URL:

https://security.feishu.cn/link/safety

Full analysis: https://app.any.run/tasks/ff7951e8-4845-4c9d-95c2-2308ae4d23a3
Verdict: Malicious activity
Analysis date: May 03, 2023, 12:02:20
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

E795F533B84CFB96E5F9E1D285AE9189

SHA1:

DA6BCFB3B3C69631D90D03FDC1E7B83B92D0362A

SHA256:

B71A463383B572A9B4A4008F392BAA5609B4B6582FA9115058EB723AF80DCE6A

SSDEEP:

3:N8N3QddZfMEDl:2ZQdbz

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Create files in a temporary directory

      • iexplore.exe (PID: 3320)
    • Application launched itself

      • iexplore.exe (PID: 3320)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
37
Monitored processes
2
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe

Process information

PID
CMD
Path
Indicators
Parent process
3320"C:\Program Files\Internet Explorer\iexplore.exe" "https://security.feishu.cn/link/safety"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
3764"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3320 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
Total events
31 152
Read events
30 952
Write events
200
Delete events
0

Modification events

(PID) Process:(3320) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
0
(PID) Process:(3320) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30847387
(PID) Process:(3320) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30847437
(PID) Process:(3320) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3320) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3320) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(3320) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3320) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3320) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3320) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
0
Suspicious files
61
Text files
28
Unknown types
1

