| URL: | http://mergedocsnow.com |
| Full analysis: | https://app.any.run/tasks/939a01cb-123c-41bb-924e-766143dbb256 |
| Verdict: | Malicious activity |
| Analysis date: | January 20, 2020, 15:22:38 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MD5: | 4F2330DC45D7D0682A2BBF9DD562F6A8 |
| SHA1: | ACDB9F23BFD5ACEAFEDB22A535586139F7CBFD13 |
| SHA256: | 9D85E5EAF113EB2C06C61CB79FE511D9ED4638639C9B92C6D441404CB4642A8C |
| SSDEEP: | 3:N1KT2daI:CAaI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 328 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:1016 CREDAT:71937 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Exit code: 0 Version: 8.00.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 656 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=992,11676119351329201946,13593565316861426279,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=17927252192475798853 --renderer-client-id=23 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=4684 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 788 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=992,11676119351329201946,13593565316861426279,131072 --enable-features=PasswordImport --lang=en-US --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=1228436253748419204 --renderer-client-id=4 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2540 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 976 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=992,11676119351329201946,13593565316861426279,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=15020149425788733264 --mojo-platform-channel-handle=5480 --ignored=" --type=renderer " /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 976 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=992,11676119351329201946,13593565316861426279,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=13381612961513005304 --mojo-platform-channel-handle=4388 --ignored=" --type=renderer " /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 1016 | "C:\Program Files\Internet Explorer\iexplore.exe" "http://mergedocsnow.com" | C:\Program Files\Internet Explorer\iexplore.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Exit code: 0 Version: 8.00.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1036 | "C:\Program Files\Internet Explorer\iexplore.exe" | C:\Program Files\Internet Explorer\iexplore.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Exit code: 0 Version: 8.00.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1152 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=992,11676119351329201946,13593565316861426279,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=network --service-request-channel-token=14242362091662653313 --mojo-platform-channel-handle=1628 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | chrome.exe | ||||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 1544 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=992,11676119351329201946,13593565316861426279,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=17009095947572219991 --renderer-client-id=58 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=4320 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| 1608 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=992,11676119351329201946,13593565316861426279,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=7505040694532222235 --mojo-platform-channel-handle=3144 --ignored=" --type=renderer " /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 75.0.3770.100 Modules
| |||||||||||||||
| (PID) Process: | (1016) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main |
| Operation: | write | Name: | CompatibilityFlags |
Value: 0 | |||
| (PID) Process: | (1016) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (1016) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
| (PID) Process: | (1016) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones |
| Operation: | write | Name: | SecuritySafe |
Value: 1 | |||
| (PID) Process: | (1016) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (1016) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
| Operation: | write | Name: | SavedLegacySettings |
Value: 4600000092000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000 | |||
| (PID) Process: | (1016) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Recovery\Active |
| Operation: | write | Name: | {B73153F7-3B98-11EA-AB41-5254004A04AF} |
Value: 0 | |||
| (PID) Process: | (1016) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore |
| Operation: | write | Name: | Type |
Value: 4 | |||
| (PID) Process: | (1016) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore |
| Operation: | write | Name: | Count |
Value: 2 | |||
| (PID) Process: | (1016) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore |
| Operation: | write | Name: | Time |
Value: E4070100010014000F0016003100EE01 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1016 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\favicon[1].ico | — | |
MD5:— | SHA256:— | |||
| 1016 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico | — | |
MD5:— | SHA256:— | |||
| 328 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YNOXWRIW\index[1].jhtml | — | |
MD5:— | SHA256:— | |||
