File name:

Octoparse 7.3.0 _ 8.1.24 Beta.zip

Full analysis: https://app.any.run/tasks/3ec9b2da-4be8-4c65-a66d-aefe6b448b0f
Verdict: Malicious activity
Analysis date: April 04, 2021, 05:38:36
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

DED7EDB1C6CC8787D8861D94672644F4

SHA1:

DF05353304CDC1243F23394F0A0E212AE00BE591

SHA256:

04BDE25D2B8125278EE966FC0144B894C135BB415CAAFF8EF32A81D7FC538F6A

SSDEEP:

12288:By8l5RURZUf21h/9BGgZCF9HAwzBDuopHjdM3ZYSc0fu4X:By8lLUXl1h/XGFbyohjduZVvGs

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops executable file immediately after starts

      • Octoparse 7.3.0 _ 8.1.24 Beta.exe (PID: 3652)
      • 7za.exe (PID: 2756)
    • Application was dropped or rewritten from another process

      • Octoparse 7.3.0 _ 8.1.24 Beta.exe (PID: 3652)
      • Octoparse 7.3.0 _ 8.1.24 Beta.exe (PID: 3812)
      • sitool.exe (PID: 2548)
    • Uses Task Scheduler to run other applications

      • sitool.exe (PID: 2548)
    • Loads the Task Scheduler COM API

      • schtasks.exe (PID: 2456)
      • schtasks.exe (PID: 2360)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Octoparse 7.3.0 _ 8.1.24 Beta.exe (PID: 3652)
      • Octoparse 7.3.0 _ 8.1.24 Beta.exe (PID: 3812)
      • WinRAR.exe (PID: 2180)
      • Octoparse 7.3.0 _ 8.1.24 Beta.tmp (PID: 2108)
      • 7za.exe (PID: 2756)
    • Reads Windows owner or organization settings

      • Octoparse 7.3.0 _ 8.1.24 Beta.tmp (PID: 2108)
    • Reads the Windows organization settings

      • Octoparse 7.3.0 _ 8.1.24 Beta.tmp (PID: 2108)
    • Drops a file with too old compile date

      • Octoparse 7.3.0 _ 8.1.24 Beta.tmp (PID: 2108)
    • Drops a file with a compile date too recent

      • 7za.exe (PID: 2756)
      • Octoparse 7.3.0 _ 8.1.24 Beta.tmp (PID: 2108)
    • Creates files in the user directory

      • Octoparse 7.3.0 _ 8.1.24 Beta.tmp (PID: 2108)
      • sitool.exe (PID: 2548)
    • Executed via COM

      • explorer.exe (PID: 2380)
      • prevhost.exe (PID: 2892)
      • prevhost.exe (PID: 2168)
  • INFO

    • Application was dropped or rewritten from another process

      • Octoparse 7.3.0 _ 8.1.24 Beta.tmp (PID: 684)
      • Octoparse 7.3.0 _ 8.1.24 Beta.tmp (PID: 2108)
      • 7za.exe (PID: 1348)
      • 7za.exe (PID: 2756)
      • 7za.exe (PID: 3912)
    • Manual execution by user

      • NOTEPAD.EXE (PID: 3192)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0001
ZipCompression: Deflated
ZipModifyDate: 2021:04:04 08:32:20
ZipCRC: 0xdf4e0769
ZipCompressedSize: 703885
ZipUncompressedSize: 777733
ZipFileName: Octoparse 7.3.0 _ 8.1.24 Beta.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
62
Monitored processes
17
Malicious processes
5
Suspicious processes
1

