analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
URL:

https://www.file.net/process/chromesetup.exe.html

Full analysis: https://app.any.run/tasks/4665932a-6f8e-4d04-9917-a3869d81cc30
Verdict: Malicious activity
Analysis date: August 13, 2019, 17:32:08
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

2E46F84DE68F2B8C4D810F2E8185BE28

SHA1:

E20F477365EA14EAE26A6BFA2F4BB69645A29E3F

SHA256:

EEB6034DA6620308FBC8DA08C7ECB5D90CC2CED4165A888CC94CEB4A01FEDA09

SSDEEP:

3:N8DSLQk0udAsG9AHRAkuNG:2OLQDR9AHRAkN

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Reads Internet Cache Settings

      • iexplore.exe (PID: 3748)
      • iexplore.exe (PID: 2632)
    • Reads settings of System Certificates

      • iexplore.exe (PID: 2632)
    • Creates files in the user directory

      • iexplore.exe (PID: 2632)
      • iexplore.exe (PID: 3748)
    • Adds / modifies Windows certificates

      • iexplore.exe (PID: 2632)
    • Reads internet explorer settings

      • iexplore.exe (PID: 3748)
    • Changes settings of System certificates

      • iexplore.exe (PID: 2632)
    • Changes internet zones settings

      • iexplore.exe (PID: 2632)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
35
Monitored processes
2
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe

Process information

PID
CMD
Path
Indicators
Parent process
2632"C:\Program Files\Internet Explorer\iexplore.exe" "https://www.file.net/process/chromesetup.exe.html"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
3748"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2632 CREDAT:71937C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Total events
440
Read events
365
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
0
Text files
14
Unknown types
5

Dropped files

PID
Process
Filename
Type
2632iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\favicon[1].ico
MD5:
SHA256:
2632iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
MD5:
SHA256:
3748iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\9WRL9M8M\addthis_widget[1].js
MD5:
SHA256:
3748iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
MD5:
SHA256:
2632iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@file[1].txttext
MD5:658B4B57C89138B6D8E680B60814EEF5
SHA256:1360E8164FB99B42AF6FA9B41110075A723C21638386700D0FE7313918F73D2F
3748iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txttext
MD5:4E79A2D28A364C64594AC998D41702B3
SHA256:CC1162623AD3D355F549C0DC77398F215951AABE0E7E9E4327140E470F1BCFE5
3748iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\admin@reimageplus[1].txttext
MD5:D8494C8BF768C79747AB5A167A18E9C8
SHA256:53E22EFBA04C92BDF183B69C766AC7938059AA620326F3D701B090DCEC715E0A
3748iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\index.datdat
MD5:4DB3B1BEF3051F90D36A301B3BE93C03
SHA256:A25A1E0CEE45F6DE1E62E09555E3F79E1C9F4643D9EC169EE909B6BCEDC1C409
3748iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\index.datdat
MD5:F8A642CEDE1DF2652BC082B5D61BE25B
SHA256:414EA257975E3F9E3541AA9CE6617DF87B59FB3EB80E8A8447E1F5E8998BA72F
3748iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\History\Low\History.IE5\MSHist012019081320190814\index.datdat
MD5:10FD07D089F8EC426A5E4FA00189E769
SHA256:D1953F2D1859CAAC2045B2D8BF0EEC55D56515604711889BEAB4C6144D533E4C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
7
DNS requests
5
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3748
iexplore.exe
GET
161.47.7.14:80
http://www.reimageplus.com/lp/rgn/index.php?channel=filenet&banner=fn_en_reimage&adgroup=direct&ads_name=direct&keyword=direct&nms=1&lpx=rvb
US
suspicious
2632
iexplore.exe
GET
200
204.79.197.200:80
http://www.bing.com/favicon.ico
US
image
237 b
whitelisted
3748
iexplore.exe
GET
301
161.47.7.14:80
http://www.reimageplus.com/includes/router_land.php?tracking=filenet&banner=fn_en_reimage&lpx=rvb
US
text
22 b
suspicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3748
iexplore.exe
172.217.22.78:443
www.google-analytics.com
Google Inc.
US
whitelisted
3748
iexplore.exe
161.47.7.14:80
www.reimageplus.com
Rackspace Ltd.
US
malicious
3748
iexplore.exe
23.210.248.44:443
s7.addthis.com
Akamai International B.V.
NL
whitelisted
3748
iexplore.exe
104.25.71.118:443
www.file.net
Cloudflare Inc
US
shared
2632
iexplore.exe
104.25.71.118:443
www.file.net
Cloudflare Inc
US
shared
2632
iexplore.exe
204.79.197.200:80
www.bing.com
Microsoft Corporation
US
whitelisted

DNS requests

Domain
IP
Reputation
www.file.net
  • 104.25.71.118
  • 104.25.72.118
suspicious
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
www.google-analytics.com
  • 172.217.22.78
whitelisted
s7.addthis.com
  • 23.210.248.44
whitelisted
www.reimageplus.com
  • 161.47.7.14
suspicious

Threats

No threats detected
No debug info