| 328 | iexplore.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\admin@mergedocsnow[2].txt | — | |
MD5:— | SHA256:— | |||
| 328 | iexplore.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\admin@mergedocsnow[1].txt | text | |
MD5:F1148CB23D330849F129F06A149B2AD5 | SHA256:9684EF32A038F19097C484259505CD1F9303111EC72E305490A43B909E2A760F | |||
| 328 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YNOXWRIW\ttDetectUtil[1].js | text | |
MD5:3C9863DC2CAA7A49BD7E87D33F753C06 | SHA256:BBA7E618A05FB82E63FCF89FD1D0C5BA1A1AABA15C33EEA5D860E92BB21FD7E2 | |||
| 328 | iexplore.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\index.dat | dat | |
MD5:DD69D8A877308D9FAF961A5BD1DCEA79 | SHA256:D090B474EE644CD683EF03562E6848A2E60C2FEEE0E8B37F083FD9ED02BD75EF | |||
| 328 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\History\Low\History.IE5\index.dat | dat | |
MD5:487B6237E84E430D958C5C1842C5FD06 | SHA256:F19D58B639AF9E8B4D2D4EE45E822B9EE76DC219B964C2A3E1FF006365128E98 | |||
| 328 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\R76YBY98\1561998334623[1].png | image | |
MD5:C9343042739BB5E44EF5D95963C37338 | SHA256:B30657D9F0598288070FD95BB0BF9C86BD389D93A14F83F3065D5B2562257598 | |||
| 328 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\index.dat | dat | |
MD5:8D7175D2194A170D5A794AE4FC5ED96A | SHA256:993890A11A7BAC62C16693C957724C84DBCC981EE032344AAB4C36B80B0A0B12 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
328 | iexplore.exe | GET | 301 | 35.244.218.203:80 | http://mergedocsnow.com/ | US | html | 236 b | whitelisted |
328 | iexplore.exe | GET | 302 | 35.244.218.203:80 | http://www.mergedocsnow.com/index.jhtml | US | — | — | whitelisted |
328 | iexplore.exe | GET | 301 | 35.244.218.203:80 | http://www.mergedocsnow.com/ | US | — | — | whitelisted |
328 | iexplore.exe | GET | 301 | 172.217.18.14:80 | http://google.com/ | US | html | 219 b | malicious |
2984 | iexplore.exe | GET | 302 | 204.79.197.203:80 | http://www.msn.com/?ocid=iehp | US | html | 152 b | whitelisted |
2984 | iexplore.exe | GET | 200 | 204.79.197.203:80 | http://www.msn.com/es-es/?ocid=iehp | US | html | 56.4 Kb | whitelisted |
328 | iexplore.exe | GET | 302 | 172.217.16.164:80 | http://www.google.com/ | US | html | 231 b | malicious |
2984 | iexplore.exe | GET | 302 | 23.8.11.188:80 | http://go.microsoft.com/fwlink/?LinkId=69157 | NL | — | — | whitelisted |
328 | iexplore.exe | GET | 200 | 172.217.16.164:80 | http://www.google.com/images/branding/googlelogo/1x/googlelogo_white_background_color_272x92dp.png | US | image | 5.35 Kb | malicious |
2984 | iexplore.exe | GET | 200 | 2.16.186.35:80 | http://static-global-s-msn-com.akamaized.net/hp-neu/sc/42/0a3221.eot? | unknown | eot | 46.9 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
328 | iexplore.exe | 35.244.218.203:80 | mergedocsnow.com | — | US | whitelisted |
1016 | iexplore.exe | 204.79.197.200:80 | www.bing.com | Microsoft Corporation | US | whitelisted |
328 | iexplore.exe | 35.244.218.203:443 | mergedocsnow.com | — | US | whitelisted |
328 | iexplore.exe | 104.108.65.89:443 | ak.staticimgfarm.com | Akamai Technologies, Inc. | NL | whitelisted |
328 | iexplore.exe | 172.217.16.170:443 | fonts.googleapis.com | Google Inc. | US | whitelisted |
328 | iexplore.exe | 172.217.23.99:443 | fonts.gstatic.com | Google Inc. | US | whitelisted |
328 | iexplore.exe | 23.37.54.24:443 | akz.imgfarm.com | Akamai Technologies, Inc. | NL | whitelisted |
1016 | iexplore.exe | 35.244.218.203:443 | mergedocsnow.com | — | US | whitelisted |
328 | iexplore.exe | 35.190.72.161:443 | c.securepaths.com | Google Inc. | US | whitelisted |
328 | iexplore.exe | 35.190.36.172:443 | cdn.fqtag.com | Google Inc. | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
mergedocsnow.com |
| whitelisted |
www.bing.com |
| whitelisted |
www.mergedocsnow.com |
| whitelisted |
fonts.googleapis.com |
| whitelisted |
ak.staticimgfarm.com |
| whitelisted |
akz.imgfarm.com |
| whitelisted |
fonts.gstatic.com |
| whitelisted |
ak.imgfarm.com |
| whitelisted |
mergedocsnow.dl.myway.com |
| whitelisted |
mergedocsnow.dl.tb.ask.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
1152 | chrome.exe | Attempted User Privilege Gain | ET INFO Session Traversal Utilities for NAT (STUN Binding Request) |
— | — | Attempted User Privilege Gain | ET INFO Session Traversal Utilities for NAT (STUN Binding Request) |
— | — | Attempted User Privilege Gain | ET INFO Session Traversal Utilities for NAT (STUN Binding Request) |
— | — | Attempted User Privilege Gain | ET INFO Session Traversal Utilities for NAT (STUN Binding Request) |
— | — | Attempted User Privilege Gain | ET INFO Session Traversal Utilities for NAT (STUN Binding Request) |
— | — | Attempted User Privilege Gain | ET INFO Session Traversal Utilities for NAT (STUN Binding Request) |
— | — | Attempted User Privilege Gain | ET INFO Session Traversal Utilities for NAT (STUN Binding Request) |
— | — | Attempted User Privilege Gain | ET INFO Session Traversal Utilities for NAT (STUN Binding Request) |
— | — | Attempted User Privilege Gain | ET INFO Session Traversal Utilities for NAT (STUN Binding Request) |
— | — | Attempted User Privilege Gain | ET INFO Session Traversal Utilities for NAT (STUN Binding Request) |