download:

index.html

Full analysis: https://app.any.run/tasks/382a3288-1e2a-4c50-874c-ad531fc33b42
Verdict: Malicious activity
Analysis date: September 03, 2019, 16:53:23
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: text/html
File info: HTML document, UTF-8 Unicode text, with very long lines
MD5:

233EB9BF9D5CFA108F2F7D4F87121EDC

SHA1:

7B4CBE855E5DE7569FC158639AEC4CBBF914CDAA

SHA256:

F3DECB7E5299CED46DBAAAF15BB432264FBD626A687911F74D69720A7ADD8F41

SSDEEP:

1536:SjO2BlwGwC/YSvxMFEhmd8PXF/vqOy7Cv/O3W89lLLBrqm0eoHJJDJCi4L8OKwZJ:6/uSqms8P0qm0eF46PI7BQ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executed via COM

      • DllHost.exe (PID: 2256)
  • INFO

    • Adds / modifies Windows certificates

      • iexplore.exe (PID: 3948)
    • Changes internet zones settings

      • iexplore.exe (PID: 3348)
    • Changes settings of System certificates

      • iexplore.exe (PID: 3948)
    • Application launched itself

      • iexplore.exe (PID: 3348)
    • Reads internet explorer settings

      • iexplore.exe (PID: 3948)
    • Reads settings of System Certificates

      • iexplore.exe (PID: 3948)
    • Creates files in the user directory

      • iexplore.exe (PID: 3948)
      • iexplore.exe (PID: 3348)
      • WINWORD.EXE (PID: 3240)
      • WINWORD.EXE (PID: 796)
    • Reads Internet Cache Settings

      • iexplore.exe (PID: 3948)
      • iexplore.exe (PID: 3348)
    • Manual execution by user

      • WINWORD.EXE (PID: 3240)
      • WINWORD.EXE (PID: 796)
    • Reads Microsoft Office registry keys

      • WINWORD.EXE (PID: 3240)
      • WINWORD.EXE (PID: 796)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.htm/html | HyperText Markup Language with DOCTYPE (80.6)
.html | HyperText Markup Language (19.3)

EXIF

HTML

ContentType: text/html; charset=UTF-8
HTTPEquivXUACompatible: IE=edge
msapplicationConfig: none
Description: Pornhub is the world’s leading free porn site. Choose from millions of hardcore videos that stream quickly and in high quality, including amazing VR Porn. The largest adult site on the Internet just keeps getting better. We have more pornstars and real amateurs than anyone else. It’s fast, it’s free, it’s Pornhub!
Title: Free Porn Videos & Sex Movies - Porno, XXX, Porn Tube | Pornhub
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
41
Monitored processes
5
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe winword.exe no specs winword.exe no specs PhotoViewer.dll no specs

Process information

PID
CMD
Path
Indicators
Parent process
796"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\Desktop\responsibilitytoys.rtf"C:\Program Files\Microsoft Office\Office14\WINWORD.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Word
Exit code:
0
Version:
14.0.6024.1000
Modules
Images
c:\program files\microsoft office\office14\winword.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
2256C:\Windows\system32\DllHost.exe /Processid:{76D0CB12-7604-4048-B83C-1005C7DDC503}C:\Windows\system32\DllHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
COM Surrogate
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\dllhost.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3240"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\Desktop\floridamiddle.rtf"C:\Program Files\Microsoft Office\Office14\WINWORD.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Word
Exit code:
0
Version:
14.0.6024.1000
Modules
Images
c:\program files\microsoft office\office14\winword.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
3348"C:\Program Files\Internet Explorer\iexplore.exe" C:\Users\admin\AppData\Local\Temp\index.htmlC:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
1
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3948"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3348 CREDAT:79873C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
1 842
Read events
1 643
Write events
169
Delete events
30

Modification events

(PID) Process:(3348) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(3348) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(3348) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(3348) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones
Operation:writeName:SecuritySafe
Value:
1
(PID) Process:(3348) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(3348) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
4600000092000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
(PID) Process:(3348) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Recovery\Active
Operation:writeName:{60E28515-CE6B-11E9-B86F-5254004A04AF}
Value:
0
(PID) Process:(3348) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Type
Value:
4
(PID) Process:(3348) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Count
Value:
2
(PID) Process:(3348) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Time
Value:
E3070900020003001000350028009402
Executable files
0
Suspicious files
5
Text files
63
Unknown types
11

