URL: | http://www.chanpinban.com/r100427626352/ |
Full analysis: | https://app.any.run/tasks/1955b063-d500-40c5-8519-e00e59148315 |
Verdict: | Malicious activity |
Analysis date: | December 03, 2019, 01:18:16 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MD5: | 04025C542B4570BCB736ACA6DDE38491 |
SHA1: | BB6157E5CD11C487C23C96A25A0A165F7FBB81AF |
SHA256: | F671FEBD07557F619A214750A85FEDCA904C9A4577AA3285C6F50122CA1A4541 |
SSDEEP: | 3:N1KJS4SzitXUZDQan:Cc4SzitENQa |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
1296 | "C:\Program Files\Internet Explorer\iexplore.exe" -nohome | C:\Program Files\Internet Explorer\iexplore.exe | explorer.exe | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Version: 8.00.7600.16385 (win7_rtm.090713-1255) | ||||
3212 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:1296 CREDAT:71937 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | |
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Version: 8.00.7600.16385 (win7_rtm.090713-1255) | ||||
1712 | C:\Windows\system32\Macromed\Flash\FlashUtil32_26_0_0_131_ActiveX.exe -Embedding | C:\Windows\system32\Macromed\Flash\FlashUtil32_26_0_0_131_ActiveX.exe | — | svchost.exe |
User: admin Company: Adobe Systems Incorporated Integrity Level: MEDIUM Description: Adobe® Flash® Player Installer/Uninstaller 26.0 r0 Version: 26,0,0,131 |
PID | Process | Filename | Type | |
---|---|---|---|---|
1296 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\favicon[1].ico | — | |
MD5:— | SHA256:— | |||
1296 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico | — | |
MD5:— | SHA256:— | |||
3212 | iexplore.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\admin@chanpinban[1].txt | text | |
MD5:F883FC7552DA8EE52EF0E20358783AF1 | SHA256:547E2246E97B234069388C30E22376A56D2C65BC4E59B43F0344A333D42F9E45 | |||
3212 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\index.dat | dat | |
MD5:B1CDECA07624B72581B995467F7C6467 | SHA256:516C96082D640D4E8782E625C6F9642BA785574A053175EC3D8595E5A3253EDE | |||
3212 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\53A9674Y\style[1].css | text | |
MD5:A925D301BABBCFA8E1AEDE5E3D9F4D9B | SHA256:AD38E89ED5344AF2E8364D74D7D7726D75EB0B15B826BE1B1E8949A38DB8CDFC | |||
3212 | iexplore.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt | text | |
MD5:EF9DEA18A0F687EEDC9253DE2400D833 | SHA256:18A88EFF56B0A437D19C58A23FAA75CE8AB15599B9425D922D2E5E0763B8C153 | |||
3212 | iexplore.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\index.dat | dat | |
MD5:7A8C855275577715EC8A4A9C6D00E12B | SHA256:49CF2AB5896C134038B3003725C2CBA2F720D0EA009A3470188888569B3F1200 | |||
3212 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OC6K6F0M\flaticon[1].css | text | |
MD5:C6187BE0199D4F31B49FB465FBEA3B71 | SHA256:EF35968B49133B6EAF5263AFF76F58C91BDD8A143360A5C3D84BAD669B9AB66E | |||
3212 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\53A9674Y\owl.carousel.min[1].css | text | |
MD5:121C894B28FF9DE00AE67FDF30C13F73 | SHA256:286A6D651A3CBCE53D1DB2443090D0BDB279CF84CFB8800854C7EB3EC0EBD28D | |||
3212 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\53A9674Y\responsive[1].css | text | |
MD5:CE7FE76DA7FBE72F08337EB9DD25BB5F | SHA256:0F5ABE323450AE8DE74BF164E3D543844AAB2B9659226E1F132373559E870FDB |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
3212 | iexplore.exe | GET | 200 | 47.104.251.168:80 | http://www.chanpinban.com/static/shop/css/owl.carousel.min.css | CN | text | 5.09 Kb | unknown |
3212 | iexplore.exe | GET | 200 | 47.104.251.168:80 | http://www.chanpinban.com/static/shop/fonts/flaticon.css | CN | text | 1.85 Kb | unknown |
3212 | iexplore.exe | GET | 200 | 47.104.251.168:80 | http://www.chanpinban.com/static/shop/css/style.css | CN | text | 71.9 Kb | unknown |
3212 | iexplore.exe | GET | 200 | 47.104.251.168:80 | http://www.chanpinban.com/static/shop/img/logo.png | CN | image | 5.76 Kb | unknown |
3212 | iexplore.exe | GET | 200 | 47.104.251.168:80 | http://www.chanpinban.com/static/shop/js/bootstrap.min.js | CN | text | 76.1 Kb | unknown |
3212 | iexplore.exe | GET | — | 36.99.142.195:80 | http://media.chanpinban.com/banner/chs_wM3WkTI.webp | CN | — | — | malicious |
3212 | iexplore.exe | GET | — | 36.99.142.195:80 | http://media.chanpinban.com/banner/7.webp | CN | — | — | malicious |
3212 | iexplore.exe | GET | 200 | 47.104.251.168:80 | http://www.chanpinban.com/static/shop/fonts/Flaticon.eot? | CN | eot | 15.0 Kb | unknown |
3212 | iexplore.exe | GET | 200 | 36.99.142.195:80 | http://media.chanpinban.com/heads/100275195507.jpg | CN | image | 3.21 Kb | malicious |
3212 | iexplore.exe | GET | 200 | 47.104.251.168:80 | http://www.chanpinban.com/static/shop/css/responsive.css | CN | text | 50.3 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
1296 | iexplore.exe | 204.79.197.200:80 | www.bing.com | Microsoft Corporation | US | whitelisted |
3212 | iexplore.exe | 47.104.251.168:80 | www.chanpinban.com | Hangzhou Alibaba Advertising Co.,Ltd. | CN | unknown |
3212 | iexplore.exe | 150.109.206.35:80 | res.wx.qq.com | — | US | unknown |
3212 | iexplore.exe | 59.80.39.108:443 | cdn.bootcss.com | China Unicom IP network | CN | malicious |
3212 | iexplore.exe | 36.99.142.195:80 | media.chanpinban.com | No.31,Jin-rong Street | CN | malicious |
3212 | iexplore.exe | 103.235.46.191:443 | hm.baidu.com | Beijing Baidu Netcom Science and Technology Co., Ltd. | HK | suspicious |
1296 | iexplore.exe | 47.104.251.168:80 | www.chanpinban.com | Hangzhou Alibaba Advertising Co.,Ltd. | CN | unknown |
Domain | IP | Reputation |
---|---|---|
www.bing.com |
| whitelisted |
www.chanpinban.com |
| unknown |
cdn.bootcss.com |
| whitelisted |
res.wx.qq.com |
| whitelisted |
hm.baidu.com |
| whitelisted |
media.chanpinban.com |
| unknown |