analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

1.htm_

Full analysis: https://app.any.run/tasks/57a7214e-71ee-4d24-bd13-c25cb55c8d62
Verdict: Malicious activity
Analysis date: June 27, 2022, 07:25:18
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: text/html
File info: HTML document, ASCII text, with very long lines, with CRLF line terminators
MD5:

3CDB09D21817E0AFB3FE970C2DEB28BD

SHA1:

E104E3F8662DAD23EB0695D12AE62A57EA964084

SHA256:

F55A65A9CF01D311AD980CA3FAE84AE0C414F55966E74989BDAB2107152F5E05

SSDEEP:

192:iAOdRoi3R5vfutm0xWgMLwAQxPKdvEFJwwwwbkAIxVNvsqECEPPPKFTdiG9QPLQl:0TdfuYYjKelqzEy3

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads Microsoft Outlook installation path

      • iexplore.exe (PID: 3360)
      • iexplore.exe (PID: 2260)
  • INFO

    • Reads the computer name

      • iexplore.exe (PID: 1500)
      • iexplore.exe (PID: 3360)
      • iexplore.exe (PID: 2260)
      • iexplore.exe (PID: 444)
    • Reads settings of System Certificates

      • iexplore.exe (PID: 3360)
      • iexplore.exe (PID: 2260)
      • iexplore.exe (PID: 1500)
    • Checks supported languages

      • iexplore.exe (PID: 3360)
      • iexplore.exe (PID: 1500)
      • iexplore.exe (PID: 2260)
      • iexplore.exe (PID: 444)
    • Changes internet zones settings

      • iexplore.exe (PID: 1500)
    • Application launched itself

      • iexplore.exe (PID: 1500)
      • iexplore.exe (PID: 2260)
    • Reads internet explorer settings

      • iexplore.exe (PID: 3360)
      • iexplore.exe (PID: 2260)
    • Checks Windows Trust Settings

      • iexplore.exe (PID: 2260)
      • iexplore.exe (PID: 3360)
      • iexplore.exe (PID: 1500)
    • Adds / modifies Windows certificates

      • iexplore.exe (PID: 2260)
      • iexplore.exe (PID: 3360)
    • Changes settings of System certificates

      • iexplore.exe (PID: 3360)
      • iexplore.exe (PID: 2260)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.html | HyperText Markup Language (100)

EXIF

HTML

Robots: none
LocLC: en-US
ReqLC: 1033
SiteID: -
PageID: ConvergedSignIn
HTTPEquivXDnsPrefetchControl: on
Expires: -1
Pragma: no-cache
viewport: width=device-width, initial-scale=1.0, maximum-scale=2.0, user-scalable=yes
Title: Sign in to your account
ContentType: text/html; charset=UTF-8
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
38
Monitored processes
4
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe iexplore.exe iexplore.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1500"C:\Program Files\Internet Explorer\iexplore.exe" "C:\Users\admin\Desktop\1.htm_.html"C:\Program Files\Internet Explorer\iexplore.exe
Explorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
3360"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:1500 CREDAT:144385 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
2260"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:1500 CREDAT:78857 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
444"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:1500 CREDAT:398593 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exeiexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Total events
14 364
Read events
14 154
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
7
Text files
9
Unknown types
4

