analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
URL:

http://ww38.qfind.net/?__jsfail_ns

Full analysis: https://app.any.run/tasks/85f0dca3-81ec-4398-af85-2335355c8dae
Verdict: Malicious activity
Analysis date: January 18, 2019, 08:58:18
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
adware
Indicators:
MD5:

501B1F255011A5933C86209EFF515443

SHA1:

A875F4748DDA149DDE97FA07BDCF490AC75D1667

SHA256:

F7008A36CB31F0AD5F6E865BC67EFE9AA56198C50CE02FAF64F852C1E1A614CE

SSDEEP:

3:N1KJS2L90RKeET6LW:CcfKNT6i

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Changes internet zones settings

      • iexplore.exe (PID: 2860)
    • Application launched itself

      • iexplore.exe (PID: 2860)
    • Reads internet explorer settings

      • iexplore.exe (PID: 3184)
    • Reads Internet Cache Settings

      • iexplore.exe (PID: 2860)
      • iexplore.exe (PID: 3184)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
31
Monitored processes
2
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe

Process information

PID
CMD
Path
Indicators
Parent process
2860"C:\Program Files\Internet Explorer\iexplore.exe" -nohomeC:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
3184"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2860 CREDAT:71937C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Total events
397
Read events
335
Write events
59
Delete events
3

Modification events

(PID) Process:(2860) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(2860) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(2860) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(2860) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones
Operation:writeName:SecuritySafe
Value:
1
(PID) Process:(2860) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(2860) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
4600000069000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
(PID) Process:(2860) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Recovery\Active
Operation:writeName:{48766B79-1AFF-11E9-BAD8-5254004A04AF}
Value:
0
(PID) Process:(2860) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Type
Value:
4
(PID) Process:(2860) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Count
Value:
3
(PID) Process:(2860) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Time
Value:
E30701000500120008003A003800F600
Executable files
0
Suspicious files
0
Text files
16
Unknown types
4

Dropped files

PID
Process
Filename
Type
3184iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OCDM6JB6\ww38_qfind_net[1].txt
MD5:
SHA256:
3184iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OCDM6JB6\saledefault[1].css
MD5:
SHA256:
3184iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PP6KS563\iyfsearch_com[1].txt
MD5:
SHA256:
2860iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RB73MZ6Y\favicon[1].ico
MD5:
SHA256:
2860iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
MD5:
SHA256:
3184iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\U2ZG9DE0\skenzo[1].csstext
MD5:258924C7D7C159A3861E9838F0B40012
SHA256:DB30F3956434FA476F2F5A605696E792A57398E8DED3AF2FEB7913C731AD7AB8
3184iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PP6KS563\min[1].jstext
MD5:5563332AD6AF63C9C94CEF15761BE544
SHA256:4EFEC11A42893D4DF0249174CBE5AFAE24A5734F5DED35C5E84C56BF9F473EC2
3184iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OCDM6JB6\ww38_qfind_net[1].htmhtml
MD5:54BFCDDF31A8E9F84A032D8463E3CCE9
SHA256:1DCCF9D2BC3C83C4EDEF54B33741FD44FB2BD89047FD91E1B44562CDBFB7CEFA
3184iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PP6KS563\sale_form[1].jstext
MD5:F875C795D8B9814FFD3E0911680E92A9
SHA256:6A8EB31355AE80BE16EA52D590C23C6157550934193D77E8AB76B3EEE3A8F142
3184iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OCDM6JB6\saledefault[2].csstext
MD5:8EFD217A0C8452C520F46F6328FD3263
SHA256:22633836724903845AC6B0B9CA1E780EEEBC0697B7AAE6DB9E54C7FC8C0E62A2
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
21
TCP/UDP connections
18
DNS requests
9
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3184
iexplore.exe
GET
200
52.222.146.147:80
http://d1lxhc4jvstzrp.cloudfront.net/themes/saledefault.css
US
text
1.48 Kb
shared
3184
iexplore.exe
GET
200
52.222.146.147:80
http://d1lxhc4jvstzrp.cloudfront.net/themes/saledefault.css
US
text
1.48 Kb
shared
3184
iexplore.exe
GET
200
52.222.146.147:80
http://d1lxhc4jvstzrp.cloudfront.net/themes/assets/skenzo.css
US
text
208 b
shared
3184
iexplore.exe
GET
200
2.16.186.106:80
http://i2.cdn-image.com/__media__/js/min.js?v2.2
unknown
text
2.97 Kb
whitelisted
3184
iexplore.exe
GET
200
185.53.179.29:80
http://ww38.qfind.net/?__jsfail_ns
DE
html
914 b
malicious
3184
iexplore.exe
GET
200
208.91.196.46:80
http://iyfsearch.com/?dn=qfind.net&pid=9PO755G95&_nozc_=1
VG
html
5.52 Kb
suspicious
3184
iexplore.exe
GET
200
185.53.178.30:80
http://c.parkingcrew.net/scripts/sale_form.js
DE
text
767 b
whitelisted
3184
iexplore.exe
GET
200
52.222.146.147:80
http://d1lxhc4jvstzrp.cloudfront.net/themes/assets/style.css
US
text
343 b
shared
3184
iexplore.exe
GET
200
2.16.186.106:80
http://i2.cdn-image.com/__media__/pics/12471/arrow.png
unknown
image
1.04 Kb
whitelisted
2860
iexplore.exe
GET
200
13.107.21.200:80
http://www.bing.com/favicon.ico
US
image
237 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2860
iexplore.exe
204.79.197.200:80
www.bing.com
Microsoft Corporation
US
whitelisted
3184
iexplore.exe
185.53.179.29:80
ww38.qfind.net
Team Internet AG
DE
malicious
2860
iexplore.exe
185.53.179.29:80
ww38.qfind.net
Team Internet AG
DE
malicious
2860
iexplore.exe
13.107.21.200:80
www.bing.com
Microsoft Corporation
US
whitelisted
3184
iexplore.exe
2.16.186.64:80
i2.cdn-image.com
Akamai International B.V.
whitelisted
3184
iexplore.exe
2.16.186.106:80
i2.cdn-image.com
Akamai International B.V.
whitelisted
3184
iexplore.exe
52.222.146.147:80
d1lxhc4jvstzrp.cloudfront.net
Amazon.com, Inc.
US
unknown
3184
iexplore.exe
185.53.178.30:80
c.parkingcrew.net
Team Internet AG
DE
suspicious
3184
iexplore.exe
208.91.196.46:80
iyfsearch.com
Confluence Networks Inc
VG
malicious

DNS requests

Domain
IP
Reputation
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
ww38.qfind.net
  • 185.53.179.29
malicious
d1lxhc4jvstzrp.cloudfront.net
  • 52.222.146.147
  • 52.222.146.64
  • 52.222.146.36
  • 52.222.146.106
shared
c.parkingcrew.net
  • 185.53.178.30
whitelisted
iyfsearch.com
  • 208.91.196.46
suspicious
i2.cdn-image.com
  • 2.16.186.106
  • 2.16.186.64
whitelisted
i4.cdn-image.com
  • 2.16.186.64
  • 2.16.186.106
whitelisted
i1.cdn-image.com
  • 2.16.186.106
  • 2.16.186.64
whitelisted
i3.cdn-image.com
  • 2.16.186.106
  • 2.16.186.64
whitelisted

Threats

PID
Process
Class
Message
3184
iexplore.exe
Misc activity
ADWARE [PTsecurity] InstantAccess
No debug info