analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

User Benchmark.zip

Full analysis: https://app.any.run/tasks/6e2293d9-df51-4b48-b50c-e551fa222a38
Verdict: Malicious activity
Analysis date: May 30, 2020, 11:05:57
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

7E72F8CDAFB9880A41785C4C711EFCF2

SHA1:

B0B61F978C066490BC0E3F5267BF821312D9D684

SHA256:

0ACB3FC963DFCCE8C01D058BFBC93D4D63A8DA8515F9A2EE28146C44560603DB

SSDEEP:

98304:RqpGUVxhjUxORyiWQQ5dKwH1UuvR2ibbuDnUpoTlQWa+o2Bo8jSLXdU:mGGaORyiENIibbYnQOQ+hljKU

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • UserBenchMark.exe (PID: 952)
    • Application was dropped or rewritten from another process

      • UBMCPUBench.exe (PID: 3968)
      • UBMRAMBench.exe (PID: 1376)
      • UserBenchMarkRunEngine.exe (PID: 2688)
      • ns487B.tmp (PID: 2492)
    • Changes settings of System certificates

      • UserBenchMark.exe (PID: 952)
  • SUSPICIOUS

    • Reads Internet Cache Settings

      • UserBenchMark.exe (PID: 952)
    • Executable content was dropped or overwritten

      • UserBenchMark.exe (PID: 952)
    • Starts application with an unusual extension

      • UserBenchMark.exe (PID: 952)
    • Adds / modifies Windows certificates

      • UserBenchMark.exe (PID: 952)
  • INFO

    • Manual execution by user

      • UserBenchMark.exe (PID: 3736)
      • UserBenchMark.exe (PID: 952)
      • control.exe (PID: 2164)
    • Reads settings of System Certificates

      • UserBenchMark.exe (PID: 952)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: User Benchmark/
ZipUncompressedSize: -
ZipCompressedSize: -
ZipCRC: 0x00000000
ZipModifyDate: 2020:05:24 15:57:22
ZipCompression: None
ZipBitFlag: -
ZipRequiredVersion: 20
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
50
Monitored processes
8
Malicious processes
1
Suspicious processes
2

Behavior graph

Click at the process to see the details
start drop and start winrar.exe no specs userbenchmark.exe no specs userbenchmark.exe ns487b.tmp no specs userbenchmarkrunengine.exe no specs ubmcpubench.exe no specs ubmrambench.exe no specs control.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2720"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\User Benchmark.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
3736"C:\Users\admin\Desktop\User Benchmark\UserBenchMark.exe" C:\Users\admin\Desktop\User Benchmark\UserBenchMark.exeexplorer.exe
User:
admin
Company:
UserBenchmark.com
Integrity Level:
MEDIUM
Description:
Benchmark Software
Exit code:
3221226540
Version:
2.9.6.0
952"C:\Users\admin\Desktop\User Benchmark\UserBenchMark.exe" C:\Users\admin\Desktop\User Benchmark\UserBenchMark.exe
explorer.exe
User:
admin
Company:
UserBenchmark.com
Integrity Level:
HIGH
Description:
Benchmark Software
Version:
2.9.6.0
2492"C:\Users\admin\AppData\Local\Temp\nsj27B3.tmp\ns487B.tmp" "C:\Users\admin\AppData\Local\Temp\UserBenchMarkTemp\UserBenchMarkRunEngine.exe" startC:\Users\admin\AppData\Local\Temp\nsj27B3.tmp\ns487B.tmpUserBenchMark.exe
User:
admin
Integrity Level:
HIGH
2688"C:\Users\admin\AppData\Local\Temp\UserBenchMarkTemp\UserBenchMarkRunEngine.exe" startC:\Users\admin\AppData\Local\Temp\UserBenchMarkTemp\UserBenchMarkRunEngine.exens487B.tmp
User:
admin
Integrity Level:
HIGH
3968UBMCPUBench.exeC:\Users\admin\AppData\Local\Temp\UserBenchMarkTemp\UBMCPUBench.exeUserBenchMarkRunEngine.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
1376UBMRAMBench.exeC:\Users\admin\AppData\Local\Temp\UserBenchMarkTemp\UBMRAMBench.exeUserBenchMarkRunEngine.exe
User:
admin
Integrity Level:
HIGH
2164"C:\Windows\System32\control.exe" SYSTEMC:\Windows\System32\control.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Control Panel
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Total events
1 781
Read events
551
Write events
0
Delete events
0

