| URL: | https://www.2020recommend.club/index.php?id=604 |
| Full analysis: | https://app.any.run/tasks/8c81cd94-98cf-4ce3-9a9f-b3516e134f58 |
| Verdict: | No threats detected |
| Analysis date: | June 10, 2020, 01:53:48 |
| OS: | Windows 10 Professional (build: 16299, 64 bit) |
| Tags: | |
| Indicators: | |
| MD5: | 61C7B85B638EE185C8395873D1BCC460 |
| SHA1: | 0D6876E0DF4B3F2AE8EBABD02FF4FED68886FF05 |
| SHA256: | EFBA81FCBB3187E66AD03435E799AEE6CE650089BA528E887C02097C35C31C20 |
| SSDEEP: | 3:N8DSLFFQGK1A8rhHHc7:2OLnQTnH4 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 3476 | "C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:4380 CREDAT:9476 /prefetch:2 | C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE | iexplore.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Exit code: 0 Version: 11.00.16299.15 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3952 | "C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe" -Embedding | C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe | — | svchost.exe | |||||||||||
User: admin Company: Adobe Systems Incorporated Integrity Level: MEDIUM Description: Adobe® Flash® Player Utility Exit code: 0 Version: 29,0,0,171 Modules
| |||||||||||||||
| 4380 | "C:\Program Files\internet explorer\iexplore.exe" "https://www.2020recommend.club/index.php?id=604" | C:\Program Files\internet explorer\iexplore.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Exit code: 0 Version: 11.00.16299.15 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4468 | "C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:4380 CREDAT:9474 /prefetch:2 | C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE | iexplore.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Exit code: 0 Version: 11.00.16299.15 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (4380) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (4380) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (4380) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (4380) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main |
| Operation: | write | Name: | CompatibilityFlags |
Value: 0 | |||
| (PID) Process: | (4380) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (4380) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (4380) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (4380) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (4380) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones |
| Operation: | write | Name: | SecuritySafe |
Value: 1 | |||
| (PID) Process: | (4380) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Recovery\Active |
| Operation: | write | Name: | {42A4F7FA-AABD-11EA-B44E-5254004AAD11} |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 4380 | iexplore.exe | C:\Users\admin\AppData\Local\Temp\~DF5D1DDAC3D3E856D2.TMP | — | |
MD5:— | SHA256:— | |||
| 4468 | IEXPLORE.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\Low\IE\ODMF9BZQ\index[1].htm | html | |
MD5:— | SHA256:— | |||
| 4468 | IEXPLORE.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\Low\IE\CHE4YA56\servlet[1].htm | html | |
MD5:— | SHA256:— | |||
| 4468 | IEXPLORE.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\Low\IE\CHE4YA56\59bg0aspj7vnhu4237bam9a1jo[1].js | text | |
MD5:— | SHA256:— | |||
| 3952 | FlashUtil_ActiveX.exe | C:\Users\admin\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\settings.sxx | sol | |
MD5:DC35E18F184BF5D008B05792DED7AE0F | SHA256:7C8C0F166C6221874C39C4A023B15D9F1E052D99A9B7EB3171816E9EDF05D97F | |||
| 3952 | FlashUtil_ActiveX.exe | C:\Users\admin\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\settings.sxx:Zone.Identifier | text | |
MD5:FBCCF14D504B7B2DBCB5A5BDA75BD93B | SHA256:EACD09517CE90D34BA562171D15AC40D302F0E691B439F91BE1B6406E25F5913 | |||
