4,17,3553 --disable-accelerated-video-decode --disable-gpu-compositing --enable-gpu-async-worker-context --service-request-channel-token=EE9626C93092B95DC0162CF4DBCB0ECB --renderer-client-id=3 --mojo-platform-channel-handle=1540 /prefetch:1C:\Program Files\Microsoft\Skype for Desktop\Skype.exeSkype.exe
User:
admin
Company:
Skype Technologies S.A.
Integrity Level:
MEDIUM
Description:
Skype
Exit code:
0
Version:
8.29.0.50
2908C:\Windows\system32\reg.exe QUERY HKCU\Software\Microsoft\Skype /v RestartForUpdateC:\Windows\system32\reg.exeSkype.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Registry Console Tool
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
2796"C:\Program Files\Microsoft\Skype for Desktop\Skype.exe" --reporter-url=https://rink.hockeyapp.net/api/2/apps/a741743329d94bc08826af367733939d/crashes/upload --application-name=skype-preview "--crashes-directory=C:\Users\admin\AppData\Local\Temp\skype-preview Crashes" --v=1C:\Program Files\Microsoft\Skype for Desktop\Skype.exe
Skype.exe
User:
admin
Company:
Skype Technologies S.A.
Integrity Level:
MEDIUM
Description:
Skype
Exit code:
2
Version:
8.29.0.50
1920"C:\Program Files\Microsoft\Skype for Desktop\Skype.exe" --type=renderer --ms-disable-indexeddb-transaction-timeout --no-sandbox --service-pipe-token=DF1327B8E34AA357495FE424A2910E17 --lang=en-US --app-user-model-id=Microsoft.Skype.SkypeDesktop --app-path="C:\Program Files\Microsoft\Skype for Desktop\resources\app.asar" --node-integration=false --webview-tag=true --no-sandbox --preload="C:\Program Files\Microsoft\Skype for Desktop\resources\app.asar\Preload.js" --context-id=1 --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;0,17,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;1,17,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;2,17,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;3,17,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553;4,17,3553 --disable-accelerated-video-decode --disable-gpu-compositing --enable-gpu-async-worker-context --service-request-channel-token=DF1327B8E34AA357495FE424A2910E17 --renderer-client-id=4 --mojo-platform-channel-handle=2608 /prefetch:1C:\Program Files\Microsoft\Skype for Desktop\Skype.exeSkype.exe
User:
admin
Company:
Skype Technologies S.A.
Integrity Level:
MEDIUM
Description:
Skype
Version:
8.29.0.50
1916"C:\Program Files\Microsoft\Skype for Desktop\Skype.exe" --reporter-url=https://rink.hockeyapp.net/api/2/apps/a741743329d94bc08826af367733939d/crashes/upload --application-name=skype-preview "--crashes-directory=C:\Users\admin\AppData\Local\Temp\skype-preview Crashes" --v=1C:\Program Files\Microsoft\Skype for Desktop\Skype.exe
Skype.exe
User:
admin
Company:
Skype Technologies S.A.
Integrity Level:
MEDIUM
Description:
Skype
Exit code:
2
Version:
8.29.0.50
Total events
727
Read events
582
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
11
Text files
61
Unknown types
9

Dropped files

PID
Process
Filename
Type
3320iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H6QNMHE9\favicon[1].ico
MD5:
SHA256:
3320iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
MD5:
SHA256:
3212iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\admin@google[1].txt
MD5:
SHA256:
3212iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZN0RM813\google_it[1].txt
MD5:
SHA256:
3212iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\index.datdat
MD5:F49DA0FB6DF868035CF6BDA1C2027867
SHA256:D8FE23606D139F4D4D63033FBA9B0507F1F9006805309AD1B959F50B75DBF3C1
3212iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\index.datdat
MD5:7A4DA5540FC6D60291DBCBA5D99E0789
SHA256:115995E59A3E3A103902B07ADAB12061664E18B30391AAFC5F1586BC00A86746
3212iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZN0RM813\google_it[1].htmhtml
MD5:503D30E7BFAD4BB06830BE6368CC54D9
SHA256:7BAFF07AF52F985D844DEB280FD1E95EDD9D9DF0D34EA2E5ECF5E5C82CC68381
3212iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\History\Low\History.IE5\MSHist012019061920190620\index.datdat
MD5:3FCA77769542DF6754EE55E6CB9B7DB2
SHA256:B00D3144038B02C1CE3103E679CA96A807C13AAE97895A5AA159F7693E345232
3320iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Feeds Cache\desktop.iniini
MD5:4A3DEB274BB5F0212C2419D3D8D08612
SHA256:2842973D15A14323E08598BE1DFB87E54BF88A76BE8C7BC94C56B079446EDF38
3212iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2QKPWXDJ\desktop.iniini
MD5:4A3DEB274BB5F0212C2419D3D8D08612
SHA256:2842973D15A14323E08598BE1DFB87E54BF88A76BE8C7BC94C56B079446EDF38
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
23
DNS requests
13
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3212
iexplore.exe
GET
31.132.4.10:80
http://malakas.mpekris.gr/
GB
malicious
3212
iexplore.exe
GET
404
31.132.4.10:80
http://malakas.mpekris.gr/re
GB
html
319 b
malicious
3212
iexplore.exe
GET
404
31.132.4.10:80
http://malakas.mpekris.gr/re/519.php
GB
html
327 b
malicious
3212
iexplore.exe
GET
404
31.132.4.10:80
http://malakas.mpekris.gr/re/519.php
GB
html
327 b
malicious
3320
iexplore.exe
GET
200
204.79.197.200:80
http://www.bing.com/favicon.ico
US
image
237 b
whitelisted
3212
iexplore.exe
GET
200
31.132.4.10:80
http://malakas.mpekris.gr/
GB
html
712 b
malicious
3212
iexplore.exe
GET
200
31.132.4.10:80
http://malakas.mpekris.gr/lef.jpg
GB
image
49.6 Kb
malicious
3212
iexplore.exe
GET
200
31.132.4.10:80
http://malakas.mpekris.gr/300-1.jpg
GB
image
12.4 Kb
malicious
3320
iexplore.exe
GET
404
31.132.4.10:80
http://malakas.mpekris.gr/favicon.ico
GB
html
328 b
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3320
iexplore.exe
204.79.197.200:80
www.bing.com
Microsoft Corporation
US
whitelisted
3212
iexplore.exe
31.132.4.10:80
malakas.mpekris.gr
UK Dedicated Servers Limited
GB
malicious
3320
iexplore.exe
31.132.4.10:80
malakas.mpekris.gr
UK Dedicated Servers Limited
GB
malicious
3320
iexplore.exe
216.58.208.35:443
www.google.it
Google Inc.
US
whitelisted
2156
Skype.exe
13.107.3.128:443
a.config.skype.com
Microsoft Corporation
US
whitelisted
3212
iexplore.exe
216.58.208.35:443
www.google.it
Google Inc.
US
whitelisted
2156
Skype.exe
13.90.95.57:443
get.skype.com
Microsoft Corporation
US
whitelisted
2156
Skype.exe
2.18.233.81:443
download.skype.com
Akamai International B.V.
whitelisted
2156
Skype.exe
216.58.206.10:443
www.googleapis.com
Google Inc.
US
whitelisted
2156
Skype.exe
52.114.128.8:443
pipe.skype.com
Microsoft Corporation
US
unknown

