analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
download:

index.html

Full analysis: https://app.any.run/tasks/c6c4e473-e19d-4afd-bc94-6ce875b92101
Verdict: Malicious activity
Analysis date: July 18, 2019, 10:14:50
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: text/html
File info: HTML document, ASCII text, with very long lines, with CRLF, LF line terminators
MD5:

A7E72FFE5C6A211004D4B10D4057365E

SHA1:

C93EE91BD26F6B55196840B04B1BCC179A4A1278

SHA256:

BD0FC820B7B46023E97D845053201B0D51B324BFD869151A31E17CC5FBA81012

SSDEEP:

384:jtpERs+1QJbnhI1idQ/YgsqLs9t0cCHZJD6er8GtiKqrnBJDdZcXe:PThI1idQ/YgsqLsnher8GsJrnBJDfcXe

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Changes internet zones settings

      • iexplore.exe (PID: 2844)
    • Manual execution by user

      • firefox.exe (PID: 3148)
    • Reads settings of System Certificates

      • iexplore.exe (PID: 348)
      • firefox.exe (PID: 3148)
    • Reads internet explorer settings

      • iexplore.exe (PID: 348)
    • Application launched itself

      • iexplore.exe (PID: 2844)
      • firefox.exe (PID: 3148)
    • Reads Internet Cache Settings

      • iexplore.exe (PID: 348)
    • Reads CPU info

      • firefox.exe (PID: 3148)
    • Dropped object may contain Bitcoin addresses

      • firefox.exe (PID: 3148)
    • Creates files in the user directory

      • firefox.exe (PID: 3148)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.html | HyperText Markup Language (100)

EXIF

HTML

Generator: WordPress 5.2.2
themeColor: #20c7d6
viewport: width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=0
Robots: INDEX, FOLLOW
Description: MaticPress Agency Login Page.
Title: MaticPress Agency Login Page
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
44
Monitored processes
10
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe firefox.exe firefox.exe no specs firefox.exe firefox.exe firefox.exe firefox.exe firefox.exe firefox.exe

Process information

PID
CMD
Path
Indicators
Parent process
2844"C:\Program Files\Internet Explorer\iexplore.exe" C:\Users\admin\AppData\Local\Temp\index.htmlC:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
1
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
348"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2844 CREDAT:79873C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
3148"C:\Program Files\Mozilla Firefox\firefox.exe" C:\Program Files\Mozilla Firefox\firefox.exe
explorer.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
67.0.4
2344"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3148.0.2032513031\77378373" -parentBuildID 20190619235627 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 3148 "\\.\pipe\gecko-crash-server-pipe.3148" 1176 gpuC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
67.0.4
2640"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3148.3.1082025894\814075760" -childID 1 -isForBrowser -prefsHandle 1648 -prefMapHandle 1332 -prefsLen 1 -prefMapSize 188076 -parentBuildID 20190619235627 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 3148 "\\.\pipe\gecko-crash-server-pipe.3148" 1716 tabC:\Program Files\Mozilla Firefox\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
67.0.4
3684"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3148.13.2081485314\787899540" -childID 2 -isForBrowser -prefsHandle 2728 -prefMapHandle 2732 -prefsLen 5842 -prefMapSize 188076 -parentBuildID 20190619235627 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 3148 "\\.\pipe\gecko-crash-server-pipe.3148" 2772 tabC:\Program Files\Mozilla Firefox\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
67.0.4
3788"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3148.20.1908234203\182520867" -childID 3 -isForBrowser -prefsHandle 3568 -prefMapHandle 3572 -prefsLen 6720 -prefMapSize 188076 -parentBuildID 20190619235627 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 3148 "\\.\pipe\gecko-crash-server-pipe.3148" 3548 tabC:\Program Files\Mozilla Firefox\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
67.0.4
1676"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3148.27.1095190151\1183183350" -childID 4 -isForBrowser -prefsHandle 7788 -prefMapHandle 7792 -prefsLen 8193 -prefMapSize 188076 -parentBuildID 20190619235627 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 3148 "\\.\pipe\gecko-crash-server-pipe.3148" 7724 tabC:\Program Files\Mozilla Firefox\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
67.0.4
3800"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3148.34.2075203343\1416319020" -childID 5 -isForBrowser -prefsHandle 3400 -prefMapHandle 3412 -prefsLen 8193 -prefMapSize 188076 -parentBuildID 20190619235627 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 3148 "\\.\pipe\gecko-crash-server-pipe.3148" 7612 tabC:\Program Files\Mozilla Firefox\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
67.0.4
4052"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3148.41.2048710627\2095693868" -childID 6 -isForBrowser -prefsHandle 7304 -prefMapHandle 3224 -prefsLen 8260 -prefMapSize 188076 -parentBuildID 20190619235627 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 3148 "\\.\pipe\gecko-crash-server-pipe.3148" 6700 tabC:\Program Files\Mozilla Firefox\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
67.0.4
Total events
1 054
Read events
963
Write events
89
Delete events
2

Modification events

(PID) Process:(2844) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(2844) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(2844) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(2844) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones
Operation:writeName:SecuritySafe
Value:
1
(PID) Process:(2844) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(2844) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
4600000077000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
(PID) Process:(2844) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Recovery\Active
Operation:writeName:{E9B60A07-A944-11E9-B506-5254004A04AF}
Value:
0
(PID) Process:(2844) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Type
Value:
4
(PID) Process:(2844) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Count
Value:
1
(PID) Process:(2844) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Time
Value:
E3070700040012000A000F000700A500
Executable files
0
Suspicious files
375
Text files
221
Unknown types
175