Modification events

No data
Executable files
20
Suspicious files
16
Text files
22
Unknown types
8

Dropped files

PID
Process
Filename
Type
2720WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2720.11482\User Benchmark\Results.txt
MD5:
SHA256:
2720WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2720.11482\User Benchmark\UserBenchMark.exe
MD5:
SHA256:
952UserBenchMark.exeC:\Users\admin\AppData\Local\Temp\UserBenchMarkTemp\UBMGPUStats.exeexecutable
MD5:D09B9DF283089E8B9FC5E85155464694
SHA256:DA56F4506BBF207E4023286C63CBD3A753D4E299E26FFFDAC5627B5A2734A426
952UserBenchMark.exeC:\Users\admin\AppData\Local\Temp\UserBenchMarkTemp\UBMCPUBench.exeexecutable
MD5:1F45B6FC955727856B4494E477DC5902
SHA256:9F9D91F1003447381F55526EC6BDA1D5BBAC5952873489E48E40DF1BB1025828
952UserBenchMark.exeC:\Users\admin\AppData\Local\Temp\UserBenchMarkTemp\UBMRAMBench.exeexecutable
MD5:E053F83C3E9275316C57A3FE118D5ADD
SHA256:235E318E6FEC5B5B329157C12DFEA645D57B86DB494FF94CB174B46E3C1D6D2D
952UserBenchMark.exeC:\Users\admin\AppData\Local\Temp\UserBenchMarkTemp\SHADOW.exeexecutable
MD5:E514EA6872333F7AD0E7BFEF579AB141
SHA256:E4BE6D52A8BA5A2CA5184681EE33C7E8FFAE926068AA5BDECF548BECA53FF359
952UserBenchMark.exeC:\Users\admin\AppData\Local\Temp\UserBenchMarkTemp\UserBenchMarkRunEngine.exeexecutable
MD5:047748D6F0B0DD506C047BB2FDDBAB49
SHA256:1509C6D19E20EF31F5EBFD1403C23013EDF7962215BC385257852407A73BA92C
952UserBenchMark.exeC:\Users\admin\AppData\Local\Temp\UserBenchMarkTemp\UBMDriveBench.exeexecutable
MD5:D7133DB9A37C99F6ADF2B1E3A2DD5D8F
SHA256:4BCDC765CDFA0632CAA32EA4FBD861E9B2176BE34DE1FFE51144F8ADEA683D3E
952UserBenchMark.exeC:\Users\admin\AppData\Local\Temp\UserBenchMarkTemp\Media\ring.xtext
MD5:6E6CC828BE6740F61339600F69DD6B1B
SHA256:7E9519C38EE1D48210C0EC794208EF70F483C34980788A8ED45511C09C511BEF
952UserBenchMark.exeC:\Users\admin\AppData\Local\Temp\UserBenchMarkTemp\Media\Airplane\airplane 2.xtext
MD5:BD4C1DDBDDF71B06068305F301F84BFB
SHA256:A3D0D0395FC5177CD47F2755962E50D9459C66CE1515798B8641C8CCCE925EFA
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
3
DNS requests
3
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
952
UserBenchMark.exe
GET
200
93.184.221.240:80
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
US
compressed
57.0 Kb
whitelisted
952
UserBenchMark.exe
GET
304
93.184.221.240:80
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
US
compressed
57.0 Kb
whitelisted
952
UserBenchMark.exe
GET
200
151.139.128.14:80
http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBReAhtobFzTvhaRmVeJ38QUchY9AwQUu69%2BAj36pvE8hI6t7jiY7NkyMtQCECsuburZdTZsFIpu26N8jAc%3D
US
der
727 b
whitelisted
952
UserBenchMark.exe
GET
200
151.139.128.14:80
http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBR64T7ooMQqLLQoy%2BemBUYZQOKh6QQUkK9qOpRaC9iQ6hJWc99DtDoo2ucCEG5WTfyjWioG40pHbBubPlo%3D
US
der
471 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
952
UserBenchMark.exe
54.39.161.167:443
www.userbenchmark.com
OVH SAS
FR
suspicious
952
UserBenchMark.exe
151.139.128.14:80
ocsp.comodoca.com
Highwinds Network Group, Inc.
US
suspicious
952
UserBenchMark.exe
93.184.221.240:80
www.download.windowsupdate.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted

DNS requests

Domain
IP
Reputation
www.userbenchmark.com
  • 54.39.161.167
suspicious
www.download.windowsupdate.com
  • 93.184.221.240
whitelisted
ocsp.comodoca.com
  • 151.139.128.14
whitelisted

Threats

No threats detected
No debug info