analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

1df94c74-2143-4abf-b85f-c92702f3181c.zip

Full analysis: https://app.any.run/tasks/0736d7c4-39c0-42ac-8efe-577f3e072686
Verdict: Malicious activity
Analysis date: February 18, 2019, 14:27:11
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

E87207BAA9FF1D27121B7F228862137B

SHA1:

9BBB869BA899CC7A0AC2D57B75D292AABE6D1303

SHA256:

06957EA14CC9536E08A7488FDF3435A516C9DBB0FC355D3627EAAE4A3ED6CFFD

SSDEEP:

3072:B+N+uC6RbGfXAC7InbslMpOrFk7d/MJZZ6ve/5RwszwxFdgG+eDzem:BS+DmXC7dloOrFUNqdX/e+k

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • SalsaClient.exe (PID: 3804)
      • SalsaClient.exe (PID: 3372)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2992)
    • Starts Internet Explorer

      • rundll32.exe (PID: 3692)
    • Uses RUNDLL32.EXE to load library

      • WinRAR.exe (PID: 2992)
    • Creates files in the program directory

      • WinRAR.exe (PID: 2992)
  • INFO

    • Reads Internet Cache Settings

      • iexplore.exe (PID: 3168)
    • Changes internet zones settings

      • iexplore.exe (PID: 2860)
    • Reads internet explorer settings

      • iexplore.exe (PID: 3168)
    • Reads settings of System Certificates

      • iexplore.exe (PID: 2860)
    • Creates files in the user directory

      • iexplore.exe (PID: 3168)
    • Adds / modifies Windows certificates

      • iexplore.exe (PID: 2860)
    • Changes settings of System certificates

      • iexplore.exe (PID: 2860)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: Users/855159/Desktop/SalsaClient.exe.jg
ZipUncompressedSize: 319566
ZipCompressedSize: 147507
ZipCRC: 0xbc9124cd
ZipModifyDate: 2007:05:04 14:29:19
ZipCompression: Deflated
ZipBitFlag: 0x0001
ZipRequiredVersion: 20
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
37
Monitored processes
7
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start drop and start start winrar.exe rundll32.exe no specs iexplore.exe iexplore.exe rundll32.exe no specs salsaclient.exe no specs salsaclient.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2992"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\1df94c74-2143-4abf-b85f-c92702f3181c.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.60.0
3692"C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\AppData\Local\Temp\Rar$DIb2992.6104\SalsaClient.exe.jgC:\Windows\system32\rundll32.exeWinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
2860"C:\Program Files\Internet Explorer\iexplore.exe" -nohomeC:\Program Files\Internet Explorer\iexplore.exe
rundll32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
1
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
3168"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2860 CREDAT:71937C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
3836"C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\AppData\Local\Temp\Rar$DIb2992.7885\SalsaClient.exe.jgC:\Windows\system32\rundll32.exeWinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
3804"C:\Users\admin\AppData\Local\Temp\Rar$EXb2992.9999\Users\855159\Desktop\SalsaClient.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb2992.9999\Users\855159\Desktop\SalsaClient.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
3372"C:\Users\admin\AppData\Local\Temp\Rar$EXb2992.11684\Users\855159\Desktop\SalsaClient.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb2992.11684\Users\855159\Desktop\SalsaClient.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Total events
1 090
Read events
973
Write events
0
Delete events
0

Modification events

No data
Executable files
4
Suspicious files
4
Text files
28
Unknown types
2

Dropped files

PID
Process
Filename
Type
2860iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RB73MZ6Y\favicon[1].ico
MD5:
SHA256:
2860iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
MD5:
SHA256:
3168iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\admin@bing[2].txt
MD5:
SHA256:
3168iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OCDM6JB6\search[1].txt
MD5:
SHA256:
3168iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\admin@bing[1].txttext
MD5:37D98593369FB6D5117F84AB3809D0F6
SHA256:49029306A79BE3C30E3AC83E140088C76B3D46BAD8C08A2C53D5BC03946659B8
3168iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BWPPCY0O\cc8437ad[1].jstext
MD5:A6C733AA5F25FEDFFEC17814DEABDF94
SHA256:31603D185BC08890EA41EB0782454B46E63EAF17ACD1F414A44411DCAA8B661B
3168iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\U2ZG9DE0\a9b12688[1].jstext
MD5:84FD3FC97FAAFCF8FCCA752ECBFF270E
SHA256:C996E21F2E6A6AEB85D1BD1B865879F9BC57BA397860ABD5BCF883EE7DA24936
2860iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012019021820190219\index.datdat
MD5:49527B57BEA8FB40C6EDFF25294095D2
SHA256:7C6C7110716E56F4C91623186C11CA871FFEB55081D1C5D07F0EAA68DF0BB4C6
3168iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\OCDM6JB6\search[1].htmhtml
MD5:84F2464F203D6EBD8BFA3C7D66E3B095
SHA256:5FA58FCB744833B07BE17B143D62E7F8C2768479B05E089A2D6AA40DE881FC12
3168iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PP6KS563\th[1].jpgimage
MD5:30C628BD419F5A01273DCAADBBAC897D
SHA256:E67DC46DF182E9082C13CCAEBF018D27BBA97F079BBE9F31CB272434E6714C73
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
11
DNS requests
4
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3168
iexplore.exe
GET
301
2.16.186.27:80
http://shell.windows.com/fileassoc/fileassoc.asp?Ext=jg
unknown
whitelisted
3168
iexplore.exe
GET
302
23.51.118.23:80
http://go.microsoft.com/fwlink/?LinkId=57426&Ext=jg
NL
whitelisted
2860
iexplore.exe
GET
200
204.79.197.200:80
http://www.bing.com/favicon.ico
US
image
237 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3168
iexplore.exe
204.79.197.200:443
www.bing.com
Microsoft Corporation
US
whitelisted
3168
iexplore.exe
2.16.186.27:80
shell.windows.com
Akamai International B.V.
whitelisted
2860
iexplore.exe
204.79.197.200:443
www.bing.com
Microsoft Corporation
US
whitelisted
3168
iexplore.exe
65.55.163.82:443
login.live.com
Microsoft Corporation
US
whitelisted
3168
iexplore.exe
23.51.118.23:80
go.microsoft.com
Akamai Technologies, Inc.
NL
whitelisted
2860
iexplore.exe
204.79.197.200:80
www.bing.com
Microsoft Corporation
US
whitelisted

DNS requests

Domain
IP
Reputation
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
go.microsoft.com
  • 23.51.118.23
whitelisted
shell.windows.com
  • 2.16.186.27
  • 2.16.186.24
whitelisted
login.live.com
  • 65.55.163.82
  • 65.55.163.76
  • 65.55.163.78
whitelisted

Threats

No threats detected
No debug info