Dropped files

PID
Process
Filename
Type
3764iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\DOTBATAV\www.larksuite[1].xmltext
MD5:C1DDEA3EF6BBEF3E7060A1A9AD89E4C5
SHA256:B71E4D17274636B97179BA2D97C742735B6510EB54F22893D3A2DAFF2CEB28DB
3764iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\26C212D9399727259664BDFCA073966E_600EF020C96CF8AAA331625500A5DDA1binary
MD5:09AA4C86916C65174B65F7E6AE1D6DEA
SHA256:BBBEF29A97373CC46142B55572083F65A884279613E8C549D26A62D4DF5AFC91
3764iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B398B80134F72209547439DB21AB308D_C30613620F21879F76DA4316E8295D21binary
MD5:34749DA66512A546E1FEDA8F9063F086
SHA256:F1785C4190D341E41E68AED6685964BF8CC92F5CEE3F3F86931AC3308FF5BACE
3764iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B398B80134F72209547439DB21AB308D_23FFFDCAABB8E63694AD1202ED02BF57binary
MD5:1A773E29294C1C6A926C74E7260D94ED
SHA256:1A1A550C0231027E7A18B650BC04E2C57655FC1EA03EF0C1E4BC433BF25B8505
3764iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B398B80134F72209547439DB21AB308D_C30613620F21879F76DA4316E8295D21binary
MD5:BDC87C2FECC50142B3C83E7EF6A04E1A
SHA256:1950C2F0E229ABBEE8D7DEF6CA017FE96343D7A0440E057AE8E4C9875E852168
3764iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\banner-sdk.1.1.6[1].jstext
MD5:F0A0D2FD46B6EB91B1DCA4A51FD7B7CC
SHA256:54D03DCA16597E69B1A86CFAD4C443373D3497FE4B77198E0D199313C789EE4E
3764iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\passport-js-apis-1.0.0.7[1].jstext
MD5:F3E745F222FF4E312CBB15D5D2A5BEE4
SHA256:2DF55CDA21635FDC23A1839F7745013F92F0E7A753BD9647759027C3E6F20C7B
3320iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157compressed
MD5:F7DCB24540769805E5BB30D193944DCE
SHA256:6B88C6AC55BBD6FEA0EBE5A760D1AD2CFCE251C59D0151A1400701CB927E36EA
3764iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\646C991C2A28825F3CC56E0A1D1E3FA9der
MD5:25CC888C0511688AB4377714BFEE473B
SHA256:40DCC1747E2B52F3401F73C2D515ADB2F996CC0C869C2274E508BA1B2B1F7C5D
3320iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:07D41F15CAE217C2B84CBFEA18ED6D21
SHA256:A93E2F046F5D8E2BBBDC1AFB28CA0C8C2E46E6FAB69CA64F89D784EA6202C720
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
18
TCP/UDP connections
67
DNS requests
27
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3764
iexplore.exe
GET
108.138.2.173:80
http://o.ss2.us//MEowSDBGMEQwQjAJBgUrDgMCGgUABBSLwZ6EW5gdYc9UaSEaaLjjETNtkAQUv1%2B30c7dH4b0W1Ws3NcQwg6piOcCCQCnDkpMNIK3fw%3D%3D
US
whitelisted
3764
iexplore.exe
GET
200
142.250.184.227:80
http://ocsp.pki.goog/gts1c3/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEQCbYOZ%2FvtI35BCTLgvKp3nV
US
der
472 b
whitelisted
3764
iexplore.exe
GET
200
192.229.221.95:80
http://crl3.digicert.com/DigiCertGlobalRootCA.crl
US
der
779 b
whitelisted
3764
iexplore.exe
GET
200
192.229.221.95:80
http://crl3.digicert.com/RapidSSLGlobalTLSRSA4096SHA2562022CA1.crl
US
binary
365 Kb
whitelisted
3764
iexplore.exe
GET
200
52.222.250.174:80
http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwdzEjgLnWaIozse2b%2BczaaODg8%3D
US
binary
1.39 Kb
shared
3764
iexplore.exe
GET
200
52.222.250.42:80
http://ocsp.rootg2.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBSIfaREXmfqfJR3TkMYnD7O5MhzEgQUnF8A36oB1zArOIiiuG1KnPIRkYMCEwZ%2FlEoqJ83z%2BsKuKwH5CO65xMY%3D
US
der
1.51 Kb
whitelisted
3764
iexplore.exe
GET
200
142.250.184.227:80
http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFNZazTHGPUBUGY%3D
US
der
724 b
whitelisted
3320
iexplore.exe
GET
200
192.229.221.95:80
http://crl3.digicert.com/Omniroot2025.crl
US
binary
7.78 Kb
whitelisted
3764
iexplore.exe
GET
200
142.250.184.227:80
http://ocsp.pki.goog/gts1c3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEH0tNUTr%2B0qZCadrlevKPFs%3D
US
der
471 b
whitelisted
3764
iexplore.exe
GET
200
52.222.250.174:80
http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwdzEjgLnWaIozse2b%2BczaaODg8%3D
US
der
1.39 Kb
shared
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3764
iexplore.exe
23.36.162.205:443
security.feishu.cn
Akamai International B.V.
DE
suspicious
3320
iexplore.exe
2.16.187.139:443
www.bing.com
Akamai International B.V.
DE
malicious
3764
iexplore.exe
209.197.3.8:80
ctldl.windowsupdate.com
STACKPATH-CDN
US
whitelisted
3764
iexplore.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
23.36.162.213:443
security.feishu.cn
Akamai International B.V.
DE
suspicious
193.108.153.7:443
www.larksuite.com
Akamai International B.V.
DE
suspicious
142.250.184.206:443
www.googleoptimize.com
GOOGLE
US
whitelisted
3764
iexplore.exe
142.250.185.109:443
accounts.google.com
GOOGLE
US
suspicious
3764
iexplore.exe
2.16.186.16:443
sf16-scmcdn.larksuitecdn.com
Akamai International B.V.
DE
whitelisted
3764
iexplore.exe
13.32.99.20:443
events.framer.com
AMAZON-02
US
unknown

DNS requests

Domain
IP
Reputation
security.feishu.cn
  • 23.36.162.205
  • 23.36.162.213
suspicious
ctldl.windowsupdate.com
  • 209.197.3.8
whitelisted
api.bing.com
  • 13.107.5.80
whitelisted
www.bing.com
  • 2.16.187.139
  • 2.16.187.106
  • 2.16.187.98
  • 2.16.187.10
  • 2.16.187.147
  • 2.16.187.59
  • 2.16.187.11
  • 2.16.187.89
  • 2.16.187.138
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
www.feishu.cn
  • 23.36.162.213
  • 23.36.162.205
malicious
www.larksuite.com
  • 193.108.153.7
  • 193.108.153.15
whitelisted
www.googleoptimize.com
  • 142.250.184.206
whitelisted
sf16-scmcdn.larksuitecdn.com
  • 2.16.186.16
  • 2.16.186.27
suspicious
lf16-oversea.goofy-cdn.com
  • 2.16.186.41
  • 2.16.186.40
suspicious

Threats

No threats detected
No debug info