| File name: | File-ATD-node-1-012b87c8-018e-11ed-84d2-ac1f6b70be50.bin |
| Full analysis: | https://app.any.run/tasks/b844d0aa-ee53-4943-a022-5d902996bc4e |
| Verdict: | Malicious activity |
| Analysis date: | July 13, 2022, 02:30:12 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | text/html |
| File info: | HTML document, UTF-8 Unicode text, with very long lines |
| MD5: | 465DBE9C4F43904AFE3EAE43B0EC7CDB |
| SHA1: | 3F96BB0B0100C9FDC879AB43369CE0FC7AD7254A |
| SHA256: | D1F1A3DED70A9EEA5E64EC673B116E92FAD80073DA8B3D0B549438FCB590C8EE |
| SSDEEP: | 1536:HrTWYa+TWYasjF/HQ0/QOz2+Jo+DgRFuvmneedCTWzeeqweeuFOee7LDbi4d6Oo/:HWGW25/HTJo1kWRG4aGE |
| .htm/html | | | HyperText Markup Language with DOCTYPE (80.6) |
|---|---|---|
| .html | | | HyperText Markup Language (19.3) |
| Title: | 领导活动 - 重庆市渝中区人民政府 |
|---|---|
| Url: | http://www.cqyz.gov.cn/zwgk_229/ldhd_new/202202/t20220211_10382406.html |
| Image: | - |
| Description: | 2月9日,渝中区委副书记、区长黄茂军会见龙湖集团重庆公司总经理黑鹏一行。将进一步整合优质资源,加大在渝中的投资力度,做大做强主导产业项目,全力服务渝中发展需求,为推动高质量发展、创造高品质生活贡献力量。 |
| Author: | 记者 袁侨偲 摄影 王欢 |
| Keywords: | 渝中区委副书记、区长黄茂军会见龙湖集团重庆公司总经理黑鹏一行 |
| ContentSource: | 渝中区委副书记、区长黄茂军会见龙湖集团重庆公司总经理黑鹏一行 |
| PubDate: | 2022-02-11 10:44 |
| ArticleTitle: | 渝中区委副书记、区长黄茂军会见龙湖集团重庆公司总经理黑鹏一行 |
| ColumnType: | 领导活动 |
| ColumnKeywords: | 领导活动 |
| ColumnDescription: | 领导活动 |
| ColumnName: | 领导活动 |
| SiteIDCode: | 5001030001 |
| SiteDomain: | www.cqyz.gov.cn/ |
| SiteName: | 重庆市渝中区人民政府 |
| viewport: | width=device-width,user-scalable=no,initial-scale=1.0,maximum-scale=1.0,minimum-scale=1.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1180 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3148 CREDAT:144385 /prefetch:2 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| 2364 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3148 CREDAT:144390 /prefetch:2 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| 2664 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3148 CREDAT:3617852 /prefetch:2 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| 3148 | "C:\Program Files\Internet Explorer\iexplore.exe" "C:\Users\admin\AppData\Local\Temp\File-ATD-node-1-012b87c8-018e-11ed-84d2-ac1f6b70be50.bin.htm" | C:\Program Files\Internet Explorer\iexplore.exe | Explorer.EXE | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| (PID) Process: | (3148) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPDaysSinceLastAutoMigration |
Value: 1 | |||
| (PID) Process: | (3148) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPLastLaunchLowDateTime |
Value: | |||
| (PID) Process: | (3148) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPLastLaunchHighDateTime |
Value: 30971488 | |||
| (PID) Process: | (3148) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager |
| Operation: | write | Name: | NextCheckForUpdateLowDateTime |
Value: | |||
| (PID) Process: | (3148) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager |
| Operation: | write | Name: | NextCheckForUpdateHighDateTime |
Value: 30971488 | |||
| (PID) Process: | (3148) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (3148) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (3148) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (3148) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main |
| Operation: | write | Name: | CompatibilityFlags |
Value: 0 | |||
| (PID) Process: | (3148) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3148 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6BADA8974A10C4BD62CC921D13E43B18_711ED44619924BA6DC33E69F97E7FF63 | der | |
MD5:— | SHA256:— | |||
| 2364 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\78RFYB7Z\xcConfirm[1].js | text | |
MD5:— | SHA256:— | |||
| 3148 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157 | binary | |
MD5:— | SHA256:— | |||
