| URL: | https://files.sberdisk.ru/s/dvAmxYSG3zfv7ie |
| Full analysis: | https://app.any.run/tasks/d4027097-8544-43df-bd12-c7ef84ecc31b |
| Verdict: | Malicious activity |
| Analysis date: | February 28, 2024, 14:49:05 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MD5: | 9F8DF25E775B482AA523232D33A59AFE |
| SHA1: | 480C949A402B8E8278B05A934198B26DF08DD280 |
| SHA256: | CD696AE530EFF525AF87C5B8E4216D2DDC4B202225C64AE89AD559F24820ACC5 |
| SSDEEP: | 3:N8MAFAN+PSBn:2MAiN7 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2168 | "C:\Users\admin\Desktop\MMCashbackFREE\MMCashbackFREE.exe" | C:\Users\admin\Desktop\MMCashbackFREE\MMCashbackFREE.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 2420 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\MMCashbackFREE.zip" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 3656 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3796 CREDAT:267521 /prefetch:2 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| 3776 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3796 | "C:\Program Files\Internet Explorer\iexplore.exe" "https://files.sberdisk.ru/s/dvAmxYSG3zfv7ie" | C:\Program Files\Internet Explorer\iexplore.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Exit code: 1 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| (PID) Process: | (3796) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPDaysSinceLastAutoMigration |
Value: 1 | |||
| (PID) Process: | (3796) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPLastLaunchLowDateTime |
Value: | |||
| (PID) Process: | (3796) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPLastLaunchHighDateTime |
Value: 31091285 | |||
| (PID) Process: | (3796) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager |
| Operation: | write | Name: | NextCheckForUpdateLowDateTime |
Value: | |||
| (PID) Process: | (3796) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager |
| Operation: | write | Name: | NextCheckForUpdateHighDateTime |
Value: 31091285 | |||
| (PID) Process: | (3796) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (3796) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (3796) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (3796) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main |
| Operation: | write | Name: | CompatibilityFlags |
Value: 0 | |||
| (PID) Process: | (3796) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3796 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\EAF8AA29A62AB29E614331747385D816_F9E4DC0B9D5C777357D7DB8DEF51118A | binary | |
MD5:F95B5BC83F9ED257E822B85149602A08 | SHA256:52D7810F2F87A9A99CAEFCACC763DAC9F9311E9A11F56465686DD4FCF90C22FB | |||
| 3796 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico | image | |
MD5:DA597791BE3B6E732F0BC8B20E38EE62 | SHA256:5B2C34B3C4E8DD898B664DBA6C3786E2FF9869EFF55D673AA48361F11325ED07 | |||
| 3796 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\EAF8AA29A62AB29E614331747385D816_F9E4DC0B9D5C777357D7DB8DEF51118A | der | |
MD5:ECFC6438DC0FBD36E52F2437D19FD3F3 | SHA256:73C4E26CC4BA3EFABBD3843B405F82CCAB1FAF535798F6DFC34F066C8488D950 | |||
| 3796 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\favicon[1].ico | image | |
MD5:DA597791BE3B6E732F0BC8B20E38EE62 | SHA256:5B2C34B3C4E8DD898B664DBA6C3786E2FF9869EFF55D673AA48361F11325ED07 | |||
| 3796 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Last Active\{920C6CC2-D648-11EE-AE0A-12A9866C77DE}.dat | binary | |
MD5:451F5EA24BD3533F6AB6A549B1B628C6 | SHA256:2667C0AFDD58CE2F93A585408C2C35ECB7FB99D241A994024AE0CA2C36194CF4 | |||
| 3796 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Last Active\RecoveryStore.{42C873D0-1D90-11EB-BA2C-12A9866C77DE}.dat | binary | |
MD5:E9018A286CBE5AE83207049468670A50 | SHA256:6C2CC5E2B4DDC3ED116C404298343F53578BC39924A1809FC6BE74CD7E8D7FFE | |||
| 3796 | iexplore.exe | C:\Users\admin\AppData\Local\Temp\~DFE8A7BB630B4C3914.TMP | gmc | |
