URL:

https://objectstorage.ap-singapore-2.oraclecloud.com/n/ax4mqlu25efi/b/tozeyourslok/o/preload-verif-processing.html

Full analysis: https://app.any.run/tasks/5e524440-1435-430f-8bd6-cf3feb89e6b5
Verdict: Malicious activity
Analysis date: March 24, 2025, 16:04:46
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
phishing
massbass
Indicators:
MD5:

A3AC7F5E666E476972F46BBACC3424DD

SHA1:

CE8625A070B1E22551BB0694D9CE2229FE347DA6

SHA256:

E5DFD07A383007D89C2ACA25E8B2B3B33A1670715B2A70F0F70D821B57A056E5

SSDEEP:

3:N8OL3CL1NfOeKQBZO00pMgf5yV0XAE+K5uJ:2OLYjOVQDOpMaUGQ3K5uJ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • PHISHING has been detected (SURICATA)

      • svchost.exe (PID: 1080)
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Application launched itself

      • iexplore.exe (PID: 2000)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
36
Monitored processes
3
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe #PHISHING svchost.exe

Process information

PID
CMD
Path
Indicators
Parent process
1080C:\Windows\system32\svchost.exe -k NetworkServiceC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1324"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2000 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2000"C:\Program Files\Internet Explorer\iexplore.exe" "https://objectstorage.ap-singapore-2.oraclecloud.com/n/ax4mqlu25efi/b/tozeyourslok/o/preload-verif-processing.html"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
Total events
24 755
Read events
24 645
Write events
89
Delete events
21

Modification events

(PID) Process:(1324) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(1324) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(1324) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(2000) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{76464F5C-7142-481A-B7C8-27207E88A00E}
Operation:writeName:WpadDecisionReason
Value:
1
(PID) Process:(2000) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{76464F5C-7142-481A-B7C8-27207E88A00E}
Operation:writeName:WpadDecisionTime
Value:
7CEF417AD69CDB01
(PID) Process:(2000) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{76464F5C-7142-481A-B7C8-27207E88A00E}
Operation:writeName:WpadDecision
Value:
0
(PID) Process:(2000) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{76464F5C-7142-481A-B7C8-27207E88A00E}
Operation:writeName:WpadNetworkName
Value:
Network 5
(PID) Process:(2000) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{76464F5C-7142-481A-B7C8-27207E88A00E}
Operation:delete valueName:WpadDetectedUrl
Value:
(PID) Process:(2000) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\d4-da-6d-42-05-8c
Operation:writeName:WpadDecisionReason
Value:
1
(PID) Process:(2000) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\d4-da-6d-42-05-8c
Operation:writeName:WpadDecisionTime
Value:
7CEF417AD69CDB01
Executable files
0
Suspicious files
22
Text files
6
Unknown types
0

