File name:

_SolidSQUAD_.7z

Full analysis: https://app.any.run/tasks/9e56e028-6f4f-4ba9-a6cf-3440a65308cc
Verdict: Malicious activity
Analysis date: July 27, 2022, 11:52:02
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-7z-compressed
File info: 7-zip archive data, version 0.4
MD5:

D4159DA216CA94EF18ABA8E7E5C42ACC

SHA1:

081866CF25F33702162689E491DA60158379E206

SHA256:

05E5F7D120701312834063A1F4C4260629A3EBBB0027D207B1914CAF1B928A16

SSDEEP:

196608:vGelZorbHH+hqX4lsc3wSq8o7ST7RjmGek37:ukZorbHHUDySKcj7ek37

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 664)
    • Application was dropped or rewritten from another process

      • installs.exe (PID: 2832)
      • installs.exe (PID: 1744)
      • lmgrd.exe (PID: 3600)
      • lmgrd.exe (PID: 2784)
      • SolidWorksCodeGenerator.exe (PID: 3316)
      • SW2010-2016.Activator.GUI.SSQ.exe (PID: 3516)
      • sw_d.exe (PID: 3780)
    • Drops executable file immediately after starts

      • WinRAR.exe (PID: 3084)
  • SUSPICIOUS

    • Reads the computer name

      • WinRAR.exe (PID: 3084)
      • SW2010-2016.Activator.GUI.SSQ.exe (PID: 3516)
      • SolidWorksCodeGenerator.exe (PID: 3316)
    • Checks supported languages

      • WinRAR.exe (PID: 3084)
      • installs.exe (PID: 1744)
      • lmgrd.exe (PID: 3600)
      • lmgrd.exe (PID: 2784)
      • sw_d.exe (PID: 3780)
      • SolidWorksCodeGenerator.exe (PID: 3316)
      • SW2010-2016.Activator.GUI.SSQ.exe (PID: 3516)
    • Creates a directory in Program Files

      • WinRAR.exe (PID: 3084)
    • Creates files in the program directory

      • WinRAR.exe (PID: 3084)
    • Drops a file with a compile date too recent

      • WinRAR.exe (PID: 3084)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3084)
    • Application launched itself

      • lmgrd.exe (PID: 3600)
  • INFO

    • Manual execution by user

      • installs.exe (PID: 1744)
      • installs.exe (PID: 2832)
      • lmgrd.exe (PID: 3600)
      • sw_d.exe (PID: 3780)
      • SolidWorksCodeGenerator.exe (PID: 3316)
      • SW2010-2016.Activator.GUI.SSQ.exe (PID: 3516)
      • regedit.exe (PID: 3488)
      • regedit.exe (PID: 2456)
    • Checks supported languages

      • regedit.exe (PID: 2456)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.7z | 7-Zip compressed archive (v0.4) (57.1)
.7z | 7-Zip compressed archive (gen) (42.8)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
57
Monitored processes
11
Malicious processes
4
Suspicious processes
2

Behavior graph

Click at the process to see the details
start winrar.exe searchprotocolhost.exe no specs installs.exe no specs installs.exe lmgrd.exe no specs lmgrd.exe no specs sw_d.exe no specs solidworkscodegenerator.exe no specs sw2010-2016.activator.gui.ssq.exe no specs regedit.exe no specs regedit.exe

