| URL: | https://arabianinfotech.fortiddns.com/~ROlah |
| Full analysis: | https://app.any.run/tasks/d59a5d08-faa1-441c-973b-74484aed4488 |
| Verdict: | Malicious activity |
| Analysis date: | December 10, 2023, 13:11:27 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MD5: | 4EE14B2042B7A86856ACBFB71E30B49D |
| SHA1: | 90AF7B530926320585726E18F9283487B64CC5F6 |
| SHA256: | B337907132B40600B644BB7039883718CB700A4D2530576BD928969D405AB9ED |
| SSDEEP: | 3:N8fma8q7saW:2fL1tW |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 148 | "C:\Users\admin\AppData\Local\Temp\GLJ435D.tmp" C:\Windows\System32\MSINET.OCX | C:\Users\admin\AppData\Local\Temp\GLJ435D.tmp | cat-xbf104x.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 284 | "C:\Users\admin\AppData\Local\Temp\GLJ435D.tmp" C:\Windows\System32\Grid32.ocx | C:\Users\admin\AppData\Local\Temp\GLJ435D.tmp | cat-xbf104x.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 564 | "C:\Users\admin\AppData\Local\Temp\GLJ435D.tmp" C:\Windows\System32\wRTF2PDF01.dll | C:\Users\admin\AppData\Local\Temp\GLJ435D.tmp | cat-xbf104x.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 1 Modules
| |||||||||||||||
| 732 | "C:\E20-II\SSNDBU10.exe" C:\E20-II\CSI11INS.INI | C:\E20-II\SSNDBU10.exe | cat-xbf104x.exe | ||||||||||||
User: admin Company: Carrier Integrity Level: HIGH Exit code: 0 Version: 1.00 Modules
| |||||||||||||||
| 752 | "C:\Users\admin\AppData\Local\Temp\GLJ435D.tmp" C:\Windows\System32\Dzip32.dll | C:\Users\admin\AppData\Local\Temp\GLJ435D.tmp | cat-xbf104x.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 1 Modules
| |||||||||||||||
| 788 | "C:\Users\admin\AppData\Local\Temp\GLJ435D.tmp" C:\Windows\System32\MSCOMCT2.OCX | C:\Users\admin\AppData\Local\Temp\GLJ435D.tmp | cat-xbf104x.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 924 | "C:\Users\admin\AppData\Local\Temp\GLJ435D.tmp" C:\Windows\System32\msxml3a.dll | C:\Users\admin\AppData\Local\Temp\GLJ435D.tmp | cat-xbf104x.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 1 Modules
| |||||||||||||||
| 952 | "C:\Users\admin\AppData\Local\Temp\GLJ435D.tmp" C:\Windows\System32\COMCT232.OCX | C:\Users\admin\AppData\Local\Temp\GLJ435D.tmp | cat-xbf104x.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 988 | C:\Windows\system32\DllHost.exe /Processid:{76D0CB12-7604-4048-B83C-1005C7DDC503} | C:\Windows\System32\dllhost.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: COM Surrogate Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1032 | "C:\Users\admin\AppData\Local\Temp\GLJ435D.tmp" C:\Windows\System32\Msjter32.dll | C:\Users\admin\AppData\Local\Temp\GLJ435D.tmp | cat-xbf104x.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 1 Modules
| |||||||||||||||
| (PID) Process: | (1996) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPDaysSinceLastAutoMigration |
Value: 0 | |||
| (PID) Process: | (1996) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPLastLaunchHighDateTime |
Value: 30847387 | |||
| (PID) Process: | (1996) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager |
| Operation: | write | Name: | NextCheckForUpdateHighDateTime |
Value: 30847437 | |||
| (PID) Process: | (1996) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (1996) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (1996) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main |
| Operation: | write | Name: | CompatibilityFlags |
Value: 0 | |||
| (PID) Process: | (1996) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (1996) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (1996) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (1996) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2632 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157 | compressed | |
MD5:1BFE591A4FE3D91B03CDF26EAACD8F89 | SHA256:9CF94355051BF0F4A45724CA20D1CC02F76371B963AB7D1E38BD8997737B13D8 | |||
| 2632 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157 | binary | |
MD5:637B37566CF15CD6E6D43092AA2AA25E | SHA256:996D419731304DADBC20F8A3647DE3414B140ECC31FC7745C3DA0974AA923B2F | |||
| 2632 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\54C62B182F5BF07FA8427C07B0A3AAF8_786EA6C36BF7ABFF201B638497282D19 | binary | |
MD5:A8E86E44B41C4ED02AA16547FE7E7241 | SHA256:7F4350585AC67F5A6FB743369739A60F42553D137D0A7D3023824FEE2BEAA6C8 | |||
| 2632 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\default[1].htm | html | |
MD5:BB24E88B57FD5BCBF0466AE233D43D93 | SHA256:C6BE65F079E43DE63775010C185437CA8E22E29D6BC97AB9FEB0E5D4FBF4D5BD | |||
| 2632 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\54C62B182F5BF07FA8427C07B0A3AAF8_786EA6C36BF7ABFF201B638497282D19 | binary | |
MD5:1731B881960AC78FBBC0FFE5ACDCD598 | SHA256:E8C9CB8012AA47F312FF30B97CD254470E1494D511EE1DB9E31FE7722D68AA7C | |||
| 2632 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\CE7B026C819922EDB9B7ED78605E20A3_AF7F10BA33CEEF74214EEC8D707EB0CD | binary | |
