File name:

AppSetup.zip

Full analysis: https://app.any.run/tasks/65a44207-b781-4af0-9dd5-b290a6b0dcd4
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: November 26, 2022, 18:54:43
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
loader
stealer
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract
MD5:

C318919DE0918D274F7B649E68135F0A

SHA1:

15F436E2E07FE45D1FAA619E8CB119AE7F6FE9D1

SHA256:

0B1D19B4BCDF6C17A2529E59F93A1ED54AACD67C68936FA43D1EE2EE9D72FA58

SSDEEP:

196608:GMg77uWSqL1+rKRVEP0e7oi+Esk7SPWGY5zHH68vv:077u6J+egyiJsk7SOh5zHH3v

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • AppSetup.exe (PID: 3816)
    • Drops the executable file immediately after the start

      • AppSetup.exe (PID: 3816)
      • AppSetup.exe (PID: 2360)
    • Stealing of credential data

      • AppSetup.exe (PID: 3816)
  • SUSPICIOUS

    • Process requests binary or script from the Internet

      • AppSetup.exe (PID: 3816)
      • AppSetup.exe (PID: 2360)
    • Executable content was dropped or overwritten

      • AppSetup.exe (PID: 3816)
      • AppSetup.exe (PID: 2360)
    • Process drops SQLite DLL files

      • AppSetup.exe (PID: 3816)
    • Connects to the server without a host name

      • AppSetup.exe (PID: 3816)
      • AppSetup.exe (PID: 2360)
    • Process drops Mozilla's DLL files

      • AppSetup.exe (PID: 3816)
      • AppSetup.exe (PID: 2360)
    • Send credential is detected

      • AppSetup.exe (PID: 3816)
  • INFO

    • Drops a file that was compiled in debug mode

      • AppSetup.exe (PID: 3816)
      • AppSetup.exe (PID: 2360)
    • Dropped object may contain Bitcoin addresses

      • AppSetup.exe (PID: 3816)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
40
Monitored processes
3
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs appsetup.exe appsetup.exe

Process information

PID
CMD
Path
Indicators
Parent process
2360"C:\Users\admin\Desktop\AppSetup.exe" C:\Users\admin\Desktop\AppSetup.exe
Explorer.EXE
User:
admin
Company:
Auslogics
Integrity Level:
MEDIUM
Description:
File Recovery Library
Exit code:
0
Version:
7.2.0.0
Modules
Images
c:\users\admin\desktop\appsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
2424"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\AppSetup.zip"C:\Program Files\WinRAR\WinRAR.exeExplorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3816"C:\Users\admin\AppData\Local\Temp\Rar$EXb2424.8282\AppSetup\AppSetup.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb2424.8282\AppSetup\AppSetup.exe
WinRAR.exe
User:
admin
Company:
Auslogics
Integrity Level:
MEDIUM
Description:
File Recovery Library
Exit code:
0
Version:
7.2.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb2424.8282\appsetup\appsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
Total events
2 499
Read events
2 431
Write events
67
Delete events
1

Modification events

(PID) Process:(2424) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2424) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2424) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16D\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2424) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(2424) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2424) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\AppSetup.zip
(PID) Process:(2424) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2424) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2424) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2424) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
8
Suspicious files
1
Text files
2
Unknown types
44

