analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
URL:

http://st.douding.cn/images_cn/people01.gif

Full analysis: https://app.any.run/tasks/6646db5e-8a22-490d-bdad-df43c3c7a617
Verdict: Malicious activity
Analysis date: August 13, 2019, 20:41:29
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

93A42DC943E32E6273B26D648246FC88

SHA1:

ED5E928B9D678A8928237EA7B67DF6B02F2CB2C4

SHA256:

A7CAABCF3A59130FB2541AAB153E8A74D6FD348CF39C4CF7CF6DC57ACDF48FE5

SSDEEP:

3:N1KNRQQWG++UL7n:CsQozn

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Creates files in the user directory

      • iexplore.exe (PID: 2612)
      • iexplore.exe (PID: 1820)
    • Application launched itself

      • iexplore.exe (PID: 2612)
    • Reads internet explorer settings

      • iexplore.exe (PID: 1820)
    • Reads Internet Cache Settings

      • iexplore.exe (PID: 1820)
    • Changes internet zones settings

      • iexplore.exe (PID: 2612)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
36
Monitored processes
2
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe

Process information

PID
CMD
Path
Indicators
Parent process
2612"C:\Program Files\Internet Explorer\iexplore.exe" "http://st.douding.cn/images_cn/people01.gif"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
1820"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2612 CREDAT:71937C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Total events
380
Read events
319
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
0
Text files
9
Unknown types
4

Dropped files

PID
Process
Filename
Type
2612iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\favicon[1].ico
MD5:
SHA256:
2612iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
MD5:
SHA256:
1820iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\U3DE0HI7\people01[1].gifimage
MD5:AA3018CEFEBE70634720A1EBDF46B153
SHA256:8A1B7C2959575392C4C57D26FE5AAB31644782F44C50589B5F52E8496BDEEEC9
1820iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\History\Low\History.IE5\index.datdat
MD5:CE2EB09F57DC51E0E32D614463FB08EE
SHA256:9BDD02392D3A21BF85C117AA83A098585EEC8A02C39B6DEF3332622EF20548CB
1820iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\index.datdat
MD5:FB99F6E75981452326EFF63AA79C728E
SHA256:BFED017E2FB529F08C49B5CB870C7429F229D048A76C4121A7DAE183BCA2F50E
1820iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\History\Low\History.IE5\MSHist012019081320190814\index.datdat
MD5:A4BEAA8C335D7CE9688544272A049136
SHA256:A2BEB7359BD8033EA7B635FBB2418D3A576AC00E24FB55FC367681299DCF8A1A
2612iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012019081320190814\index.datdat
MD5:1978D653A48680B916984DB8C62C9A85
SHA256:DCBA5D24022C8ADAF2096FEB92A2286234B6036943ED720BD94568B9C14D22B7
1820iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\8JPRJ8WW\page[1]image
MD5:546F8595BFEFD0AF3418AC99F2F00243
SHA256:52EEB78B165D39971042A910AF7EF991EB712326CA973E0346CF986173657068
1820iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\WSBDT7EL\docbrows[1]text
MD5:BFABAE6905F98B838415EE9C239B337C
SHA256:055DB79C14CCC2AAE85342ABDAF6FF9B87AC953841C7C5E7A8F8D02ED9BD56F4
1820iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\WSBDT7EL\desktop.iniini
MD5:4A3DEB274BB5F0212C2419D3D8D08612
SHA256:2842973D15A14323E08598BE1DFB87E54BF88A76BE8C7BC94C56B079446EDF38
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
3
DNS requests
2
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1820
iexplore.exe
GET
200
163.171.132.119:80
http://st.douding.cn/images_cn/people01.gif
US
image
1.66 Kb
malicious
2612
iexplore.exe
GET
200
163.171.132.119:80
http://st.douding.cn/favicon.ico
US
image
894 b
malicious
2612
iexplore.exe
GET
200
204.79.197.200:80
http://www.bing.com/favicon.ico
US
image
237 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2612
iexplore.exe
163.171.132.119:80
st.douding.cn
US
malicious
1820
iexplore.exe
163.171.132.119:80
st.douding.cn
US
malicious
2612
iexplore.exe
204.79.197.200:80
www.bing.com
Microsoft Corporation
US
whitelisted

DNS requests

Domain
IP
Reputation
st.douding.cn
  • 163.171.132.119
malicious
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted

Threats

No threats detected
No debug info