| URL: | https://security.feishu.cn/link/safety |
| Full analysis: | https://app.any.run/tasks/ff7951e8-4845-4c9d-95c2-2308ae4d23a3 |
| Verdict: | Malicious activity |
| Analysis date: | May 03, 2023, 12:02:20 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MD5: | E795F533B84CFB96E5F9E1D285AE9189 |
| SHA1: | DA6BCFB3B3C69631D90D03FDC1E7B83B92D0362A |
| SHA256: | B71A463383B572A9B4A4008F392BAA5609B4B6582FA9115058EB723AF80DCE6A |
| SSDEEP: | 3:N8N3QddZfMEDl:2ZQdbz |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 3320 | "C:\Program Files\Internet Explorer\iexplore.exe" "https://security.feishu.cn/link/safety" | C:\Program Files\Internet Explorer\iexplore.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| 3764 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3320 CREDAT:267521 /prefetch:2 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| (PID) Process: | (3320) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPDaysSinceLastAutoMigration |
Value: 0 | |||
| (PID) Process: | (3320) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPLastLaunchHighDateTime |
Value: 30847387 | |||
| (PID) Process: | (3320) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager |
| Operation: | write | Name: | NextCheckForUpdateHighDateTime |
Value: 30847437 | |||
| (PID) Process: | (3320) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (3320) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (3320) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main |
| Operation: | write | Name: | CompatibilityFlags |
Value: 0 | |||
| (PID) Process: | (3320) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (3320) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (3320) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (3320) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3764 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\DOTBATAV\www.larksuite[1].xml | text | |
MD5:C1DDEA3EF6BBEF3E7060A1A9AD89E4C5 | SHA256:B71E4D17274636B97179BA2D97C742735B6510EB54F22893D3A2DAFF2CEB28DB | |||
| 3764 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\26C212D9399727259664BDFCA073966E_600EF020C96CF8AAA331625500A5DDA1 | binary | |
MD5:09AA4C86916C65174B65F7E6AE1D6DEA | SHA256:BBBEF29A97373CC46142B55572083F65A884279613E8C549D26A62D4DF5AFC91 | |||
| 3764 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B398B80134F72209547439DB21AB308D_C30613620F21879F76DA4316E8295D21 | binary | |
MD5:34749DA66512A546E1FEDA8F9063F086 | SHA256:F1785C4190D341E41E68AED6685964BF8CC92F5CEE3F3F86931AC3308FF5BACE | |||
| 3764 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B398B80134F72209547439DB21AB308D_23FFFDCAABB8E63694AD1202ED02BF57 | binary | |
MD5:1A773E29294C1C6A926C74E7260D94ED | SHA256:1A1A550C0231027E7A18B650BC04E2C57655FC1EA03EF0C1E4BC433BF25B8505 | |||
| 3764 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B398B80134F72209547439DB21AB308D_C30613620F21879F76DA4316E8295D21 | binary | |
MD5:BDC87C2FECC50142B3C83E7EF6A04E1A | SHA256:1950C2F0E229ABBEE8D7DEF6CA017FE96343D7A0440E057AE8E4C9875E852168 | |||
| 3764 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\banner-sdk.1.1.6[1].js | text | |
MD5:F0A0D2FD46B6EB91B1DCA4A51FD7B7CC | SHA256:54D03DCA16597E69B1A86CFAD4C443373D3497FE4B77198E0D199313C789EE4E | |||
| 3764 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\passport-js-apis-1.0.0.7[1].js | text | |
MD5:F3E745F222FF4E312CBB15D5D2A5BEE4 | SHA256:2DF55CDA21635FDC23A1839F7745013F92F0E7A753BD9647759027C3E6F20C7B | |||
| 3320 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157 | compressed | |
MD5:F7DCB24540769805E5BB30D193944DCE | SHA256:6B88C6AC55BBD6FEA0EBE5A760D1AD2CFCE251C59D0151A1400701CB927E36EA | |||
