URL:

http://hebrasdepaz.org

Full analysis: https://app.any.run/tasks/f8c12951-04e2-44bf-aeb9-292fe4777ecd
Verdict: Malicious activity
Analysis date: April 26, 2023, 12:11:32
OS: Windows 10 Professional (build: 19044, 32 bit)
Indicators:
MD5:

1622A7B0E5CBE1707BC2C8BEBAB7BC63

SHA1:

372491C6DF5FD37E2A94823523692F0A18C0B57C

SHA256:

E88545BB726F66378E56235938C1B185E3CA4346B19443E8A00A2D2A146BA1EE

SSDEEP:

3:N1KWA3/2u3:CW0/

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Create files in a temporary directory

      • iexplore.exe (PID: 2016)
      • msedge.exe (PID: 2160)
      • msedge.exe (PID: 8)
    • Application launched itself

      • iexplore.exe (PID: 2016)
      • msedge.exe (PID: 8)
    • The process checks LSA protection

      • identity_helper.exe (PID: 4832)
      • cookie_exporter.exe (PID: 5852)
    • Checks supported languages

      • cookie_exporter.exe (PID: 5852)
      • identity_helper.exe (PID: 4832)
    • Reads the computer name

      • cookie_exporter.exe (PID: 5852)
      • identity_helper.exe (PID: 4832)
    • Checks proxy server information

      • cookie_exporter.exe (PID: 5852)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
108
Monitored processes
32
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe ie_to_edge_stub.exe no specs ie_to_edge_stub.exe no specs ie_to_edge_stub.exe no specs ie_to_edge_stub.exe no specs msedge.exe no specs msedge.exe no specs iexplore.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs cookie_exporter.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
8"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --from-ie-to-edge=3 --ie-frame-hwnd=60220C:\Program Files\Microsoft\Edge\Application\msedge.exeie_to_edge_stub.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
111.0.1661.62
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\111.0.1661.62\msedge_elf.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\cryptbase.dll
228"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --mojo-platform-channel-handle=5136 --field-trial-handle=2052,i,15269856144885119696,15988039692460097130,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
111.0.1661.62
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\program files\microsoft\edge\application\111.0.1661.62\msedge_elf.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cryptbase.dll
544"C:\Program Files\Microsoft\Edge\Application\111.0.1661.62\BHO\ie_to_edge_stub.exe" --from-ie-to-edge=3 --ie-frame-hwnd=60220C:\Program Files\Microsoft\Edge\Application\111.0.1661.62\BHO\ie_to_edge_stub.exeiexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
IEToEdge BHO
Exit code:
0
Version:
111.0.1661.62
Modules
Images
c:\program files\microsoft\edge\application\111.0.1661.62\bho\ie_to_edge_stub.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
616"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=9 --mojo-platform-channel-handle=4308 --field-trial-handle=2052,i,15269856144885119696,15988039692460097130,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
111.0.1661.62
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\111.0.1661.62\msedge_elf.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cryptbase.dll
696"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2016 CREDAT:9474 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
1288"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=5788 --field-trial-handle=2052,i,15269856144885119696,15988039692460097130,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
111.0.1661.62
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\program files\microsoft\edge\application\111.0.1661.62\msedge_elf.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cryptbase.dll
1516"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=6700 --field-trial-handle=2052,i,15269856144885119696,15988039692460097130,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
111.0.1661.62
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\111.0.1661.62\msedge_elf.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cryptbase.dll
1652"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=19 --mojo-platform-channel-handle=4608 --field-trial-handle=2052,i,15269856144885119696,15988039692460097130,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
111.0.1661.62
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\111.0.1661.62\msedge_elf.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cryptbase.dll
2016"C:\Program Files\Internet Explorer\iexplore.exe" "http://hebrasdepaz.org"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
1
Version:
11.00.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\msvcp_win.dll
2136"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=5760 --field-trial-handle=2052,i,15269856144885119696,15988039692460097130,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
111.0.1661.62
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\111.0.1661.62\msedge_elf.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cryptbase.dll
Total events
20 332
Read events
20 094
Write events
204
Delete events
34

Modification events

(PID) Process:(2016) iexplore.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(2016) iexplore.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(2016) iexplore.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main
Operation:writeName:OperationalData
Value:
0C00000000000000
(PID) Process:(2016) iexplore.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\BrowserEmulation
Operation:writeName:CVListXMLVersionLow
Value:
395196024
(PID) Process:(2016) iexplore.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\BrowserEmulation
Operation:writeName:CVListXMLVersionHigh
Value:
268435456
(PID) Process:(2016) iexplore.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Spartan
Operation:writeName:RAC_LaunchFlags
Value:
53
(PID) Process:(2016) iexplore.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\GPU
Operation:writeName:SoftwareFallback
Value:
0
(PID) Process:(2016) iexplore.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\GPU
Operation:writeName:VendorId
Value:
5140
(PID) Process:(2016) iexplore.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\GPU
Operation:writeName:DeviceId
Value:
140
(PID) Process:(2016) iexplore.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\GPU
Operation:writeName:SubSysId
Value:
0
Executable files
0
Suspicious files
160
Text files
192
Unknown types
80

