File name:

amtemu.v0.9.2-painter.zip

Full analysis: https://app.any.run/tasks/50718ab9-9830-4c45-98e8-5bc0b02a9ba0
Verdict: Malicious activity
Analysis date: April 14, 2018, 14:50:22
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

CB0958A7A1600F21570548598975C190

SHA1:

5518D58261546752A355B87892840FF2D8F89B89

SHA256:

034CCDADCEDE8C353CD1C96A5FACC984F21B22F592C2F65A00319545E9335EC2

SSDEEP:

49152:dxx+JkxcpiCXRLQ3x7SXAiGP/7BGsVhla23Slw/m3Ko/X456LdiaFkSRKLC+xAKh:ojxgmQTP/NFhadamh/XqjpSuVACj0LfS

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • amtemu.v0.9.2-painter.exe (PID: 2248)
      • amtemu.v0.9.2-painter.exe (PID: 1248)
    • Application loaded dropped or rewritten executable

      • amtemu.v0.9.2-painter.exe (PID: 1248)
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Dropped object may contain URL's

      • amtemu.v0.9.2-painter.exe (PID: 1248)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2018:04:14 16:46:05
ZipCRC: 0x2d265155
ZipCompressedSize: 1766918
ZipUncompressedSize: 2506752
ZipFileName: amtemu.v0.9.2-painter.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
42
Monitored processes
3
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start 7zfm.exe no specs amtemu.v0.9.2-painter.exe no specs amtemu.v0.9.2-painter.exe

Process information

PID
CMD
Path
Indicators
Parent process
1248"C:\Users\admin\Desktop\amtemu.v0.9.2-painter.exe" C:\Users\admin\Desktop\amtemu.v0.9.2-painter.exe
explorer.exe
User:
admin
Company:
PainteR
Integrity Level:
HIGH
Description:
ProxyEmu
Exit code:
0
Version:
0.9.2.0
Modules
Images
c:\users\admin\desktop\amtemu.v0.9.2-painter.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2248"C:\Users\admin\Desktop\amtemu.v0.9.2-painter.exe" C:\Users\admin\Desktop\amtemu.v0.9.2-painter.exeexplorer.exe
User:
admin
Company:
PainteR
Integrity Level:
MEDIUM
Description:
ProxyEmu
Exit code:
3221226540
Version:
0.9.2.0
Modules
Images
c:\users\admin\desktop\amtemu.v0.9.2-painter.exe
c:\systemroot\system32\ntdll.dll
2668"C:\Program Files\7-Zip\7zFM.exe" "C:\Users\admin\AppData\Local\Temp\amtemu.v0.9.2-painter.zip"C:\Program Files\7-Zip\7zFM.exeexplorer.exe
User:
admin
Company:
Igor Pavlov
Integrity Level:
MEDIUM
Description:
7-Zip File Manager
Exit code:
0
Version:
16.04
Modules
Images
c:\program files\7-zip\7zfm.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
296
Read events
251
Write events
44
Delete events
1

Modification events

(PID) Process:(2668) 7zFM.exeKey:HKEY_CURRENT_USER\Software\7-Zip\FM
Operation:writeName:FolderShortcuts
Value:
(PID) Process:(2668) 7zFM.exeKey:HKEY_CURRENT_USER\Software\7-Zip\FM
Operation:writeName:FolderHistory
Value:
43003A005C00550073006500720073005C00610064006D0069006E005C0041007000700044006100740061005C004C006F00630061006C005C00540065006D0070005C0061006D00740065006D0075002E00760030002E0039002E0032002D007000610069006E007400650072002E007A00690070005C000000
(PID) Process:(2668) 7zFM.exeKey:HKEY_CURRENT_USER\Software\7-Zip\FM
Operation:writeName:PanelPath0
Value:
C:\Users\admin\AppData\Local\Temp\
(PID) Process:(2668) 7zFM.exeKey:HKEY_CURRENT_USER\Software\7-Zip\FM
Operation:writeName:FlatViewArc0
Value:
0
(PID) Process:(2668) 7zFM.exeKey:HKEY_CURRENT_USER\Software\7-Zip\FM
Operation:writeName:PanelPath1
Value:
(PID) Process:(2668) 7zFM.exeKey:HKEY_CURRENT_USER\Software\7-Zip\FM
Operation:writeName:FlatViewArc1
Value:
0
(PID) Process:(2668) 7zFM.exeKey:HKEY_CURRENT_USER\Software\7-Zip\FM
Operation:writeName:ListMode
Value:
771
(PID) Process:(2668) 7zFM.exeKey:HKEY_CURRENT_USER\Software\7-Zip\FM
Operation:writeName:Position
Value:
1600000016000000D60300000B02000000000000
(PID) Process:(2668) 7zFM.exeKey:HKEY_CURRENT_USER\Software\7-Zip\FM
Operation:writeName:Panels
Value:
0100000000000000DA010000
(PID) Process:(1248) amtemu.v0.9.2-painter.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\FirstFolder
Operation:writeName:0
Value:
43003A005C00550073006500720073005C00610064006D0069006E005C004400650073006B0074006F0070005C0061006D00740065006D0075002E00760030002E0039002E0032002D007000610069006E007400650072002E00650078006500000043003A005C00550073006500720073005C00610064006D0069006E005C004400650073006B0074006F0070000000
Executable files
3
Suspicious files
0
Text files
9
Unknown types
0

Dropped files

PID
Process
Filename
Type
26687zFM.exeC:\Users\admin\AppData\Local\Temp\7zEC6A94025\amtemu.v0.9.2-painter.exe
MD5:
SHA256:
26687zFM.exeC:\Users\admin\AppData\Local\Temp\7zEC6A94025\amtlib.dll
MD5:
SHA256:
1248amtemu.v0.9.2-painter.exeC:\Users\admin\Desktop\amtlib.dll.DELexecutable
MD5:
SHA256:
1248amtemu.v0.9.2-painter.exeC:\Users\admin\Desktop\painter.initext
MD5:
SHA256:
1248amtemu.v0.9.2-painter.exeC:\Users\admin\AppData\Local\Temp\spc_player.dllexecutable
MD5:41AFBF49BA7F6EE164F31FAA2CD38E15
SHA256:50D30B7AA7B9858F91F33165314C7CF7F2ACC97157091676C7E7925E018FD387
1248amtemu.v0.9.2-painter.exeC:\Users\admin\Desktop\amtlib.dllexecutable
MD5:B773CEE8AAE74E5EB7E0DD3ADA08A21E
SHA256:5C4606E5734CE62AE45228641A6A4A49491F1B70D6C7DA8C0335CB7B11862841
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

Domain
IP
Reputation
teredo.ipv6.microsoft.com
whitelisted

Threats

No threats detected
No debug info