Behavior graph

Click at the process to see the details
drop and start start drop and start drop and start drop and start drop and start drop and start drop and start winrar.exe octoparse 7.3.0 _ 8.1.24 beta.exe octoparse 7.3.0 _ 8.1.24 beta.tmp no specs octoparse 7.3.0 _ 8.1.24 beta.exe octoparse 7.3.0 _ 8.1.24 beta.tmp 7za.exe no specs 7za.exe 7za.exe no specs sitool.exe no specs schtasks.exe no specs schtasks.exe no specs explorer.exe no specs explorer.exe no specs notepad.exe no specs prevhost.exe no specs prevhost.exe no specs notepad.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
548"C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\Octoparse 7.3.0 _ 8.1.24 Beta\license.txtC:\Windows\system32\NOTEPAD.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
684"C:\Users\admin\AppData\Local\Temp\is-66QHH.tmp\Octoparse 7.3.0 _ 8.1.24 Beta.tmp" /SL5="$20160,387272,121344,C:\Users\admin\AppData\Local\Temp\Rar$EXb2180.7959\Octoparse 7.3.0 _ 8.1.24 Beta.exe" C:\Users\admin\AppData\Local\Temp\is-66QHH.tmp\Octoparse 7.3.0 _ 8.1.24 Beta.tmpOctoparse 7.3.0 _ 8.1.24 Beta.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-66qhh.tmp\octoparse 7.3.0 _ 8.1.24 beta.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1348"C:\Users\admin\AppData\Local\Temp\is-87321.tmp\7za.exe" x "C:\Users\admin\AppData\Local\Temp\is-87321.tmp\sub.res" -p"b1lig@n_vl"C:\Users\admin\AppData\Local\Temp\is-87321.tmp\7za.exeOctoparse 7.3.0 _ 8.1.24 Beta.tmp
User:
admin
Company:
Igor Pavlov
Integrity Level:
HIGH
Description:
7-Zip Standalone Console
Exit code:
0
Version:
4.65
Modules
Images
c:\users\admin\appdata\local\temp\is-87321.tmp\7za.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
2108"C:\Users\admin\AppData\Local\Temp\is-76UPP.tmp\Octoparse 7.3.0 _ 8.1.24 Beta.tmp" /SL5="$3017C,387272,121344,C:\Users\admin\AppData\Local\Temp\Rar$EXb2180.7959\Octoparse 7.3.0 _ 8.1.24 Beta.exe" /SPAWNWND=$2017E /NOTIFYWND=$20160 C:\Users\admin\AppData\Local\Temp\is-76UPP.tmp\Octoparse 7.3.0 _ 8.1.24 Beta.tmp
Octoparse 7.3.0 _ 8.1.24 Beta.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-76upp.tmp\octoparse 7.3.0 _ 8.1.24 beta.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2168C:\Windows\system32\prevhost.exe {914FEED8-267A-4BAA-B8AA-21E233792679} -EmbeddingC:\Windows\system32\prevhost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Preview Handler Surrogate Host
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\prevhost.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
2180"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Octoparse 7.3.0 _ 8.1.24 Beta.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2360"C:\Windows\system32\schtasks.exe" /Create /f /XML "C:\Users\admin\AppData\Roaming\SysInfoTool\data.xml" /tn "Microsoft\Windows\Windows Error Reporting\SystemInfoTool"C:\Windows\system32\schtasks.exesitool.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Manages scheduled tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
2380C:\Windows\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -EmbeddingC:\Windows\explorer.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2456"C:\Windows\system32\schtasks.exe" /Delete /tn "Microsoft\Windows\Windows Error Reporting\SystemInfoTool" /fC:\Windows\system32\schtasks.exesitool.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Manages scheduled tasks
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
2548"C:\Users\admin\AppData\Roaming\SysInfoTool\sitool.exe" -cr -tu 7C:\Users\admin\AppData\Roaming\SysInfoTool\sitool.exeOctoparse 7.3.0 _ 8.1.24 Beta.tmp
User:
admin
Integrity Level:
HIGH
Description:
System Info Client
Exit code:
0
Version:
2.0.98.88
Modules
Images
c:\users\admin\appdata\roaming\sysinfotool\sitool.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
1 780
Read events
1 604
Write events
172
Delete events
4