Dropped files

PID
Process
Filename
Type
3348iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\favicon[1].ico
MD5:
SHA256:
3348iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
MD5:
SHA256:
3948iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGRR2OYX\css[1].txttext
MD5:99B94D072C28C9CC881236E92C0FB2BB
SHA256:CC71D3AA49AC78E3613C7A6CC8BDF65045ED12DE8956F59C15EAFDA8228187AA
3948iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H6QNMHE9\large[1].csstext
MD5:E4536C289B7CD26E4981A673F94F408C
SHA256:951EF0CDDBB936BA9541954A3324715A51F7D1D939AE16F334182FA2D78B3286
3948iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0488CJO\ph-functions[1].jshtml
MD5:97F0492AD9FBCCFCC13D0A81259F6D37
SHA256:BC4C088F26411D3246052D2DCFA5CDD4D3118BE41D879A9A4B671A18F34055A8
3948iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\front-index-pc[1].csstext
MD5:67F1AA3160D83085541E4DD87FB976D0
SHA256:883E0B926FCD4484A8CB90A651A4F4DEB0E26911F9C81AE50A719EA49252916C
3948iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0488CJO\premium-modals[1].csstext
MD5:83FCA7F105A5612EDC323E7FF659101A
SHA256:8F20540BBD87C0378200B6B19D64C15D0B3ED29E33DD635F458123C8F26FA7B5
3948iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\ph-tracking[1].jstext
MD5:4B8296FB5F8C4EDB3BB10CDCB8FDF8D7
SHA256:0EFDB7573776D190A2B35E2D51199F214AB58F959F4523430B4FD41AA829483D
3948iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H6QNMHE9\mg_utils-1.0.0[1].jstext
MD5:76BB3A5D7C40A1D09F8F65151CC545F2
SHA256:DDC9F4F47E1899AC87825AB4FF864E5CDB861BCB237FF6F9971D0EAD18B45CBB
3948iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\generated-header[1].csstext
MD5:C4E62546858C2F0D5BB2FEC2374BF38B
SHA256:BA5ED23A230D9EDC8BC9F9E6058B1DF5EFD3181CE4F52EA48C5C57CE76C69A6A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
33
DNS requests
13
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3348
iexplore.exe
GET
200
204.79.197.200:80
http://www.bing.com/favicon.ico
US
image
237 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3948
iexplore.exe
172.217.23.163:443
fonts.gstatic.com
Google Inc.
US
whitelisted
3348
iexplore.exe
204.79.197.200:80
www.bing.com
Microsoft Corporation
US
whitelisted
3948
iexplore.exe
152.195.34.118:443
ci.phncdn.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
3948
iexplore.exe
172.217.21.234:443
fonts.googleapis.com
Google Inc.
US
whitelisted
3948
iexplore.exe
69.16.175.10:443
smpop.icfcdn.com
Highwinds Network Group, Inc.
US
malicious
3948
iexplore.exe
66.254.114.38:443
ads.trafficjunky.net
Reflected Networks, Inc.
US
unknown
3948
iexplore.exe
31.186.170.69:443
adiktivebanners.com
LeaseWeb Netherlands B.V.
NL
unknown
3948
iexplore.exe
216.18.168.166:443
a.adtng.com
Reflected Networks, Inc.
US
suspicious
3948
iexplore.exe
205.185.208.78:443
hw-cdn2.contentabc.com
Highwinds Network Group, Inc.
US
suspicious
3948
iexplore.exe
205.185.208.142:443
cdn1d-static-shared.phncdn.com
Highwinds Network Group, Inc.
US
suspicious

DNS requests

Domain
IP
Reputation
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
smpop.icfcdn.com
  • 69.16.175.10
  • 69.16.175.42
malicious
ci.phncdn.com
  • 152.195.34.118
whitelisted
fonts.googleapis.com
  • 172.217.21.234
whitelisted
fonts.gstatic.com
  • 172.217.23.163
whitelisted
cdn1d-static-shared.phncdn.com
  • 205.185.208.142
whitelisted
static.trafficjunky.com
  • 205.185.208.79
whitelisted
di.phncdn.com
  • 205.185.208.142
whitelisted
ads.trafficjunky.net
  • 66.254.114.38
whitelisted
adiktivebanners.com
  • 31.186.170.69
unknown

Threats

No threats detected
No debug info