Dropped files

PID
Process
Filename
Type
1324iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157compressed
MD5:77B20B5CD41BC6BB475CCA3F91AE6E3C
SHA256:5511A9B9F9144ED7BDE4CCB074733B7C564D918D2A8B10D391AFC6BE5B3B1509
1324iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_49536AB5156BDD74EFF881D01C36A419binary
MD5:D9375D43C5304E9908A07F28E6F1B95F
SHA256:C20DE907A6B30FE3F7342609044EEDEF974082A6ED315B6C5F210A278E99EE52
1324iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\59D76868C250B3240414CE3EFBB12518_6660E78D902AE8ED55523D87DB9127A9binary
MD5:D5B06BDE1DCB191D7BD8EA4DEEA6C0A0
SHA256:DCAAB8CA51A96E499CE831B276C0B154A043FC593313514EE6D4D9271A99867C
1080svchost.exeC:\Windows\ServiceProfiles\NetworkService\AppData\Local\Temp\Tar2268.tmpbinary
MD5:91A1B89AA7A488DBB204DBB4767F1F21
SHA256:F6BE95C88C20EF82EE8A6878E16F9ECD77300BC1905EB826592A0DD41AD1C0F8
1324iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8B2B9A00839EED1DFDCCC3BFC2F5DF12binary
MD5:C9BE626E9715952E9B70F92F912B9787
SHA256:C13E8D22800C200915F87F71C31185053E4E60CA25DE2E41E160E09CD2D815D4
1324iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:874DB3C546C38E3CCFA8D59727271A8F
SHA256:DFBC905C23CAD9C78D4EF8EB4D61EF924824AF8834FD07FED6299BEF083EA757
1324iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\59D76868C250B3240414CE3EFBB12518_6660E78D902AE8ED55523D87DB9127A9binary
MD5:3390C3B0F27DB6C4829BC60CAB31E8D8
SHA256:4114421E3814729CD4CEC1EE3D508AE95899BEEAFDB8D31CBFD3CA95EE26AF9F
1324iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\all.min[1].csstext
MD5:3D5EF2BF867C4054A2F336CDBAD9E1DC
SHA256:A361E7885C36BACB3FD9CB068DA207C3B9329962CAC022D06E28923939F575E8
2000iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\26C212D9399727259664BDFCA073966E_F9F7D6A7ECE73106D2A8C63168CDA10Dbinary
MD5:4872BABAF39AA62B8D32695EBB7E9173
SHA256:2EE85DF86EE29BBEB3DCA81AA29B6DE204F605A2769B84C728A329178A2D0999
1324iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8B2B9A00839EED1DFDCCC3BFC2F5DF12binary
MD5:811362B22F02EE7F077CB7845702EB76
SHA256:73AFCD3CC5A650F7774EF5CCDB4A1CC88086B59B307968F511A175667A327B58
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
24
DNS requests
16
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1324
iexplore.exe
GET
200
217.20.57.35:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?2c1c1224967e261d
unknown
whitelisted
1324
iexplore.exe
GET
200
23.54.109.203:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSnxLiz3Fu1WB6n1%2FE6xWn1b0jXiQQUdIWAwGbH3zfez70pN6oDHb7tzRcCEAVhVKfiha3SF49An%2B7nx24%3D
unknown
whitelisted
1324
iexplore.exe
GET
200
142.250.184.227:80
http://c.pki.goog/r/gsr1.crl
unknown
whitelisted
1324
iexplore.exe
GET
200
142.250.184.227:80
http://o.pki.goog/we2/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTuMJxAT2trYla0jia%2F5EUSmLrk3QQUdb7Ed66J9kQ3fc%2BxaB8dGuvcNFkCEQDmpjMpZqu4LxJugBCwTODC
unknown
whitelisted
1324
iexplore.exe
GET
200
142.250.184.227:80
http://c.pki.goog/r/r4.crl
unknown
whitelisted
1324
iexplore.exe
GET
200
23.54.109.203:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAz1vQYrVgL0erhQLCPM8GY%3D
unknown
whitelisted
2000
iexplore.exe
GET
200
23.54.109.203:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
1324
iexplore.exe
GET
200
217.20.57.35:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?ba3ae9903a34c873
unknown
whitelisted
2000
iexplore.exe
GET
200
23.54.109.203:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:138
whitelisted
1324
iexplore.exe
217.142.168.1:443
objectstorage.ap-singapore-2.oraclecloud.com
Primlight AB
SE
whitelisted
1324
iexplore.exe
217.20.57.35:80
ctldl.windowsupdate.com
US
whitelisted
1324
iexplore.exe
23.54.109.203:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
1324
iexplore.exe
104.17.25.14:443
cdnjs.cloudflare.com
CLOUDFLARENET
whitelisted
1324
iexplore.exe
142.250.185.131:443
www.gstatic.com
GOOGLE
US
whitelisted
1324
iexplore.exe
142.250.184.227:80
c.pki.goog
GOOGLE
US
whitelisted
2000
iexplore.exe
217.142.168.1:443
objectstorage.ap-singapore-2.oraclecloud.com
Primlight AB
SE
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.186.46
whitelisted
objectstorage.ap-singapore-2.oraclecloud.com
  • 217.142.168.1
whitelisted
ctldl.windowsupdate.com
  • 217.20.57.35
  • 217.20.57.34
  • 217.20.57.36
  • 217.20.57.18
  • 217.20.57.19
  • 84.201.210.23
  • 217.20.57.20
  • 84.201.210.39
whitelisted
ocsp.digicert.com
  • 23.54.109.203
whitelisted
cdnjs.cloudflare.com
  • 104.17.25.14
  • 104.17.24.14
whitelisted
www.gstatic.com
  • 142.250.185.131
whitelisted
c.pki.goog
  • 142.250.184.227
whitelisted
o.pki.goog
  • 142.250.184.227
whitelisted
api.bing.com
  • 13.107.5.80
whitelisted
www.bing.com
  • 104.126.37.171
  • 104.126.37.160
  • 104.126.37.168
  • 104.126.37.163
  • 104.126.37.153
  • 104.126.37.170
  • 104.126.37.147
  • 104.126.37.155
  • 104.126.37.162
whitelisted

Threats

PID
Process
Class
Message
1080
svchost.exe
Possible Social Engineering Attempted
PHISHING [ANY.RUN] Suspected AllBass Phishing (objectstorage .ap-singapore-2 .oraclecloud .com)
1080
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
No debug info