File name:

driveroff.zip

Full analysis: https://app.any.run/tasks/87559c61-c2a9-48c2-a2f5-552506a31ca7
Verdict: Malicious activity
Analysis date: April 18, 2019, 13:22:40
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

9D76474927EAAB9D5A9D8478EE6BB26B

SHA1:

77D5BC14843F565A70051DAA75E8FDE11DD97B4A

SHA256:

00D1893232CCDACA51F9FEE1A73365CEFC71AB8C99CEBA17BBD9462C8C00658A

SSDEEP:

12288:/6hW7lKvwtLla9etfiC3RvlaE1Tjbq0Tf1cjLC3uypTI+QF+:rl5Ta9etfiC3Tag3b12jLCpTX

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • DRIVEROFF[1].EXE (PID: 3104)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2536)
    • Starts Internet Explorer

      • DRIVEROFF[1].EXE (PID: 3104)
  • INFO

    • Application launched itself

      • iexplore.exe (PID: 2712)
    • Creates files in the user directory

      • iexplore.exe (PID: 296)
    • Reads Internet Cache Settings

      • iexplore.exe (PID: 296)
    • Changes internet zones settings

      • iexplore.exe (PID: 2712)
    • Reads internet explorer settings

      • iexplore.exe (PID: 296)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0009
ZipCompression: Deflated
ZipModifyDate: 2019:04:18 15:16:21
ZipCRC: 0xe7a181ba
ZipCompressedSize: 595117
ZipUncompressedSize: 1729024
ZipFileName: DRIVEROFF[1].EXE
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
37
Monitored processes
4
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe driveroff[1].exe iexplore.exe iexplore.exe

Process information

PID
CMD
Path
Indicators
Parent process
296"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2712 CREDAT:71937C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2536"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\driveroff.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\comdlg32.dll
2712"C:\Program Files\Internet Explorer\iexplore.exe" -nohomeC:\Program Files\Internet Explorer\iexplore.exe
DRIVEROFF[1].EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
1
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3104"C:\Users\admin\Desktop\driveroff\DRIVEROFF[1].EXE" C:\Users\admin\Desktop\driveroff\DRIVEROFF[1].EXE
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\driveroff\driveroff[1].exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
Total events
712
Read events
657
Write events
54
Delete events
1

Modification events

(PID) Process:(2536) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2536) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2536) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2536) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\driveroff.zip
(PID) Process:(2536) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2536) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2536) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2536) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2536) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath
Operation:writeName:0
Value:
C:\Users\admin\Desktop\driveroff
(PID) Process:(2536) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
Executable files
1
Suspicious files
3
Text files
21
Unknown types
7

Dropped files

PID
Process
Filename
Type
296iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
MD5:
SHA256:
2712iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H6QNMHE9\favicon[1].ico
MD5:
SHA256:
2712iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
MD5:
SHA256:
296iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\3OG7AQD8\index[1].php
MD5:
SHA256:
2536WinRAR.exeC:\Users\admin\Desktop\driveroff\DRIVEROFF[1].EXEexecutable
MD5:
SHA256:
296iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txttext
MD5:
SHA256:
296iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\History\Low\History.IE5\index.datdat
MD5:
SHA256:
296iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\3OG7AQD8\desktop.iniini
MD5:4A3DEB274BB5F0212C2419D3D8D08612
SHA256:2842973D15A14323E08598BE1DFB87E54BF88A76BE8C7BC94C56B079446EDF38
296iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\3M76N2CA\button[1].csstext
MD5:
SHA256:
2712iexplore.exeC:\Users\admin\AppData\Local\Temp\~DFDFC5FB83251ADFBC.TMP
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
15
DNS requests
9
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
296
iexplore.exe
GET
302
136.243.146.142:80
http://www.driveroff.com/scan/desktop.php?scanid=adf3ac1b6902f4f5f23fef46efd0f142&mypc_name=USER-PC
DE
malicious
3104
DRIVEROFF[1].EXE
POST
200
136.243.146.142:80
http://www.driveroff.com/scan/desktop.php?scanid=adf3ac1b6902f4f5f23fef46efd0f142&mypc_name=USER-PC
DE
text
32 b
malicious
296
iexplore.exe
GET
302
136.243.146.142:80
http://www.driveroff.com/index.php
DE
html
219 b
malicious
2712
iexplore.exe
GET
200
13.107.21.200:80
http://www.bing.com/favicon.ico
US
image
237 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
296
iexplore.exe
136.243.146.142:443
www.driveroff.com
Hetzner Online GmbH
DE
unknown
296
iexplore.exe
172.217.16.2:443
pagead2.googlesyndication.com
Google Inc.
US
whitelisted
296
iexplore.exe
23.111.8.154:443
oss.maxcdn.com
netDNA
US
unknown
296
iexplore.exe
172.217.21.194:443
adservice.google.nl
Google Inc.
US
whitelisted
296
iexplore.exe
172.217.20.202:443
ajax.googleapis.com
Google Inc.
US
whitelisted
3104
DRIVEROFF[1].EXE
136.243.146.142:80
www.driveroff.com
Hetzner Online GmbH
DE
unknown
296
iexplore.exe
136.243.146.142:80
www.driveroff.com
Hetzner Online GmbH
DE
unknown
2712
iexplore.exe
13.107.21.200:80
www.bing.com
Microsoft Corporation
US
whitelisted
296
iexplore.exe
172.217.16.34:443
adservice.google.com
Google Inc.
US
whitelisted

DNS requests

Domain
IP
Reputation
www.driveroff.com
  • 136.243.146.142
malicious
www.bing.com
  • 13.107.21.200
whitelisted
oss.maxcdn.com
  • 23.111.8.154
whitelisted
pagead2.googlesyndication.com
  • 172.217.16.2
whitelisted
ajax.googleapis.com
  • 172.217.20.202
whitelisted
adservice.google.nl
  • 172.217.21.194
whitelisted
adservice.google.com
  • 172.217.16.34
whitelisted
www.google-analytics.com
  • 216.58.215.78
whitelisted

Threats

No threats detected
No debug info