download:

index.html

Full analysis: https://app.any.run/tasks/3513c2eb-ac19-4c56-9253-6a9d9fd26667
Verdict: No threats detected
Analysis date: November 19, 2019, 15:47:58
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: text/html
File info: HTML document, UTF-8 Unicode text, with very long lines, with CRLF, LF line terminators
MD5:

4F8C7916902D4C2E75CEE6F46CB01AB6

SHA1:

42D3F6DDC350705894A92B882955F76B647EFC1D

SHA256:

E55B9E82E78805BEB7B5C8953218117FBC12D79AF114C51FF8B04EF1BB0C3258

SSDEEP:

384:YMPkimqmMFRAH3+SXqDDNHDm+cqDDNzohC+LqDDNzmiBIIC2YDOqbxOlcB3+76P3:Yjim3vKDDrDDCuDDTA7k3s9sghak

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executed via COM

      • sdiagnhost.exe (PID: 3040)
    • Executable content was dropped or overwritten

      • msdt.exe (PID: 3276)
    • Uses IPCONFIG.EXE to discover IP address

      • sdiagnhost.exe (PID: 3040)
  • INFO

    • Changes internet zones settings

      • iexplore.exe (PID: 1888)
    • Creates files in the user directory

      • iexplore.exe (PID: 2152)
    • Application launched itself

      • iexplore.exe (PID: 1888)
    • Reads Internet Cache Settings

      • iexplore.exe (PID: 1888)
      • iexplore.exe (PID: 2152)
    • Reads internet explorer settings

      • iexplore.exe (PID: 2152)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.html | HyperText Markup Language (100)

EXIF

HTML

Keywords: 税友,软件,纳税,税收服务,营改增,筹划工具,税友软件集团股份有限公司,报税,纳税人,财税咨询,税务信息化,办税软件,风险评估,税务软件,纳税服务
Description: 本网站是税友软件集团股份有限公司(SERVYOU GROUP)的官方网站(以下简称“税友集团”)。税友集团是以软件研发、高级业务咨询、软件与系统运维服务等为主营业务的综合性企业集团。税友集团一直以“为税务信息化服务,做全体纳税人忠实的朋友”为己任,为全国范围内超过500万家企业和政府组织提供财税咨询和信息化服务。 十多年来,从标准化办税软件到各种办税工具软件,从办税服务到财税风险评估和财税咨询。税友集团以孜孜以求的不懈努力,在业界树立起了“有税友•无税忧”的全面涉税咨询服务专家形象,奠定了税友集团在中国税务软件和纳税服务市场的领先地位。 经过多年的快速发展,税友集团先后通过了ISO9001国际质量体系、CMMI ML4、ITIL、系统集成一级等资质认证。同时,税友集团也是国家规划布局内重点软件企业、国家高科技产业化示范基地、中国税务软件重要供应商、中国纳税服务市场主流厂商。
Title: 税友软件集团股份有限公司
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
42
Monitored processes
7
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe msdt.exe sdiagnhost.exe no specs ipconfig.exe no specs route.exe no specs makecab.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
944"C:\Windows\system32\ipconfig.exe" /allC:\Windows\system32\ipconfig.exesdiagnhost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
IP Configuration Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ipconfig.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\ws2_32.dll
1888"C:\Program Files\Internet Explorer\iexplore.exe" C:\Users\admin\AppData\Local\Temp\index.htmlC:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2152"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:1888 CREDAT:79873C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2916"C:\Windows\system32\ROUTE.EXE" printC:\Windows\system32\ROUTE.EXEsdiagnhost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
TCP/IP Route Command
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\route.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
3040C:\Windows\System32\sdiagnhost.exe -EmbeddingC:\Windows\System32\sdiagnhost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Scripted Diagnostics Native Host
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\sdiagnhost.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
3276 -modal 262438 -skip TRUE -path C:\Windows\diagnostics\system\networking -af C:\Users\admin\AppData\Local\Temp\NDFF310.tmp -ep NetworkDiagnosticsWebC:\Windows\system32\msdt.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Diagnostics Troubleshooting Wizard
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msdt.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
3900"C:\Windows\system32\makecab.exe" /f NetworkConfiguration.ddfC:\Windows\system32\makecab.exesdiagnhost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft® Cabinet Maker
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\makecab.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
487
Read events
382
Write events
104
Delete events
1

Modification events

(PID) Process:(1888) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(1888) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(1888) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(1888) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones
Operation:writeName:SecuritySafe
Value:
1
(PID) Process:(1888) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(1888) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
4600000092000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
(PID) Process:(2152) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Operation:writeName:Type
Value:
3
(PID) Process:(2152) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Operation:writeName:Count
Value:
2
(PID) Process:(2152) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Operation:writeName:Time
Value:
E3070B00020013000F0030001200C000
(PID) Process:(2152) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Operation:writeName:LoadTime
Value:
10
Executable files
2
Suspicious files
4
Text files
47
Unknown types
23