| 3952 | FlashUtil_ActiveX.exe | C:\Users\admin\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\settings.sol | sol | |
MD5:DC35E18F184BF5D008B05792DED7AE0F | SHA256:7C8C0F166C6221874C39C4A023B15D9F1E052D99A9B7EB3171816E9EDF05D97F | |||
| 4468 | IEXPLORE.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\Low\MSIMGSIZ.DAT | smt | |
MD5:0392ADA071EB68355BED625D8F9695F3 | SHA256:B1313DD95EAF63F33F86F72F09E2ECD700D11159A8693210C37470FCB84038F7 | |||
| 3952 | FlashUtil_ActiveX.exe | C:\Users\admin\AppData\Roaming\Adobe\Flash Player\NativeCache\NativeCache.directory:Zone.Identifier | text | |
MD5:FBCCF14D504B7B2DBCB5A5BDA75BD93B | SHA256:EACD09517CE90D34BA562171D15AC40D302F0E691B439F91BE1B6406E25F5913 | |||
| 4468 | IEXPLORE.EXE | C:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\USYG4YNZ\www.2020recommend[1].xml | text | |
MD5:C1DDEA3EF6BBEF3E7060A1A9AD89E4C5 | SHA256:B71E4D17274636B97179BA2D97C742735B6510EB54F22893D3A2DAFF2CEB28DB | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1944 | svchost.exe | GET | 404 | 38.75.137.81:443 | https://www.2020recommend.club/favicon.ico | US | — | — | malicious |
3476 | IEXPLORE.EXE | GET | 302 | 104.111.238.86:80 | http://go.microsoft.com/fwlink/?LinkId=838604 | NL | — | — | whitelisted |
1944 | svchost.exe | GET | 302 | 104.111.238.86:443 | https://go.microsoft.com/fwlink/?LinkId=517287 | NL | — | — | whitelisted |
3476 | IEXPLORE.EXE | GET | 301 | 2.18.233.62:443 | https://www.microsoft.com/edge/?form=MA13DL&OCID=MA13DL | unknown | — | — | whitelisted |
3476 | IEXPLORE.EXE | GET | 301 | 2.18.233.62:443 | https://www.microsoft.com/en-us/edge/?form=MA13DL&OCID=MA13DL | unknown | — | — | whitelisted |
3476 | IEXPLORE.EXE | HEAD | 200 | 2.18.232.120:443 | https://fs.microsoft.com/fs/windows/config.json | unknown | — | — | whitelisted |
1944 | svchost.exe | GET | 200 | 38.75.137.81:443 | https://www.2020recommend.club/logo.swf | US | swf | 638 b | malicious |
3476 | IEXPLORE.EXE | GET | 301 | 2.18.233.62:443 | https://www.microsoft.com/ja-jp/welcomeie11/ | unknown | — | — | whitelisted |
3476 | IEXPLORE.EXE | GET | 200 | 38.75.137.81:443 | https://www.2020recommend.club/pubs/servlet.php?fp=f902a91c267992ceaf32345cee8825d2&lang=en-US&token=&id=49701&sign=da3faf78447d3f7610e2eeba1bd35210&validate=078a764123c31f09f6fb1a2e8b8027ea | US | html | 32 b | malicious |
1944 | svchost.exe | GET | 404 | 38.75.137.81:443 | https://www.2020recommend.club/static/error-img.png | US | — | — | malicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4468 | IEXPLORE.EXE | 38.75.137.81:443 | www.2020recommend.club | Cogent Communications | US | malicious |
4380 | iexplore.exe | 38.75.137.81:443 | www.2020recommend.club | Cogent Communications | US | malicious |
3476 | IEXPLORE.EXE | 104.111.238.86:443 | go.microsoft.com | Akamai International B.V. | NL | whitelisted |
3476 | IEXPLORE.EXE | 104.111.238.86:80 | go.microsoft.com | Akamai International B.V. | NL | whitelisted |
3476 | IEXPLORE.EXE | 2.18.233.62:443 | www.microsoft.com | Akamai International B.V. | — | whitelisted |
— | — | 2.18.233.62:443 | www.microsoft.com | Akamai International B.V. | — | whitelisted |
1248 | svchost.exe | 2.18.232.120:443 | fs.microsoft.com | Akamai International B.V. | — | whitelisted |
4468 | IEXPLORE.EXE | 2.18.233.74:443 | geo2.adobe.com | Akamai International B.V. | — | whitelisted |
4468 | IEXPLORE.EXE | 2.18.235.69:443 | fpdownload.macromedia.com | Akamai International B.V. | — | whitelisted |
Domain | IP | Reputation |
|---|---|---|
www.2020recommend.club |
| malicious |
go.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
fs.microsoft.com |
| whitelisted |
geo2.adobe.com |
| whitelisted |
fpdownload.macromedia.com |
| whitelisted |