| 3764 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\646C991C2A28825F3CC56E0A1D1E3FA9 | der | |
MD5:25CC888C0511688AB4377714BFEE473B | SHA256:40DCC1747E2B52F3401F73C2D515ADB2F996CC0C869C2274E508BA1B2B1F7C5D | |||
| 3320 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157 | binary | |
MD5:07D41F15CAE217C2B84CBFEA18ED6D21 | SHA256:A93E2F046F5D8E2BBBDC1AFB28CA0C8C2E46E6FAB69CA64F89D784EA6202C720 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3764 | iexplore.exe | GET | — | 108.138.2.173:80 | http://o.ss2.us//MEowSDBGMEQwQjAJBgUrDgMCGgUABBSLwZ6EW5gdYc9UaSEaaLjjETNtkAQUv1%2B30c7dH4b0W1Ws3NcQwg6piOcCCQCnDkpMNIK3fw%3D%3D | US | — | — | whitelisted |
3764 | iexplore.exe | GET | 200 | 142.250.184.227:80 | http://ocsp.pki.goog/gts1c3/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEQCbYOZ%2FvtI35BCTLgvKp3nV | US | der | 472 b | whitelisted |
3764 | iexplore.exe | GET | 200 | 192.229.221.95:80 | http://crl3.digicert.com/DigiCertGlobalRootCA.crl | US | der | 779 b | whitelisted |
3764 | iexplore.exe | GET | 200 | 192.229.221.95:80 | http://crl3.digicert.com/RapidSSLGlobalTLSRSA4096SHA2562022CA1.crl | US | binary | 365 Kb | whitelisted |
3764 | iexplore.exe | GET | 200 | 52.222.250.174:80 | http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwdzEjgLnWaIozse2b%2BczaaODg8%3D | US | binary | 1.39 Kb | shared |
3764 | iexplore.exe | GET | 200 | 52.222.250.42:80 | http://ocsp.rootg2.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBSIfaREXmfqfJR3TkMYnD7O5MhzEgQUnF8A36oB1zArOIiiuG1KnPIRkYMCEwZ%2FlEoqJ83z%2BsKuKwH5CO65xMY%3D | US | der | 1.51 Kb | whitelisted |
3764 | iexplore.exe | GET | 200 | 142.250.184.227:80 | http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFNZazTHGPUBUGY%3D | US | der | 724 b | whitelisted |
3320 | iexplore.exe | GET | 200 | 192.229.221.95:80 | http://crl3.digicert.com/Omniroot2025.crl | US | binary | 7.78 Kb | whitelisted |
3764 | iexplore.exe | GET | 200 | 142.250.184.227:80 | http://ocsp.pki.goog/gts1c3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEH0tNUTr%2B0qZCadrlevKPFs%3D | US | der | 471 b | whitelisted |
3764 | iexplore.exe | GET | 200 | 52.222.250.174:80 | http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwdzEjgLnWaIozse2b%2BczaaODg8%3D | US | der | 1.39 Kb | shared |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3764 | iexplore.exe | 23.36.162.205:443 | security.feishu.cn | Akamai International B.V. | DE | suspicious |
3320 | iexplore.exe | 2.16.187.139:443 | www.bing.com | Akamai International B.V. | DE | malicious |
3764 | iexplore.exe | 209.197.3.8:80 | ctldl.windowsupdate.com | STACKPATH-CDN | US | whitelisted |
3764 | iexplore.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
— | — | 23.36.162.213:443 | security.feishu.cn | Akamai International B.V. | DE | suspicious |
— | — | 193.108.153.7:443 | www.larksuite.com | Akamai International B.V. | DE | suspicious |
— | — | 142.250.184.206:443 | www.googleoptimize.com | GOOGLE | US | whitelisted |
3764 | iexplore.exe | 142.250.185.109:443 | accounts.google.com | GOOGLE | US | suspicious |
3764 | iexplore.exe | 2.16.186.16:443 | sf16-scmcdn.larksuitecdn.com | Akamai International B.V. | DE | whitelisted |
3764 | iexplore.exe | 13.32.99.20:443 | events.framer.com | AMAZON-02 | US | unknown |
Domain | IP | Reputation |
|---|---|---|
security.feishu.cn |
| suspicious |
ctldl.windowsupdate.com |
| whitelisted |
api.bing.com |
| whitelisted |
www.bing.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
www.feishu.cn |
| malicious |
www.larksuite.com |
| whitelisted |
www.googleoptimize.com |
| whitelisted |
sf16-scmcdn.larksuitecdn.com |
| suspicious |
lf16-oversea.goofy-cdn.com |
| suspicious |