Dropped files

PID
Process
Filename
Type
1888iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0488CJO\favicon[1].ico
MD5:
SHA256:
1888iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
MD5:
SHA256:
2152iexplore.exeC:\Users\admin\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\settings.sxx
MD5:
SHA256:
2152iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@~~local~~[1].txt
MD5:
SHA256:
2152iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\core[1].phphtml
MD5:
SHA256:
2152iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@mmstat[1].txttext
MD5:
SHA256:
2152iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H6QNMHE9\pic[1].gifimage
MD5:BCDD9AA92C5876F207F70567D101A896
SHA256:98A4AB97E12555AB969012D151A578DAE7A3B8699D202485FCF8116E55497735
2152iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0488CJO\stat[1].phptext
MD5:
SHA256:
2152iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012019111920191120\index.datdat
MD5:
SHA256:
2152iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@~~local~~[2].txttext
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
12
DNS requests
10
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2152
iexplore.exe
GET
200
119.96.207.121:80
http://s95.cnzz.com/stat.php?id=4246816&web_id=4246816&show=pic
CN
text
3.96 Kb
whitelisted
2152
iexplore.exe
GET
301
23.210.248.158:80
http://www.adobe.com/images/shared/download_buttons/get_flash_player.gif
NL
html
281 b
whitelisted
2152
iexplore.exe
GET
200
119.96.207.121:80
http://icon.cnzz.com/img/pic.gif
CN
image
719 b
whitelisted
2152
iexplore.exe
GET
302
198.11.132.221:80
http://cnzz.mmstat.com/9.gif?abc=1&rnd=1889792589
US
image
43 b
whitelisted
2152
iexplore.exe
GET
302
198.11.132.221:80
http://cnzz.mmstat.com/9.gif?abc=1&rnd=664710149
US
image
43 b
whitelisted
2152
iexplore.exe
GET
200
119.96.207.121:80
http://c.cnzz.com/core.php?web_id=4246816&show=pic&t=z
CN
html
618 b
whitelisted
2152
iexplore.exe
GET
200
203.119.129.114:80
http://hzs4.cnzz.com/stat.htm?id=4246816&r=&lg=en-us&ntime=1574173458&cnzz_eid=563124394-1574173458-&showp=1280x720&p=file%3A%2F%2F%2FC%3A%2FUsers%2Fadmin%2FAppData%2FLocal%2FTemp%2Findex.html&t=%E7%A8%8E%E5%8F%8B%E8%BD%AF%E4%BB%B6%E9%9B%86%E5%9B%A2%E8%82%A1%E4%BB%BD%E6%9C%89%E9%99%90%E5%85%AC%E5%8F%B8&umuuid=16e845a17e3f96-078e6b3ea191ff4-44703418-e1000-16e845a17f31738&h=1&rnd=1958136805
CN
text
22 b
suspicious
2152
iexplore.exe
GET
200
106.11.92.15:80
http://pcookie.cnzz.com/app.gif?&cna=8/xaFvx4WGsCAVXLLAvxXzen
CN
image
43 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1888
iexplore.exe
204.79.197.200:80
www.bing.com
Microsoft Corporation
US
whitelisted
2152
iexplore.exe
119.96.207.121:80
s95.cnzz.com
No.31,Jin-rong Street
CN
unknown
2152
iexplore.exe
203.119.129.114:80
hzs4.cnzz.com
CN
malicious
2152
iexplore.exe
23.210.248.158:80
www.adobe.com
Akamai International B.V.
NL
malicious
2152
iexplore.exe
23.210.248.158:443
www.adobe.com
Akamai International B.V.
NL
malicious
2152
iexplore.exe
106.11.92.15:80
pcookie.cnzz.com
Hangzhou Alibaba Advertising Co.,Ltd.
CN
suspicious
2152
iexplore.exe
198.11.132.221:80
cnzz.mmstat.com
Alibaba (China) Technology Co., Ltd.
US
suspicious

DNS requests

Domain
IP
Reputation
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
www.adobe.com
  • 23.210.248.158
whitelisted
s95.cnzz.com
  • 119.96.207.121
whitelisted
hzs4.cnzz.com
  • 203.119.129.114
suspicious
c.cnzz.com
  • 119.96.207.121
whitelisted
cnzz.mmstat.com
  • 198.11.132.221
whitelisted
icon.cnzz.com
  • 119.96.207.121
whitelisted
pcookie.cnzz.com
  • 106.11.92.15
whitelisted

Threats

No threats detected
No debug info