MD5:60FA1089EF406685EAABA1F16C605728 | SHA256:A6036E1360C2393767B5DD2E8FE77464F696E2CEE94432A99AC92C68D8C95F22 | |||
| 3796 | iexplore.exe | C:\Users\admin\AppData\Local\Temp\~DF7FAF15C137A2DB14.TMP | gmc | |
MD5:6529B05CEEB9AE26F3E7AB09A4F1DE49 | SHA256:50759D229B3987959DA6C18F2D2E02C0885BFA67DCE5B28860EACC1FC30D5BFB | |||
| 3796 | iexplore.exe | C:\Users\admin\AppData\Local\Temp\~DF17A80295D2381915.TMP | gmc | |
MD5:7F8D0B7511F6B9D14D31B9202E1334A5 | SHA256:D820C3884A0A4A72A4CB00003A677B20F10F64A9E26FA76074078A607CF7C727 | |||
| 3796 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{8A26A2A5-D648-11EE-AE0A-12A9866C77DE}.dat | binary | |
MD5:0940CA473003EFB97771E6BCFDE33DC4 | SHA256:D8F21B27A925EB20A3C3F7838D82BAF7EC8C3ACD17466B9664A98FF0C7619E7A | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3796 | iexplore.exe | GET | 304 | 184.24.77.186:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?70d85e3b0e586cab | unknown | — | — | unknown |
3796 | iexplore.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAzlnDD9eoNTLi0BRrMy%2BWU%3D | unknown | binary | 313 b | unknown |
2168 | MMCashbackFREE.exe | GET | 206 | 54.37.204.238:80 | http://downloads.bablosoft.com/distr/FastExecuteScriptProtected32/26.5.1/FastExecuteScriptProtected.x32.zip | unknown | compressed | 10.0 Mb | unknown |
3796 | iexplore.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | binary | 471 b | unknown |
2168 | MMCashbackFREE.exe | GET | 206 | 54.37.204.238:80 | http://downloads.bablosoft.com/distr/FastExecuteScriptProtected32/26.5.1/FastExecuteScriptProtected.x32.zip | unknown | binary | 10.0 Mb | unknown |
2168 | MMCashbackFREE.exe | GET | 206 | 54.37.204.238:80 | http://downloads.bablosoft.com/distr/FastExecuteScriptProtected32/26.5.1/FastExecuteScriptProtected.x32.zip | unknown | binary | 10.0 Mb | unknown |
1080 | svchost.exe | GET | 200 | 184.24.77.211:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?fc91d912a85a08d5 | unknown | compressed | 67.5 Kb | unknown |
1080 | svchost.exe | GET | 304 | 184.24.77.211:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?6776476d79efed94 | unknown | compressed | 67.5 Kb | unknown |
2168 | MMCashbackFREE.exe | GET | 206 | 54.37.204.238:80 | http://downloads.bablosoft.com/distr/FastExecuteScriptProtected32/26.5.1/FastExecuteScriptProtected.x32.zip | unknown | binary | 10.0 Mb | unknown |
2168 | MMCashbackFREE.exe | GET | 206 | 54.37.204.238:80 | http://downloads.bablosoft.com/distr/FastExecuteScriptProtected32/26.5.1/FastExecuteScriptProtected.x32.zip | unknown | binary | 10.0 Mb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
3656 | iexplore.exe | 37.18.107.192:443 | files.sberdisk.ru | Cloud technology Limited (Ltd.) | RU | unknown |
3796 | iexplore.exe | 104.126.37.179:443 | www.bing.com | Akamai International B.V. | DE | unknown |
3796 | iexplore.exe | 184.24.77.186:80 | ctldl.windowsupdate.com | Akamai International B.V. | DE | unknown |
3796 | iexplore.exe | 184.24.77.179:80 | ctldl.windowsupdate.com | Akamai International B.V. | DE | unknown |
3796 | iexplore.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
2168 | MMCashbackFREE.exe | 51.38.126.82:443 | bablosoft.com | OVH SAS | FR | unknown |
2168 | MMCashbackFREE.exe | 54.37.204.238:80 | downloads.bablosoft.com | OVH SAS | FR | unknown |
Domain | IP | Reputation |
|---|---|---|
files.sberdisk.ru |
| unknown |
api.bing.com |
| whitelisted |
www.bing.com |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
bablosoft.com |
| whitelisted |
downloads.bablosoft.com |
| malicious |
iecvlist.microsoft.com |
| whitelisted |
r20swj13mr.microsoft.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2168 | MMCashbackFREE.exe | Potentially Bad Traffic | ET INFO Observed Bablosoft BAS Related SSL Cert (bablosoft .com) |
2168 | MMCashbackFREE.exe | Potentially Bad Traffic | ET INFO Observed Bablosoft BAS Related SSL Cert (bablosoft .com) |
1080 | svchost.exe | Potentially Bad Traffic | ET MALWARE Observed DNS Query to bablosoft Domain (downloads .bablosoft .com) |