| 1180 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\xcConfirm[1].css | text | |
MD5:— | SHA256:— | |||
| 1180 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\78RFYB7Z\fontSize[1].css | text | |
MD5:— | SHA256:— | |||
| 3148 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6BADA8974A10C4BD62CC921D13E43B18_711ED44619924BA6DC33E69F97E7FF63 | binary | |
MD5:— | SHA256:— | |||
| 2364 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\xcConfirm[1].css | text | |
MD5:— | SHA256:— | |||
| 1180 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\78RFYB7Z\esdToolsInit[1].js | text | |
MD5:— | SHA256:— | |||
| 1180 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\xcConfirm[1].js | text | |
MD5:— | SHA256:— | |||
| 1180 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\78RFYB7Z\public-xl[1].css | text | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2364 | iexplore.exe | GET | 200 | 221.7.113.13:80 | http://www.cqyz.gov.cn/material/assets/css/core.css?v=2022070815 | CN | text | 76.5 Kb | unknown |
2364 | iexplore.exe | GET | 200 | 221.7.113.13:80 | http://www.cqyz.gov.cn//images/esdToolsInit.js | CN | text | 4.33 Kb | unknown |
1180 | iexplore.exe | GET | 200 | 221.7.113.13:80 | http://www.cqyz.gov.cn/images/xcConfirm.css | CN | text | 2.29 Kb | unknown |
2364 | iexplore.exe | GET | 200 | 221.7.113.13:80 | http://www.cqyz.gov.cn/images/xcConfirm.css | CN | text | 2.29 Kb | unknown |
1180 | iexplore.exe | GET | 200 | 221.7.113.13:80 | http://www.cqyz.gov.cn/material/assets/css/public-xl.css | CN | text | 289 b | unknown |
2364 | iexplore.exe | GET | 200 | 221.7.113.13:80 | http://www.cqyz.gov.cn/images/xcConfirm.js | CN | text | 5.06 Kb | unknown |
1180 | iexplore.exe | GET | 200 | 221.7.113.13:80 | http://www.cqyz.gov.cn//images/esdToolsInit.js | CN | text | 4.33 Kb | unknown |
1180 | iexplore.exe | GET | 200 | 221.7.113.13:80 | http://www.cqyz.gov.cn/material/assets/js/posfixed.js?v=20210316 | CN | text | 22.0 Kb | unknown |
1180 | iexplore.exe | GET | 200 | 221.7.113.13:80 | http://www.cqyz.gov.cn/material/assets/css/core.css?v=2022070815 | CN | text | 76.5 Kb | unknown |
1180 | iexplore.exe | GET | 200 | 221.7.113.13:80 | http://www.cqyz.gov.cn/images/xcConfirm.js | CN | text | 5.06 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 42.4.53.211:445 | gov.govwza.cn | CHINA UNICOM China169 Backbone | CN | suspicious |
— | — | 101.70.154.81:445 | gov.govwza.cn | CHINA UNICOM China169 Backbone | CN | unknown |
— | — | 61.54.91.250:445 | gov.govwza.cn | CHINA UNICOM China169 Backbone | CN | suspicious |
— | — | 112.90.43.190:445 | gov.govwza.cn | China Unicom IP network China169 Guangdong province | CN | suspicious |
— | — | 116.169.51.71:445 | gov.govwza.cn | — | CN | suspicious |
1180 | iexplore.exe | 221.7.113.13:80 | www.cqyz.gov.cn | CHINA UNICOM China169 Backbone | CN | unknown |
4 | System | 47.95.136.155:445 | ta.trs.cn | Hangzhou Alibaba Advertising Co.,Ltd. | CN | unknown |
2364 | iexplore.exe | 104.18.21.226:80 | ocsp.globalsign.com | Cloudflare Inc | US | shared |
1180 | iexplore.exe | 39.156.68.163:80 | bdimg.share.baidu.com | Guangdong Mobile Communication Co.Ltd. | CN | suspicious |
2364 | iexplore.exe | 39.156.68.163:80 | bdimg.share.baidu.com | Guangdong Mobile Communication Co.Ltd. | CN | suspicious |
Domain | IP | Reputation |
|---|---|---|
www.cqyz.gov.cn |
| unknown |
ta.trs.cn |
| unknown |
api.bing.com |
| whitelisted |
www.bing.com |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
gov.govwza.cn |
| malicious |
iecvlist.microsoft.com |
| whitelisted |
r20swj13mr.microsoft.com |
| whitelisted |
hm.baidu.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2364 | iexplore.exe | Generic Protocol Command Decode | SURICATA STREAM CLOSEWAIT FIN out of window |