Dropped files

PID
Process
Filename
Type
2424WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2424.8282\AppSetup\About\Windows.Data.TimeZones\pris\Windows.Data.TimeZones.bg-BG.pripri
MD5:7427EB5B4A8806490D5BA8FB4F26A88B
SHA256:BCE051C6EF5406F995468C92F4CF24B925FAE820B16440075F693520DAE0938C
2424WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2424.8282\AppSetup\About\Windows.Data.TimeZones\pris\Windows.Data.TimeZones.et-EE.pripri
MD5:8CF19D37BBDF2BEB7809716CC0AD6649
SHA256:AD0664E8B0BA063702370D23DD4F28A3F6798BDF4533A3A57982AE6F277C3CFD
2424WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2424.8282\AppSetup\About\Windows.Data.TimeZones\pris\Windows.Data.TimeZones.fr-FR.pripri
MD5:BA4D5212CC05B3418A75A680FE9C60BB
SHA256:FE55AE7FAF9F5EF2D1ECCCE242E4067CE1EB80D43E929D9B06E2B532AFB4538A
2424WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2424.8282\AppSetup\About\Windows.Data.TimeZones\pris\Windows.Data.TimeZones.el-GR.pripri
MD5:12BC00AAA53AFFC4AC75CA36026B0F7E
SHA256:4FFBF81520FF1799FF2BB9980E4F2A0C1A481B8A81FFEA47336C3DA247A21955
2424WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2424.8282\AppSetup\About\Windows.Data.TimeZones\pris\Windows.Data.TimeZones.en-US.pripri
MD5:C9FC44D96AAD7AA18256C3275AFC89C1
SHA256:DC7619AE9CA45A9EE10F529790739F389E6CB48A8EF43C3B8C0994416FE313BE
2424WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2424.8282\AppSetup\About\Windows.Data.TimeZones\pris\Windows.Data.TimeZones.cs-CZ.pripri
MD5:DC3D2747AFB38474BFC398C6A81BB667
SHA256:6333F54BDC5DADC273BC81E2147946EC5EEAD2A4C1DD1C02F45F7AAA7F96282F
2424WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2424.8282\AppSetup\About\Windows.Data.TimeZones\pris\Windows.Data.TimeZones.de-DE.pripri
MD5:F4406A7B443CE9D6847833521A592EE5
SHA256:255406E56CED1DC62FC3A10F090055D5F8F209018363CD26A264D058D9E1AC15
2424WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2424.8282\AppSetup\About\Windows.Data.TimeZones\pris\Windows.Data.TimeZones.hu-HU.pripri
MD5:F2F1668003837E1A2E1D772B71455E3A
SHA256:7E1026B000B1A19D290670F76196EF7EF989BCE1A3332BC357BBADBACC130E95
2424WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2424.8282\AppSetup\About\Windows.Data.TimeZones\pris\Windows.Data.TimeZones.ko-KR.pripri
MD5:CB8A60E502D21A5630F852F8BB24C0FB
SHA256:25004071482B8B8C3B632EA3FFFEA1E2F3E08C8563CD9A43EF6871993ECFF554
2424WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2424.8282\AppSetup\About\Windows.Data.TimeZones\pris\Windows.Data.TimeZones.fi-FI.pripri
MD5:2CF2BBE7FD1D66B8FC0F8A117D88E023
SHA256:98F11F4083F64B577ED9273847210138B235E6DB525A1C92DE91634CA0DB85D1
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
17
TCP/UDP connections
2
DNS requests
0
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3816
AppSetup.exe
POST
200
2.56.10.105:80
http://2.56.10.105/
NL
text
6.72 Kb
unknown
2360
AppSetup.exe
POST
200
2.56.10.105:80
http://2.56.10.105/
NL
text
6.72 Kb
unknown
3816
AppSetup.exe
GET
200
2.56.10.105:80
http://2.56.10.105/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/sqlite3.dll
NL
executable
1.05 Mb
unknown
3816
AppSetup.exe
GET
200
2.56.10.105:80
http://2.56.10.105/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/nss3.dll
NL
executable
1.95 Mb
unknown
2360
AppSetup.exe
GET
200
2.56.10.105:80
http://2.56.10.105/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/nss3.dll
NL
executable
1.95 Mb
unknown
3816
AppSetup.exe
POST
200
2.56.10.105:80
http://2.56.10.105/1d2bbed7b83be82af5b79c50ba15347c
NL
text
8 b
unknown
3816
AppSetup.exe
POST
200
2.56.10.105:80
http://2.56.10.105/1d2bbed7b83be82af5b79c50ba15347c
NL
text
8 b
unknown
2360
AppSetup.exe
GET
200
2.56.10.105:80
http://2.56.10.105/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/vcruntime140.dll
NL
executable
78.2 Kb
unknown
3816
AppSetup.exe
GET
200
2.56.10.105:80
http://2.56.10.105/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/vcruntime140.dll
NL
executable
78.2 Kb
unknown
2360
AppSetup.exe
GET
200
2.56.10.105:80
http://2.56.10.105/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/mozglue.dll
NL
executable
612 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3816
AppSetup.exe
2.56.10.105:80
IP Connect Inc
NL
unknown
2360
AppSetup.exe
2.56.10.105:80
IP Connect Inc
NL
unknown

DNS requests

No data

Threats

No threats detected
No debug info