analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
URL:

http://www.apothekerbank.com

Full analysis: https://app.any.run/tasks/e728fd46-9947-4315-861b-639c1bcc354c
Verdict: Malicious activity
Analysis date: July 18, 2019, 10:54:05
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
adware
Indicators:
MD5:

B8BC324E4A852EAC9F3DBA8CD5A7B246

SHA1:

AA8B2155667104A9001C5AA79775C35952943E47

SHA256:

B3837AE93865EEACEB63E2868E4E46D91BD25E2F77ED9994A3C13D359B478394

SSDEEP:

3:N1KJS4bUvY:Cc4gvY

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Application launched itself

      • iexplore.exe (PID: 3692)
    • Changes internet zones settings

      • iexplore.exe (PID: 3692)
    • Reads internet explorer settings

      • iexplore.exe (PID: 3744)
    • Reads Internet Cache Settings

      • iexplore.exe (PID: 3744)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
36
Monitored processes
2
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe

Process information

PID
CMD
Path
Indicators
Parent process
3692"C:\Program Files\Internet Explorer\iexplore.exe" -nohomeC:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
3744"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3692 CREDAT:71937C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Total events
376
Read events
315
Write events
59
Delete events
2

Modification events

(PID) Process:(3692) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(3692) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(3692) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(3692) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones
Operation:writeName:SecuritySafe
Value:
1
(PID) Process:(3692) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(3692) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
4600000078000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
(PID) Process:(3692) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Recovery\Active
Operation:writeName:{6510BF85-A94A-11E9-95C0-5254004A04AF}
Value:
0
(PID) Process:(3692) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Type
Value:
4
(PID) Process:(3692) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Count
Value:
2
(PID) Process:(3692) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Time
Value:
E3070700040012000A00360015002201
Executable files
0
Suspicious files
0
Text files
4
Unknown types
3

Dropped files

PID
Process
Filename
Type
3692iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGRR2OYX\favicon[1].ico
MD5:
SHA256:
3692iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
MD5:
SHA256:
3744iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\8BW8CI0Y\apothekerbank_com[1].txt
MD5:
SHA256:
3744iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PUF80D1U\iyfsearch_com[1].txt
MD5:
SHA256:
3692iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012019071820190719\index.datdat
MD5:164623AAEBF23524A569479F6040C2F1
SHA256:961B7329297A8AF2DEA6332B82DE129661840F398E935A1E51E87A725C89D767
3744iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\THOJPES7\apothekerbank_com[1].htmhtml
MD5:7BD5C5BD545A79F2502AEEE7DF48A828
SHA256:C0C03D239A06C65217DDF71B7066C4BE108771F0DA2FB6ED14E0A07F09039E27
3744iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\History\Low\History.IE5\index.datdat
MD5:79CF49B0C1FA9E963958E92033B83439
SHA256:B8915BC1063AF23FF6E957828C7834FAB95544E93231E4795EA252B580C5AA57
3744iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\8BW8CI0Y\js3[1].jstext
MD5:DB3CACFB57BA35D3FCFDBBCF7D46BD42
SHA256:A606134E35DB97024D04789609660C94F87F660DC259D91DB5180E32787D4DAD
3744iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\History\Low\History.IE5\MSHist012019071820190719\index.datdat
MD5:010DA20FAEC3BB5A71F7A993D76C8FC8
SHA256:3AA6CEEA9269A47F0361B6B552A1B5C60839F2EA4CCE9072054CBF4815531B92
3692iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGRR2OYX\favicon[1].pngimage
MD5:9FB559A691078558E77D6848202F6541
SHA256:6D8A01DC7647BC218D003B58FE04049E24A9359900B7E0CEBAE76EDF85B8B914
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
6
DNS requests
4
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3692
iexplore.exe
GET
200
185.53.179.6:80
http://www.apothekerbank.com/favicon.ico
DE
malicious
3744
iexplore.exe
GET
200
185.53.179.6:80
http://www.apothekerbank.com/
DE
html
923 b
malicious
3744
iexplore.exe
GET
200
185.53.179.29:80
http://parkingcrew.net/assets/scripts/js3.js
DE
text
17.5 Kb
whitelisted
3692
iexplore.exe
GET
200
204.79.197.200:80
http://www.bing.com/favicon.ico
US
image
237 b
whitelisted
3744
iexplore.exe
GET
200
185.53.179.6:80
http://www.apothekerbank.com/track.php?domain=apothekerbank.com&toggle=browserjs&uid=MTU2MzQ0NzI2MS44Njg5Ojk5MDI0YzczMzc1MWRhNDA2MzUyNGNkNmRjNjUzZWZlOWEyYjhmMzcwMTFhZDk4NzIwNDdhMjhjNDVmYWYzYWI6NWQzMDRmZGRkNDI3MQ%3D%3D
DE
binary
20 b
malicious
3744
iexplore.exe
GET
200
208.91.196.46:80
http://iyfsearch.com/?dn=apothekerbank.com&pid=9PO755G95
VG
html
196 b
suspicious
3692
iexplore.exe
GET
404
208.91.196.46:80
http://iyfsearch.com/favicon.ico
VG
text
30 b
suspicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3692
iexplore.exe
204.79.197.200:80
www.bing.com
Microsoft Corporation
US
whitelisted
3744
iexplore.exe
185.53.179.29:80
parkingcrew.net
Team Internet AG
DE
malicious
3744
iexplore.exe
185.53.179.6:80
www.apothekerbank.com
Team Internet AG
DE
malicious
3692
iexplore.exe
185.53.179.6:80
www.apothekerbank.com
Team Internet AG
DE
malicious
3744
iexplore.exe
208.91.196.46:80
iyfsearch.com
Confluence Networks Inc
VG
malicious
3692
iexplore.exe
208.91.196.46:80
iyfsearch.com
Confluence Networks Inc
VG
malicious

DNS requests

Domain
IP
Reputation
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
www.apothekerbank.com
  • 185.53.179.6
malicious
parkingcrew.net
  • 185.53.179.29
whitelisted
iyfsearch.com
  • 208.91.196.46
suspicious

Threats

PID
Process
Class
Message
3744
iexplore.exe
Misc activity
ADWARE [PTsecurity] InstantAccess
No debug info