URL:

https://www.coolutils.com/Downloads/MailViewer.exe

Full analysis: https://app.any.run/tasks/8a4ecf65-930f-4e9d-83da-5b166fd20e32
Verdict: Suspicious activity
Analysis date: August 29, 2019, 05:03:14
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

FB34CF3CB724D78F630DF38545509425

SHA1:

7A8A12845E2627F856569ADCB5DD435AF422BA19

SHA256:

A2D1A95B4066F5424C111A2B334B7E962E544A0D1254CF5D09AB1D44B0458643

SSDEEP:

3:N8DSL0QRxZgKyJzB7LAdA:2OL0ELPyJF4C

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • MailViewer[1].exe (PID: 2444)
      • MailViewer[1].exe (PID: 3060)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • iexplore.exe (PID: 3196)
      • iexplore.exe (PID: 2868)
      • MailViewer[1].exe (PID: 2444)
      • MailViewer[1].exe (PID: 3060)
      • MailViewer[1].tmp (PID: 2808)
    • Reads the Windows organization settings

      • MailViewer[1].tmp (PID: 2808)
    • Reads Windows owner or organization settings

      • MailViewer[1].tmp (PID: 2808)
    • Modifies the open verb of a shell class

      • MailViewer[1].tmp (PID: 2808)
    • Starts Internet Explorer

      • MailViewer[1].tmp (PID: 1512)
    • Reads Environment values

      • MailViewer.exe (PID: 3980)
    • Executed via COM

      • FlashUtil32_26_0_0_131_ActiveX.exe (PID: 3208)
  • INFO

    • Changes internet zones settings

      • iexplore.exe (PID: 2868)
      • iexplore.exe (PID: 3264)
    • Reads Internet Cache Settings

      • iexplore.exe (PID: 3196)
      • iexplore.exe (PID: 2884)
    • Application launched itself

      • iexplore.exe (PID: 2868)
      • iexplore.exe (PID: 3264)
    • Creates files in the user directory

      • iexplore.exe (PID: 3196)
      • FlashUtil32_26_0_0_131_ActiveX.exe (PID: 3208)
      • iexplore.exe (PID: 2884)
      • iexplore.exe (PID: 3264)
    • Loads dropped or rewritten executable

      • MailViewer[1].tmp (PID: 2808)
    • Application was dropped or rewritten from another process

      • MailViewer[1].tmp (PID: 1512)
      • MailViewer[1].tmp (PID: 2808)
    • Creates files in the program directory

      • MailViewer[1].tmp (PID: 2808)
    • Creates a software uninstall entry

      • MailViewer[1].tmp (PID: 2808)
    • Reads settings of System Certificates

      • iexplore.exe (PID: 3264)
    • Reads internet explorer settings

      • iexplore.exe (PID: 2884)
    • Adds / modifies Windows certificates

      • iexplore.exe (PID: 3264)
    • Changes settings of System certificates

      • iexplore.exe (PID: 3264)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
46
Monitored processes
10
Malicious processes
0
Suspicious processes
4

Behavior graph

Click at the process to see the details
drop and start start drop and start drop and start iexplore.exe iexplore.exe mailviewer[1].exe mailviewer[1].tmp no specs mailviewer[1].exe mailviewer[1].tmp mailviewer.exe iexplore.exe iexplore.exe flashutil32_26_0_0_131_activex.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1512"C:\Users\admin\AppData\Local\Temp\is-FH0A9.tmp\MailViewer[1].tmp" /SL5="$301C0,18783646,119296,C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\MailViewer[1].exe" C:\Users\admin\AppData\Local\Temp\is-FH0A9.tmp\MailViewer[1].tmpMailViewer[1].exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-fh0a9.tmp\mailviewer[1].tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
2444"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\MailViewer[1].exe" /SPAWNWND=$3018A /NOTIFYWND=$301C0 C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\MailViewer[1].exe
MailViewer[1].tmp
User:
admin
Company:
Softplicity, Inc.
Integrity Level:
HIGH
Description:
CoolUtils Mail Viewer Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\lh043oam\mailviewer[1].exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2808"C:\Users\admin\AppData\Local\Temp\is-GU9BQ.tmp\MailViewer[1].tmp" /SL5="$4016A,18783646,119296,C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\MailViewer[1].exe" /SPAWNWND=$3018A /NOTIFYWND=$301C0 C:\Users\admin\AppData\Local\Temp\is-GU9BQ.tmp\MailViewer[1].tmp
MailViewer[1].exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-gu9bq.tmp\mailviewer[1].tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2868"C:\Program Files\Internet Explorer\iexplore.exe" -nohomeC:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
1
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2884"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3264 CREDAT:71937C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3060"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\MailViewer[1].exe" C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\MailViewer[1].exe
iexplore.exe
User:
admin
Company:
Softplicity, Inc.
Integrity Level:
MEDIUM
Description:
CoolUtils Mail Viewer Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\lh043oam\mailviewer[1].exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
3196"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2868 CREDAT:71937C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3208C:\Windows\system32\Macromed\Flash\FlashUtil32_26_0_0_131_ActiveX.exe -EmbeddingC:\Windows\system32\Macromed\Flash\FlashUtil32_26_0_0_131_ActiveX.exesvchost.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
MEDIUM
Description:
Adobe® Flash® Player Installer/Uninstaller 26.0 r0
Exit code:
0
Version:
26,0,0,131
Modules
Images
c:\windows\system32\macromed\flash\flashutil32_26_0_0_131_activex.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3264"C:\Program Files\Internet Explorer\iexplore.exe" -nohomeC:\Program Files\Internet Explorer\iexplore.exe
MailViewer[1].tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3980"C:\Program Files\CoolUtils\CoolUtils Mail Viewer\MailViewer.exe" -initC:\Program Files\CoolUtils\CoolUtils Mail Viewer\MailViewer.exe
MailViewer[1].tmp
User:
admin
Company:
Softplicity
Integrity Level:
MEDIUM
Description:
Mail Viewer
Exit code:
0
Version:
4.1.0.15
Modules
Images
c:\program files\coolutils\coolutils mail viewer\mailviewer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
Total events
1 828
Read events
1 652
Write events
166
Delete events
10