MD5:224CCD57E01039272C5054629F5A4330 | SHA256:DAC048C2D1E28843EF083116B9E6AC915E960D44634AD5C903FDB8582F5989B2 | |||
| 2632 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\main.popup.bundle.min[1].css | text | |
MD5:5881391F45CAFD2FC858E3F14E54B9F4 | SHA256:0E9B826DEA54F30650091A0547B60614C8D8C90203724AAC05F07461C68C234C | |||
| 2632 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\intranet-common.min[1].css | text | |
MD5:C58B59964F1EFE8AEC5FD6A01AB11701 | SHA256:53A635376D76CB25DCDA38D08ED5B7E1897F47ABDF2ED1A54892D43D0F43AD51 | |||
| 2632 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\ui.design-tokens.min[1].css | text | |
MD5:8178992021C7160F587A2BFB4EE68011 | SHA256:82B3457E90BC5418C672127C440E8A8A9BDC72CBCDE7672ADC98BA94A7CE0334 | |||
| 2632 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\bitrix24-design-tokens.min[1].css | text | |
MD5:44160F099A56298219CA37C452F5D1A8 | SHA256:95A4C11BE57D915F3E67D6037E3A2E4AFA21CED834958A0AEE7AE5116D8FE33A | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2632 | iexplore.exe | GET | 200 | 184.24.77.202:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?282a5f2988aaef25 | unknown | compressed | 4.66 Kb | unknown |
2632 | iexplore.exe | GET | 200 | 184.24.77.202:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?b27ea2cbe4dcc735 | unknown | compressed | 4.66 Kb | unknown |
2632 | iexplore.exe | GET | 200 | 100.24.223.135:80 | http://ocsps.ssl.com/MEkwRzBFMEMwQTAJBgUrDgMCGgUABBQMDtATfnJO6JAXDQoHl8pAaJdhTQQU3QQJB6L1en1SUxKSle44gCUNplkCCAmX7RCdHwf8 | unknown | binary | 719 b | unknown |
2632 | iexplore.exe | GET | 200 | 100.24.223.135:80 | http://ocsps.ssl.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTUkpS%2BK0oZhSMx%2FmmCZ76UqdjUxQQUJhR%2B4NzXpvfi1AQn32HxwuznMsoCEEzIi4BfbVSq%2Fo8GLSr%2FMe4%3D | unknown | binary | 1.77 Kb | unknown |
1996 | iexplore.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAzlnDD9eoNTLi0BRrMy%2BWU%3D | unknown | binary | 313 b | unknown |
1080 | svchost.exe | GET | 200 | 88.221.110.106:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?a7e79e1b6451585f | unknown | compressed | 65.2 Kb | unknown |
1996 | iexplore.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | binary | 471 b | unknown |
1996 | iexplore.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAqvpsXKY8RRQeo74ffHUxc%3D | unknown | binary | 471 b | unknown |
1996 | iexplore.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | binary | 471 b | unknown |
1996 | iexplore.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA177el9ggmWelJjG4vdGL0%3D | unknown | binary | 471 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2632 | iexplore.exe | 86.98.52.11:443 | arabianinfotech.fortiddns.com | Emirates Telecommunications Corporation | AE | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
2632 | iexplore.exe | 184.24.77.202:80 | ctldl.windowsupdate.com | Akamai International B.V. | DE | unknown |
2632 | iexplore.exe | 100.24.223.135:80 | ocsps.ssl.com | AMAZON-AES | US | unknown |
1996 | iexplore.exe | 86.98.52.11:443 | arabianinfotech.fortiddns.com | Emirates Telecommunications Corporation | AE | unknown |
1996 | iexplore.exe | 92.123.104.33:443 | www.bing.com | Akamai International B.V. | DE | unknown |
1996 | iexplore.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
arabianinfotech.fortiddns.com |
| unknown |
ctldl.windowsupdate.com |
| whitelisted |
ocsps.ssl.com |
| whitelisted |
api.bing.com |
| whitelisted |
www.bing.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
r20swj13mr.microsoft.com |
| whitelisted |
iecvlist.microsoft.com |
| whitelisted |
ieonline.microsoft.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
Process | Message |
|---|---|
cat-xbf104x.exe | FTH: (3812): *** Fault tolerant heap shim applied to current process. This is usually due to previous crashes. ***
|
FWRunning.exe | FTH: (2760): *** Fault tolerant heap shim applied to current process. This is usually due to previous crashes. ***
|
XBGetRegion10.exe | FTH: (2972): *** Fault tolerant heap shim applied to current process. This is usually due to previous crashes. ***
|
CompatMode.exe | FTH: (3724): *** Fault tolerant heap shim applied to current process. This is usually due to previous crashes. ***
|
ecat-ECP211.exe | FTH: (2892): *** Fault tolerant heap shim applied to current process. This is usually due to previous crashes. ***
|
GLJE1D0.tmp | FTH: (2924): *** Fault tolerant heap shim applied to current process. This is usually due to previous crashes. ***
|
GLJ435D.tmp | FTH: (3248): *** Fault tolerant heap shim applied to current process. This is usually due to previous crashes. ***
|
GLJ435D.tmp | FTH: (1992): *** Fault tolerant heap shim applied to current process. This is usually due to previous crashes. ***
|
GLJ435D.tmp | FTH: (3324): *** Fault tolerant heap shim applied to current process. This is usually due to previous crashes. ***
|
GLJ435D.tmp | FTH: (3532): *** Fault tolerant heap shim applied to current process. This is usually due to previous crashes. ***
|