Process information

PID
CMD
Path
Indicators
Parent process
664"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe4_ Global\UsGthrCtrlFltPipeMssGthrPipe4 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\system32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7601.24542 (win7sp1_ldr_escrow.191209-2211)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1744"C:\Users\admin\Desktop\LicenseServer\installs.exe" C:\Users\admin\Desktop\LicenseServer\installs.exe
Explorer.EXE
User:
admin
Integrity Level:
HIGH
Exit code:
1
Modules
Images
c:\users\admin\desktop\licenseserver\installs.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2456"regedit.exe" "C:\Users\admin\Desktop\SolidWorksSerialNumbers2016.reg"C:\Windows\regedit.exe
Explorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Registry Editor
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\regedit.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2784"C:\Users\admin\Desktop\LicenseServer\lmgrd.exe" -z2C:\Users\admin\Desktop\LicenseServer\lmgrd.exelmgrd.exe
User:
admin
Company:
Flexera Software LLC
Integrity Level:
MEDIUM
Description:
Flexera Software LLC
Exit code:
4294967295
Version:
11.11.1.2 build 134011
Modules
Images
c:\users\admin\desktop\licenseserver\lmgrd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\user32.dll
2832"C:\Users\admin\Desktop\LicenseServer\installs.exe" C:\Users\admin\Desktop\LicenseServer\installs.exeExplorer.EXE
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\licenseserver\installs.exe
c:\windows\system32\ntdll.dll
3084"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\_SolidSQUAD_.7z"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3316"C:\Users\admin\Desktop\SolidWorksCodeGenerator.exe" C:\Users\admin\Desktop\SolidWorksCodeGenerator.exeExplorer.EXE
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\solidworkscodegenerator.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
3488"regedit.exe" "C:\Users\admin\Desktop\SolidWorksSerialNumbers2016.reg"C:\Windows\regedit.exeExplorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Registry Editor
Exit code:
3221226540
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\regedit.exe
3516"C:\Users\admin\Desktop\SW2010-2016.Activator.GUI.SSQ.exe" C:\Users\admin\Desktop\SW2010-2016.Activator.GUI.SSQ.exeExplorer.EXE
User:
admin
Company:
Dassault Systèmes SolidWorks Corp.
Integrity Level:
MEDIUM
Description:
SolidWorks Activation Wizard
Exit code:
0
Version:
19.0.0.4021
Modules
Images
c:\users\admin\desktop\sw2010-2016.activator.gui.ssq.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msctf.dll
3600"C:\Users\admin\Desktop\LicenseServer\lmgrd.exe" C:\Users\admin\Desktop\LicenseServer\lmgrd.exeExplorer.EXE
User:
admin
Company:
Flexera Software LLC
Integrity Level:
MEDIUM
Description:
Flexera Software LLC
Exit code:
0
Version:
11.11.1.2 build 134011
Modules
Images
c:\users\admin\desktop\licenseserver\lmgrd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\user32.dll
Total events
2 269
Read events
2 214
Write events
55
Delete events
0

Modification events

(PID) Process:(3084) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3084) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3084) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3084) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(3084) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3084) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\_SolidSQUAD_.7z
(PID) Process:(3084) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3084) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3084) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3084) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
10
Suspicious files
0
Text files
5
Unknown types
0

Dropped files

PID
Process
Filename
Type
3084WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3084.39248\readme_SW-SSQ.txttext
MD5:
SHA256:
3084WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3084.39248\SolidWorksPDM\LicenseServer\installlicenseserver.battext
MD5:
SHA256:
3084WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3084.39248\SolidWorksPDM\readme_PDM-SSQ.txttext
MD5:
SHA256:
3084WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3084.39248\SolidWorksSerialNumbers2016.regtext
MD5:
SHA256:
3084WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3084.39248\SolidWorksCodeGenerator.exeexecutable
MD5:
SHA256:
3084WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3084.39248\SolidWorksPDM\LicenseServer\sw_d.exeexecutable
MD5:
SHA256:
3084WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3084.39248\SolidWorksPDM\LicenseServer\swepdm2016.dattext
MD5:
SHA256:
3084WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3084.39248\SolidWorksPDM\LicenseServer\lmgrd.exeexecutable
MD5:
SHA256:
3084WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3084.39248\SolidWorksPDM\LicenseServer\installs.exeexecutable
MD5:40AD52111E2997DC064E000DC32ECEE3
SHA256:5357844C0F6CA3154CA7F1EA552410738C9BFE92CDC81BFDFDF47F3C06DA25AD
3084WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3084.39248\SolidWorksPDM\NewInstall\Win64\Program Files\SOLIDWORKS Corp\SOLIDWORKS PDM\licensemgr.dllexecutable
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info