Modification events

(PID) Process:(2868) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(2868) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(2868) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(2868) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones
Operation:writeName:SecuritySafe
Value:
1
(PID) Process:(2868) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(2868) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
4600000092000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
(PID) Process:(2868) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Recovery\Active
Operation:writeName:{54B1BA8B-CA1A-11E9-B86F-5254004A04AF}
Value:
0
(PID) Process:(2868) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Type
Value:
4
(PID) Process:(2868) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Count
Value:
2
(PID) Process:(2868) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Time
Value:
E307080004001D00050003001A007001
Executable files
8
Suspicious files
2
Text files
92
Unknown types
32

Dropped files

PID
Process
Filename
Type
2868iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\favicon[1].ico
MD5:
SHA256:
2868iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
MD5:
SHA256:
2868iexplore.exeC:\Users\admin\AppData\Local\Temp\~DFBB0D1AB87B34FAEA.TMP
MD5:
SHA256:
2868iexplore.exeC:\Users\admin\AppData\Local\Temp\~DFA110C260B40FD175.TMP
MD5:
SHA256:
2868iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{54B1BA8B-CA1A-11E9-B86F-5254004A04AF}.dat
MD5:
SHA256:
3196iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\index.datdat
MD5:
SHA256:
2808MailViewer[1].tmpC:\Program Files\CoolUtils\CoolUtils Mail Viewer\is-DPBUG.tmp
MD5:
SHA256:
3196iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\History\Low\History.IE5\index.datdat
MD5:
SHA256:
2808MailViewer[1].tmpC:\Program Files\CoolUtils\CoolUtils Mail Viewer\is-76VCF.tmp
MD5:
SHA256:
3196iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\admin@coolutils[1].txttext
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
37
DNS requests
15
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2884
iexplore.exe
GET
301
104.27.156.34:80
http://www.coolutils.com/MailViewer/
US
whitelisted
2868
iexplore.exe
GET
200
204.79.197.200:80
http://www.bing.com/favicon.ico
US
image
237 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2868
iexplore.exe
204.79.197.200:80
www.bing.com
Microsoft Corporation
US
whitelisted
3196
iexplore.exe
104.27.156.34:443
www.coolutils.com
Cloudflare Inc
US
shared
2884
iexplore.exe
104.27.156.34:443
www.coolutils.com
Cloudflare Inc
US
shared
2884
iexplore.exe
104.27.156.34:80
www.coolutils.com
Cloudflare Inc
US
shared
2884
iexplore.exe
205.185.208.52:443
code.jquery.com
Highwinds Network Group, Inc.
US
unknown
2884
iexplore.exe
209.197.3.15:443
maxcdn.bootstrapcdn.com
Highwinds Network Group, Inc.
US
whitelisted
2884
iexplore.exe
172.217.18.104:443
www.googletagmanager.com
Google Inc.
US
suspicious
2884
iexplore.exe
104.18.71.113:443
assets.zendesk.com
Cloudflare Inc
US
shared
2884
iexplore.exe
172.217.18.3:443
ssl.gstatic.com
Google Inc.
US
whitelisted
2884
iexplore.exe
172.217.16.142:443
www.youtube.com
Google Inc.
US
whitelisted

DNS requests

Domain
IP
Reputation
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
www.coolutils.com
  • 104.27.156.34
  • 104.27.157.34
whitelisted
code.jquery.com
  • 205.185.208.52
whitelisted
maxcdn.bootstrapcdn.com
  • 209.197.3.15
whitelisted
www.googletagmanager.com
  • 172.217.18.104
whitelisted
assets.zendesk.com
  • 104.18.71.113
  • 104.18.72.113
  • 104.18.73.113
  • 104.18.74.113
  • 104.18.70.113
whitelisted
ssl.gstatic.com
  • 172.217.18.3
whitelisted
www.youtube.com
  • 172.217.16.142
  • 172.217.22.46
  • 172.217.22.78
  • 216.58.210.14
  • 172.217.16.206
  • 172.217.18.110
  • 172.217.23.174
  • 172.217.21.206
  • 216.58.205.238
  • 172.217.18.14
  • 172.217.18.174
  • 172.217.23.142
  • 216.58.206.14
  • 216.58.207.46
  • 216.58.207.78
  • 172.217.16.174
whitelisted
www.google-analytics.com
  • 172.217.16.174
whitelisted
mc.yandex.ru
  • 87.250.251.119
  • 87.250.250.119
  • 77.88.21.119
  • 93.158.134.119
whitelisted

Threats

No threats detected
Process
Message
MailViewer.exe
TMailEMLTask
MailViewer.exe
TEMLViewerTask
MailViewer.exe
TEMLViewerTask
MailViewer.exe
TEMLViewerTask
MailViewer.exe
TEMLViewerTask
MailViewer.exe
TMailHTMLTask
MailViewer.exe
ThclHTMTIFFTask
MailViewer.exe
TMailTaskOther
MailViewer.exe
TMailTaskOther
MailViewer.exe
TMailTaskOther