Dropped files

PID
Process
Filename
Type
696iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\Low\IE\XPIOF5VQ\0E5IRSLR.htmhtml
MD5:4E04331BF298C688E344F5D30AACB674
SHA256:67178D3AD6AFA21E0748C03BCF4DEE19A8DC0FC71DDAAD0E5C32A4CBCADCD811
8msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old~RF31f28f.TMP
MD5:
SHA256:
696iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\Low\IE\O6HH16FW\icon-exclamation[1].pngimage
MD5:C33DE66281E933259772399D10A6AFE8
SHA256:F1591A5221136C49438642155691AE6C68E25B7241F3D7EBE975B09A77662016
8msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old
MD5:
SHA256:
8msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\60ff6f2c-1b90-4cd2-a934-0e35d2d0d35f.tmptext
MD5:E28B8D37CD868AC80DCDB72BB46ED85A
SHA256:3268DF02B3F87071C77559EAD090414170B1239520CC271091D9D831CA101606
8msedge.exeC:\USERS\ADMIN\APPDATA\LOCAL\MICROSOFT\EDGE\USER DATA\CRASHPAD\SETTINGS.DATbinary
MD5:EB47346CA7428F0A534B2C7639EFD344
SHA256:A5A3A7B62E8E9364943C9813A7D365B5A5635E3DC0523ECC6631B1B9320F79A5
696iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\Low\MSIMGSIZ.DATsmt
MD5:0392ADA071EB68355BED625D8F9695F3
SHA256:B1313DD95EAF63F33F86F72F09E2ECD700D11159A8693210C37470FCB84038F7
8msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\History-journal
MD5:
SHA256:
8msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Last Versiontext
MD5:D6DB6EA02FE506F2DA98F1C137243587
SHA256:126173A7D7D0F54A9FCE5465180BC49DB023E723A41BB55A0F9497BE76FBAA28
8msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\ShaderCache\data_0vxd
MD5:CF89D16BB9107C631DAABF0C0EE58EFB
SHA256:D6A5FE39CD672781B256E0E3102F7022635F1D4BB7CFCC90A80FFFE4D0F3877E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
65
DNS requests
53
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
696
iexplore.exe
GET
200
172.67.203.139:80
http://hebrasdepaz.org/
US
html
1.73 Kb
suspicious
696
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEALnkXH7gCHpP%2BLZg4NMUMA%3D
US
der
471 b
whitelisted
696
iexplore.exe
GET
200
172.67.203.139:80
http://hebrasdepaz.org/cdn-cgi/images/icon-exclamation.png?1376755637
US
image
452 b
suspicious
2016
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
der
471 b
whitelisted
696
iexplore.exe
GET
200
172.67.203.139:80
http://hebrasdepaz.org/cdn-cgi/styles/cf.errors.css
US
text
4.42 Kb
suspicious
696
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAqvpsXKY8RRQeo74ffHUxc%3D
US
der
471 b
whitelisted
2016
iexplore.exe
GET
410
172.67.203.139:80
http://hebrasdepaz.org/favicon.ico
US
html
109 b
suspicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
696
iexplore.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
696
iexplore.exe
204.79.197.239:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
2172
msedge.exe
13.107.21.239:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
2016
iexplore.exe
104.126.37.176:443
www.bing.com
Akamai International B.V.
DE
suspicious
2016
iexplore.exe
23.38.22.250:443
go.microsoft.com
AKAMAI-AS
NL
malicious
2016
iexplore.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
2172
msedge.exe
23.38.22.250:443
go.microsoft.com
AKAMAI-AS
NL
malicious
2172
msedge.exe
20.8.16.139:443
nav-edge.smartscreen.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2172
msedge.exe
20.105.73.143:443
data-edge.smartscreen.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2172
msedge.exe
20.40.24.37:443
microsoftedgewelcome.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown

DNS requests

Domain
IP
Reputation
go.microsoft.com
  • 23.38.22.250
  • 104.64.117.184
whitelisted
config.edge.skype.com
  • 13.107.42.16
malicious
ocsp.digicert.com
  • 192.229.221.95
whitelisted
edge.microsoft.com
  • 204.79.197.239
  • 13.107.21.239
whitelisted
officeclient.microsoft.com
  • 52.109.20.82
whitelisted
www.bing.com
  • 104.126.37.176
  • 104.126.37.161
  • 104.126.37.177
  • 104.126.37.160
  • 104.126.37.171
  • 104.126.37.163
  • 104.126.37.179
  • 104.126.37.178
  • 104.126.37.170
  • 104.126.37.153
  • 104.126.37.144
  • 104.126.37.145
  • 104.126.37.137
  • 104.126.37.139
  • 104.126.37.152
  • 104.126.37.131
  • 104.126.37.154
  • 104.126.37.130
  • 92.123.104.31
  • 92.123.104.22
  • 92.123.104.33
  • 92.123.104.18
  • 92.123.104.34
  • 92.123.104.21
  • 92.123.104.23
  • 92.123.104.30
  • 92.123.104.26
whitelisted
ieonline.microsoft.com
  • 204.79.197.200
whitelisted
nav-edge.smartscreen.microsoft.com
  • 20.8.16.139
whitelisted
microsoftedgewelcome.microsoft.com
  • 20.40.24.37
whitelisted
data-edge.smartscreen.microsoft.com
  • 20.105.73.143
whitelisted

Threats

PID
Process
Class
Message
696
iexplore.exe
A Network Trojan was detected
AV POLICY CloudFlare Anti-Phishing Protection Warning in HTML Inbound
No debug info