DNS requests

Domain
IP
Reputation
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
www.google.it
  • 216.58.208.35
whitelisted
malakas.mpekris.gr
  • 31.132.4.10
malicious
get.skype.com
  • 13.90.95.57
whitelisted
a.config.skype.com
  • 13.107.3.128
whitelisted
pipe.skype.com
  • 52.114.128.8
whitelisted
download.skype.com
  • 2.18.233.81
whitelisted
www.googleapis.com
  • 216.58.206.10
  • 216.58.207.42
  • 216.58.207.74
  • 172.217.16.170
  • 172.217.22.42
  • 172.217.22.106
  • 172.217.18.106
  • 216.58.205.234
  • 172.217.22.10
  • 172.217.18.10
whitelisted
avatar.skype.com
  • 40.79.33.178
whitelisted
config.edge.skype.com
  • 13.107.3.128
whitelisted

Threats

No threats detected
Process
Message
Skype.exe
[2796:1024:0619/091530.774:VERBOSE1:crash_service_main.cc(78)] Session start. cmdline is [--reporter-url=https://rink.hockeyapp.net/api/2/apps/a741743329d94bc08826af367733939d/crashes/upload --application-name=skype-preview "--crashes-directory=C:\Users\admin\AppData\Local\Temp\skype-preview Crashes" --v=1]
Skype.exe
[2796:1024:0619/091530.774:VERBOSE1:crash_service.cc(145)] window handle is 0006012A
Skype.exe
[2796:1024:0619/091530.774:VERBOSE1:crash_service.cc(300)] pipe name is \\.\pipe\skype-preview Crash Service dumps at C:\Users\admin\AppData\Local\Temp\skype-preview Crashes
Skype.exe
[2796:1024:0619/091530.774:VERBOSE1:crash_service.cc(304)] checkpoint is C:\Users\admin\AppData\Local\Temp\skype-preview Crashes\crash_checkpoint.txt server is https://rink.hockeyapp.net/api/2/apps/a741743329d94bc08826af367733939d/crashes/upload maximum 128 reports/day reporter is electron-crash-service
Skype.exe
[2796:1024:0619/091530.774:ERROR:crash_service.cc(311)] could not start dumper
Skype.exe
[1916:2876:0619/091538.510:VERBOSE1:crash_service_main.cc(78)] Session start. cmdline is [--reporter-url=https://rink.hockeyapp.net/api/2/apps/a741743329d94bc08826af367733939d/crashes/upload --application-name=skype-preview "--crashes-directory=C:\Users\admin\AppData\Local\Temp\skype-preview Crashes" --v=1]
Skype.exe
[1916:2876:0619/091538.513:VERBOSE1:crash_service.cc(145)] window handle is 00070222
Skype.exe
[1916:2876:0619/091538.514:VERBOSE1:crash_service.cc(300)] pipe name is \\.\pipe\skype-preview Crash Service dumps at C:\Users\admin\AppData\Local\Temp\skype-preview Crashes
Skype.exe
[1916:2876:0619/091538.514:VERBOSE1:crash_service.cc(304)] checkpoint is C:\Users\admin\AppData\Local\Temp\skype-preview Crashes\crash_checkpoint.txt server is https://rink.hockeyapp.net/api/2/apps/a741743329d94bc08826af367733939d/crashes/upload maximum 128 reports/day reporter is electron-crash-service
Skype.exe
[1916:2876:0619/091538.515:ERROR:crash_service.cc(311)] could not start dumper