URL:

http://www.ddooo.com/zt/xlwybbdq.htm

Full analysis: https://app.any.run/tasks/ea26501b-4dca-4e81-a5b3-bad57eb6d23a
Verdict: Malicious activity
Analysis date: December 05, 2023, 08:56:51
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
qrcode
Indicators:
MD5:

621412A054902BF065865CF3EE032433

SHA1:

891824ECED5BD50A28F7B02F930345DC37084A04

SHA256:

CDC8112B48CAC322F06317227D9061E3AF492495258AA483934C39CC0F077DFB

SSDEEP:

3:N1KJS4ctNLNu:Cc4/

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Reads the computer name

      • wmpnscfg.exe (PID: 3680)
    • Checks supported languages

      • wmpnscfg.exe (PID: 3680)
    • Application launched itself

      • iexplore.exe (PID: 3048)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 3680)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
40
Monitored processes
3
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2620"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3048 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
3048"C:\Program Files\Internet Explorer\iexplore.exe" "http://www.ddooo.com/zt/xlwybbdq.htm"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
3680"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
17 619
Read events
17 553
Write events
64
Delete events
2

Modification events

(PID) Process:(3048) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
0
(PID) Process:(3048) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30847387
(PID) Process:(3048) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30847437
(PID) Process:(3048) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3048) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3048) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(3048) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3048) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3048) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3048) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
0
Suspicious files
20
Text files
47
Unknown types
0

Dropped files

PID
Process
Filename
Type
2620iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\xlwybbdq[1].htmhtml
MD5:7EC05AAE518AB2FFB7C2FAA32BDD7D11
SHA256:FE98D9D9533A27A43F935D1C866E6E54F68613CC2B8FEC00E9C2155D3FF83F75
2620iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\07CEF2F654E3ED6050FFC9B6EB844250_DD02D25E799024F48A93E8EE3BDDA41Abinary
MD5:03363CD06C776740091671B5F78FA544
SHA256:8C39FE4E188059350E961453725A79DFB896CD47D7A07FB519158AF10EB3A0DD
2620iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\nstructure[1].csstext
MD5:3C003006A50EFED91D3FBC863037A32D
SHA256:7AC6D13B37A4B9A557AB7CC390E9F5C3C2226101EB23869A30AF1DC6A5DE9053
2620iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\m_ddooo[1].pngimage
MD5:178A6999B86BD66F9176BA7F89856D69
SHA256:E3EC85BF57DBC93122D6BDCFD01D38453EEFCD13F51CAB3C0EB24CCABF08EE47
2620iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\ddooo_logo[1].pngimage
MD5:A301BA71B4D232257F113235F0861F8F
SHA256:B6F983A694CCBF8129D63B1C9E0CBF9D6A59306FF76909399498F690CA02A613
2620iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\ga[1].pngimage
MD5:D0289DC0A46FC5B15B3363FFA78CF6C7
SHA256:A20583C81805FE64F7FA210851CE29754AF9D25FD6AA5A3225A9557529602513
2620iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157compressed
MD5:1BFE591A4FE3D91B03CDF26EAACD8F89
SHA256:9CF94355051BF0F4A45724CA20D1CC02F76371B963AB7D1E38BD8997737B13D8
2620iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:ACEA5381A43AD4F595E3FCD7402E260D
SHA256:8832B6AD20014D78DC712C91AB922C19FAAAA942FD798BEC6C8B0002824063BD
2620iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\202206201029565094[1].pngimage
MD5:27DF4413F938C7D0268A1E62411BF43E
SHA256:40F0FD8BAFABD664171490B759F43B5C98502B6AB49FAC0ED0E7F0335E54618C
2620iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\202304271618359257[1].jpgimage
MD5:36BAF305C218724A11BD4A4C8C41DEAD
SHA256:776B7201FD0BB4AA87EE688613E8D5CCF64F9F082813038139DA91C703B951EE
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
36
TCP/UDP connections
47
DNS requests
24
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2620
iexplore.exe
GET
200
185.23.181.28:80
http://www.ddooo.com/zt/xlwybbdq.htm
DE
html
9.75 Kb
unknown
2620
iexplore.exe
GET
200
185.23.181.28:80
http://www.ddooo.com/css/nzt_column.css
DE
text
8.96 Kb
unknown
2620
iexplore.exe
GET
200
185.23.181.28:80
http://www.ddooo.com/images/m_ddooo.png
DE
image
6.30 Kb
unknown
2620
iexplore.exe
GET
200
185.23.181.28:80
http://www.ddooo.com/images/ddooo_logo.png
DE
image
10.4 Kb
unknown
2620
iexplore.exe
GET
200
185.23.181.28:80
http://www.ddooo.com/images/ga.png
DE
image
18.8 Kb
unknown
2620
iexplore.exe
GET
200
138.113.149.152:80
http://img.ddooo.com/logo/210509/20210509115013645.png
US
image
11.1 Kb
unknown
2620
iexplore.exe
GET
200
138.113.149.152:80
http://img.ddooo.com/logo/230427/202304271618359257.jpg
US
image
9.64 Kb
unknown
2620
iexplore.exe
GET
200
138.113.149.152:80
http://img.ddooo.com/logo/220423/202204231805048073.png
US
image
5.09 Kb
unknown
2620
iexplore.exe
GET
200
138.113.149.152:80
http://img.ddooo.com/logo/220620/202206201029565094.png
US
image
6.79 Kb
unknown
2620
iexplore.exe
GET
200
138.113.149.152:80
http://img.ddooo.com/logo/230710/202307101117487712.png
US
image
76.2 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2620
iexplore.exe
185.23.181.28:80
www.ddooo.com
Kaopu Cloud HK Limited
DE
unknown
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
2588
svchost.exe
239.255.255.250:1900
whitelisted
2620
iexplore.exe
185.23.181.28:443
www.ddooo.com
Kaopu Cloud HK Limited
DE
unknown
2620
iexplore.exe
138.113.149.152:80
img.ddooo.com
QUANTILNETWORKS
US
unknown
2620
iexplore.exe
23.53.40.65:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
2620
iexplore.exe
172.64.149.23:80
ocsp.comodoca.com
CLOUDFLARENET
US
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
2620
iexplore.exe
104.18.38.233:80
ocsp.comodoca.com
CLOUDFLARENET
shared

DNS requests

Domain
IP
Reputation
www.ddooo.com
  • 185.23.181.28
  • 185.23.181.26
unknown
img.ddooo.com
  • 138.113.149.152
unknown
ctldl.windowsupdate.com
  • 23.53.40.65
  • 23.53.40.74
  • 23.53.40.67
  • 23.53.40.80
  • 23.53.40.59
  • 23.53.40.64
  • 23.53.40.75
  • 23.53.40.81
  • 23.53.40.10
whitelisted
ocsp.comodoca.com
  • 172.64.149.23
  • 104.18.38.233
whitelisted
ocsp.usertrust.com
  • 104.18.38.233
  • 172.64.149.23
whitelisted
ocsp.trust-provider.cn
  • 36.143.236.7
  • 111.13.153.152
  • 111.48.138.18
  • 111.206.23.199
  • 119.36.90.164
malicious
api.ddooo.com
  • 138.113.101.20
unknown
s9.cnzz.com
  • 122.225.212.183
unknown
s4.cnzz.com
  • 122.225.212.183
whitelisted
ocsp.globalsign.com
  • 104.18.20.226
  • 104.18.21.226
whitelisted

Threats

No threats detected
No debug info