analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
URL:

http://mail.namusoft.kr/jsp/user/eam/board.jsp

Full analysis: https://app.any.run/tasks/7a8f65c4-2ab3-42e3-9bbc-f73b5e6472fc
Verdict: Malicious activity
Analysis date: August 12, 2022, 17:54:44
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

413AF562656759094725E460324F3D5C

SHA1:

41C9F39BF22816D47E427F1CAD960419AFBF8788

SHA256:

DB8A6474607493FE24E80569BFBD6BE2CF9C7F5F232E8E8937D449A10F1C6E13

SSDEEP:

3:N1KTrh46EWgDZZBLPWV:ChBg9DPS

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops executable file immediately after starts

      • chrome.exe (PID: 1984)
  • SUSPICIOUS

    • Reads Microsoft Outlook installation path

      • iexplore.exe (PID: 2548)
    • Modifies files in Chrome extension folder

      • chrome.exe (PID: 2972)
    • Executable content was dropped or overwritten

      • chrome.exe (PID: 1984)
    • Drops a file with a compile date too recent

      • chrome.exe (PID: 1984)
  • INFO

    • Checks supported languages

      • iexplore.exe (PID: 560)
      • iexplore.exe (PID: 2548)
      • chrome.exe (PID: 2972)
      • chrome.exe (PID: 3164)
      • chrome.exe (PID: 2540)
      • chrome.exe (PID: 2560)
      • chrome.exe (PID: 2416)
      • chrome.exe (PID: 268)
      • chrome.exe (PID: 2020)
      • chrome.exe (PID: 2280)
      • chrome.exe (PID: 3604)
      • chrome.exe (PID: 1336)
      • chrome.exe (PID: 2236)
      • chrome.exe (PID: 2700)
      • chrome.exe (PID: 492)
      • chrome.exe (PID: 2636)
      • chrome.exe (PID: 2008)
      • chrome.exe (PID: 628)
      • chrome.exe (PID: 2492)
      • chrome.exe (PID: 3168)
      • chrome.exe (PID: 1188)
      • chrome.exe (PID: 3808)
      • chrome.exe (PID: 2364)
      • chrome.exe (PID: 1984)
    • Reads the computer name

      • iexplore.exe (PID: 560)
      • iexplore.exe (PID: 2548)
      • chrome.exe (PID: 2972)
      • chrome.exe (PID: 2540)
      • chrome.exe (PID: 2560)
      • chrome.exe (PID: 3604)
      • chrome.exe (PID: 2700)
      • chrome.exe (PID: 2492)
      • chrome.exe (PID: 1188)
      • chrome.exe (PID: 3168)
    • Changes internet zones settings

      • iexplore.exe (PID: 560)
    • Application launched itself

      • iexplore.exe (PID: 560)
      • chrome.exe (PID: 2972)
    • Reads settings of System Certificates

      • iexplore.exe (PID: 560)
      • chrome.exe (PID: 2540)
    • Checks Windows Trust Settings

      • iexplore.exe (PID: 560)
    • Manual execution by user

      • chrome.exe (PID: 2972)
    • Reads internet explorer settings

      • iexplore.exe (PID: 2548)
    • Reads the date of Windows installation

      • iexplore.exe (PID: 560)
      • chrome.exe (PID: 3168)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
60
Monitored processes
24
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe

Process information

PID
CMD
Path
Indicators
Parent process
560"C:\Program Files\Internet Explorer\iexplore.exe" "http://mail.namusoft.kr/jsp/user/eam/board.jsp"C:\Program Files\Internet Explorer\iexplore.exe
Explorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
1
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
2548"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:560 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
2972"C:\Program Files\Google\Chrome\Application\chrome.exe" C:\Program Files\Google\Chrome\Application\chrome.exe
Explorer.EXE
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Version:
86.0.4240.198
3164"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win32 --annotation=prod=Chrome --annotation=ver=86.0.4240.198 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xd4,0x6eedd988,0x6eedd998,0x6eedd9a4C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Version:
86.0.4240.198
2560"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=1052,10475279790061834813,5947940506768853394,131072 --enable-features=PasswordImport --gpu-preferences=MAAAAAAAAADgAAAwAAAAAAAAAAAAAAAAAABgAAAAAAAQAAAAAAAAAAAAAAAAAAAAKAAAAAQAAAAgAAAAAAAAACgAAAAAAAAAMAAAAAAAAAA4AAAAAAAAABAAAAAAAAAAAAAAAAUAAAAQAAAAAAAAAAAAAAAGAAAAEAAAAAAAAAABAAAABQAAABAAAAAAAAAAAQAAAAYAAAA= --mojo-platform-channel-handle=1060 /prefetch:2C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
86.0.4240.198
2540"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1052,10475279790061834813,5947940506768853394,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=network --mojo-platform-channel-handle=1304 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exe
chrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Version:
86.0.4240.198
2416"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1052,10475279790061834813,5947940506768853394,131072 --enable-features=PasswordImport --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=1940 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Version:
86.0.4240.198
1336"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1052,10475279790061834813,5947940506768853394,131072 --enable-features=PasswordImport --lang=en-US --instant-process --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=1956 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
86.0.4240.198
268"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1052,10475279790061834813,5947940506768853394,131072 --enable-features=PasswordImport --lang=en-US --extension-process --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=4 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2364 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
86.0.4240.198
2020"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --field-trial-handle=1052,10475279790061834813,5947940506768853394,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --mojo-platform-channel-handle=2828 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
86.0.4240.198
Total events
19 896
Read events
19 653
Write events
0
Delete events
0