Dropped files

PID
Process
Filename
Type
2844iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGRR2OYX\favicon[1].ico
MD5:
SHA256:
2844iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
MD5:
SHA256:
348iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0488CJO\sow-headline-default-1c3844e99402[1].csstext
MD5:D3A66F67C9828E1B9024DAA571AC5927
SHA256:23FB9CD4B8DC5286DD1A1EA467167BF6EC6D9A89CBE8A59520F223BB5905824C
348iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H6QNMHE9\style[1].csstext
MD5:6ABDBF7DFACA96EB9A653F6338558D14
SHA256:07A57E3623FFD6BC3EA08C09881565628C3208107CF8A53434CA14D12DDB54D9
348iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\default[1].csstext
MD5:F4828FCAC8F6771F47E5E0998A48BEA1
SHA256:2493C65A379CBCA681B3A3366492F05F6B9DE4F5BEF944741EA00C702B732CD8
348iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H6QNMHE9\wpdigipro-tickets-front[1].csstext
MD5:34DB168D7ED37088B437DBD42914D66D
SHA256:1429FD2192E872B6930A653A1F476D02147D77587BB2243C35D1FE88AB6DB9BD
348iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\animate[1].csstext
MD5:04A38C3DFABC08B50E8C6E2B6A9F0B18
SHA256:645FD2F904FB3258FC81305236EE729F3399989AE13EC25C117650411181E9B7
348iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGRR2OYX\wpdigipro-front-dashboard[1].csstext
MD5:915EF8EF01F6774B53704828F68BA441
SHA256:DD35437292DFDC23F5A134892793AF5BB3457BF70EADCA39F612200F83E9C746
348iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\sow-button-flat-1607e17f6afe[1].csstext
MD5:F09972BBF11E9B2C5DEBA4D305692D86
SHA256:D855A121BCB8DA6554318B8C4028C31834D2534A3C6320B5A302513CF95E7699
348iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0488CJO\star-rating.min[1].csstext
MD5:2AD3FF94EB6F43EBD8AA26138E9B8200
SHA256:65A078278E0365B1A552F52A6C4189D5363CDA6EE3162B6CDB53E91D1721E8A2
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
36
TCP/UDP connections
182
DNS requests
245
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3148
firefox.exe
POST
200
93.184.220.29:80
http://ocsp.digicert.com/
US
der
471 b
whitelisted
3148
firefox.exe
POST
200
93.184.220.29:80
http://ocsp.digicert.com/
US
der
471 b
whitelisted
3148
firefox.exe
POST
200
216.58.206.3:80
http://ocsp.pki.goog/GTSGIAG3
US
der
471 b
whitelisted
3148
firefox.exe
GET
301
192.241.181.195:80
http://maticpress.com/
US
html
311 b
malicious
3148
firefox.exe
POST
200
93.184.220.29:80
http://ocsp.digicert.com/
US
der
471 b
whitelisted
3148
firefox.exe
POST
200
216.58.206.3:80
http://ocsp.pki.goog/GTSGIAG3
US
der
471 b
whitelisted
3148
firefox.exe
POST
200
216.58.206.3:80
http://ocsp.pki.goog/GTSGIAG3
US
der
471 b
whitelisted
3148
firefox.exe
POST
200
216.58.206.3:80
http://ocsp.pki.goog/GTSGIAG3
US
der
471 b
whitelisted
3148
firefox.exe
POST
200
216.58.206.3:80
http://ocsp.pki.goog/GTSGIAG3
US
der
471 b
whitelisted
3148
firefox.exe
POST
200
151.139.128.14:80
http://ocsp.sectigo.com/
US
der
471 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3148
firefox.exe
2.16.186.50:80
detectportal.firefox.com
Akamai International B.V.
whitelisted
2844
iexplore.exe
204.79.197.200:80
www.bing.com
Microsoft Corporation
US
whitelisted
348
iexplore.exe
192.241.181.195:443
maticpress.com
Digital Ocean, Inc.
US
unknown
3148
firefox.exe
108.128.247.43:443
location.services.mozilla.com
AT&T Services, Inc.
US
unknown
3148
firefox.exe
52.35.96.157:443
tiles.services.mozilla.com
Amazon.com, Inc.
US
unknown
3148
firefox.exe
54.149.145.192:443
push.services.mozilla.com
Amazon.com, Inc.
US
malicious
3148
firefox.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
3148
firefox.exe
54.192.202.51:443
snippets.cdn.mozilla.net
Amazon.com, Inc.
US
unknown
3148
firefox.exe
172.217.16.202:443
safebrowsing.googleapis.com
Google Inc.
US
whitelisted
3148
firefox.exe
216.58.206.3:80
ocsp.pki.goog
Google Inc.
US
whitelisted

DNS requests

Domain
IP
Reputation
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
maticpress.com
  • 192.241.181.195
malicious
detectportal.firefox.com
  • 2.16.186.50
  • 2.16.186.112
whitelisted
a1089.dscd.akamai.net
  • 2.16.186.112
  • 2.16.186.50
whitelisted
location.services.mozilla.com
  • 108.128.247.43
  • 52.210.139.31
  • 52.50.56.62
whitelisted
locprod1-elb-eu-west-1.prod.mozaws.net
  • 52.50.56.62
  • 52.210.139.31
  • 108.128.247.43
whitelisted
push.services.mozilla.com
  • 54.149.145.192
whitelisted
ocsp.digicert.com
  • 93.184.220.29
whitelisted
autopush.prod.mozaws.net
  • 54.149.145.192
whitelisted
cs9.wac.phicdn.net
  • 93.184.220.29
whitelisted

Threats

No threats detected
No debug info