Dropped files

PID
Process
Filename
Type
2260iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\646C991C2A28825F3CC56E0A1D1E3FA9der
MD5:3523BFA7B3ACACA361AC9814166709AD
SHA256:CE82F93FDB091E30497236D7F04BB67F7008E8E4133D2A8445B531C16D13AA67
1500iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6BADA8974A10C4BD62CC921D13E43B18_711ED44619924BA6DC33E69F97E7FF63binary
MD5:E8371CEC97A11B8D324CAAFEF4BAE00D
SHA256:E1F41A48D78462FECFFA68A5EE5D7B717F78971FE38334641A789A6160A0C776
2260iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:491238B0DC4FFC36443039F814557A4D
SHA256:561C4E6B436C1173141E5CF0655228CAD921130247185AB2080FA1044E321D32
2260iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\646C991C2A28825F3CC56E0A1D1E3FA9binary
MD5:11F4C403521936E74F58520D93D19ECE
SHA256:7C936850C0834FF9446170F28869AA9E22E66CE6B0C65C7F194A69DA33E75112
2260iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\CAF4703619713E3F18D8A9D5D88D6288_45E3C223BCF135987E4038FB6B0DBA13binary
MD5:0D07F21A2ED44CC69C3E3ACF4C59AB12
SHA256:F6010AD4194407094594224D9BC2183A8305200E0F407B94CEFA38F4D405061A
1500iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6BADA8974A10C4BD62CC921D13E43B18_711ED44619924BA6DC33E69F97E7FF63der
MD5:28CC3D4B0DA8A29A9DCD6D4755C84342
SHA256:A4CA2DD1D4545838F7A9102623442BC76BDEB2185E9991A294BCB0B6456DDA0E
3360iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7423F88C7F265F0DEFC08EA88C3BDE45_AA1E8580D4EBC816148CE81268683776binary
MD5:DABB71D6B6E2DB9886EB7E918E6F17D8
SHA256:FA8B63684878B576B072CB3CFDFE5108BC95EF734C06E7DD49A290C6CEB0DA1F
1500iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\favicon[1].icoimage
MD5:DA597791BE3B6E732F0BC8B20E38EE62
SHA256:5B2C34B3C4E8DD898B664DBA6C3786E2FF9869EFF55D673AA48361F11325ED07
2260iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\CAF4703619713E3F18D8A9D5D88D6288_45E3C223BCF135987E4038FB6B0DBA13der
MD5:37D9737D87E736F32071BC84631A152D
SHA256:55961D82ABE79DE45FBDA7F4E7B4EC02F37A53D0617DF5A69C6FCC95D18C0258
3360iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7423F88C7F265F0DEFC08EA88C3BDE45_AA1E8580D4EBC816148CE81268683776der
MD5:2232627DB4A5E856F3BC0D3E5B8D9D9E
SHA256:040579DA7AD446E376B233B9AC1E558476FA9842623D4EF73C8498C4B451A0C6
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
23
DNS requests
9
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2260
iexplore.exe
GET
200
142.250.186.35:80
http://crl.pki.goog/gsr1/gsr1.crl
US
der
1.61 Kb
whitelisted
3360
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
der
471 b
whitelisted
1500
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA8Ull8gIGmZT9XHrHiJQeI%3D
US
der
1.47 Kb
whitelisted
2260
iexplore.exe
GET
200
142.250.186.131:80
http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIAjrICMzZli2TN25s%3D
US
der
724 b
whitelisted
2260
iexplore.exe
GET
200
67.27.158.126:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?98c25a58554e5f02
US
compressed
4.70 Kb
whitelisted
3360
iexplore.exe
GET
200
8.248.119.254:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?25ecb450f1085071
US
compressed
4.70 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3360
iexplore.exe
67.27.158.126:80
ctldl.windowsupdate.com
Level 3 Communications, Inc.
US
malicious
1500
iexplore.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
1500
iexplore.exe
204.79.197.200:443
www.bing.com
Microsoft Corporation
US
whitelisted
1500
iexplore.exe
13.107.21.200:443
www.bing.com
Microsoft Corporation
US
whitelisted
152.199.19.161:443
r20swj13mr.microsoft.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
8.248.119.254:80
ctldl.windowsupdate.com
Level 3 Communications, Inc.
US
suspicious
2260
iexplore.exe
199.36.158.100:443
js-82wha8sw738.web.app
US
malicious
2260
iexplore.exe
67.27.158.126:80
ctldl.windowsupdate.com
Level 3 Communications, Inc.
US
malicious
2260
iexplore.exe
142.250.186.131:80
ocsp.pki.goog
Google Inc.
US
whitelisted
2260
iexplore.exe
142.250.186.35:80
crl.pki.goog
Google Inc.
US
whitelisted

DNS requests

Domain
IP
Reputation
js-82wha8sw738.web.app
  • 199.36.158.100
suspicious
ctldl.windowsupdate.com
  • 67.27.158.126
  • 8.248.119.254
  • 67.27.158.254
  • 67.26.137.254
  • 67.27.159.126
whitelisted
ocsp.pki.goog
  • 142.250.186.131
whitelisted
api.bing.com
  • 13.107.5.80
whitelisted
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
ocsp.digicert.com
  • 93.184.220.29
whitelisted
crl.pki.goog
  • 142.250.186.35
whitelisted
r20swj13mr.microsoft.com
  • 152.199.19.161
whitelisted
iecvlist.microsoft.com
  • 152.199.19.161
whitelisted

Threats

No threats detected
No debug info