Modification events

No data
Executable files
1
Suspicious files
132
Text files
120
Unknown types
14

Dropped files

PID
Process
Filename
Type
2972chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-62F693F4-B9C.pma
MD5:
SHA256:
560iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6BADA8974A10C4BD62CC921D13E43B18_711ED44619924BA6DC33E69F97E7FF63der
MD5:EE87BB11E233C12009CC11725035DBDC
SHA256:D82930A5B051B3C3F1639C24E83BDDF41D5AA66E467A0944D1AC3D59AE6330C5
560iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:E59FA692524D32C357E2FB4CA9C8CDB8
SHA256:CA0BBC5B63FACBFE3F17BD183C95C40E59E1278A11D84F423894A0295CEBC250
560iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6BADA8974A10C4BD62CC921D13E43B18_711ED44619924BA6DC33E69F97E7FF63binary
MD5:13C514D31D691A96173404D7FF6411E7
SHA256:44BAC0850D392FD7F255DB7ECA13E78CB2CCD6EF6EFA65D4864952850F79B686
560iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.icoimage
MD5:DA597791BE3B6E732F0BC8B20E38EE62
SHA256:5B2C34B3C4E8DD898B664DBA6C3786E2FF9869EFF55D673AA48361F11325ED07
2972chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\0c04f662-2c90-4495-93a4-eccf502894a8.tmpbinary
MD5:5058F1AF8388633F609CADB75A75DC9D
SHA256:CDB4EE2AEA69CC6A83331BBE96DC2CAA9A299D21329EFB0336FC02A82E1839A8
560iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\favicon[1].icoimage
MD5:DA597791BE3B6E732F0BC8B20E38EE62
SHA256:5B2C34B3C4E8DD898B664DBA6C3786E2FF9869EFF55D673AA48361F11325ED07
2972chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad\settings.datbinary
MD5:9C016064A1F864C8140915D77CF3389A
SHA256:0E7265D4A8C16223538EDD8CD620B8820611C74538E420A88E333BE7F62AC787
2972chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOG.old~RFdc6db.TMPtext
MD5:81F483F77EE490F35306A4F94DB2286B
SHA256:82434CE3C9D13F509EBEEBE3A7A1A1DE9AB4557629D9FC855761E0CFA45E8BCE
560iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\favicon[2].icoimage
MD5:DA597791BE3B6E732F0BC8B20E38EE62
SHA256:5B2C34B3C4E8DD898B664DBA6C3786E2FF9869EFF55D673AA48361F11325ED07
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
29
TCP/UDP connections
56
DNS requests
23
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
880
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/ac5q25btpqhkjhcekqoslcldvuya_1.3.36.141/ihnlcenocehgdaegdmhbidjhnhdchfmm_1.3.36.141_win_ehzjmd5kjmert7jdgsrj4xqxj4.crx3
US
binary
9.70 Kb
whitelisted
2548
iexplore.exe
GET
200
182.162.89.146:80
http://mail.namusoft.kr/error/error_bg01.gif
KR
image
4.76 Kb
malicious
2540
chrome.exe
GET
404
182.162.89.146:80
http://mail.namusoft.kr/jsp/user/eam/board.jsp
KR
html
1007 b
malicious
2540
chrome.exe
GET
404
182.162.89.146:80
http://mail.namusoft.kr/favicon.ico
KR
html
1007 b
malicious
880
svchost.exe
HEAD
200
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/ac5q25btpqhkjhcekqoslcldvuya_1.3.36.141/ihnlcenocehgdaegdmhbidjhnhdchfmm_1.3.36.141_win_ehzjmd5kjmert7jdgsrj4xqxj4.crx3
US
whitelisted
2548
iexplore.exe
GET
200
182.162.89.146:80
http://mail.namusoft.kr/error/404.gif
KR
image
2.17 Kb
malicious
2548
iexplore.exe
GET
404
182.162.89.146:80
http://mail.namusoft.kr/jsp/user/eam/board.jsp
KR
html
1007 b
malicious
560
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA8Ull8gIGmZT9XHrHiJQeI%3D
US
der
1.47 Kb
whitelisted
2540
chrome.exe
GET
200
182.162.89.146:80
http://mail.namusoft.kr/error/error_bg01.gif
KR
image
4.76 Kb
malicious
880
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/ac5q25btpqhkjhcekqoslcldvuya_1.3.36.141/ihnlcenocehgdaegdmhbidjhnhdchfmm_1.3.36.141_win_ehzjmd5kjmert7jdgsrj4xqxj4.crx3
US
binary
9.66 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
560
iexplore.exe
204.79.197.200:443
www.bing.com
Microsoft Corporation
US
whitelisted
560
iexplore.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
560
iexplore.exe
209.197.3.8:80
ctldl.windowsupdate.com
Highwinds Network Group, Inc.
US
whitelisted
2540
chrome.exe
142.250.185.142:443
clients2.google.com
Google Inc.
US
whitelisted
2540
chrome.exe
142.250.185.195:443
clientservices.googleapis.com
Google Inc.
US
whitelisted
2548
iexplore.exe
182.162.89.146:80
mail.namusoft.kr
LG DACOM Corporation
KR
malicious
2540
chrome.exe
142.250.185.129:443
clients2.googleusercontent.com
Google Inc.
US
whitelisted
2540
chrome.exe
216.58.212.132:443
www.google.com
Google Inc.
US
whitelisted
2540
chrome.exe
142.250.185.227:443
www.gstatic.com
Google Inc.
US
whitelisted
2540
chrome.exe
172.217.23.109:443
accounts.google.com
Google Inc.
US
suspicious

DNS requests

Domain
IP
Reputation
mail.namusoft.kr
  • 182.162.89.146
malicious
api.bing.com
  • 13.107.5.80
whitelisted
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
ctldl.windowsupdate.com
  • 209.197.3.8
whitelisted
ocsp.digicert.com
  • 93.184.220.29
whitelisted
clients2.google.com
  • 142.250.185.142
whitelisted
clientservices.googleapis.com
  • 142.250.185.195
whitelisted
accounts.google.com
  • 172.217.23.109
shared
www.google.com
  • 216.58.212.132
whitelisted
clients2.googleusercontent.com
  • 142.250.185.129
whitelisted

Threats

No threats detected
No debug info