Modification events

(PID) Process:(2180) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2180) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2180) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2180) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E
Operation:writeName:@C:\Windows\system32\NetworkExplorer.dll,-1
Value:
Network
(PID) Process:(2180) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Octoparse 7.3.0 _ 8.1.24 Beta.zip
(PID) Process:(2180) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2180) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2180) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2180) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2180) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
Executable files
6
Suspicious files
3
Text files
6
Unknown types
0

Dropped files

PID
Process
Filename
Type
2108Octoparse 7.3.0 _ 8.1.24 Beta.tmpC:\Users\admin\AppData\Local\Temp\{C56DD03B-C4C3-451F-B3EC-F1B6F02D5B84}\is-DO92V.tmp
MD5:
SHA256:
2108Octoparse 7.3.0 _ 8.1.24 Beta.tmpC:\Users\admin\AppData\Local\Temp\{C56DD03B-C4C3-451F-B3EC-F1B6F02D5B84}\license.txt
MD5:
SHA256:
2180WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2180.7959\Octoparse 7.3.0 _ 8.1.24 Beta.exeexecutable
MD5:
SHA256:
2108Octoparse 7.3.0 _ 8.1.24 Beta.tmpC:\Users\admin\Desktop\Octoparse 7.3.0 _ 8.1.24 Beta\license.txttext
MD5:
SHA256:
27567za.exeC:\Users\admin\AppData\Local\Temp\is-87321.tmp\form.exeexecutable
MD5:
SHA256:
2108Octoparse 7.3.0 _ 8.1.24 Beta.tmpC:\Users\admin\AppData\Roaming\SysInfoTool\sitool.exeexecutable
MD5:
SHA256:
2548sitool.exeC:\Users\admin\AppData\Roaming\SysInfoTool\data.xmlxml
MD5:
SHA256:
2108Octoparse 7.3.0 _ 8.1.24 Beta.tmpC:\Users\admin\AppData\Local\Temp\is-87321.tmp\form.rescompressed
MD5:
SHA256:
2108Octoparse 7.3.0 _ 8.1.24 Beta.tmpC:\Users\admin\AppData\Local\Temp\is-87321.tmp\sub.rescompressed
MD5:AE50AD46B7EF3517F5DF5EDF2B96443E
SHA256:F4A2B3FA7460606D58AD078D320AFCEAD400285304DC49E8F2BA3FA9800854DC
3652Octoparse 7.3.0 _ 8.1.24 Beta.exeC:\Users\admin\AppData\Local\Temp\is-66QHH.tmp\Octoparse 7.3.0 _ 8.1.24 Beta.tmpexecutable
MD5:34ACC2BDB45A9C436181426828C4CB49
SHA256:9C81817ACD4982632D8C7F1DF3898FCA1477577738184265D735F49FC5480F07
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
2
DNS requests
2
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2108
Octoparse 7.3.0 _ 8.1.24 Beta.tmp
POST
200
142.250.186.142:80
http://www.google-analytics.com/collect
US
image
35 b
whitelisted
2108
Octoparse 7.3.0 _ 8.1.24 Beta.tmp
POST
200
142.250.186.142:80
http://www.google-analytics.com/collect
US
image
35 b
whitelisted
2108
Octoparse 7.3.0 _ 8.1.24 Beta.tmp
GET
200
172.67.199.251:80
http://worldofbooks.org/getchannel
US
binary
1 b
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2108
Octoparse 7.3.0 _ 8.1.24 Beta.tmp
142.250.186.142:80
www.google-analytics.com
Google Inc.
US
whitelisted
2108
Octoparse 7.3.0 _ 8.1.24 Beta.tmp
172.67.199.251:80
worldofbooks.org
US
suspicious

DNS requests

Domain
IP
Reputation
www.google-analytics.com
  • 142.250.186.142
whitelisted
worldofbooks.org
  • 172.67.199.251
  • 104.21.44.128
malicious

Threats

PID
Process
Class
Message
2108
Octoparse 7.3.0 _ 8.1.24 Beta.tmp
Unknown Traffic
ET INFO Suspicious User-Agent (1 space)
1 ETPRO signatures available at the full report
No debug info