File name:

AppSetup.zip

Full analysis: https://app.any.run/tasks/65a44207-b781-4af0-9dd5-b290a6b0dcd4
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: November 26, 2022, 18:54:43
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
loader
stealer
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract
MD5:

C318919DE0918D274F7B649E68135F0A

SHA1:

15F436E2E07FE45D1FAA619E8CB119AE7F6FE9D1

SHA256:

0B1D19B4BCDF6C17A2529E59F93A1ED54AACD67C68936FA43D1EE2EE9D72FA58

SSDEEP:

196608:GMg77uWSqL1+rKRVEP0e7oi+Esk7SPWGY5zHH68vv:077u6J+egyiJsk7SOh5zHH3v

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Stealing of credential data

      • AppSetup.exe (PID: 3816)
    • Drops the executable file immediately after the start

      • AppSetup.exe (PID: 3816)
      • AppSetup.exe (PID: 2360)
    • Loads dropped or rewritten executable

      • AppSetup.exe (PID: 3816)
  • SUSPICIOUS

    • Connects to the server without a host name

      • AppSetup.exe (PID: 3816)
      • AppSetup.exe (PID: 2360)
    • Process drops Mozilla's DLL files

      • AppSetup.exe (PID: 3816)
      • AppSetup.exe (PID: 2360)
    • Process requests binary or script from the Internet

      • AppSetup.exe (PID: 3816)
      • AppSetup.exe (PID: 2360)
    • Executable content was dropped or overwritten

      • AppSetup.exe (PID: 3816)
      • AppSetup.exe (PID: 2360)
    • Send credential is detected

      • AppSetup.exe (PID: 3816)
    • Process drops SQLite DLL files

      • AppSetup.exe (PID: 3816)
  • INFO

    • Dropped object may contain Bitcoin addresses

      • AppSetup.exe (PID: 3816)
    • Drops a file that was compiled in debug mode

      • AppSetup.exe (PID: 3816)
      • AppSetup.exe (PID: 2360)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
40
Monitored processes
3
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs appsetup.exe appsetup.exe

Process information

PID
CMD
Path
Indicators
Parent process
2424"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\AppSetup.zip"C:\Program Files\WinRAR\WinRAR.exeExplorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3816"C:\Users\admin\AppData\Local\Temp\Rar$EXb2424.8282\AppSetup\AppSetup.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb2424.8282\AppSetup\AppSetup.exe
WinRAR.exe
User:
admin
Company:
Auslogics
Integrity Level:
MEDIUM
Description:
File Recovery Library
Exit code:
0
Version:
7.2.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb2424.8282\appsetup\appsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
2360"C:\Users\admin\Desktop\AppSetup.exe" C:\Users\admin\Desktop\AppSetup.exe
Explorer.EXE
User:
admin
Company:
Auslogics
Integrity Level:
MEDIUM
Description:
File Recovery Library
Version:
7.2.0.0
Modules
Images
c:\users\admin\desktop\appsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
Total events
2 499
Read events
2 431
Write events
67
Delete events
1

Modification events

(PID) Process:(2424) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2424) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2424) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16D\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2424) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(2424) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2424) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\AppSetup.zip
(PID) Process:(2424) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2424) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2424) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2424) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
8
Suspicious files
1
Text files
2
Unknown types
44

Dropped files

PID
Process
Filename
Type
2424WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2424.8282\AppSetup\About\Windows.Data.TimeZones\pris\Windows.Data.TimeZones.es-ES.pripri
MD5:814041542F6BDFB3096420196E1F9947
SHA256:BE74A52AEFC4477746DE5A724986DAC67FE25AF44F08140F6460AEC03289AC46
2424WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2424.8282\AppSetup\About\Windows.Data.TimeZones\pris\Windows.Data.TimeZones.de-DE.pripri
MD5:F4406A7B443CE9D6847833521A592EE5
SHA256:255406E56CED1DC62FC3A10F090055D5F8F209018363CD26A264D058D9E1AC15
2424WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2424.8282\AppSetup\About\Windows.Data.TimeZones\pris\Windows.Data.TimeZones.cs-CZ.pripri
MD5:DC3D2747AFB38474BFC398C6A81BB667
SHA256:6333F54BDC5DADC273BC81E2147946EC5EEAD2A4C1DD1C02F45F7AAA7F96282F
2424WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2424.8282\AppSetup\About\Windows.Data.TimeZones\pris\Windows.Data.TimeZones.hu-HU.pripri
MD5:F2F1668003837E1A2E1D772B71455E3A
SHA256:7E1026B000B1A19D290670F76196EF7EF989BCE1A3332BC357BBADBACC130E95
2424WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2424.8282\AppSetup\About\Windows.Data.TimeZones\pris\Windows.Data.TimeZones.lt-LT.pripri
MD5:10FF25D3AB636563273CC8CBA30A0DAC
SHA256:D251CF0A77C6582B964534FE8A79F145FAB0B287BF8790C2BBE743B9EE226BB2
2424WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2424.8282\AppSetup\About\Windows.Data.TimeZones\pris\Windows.Data.TimeZones.ja-JP.pripri
MD5:38327A60E9BA52306679DE6DF9F4C55D
SHA256:BB334B03CFDAD0E04EF026F17F48E860F1570166921A0B634A05D05373F42918
2424WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2424.8282\AppSetup\About\Windows.Data.TimeZones\pris\Windows.Data.TimeZones.en-GB.pripri
MD5:AAE5B8CF9D71D1FE93E3ACB9B11C0571
SHA256:F115194EF0C5CA1FB6B5DB282ECDD1589A72B19CF07B7625BB84999BEEBC6E6A
2424WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2424.8282\AppSetup\About\Windows.Data.TimeZones\pris\Windows.Data.TimeZones.he-IL.pripri
MD5:76920B889D7EB6925A8FDC2A10B58BC5
SHA256:FB0075517B20084F88759ECBB9D8F770018BB5B92764138BE95931D58943F1D9
2424WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2424.8282\AppSetup\About\Windows.Data.TimeZones\pris\Windows.Data.TimeZones.fi-FI.pripri
MD5:2CF2BBE7FD1D66B8FC0F8A117D88E023
SHA256:98F11F4083F64B577ED9273847210138B235E6DB525A1C92DE91634CA0DB85D1
2424WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2424.8282\AppSetup\About\Windows.Data.TimeZones\pris\Windows.Data.TimeZones.ar-SA.pripri
MD5:CD06F6C5E16D133F513A7BF04B03A975
SHA256:5235F088ABF83567158EBC9823361C6D48A6760A30D94C9C1278F344B4F1BC27
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
17
TCP/UDP connections
2
DNS requests
0
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3816
AppSetup.exe
POST
200
2.56.10.105:80
http://2.56.10.105/
NL
text
6.72 Kb
unknown
3816
AppSetup.exe
GET
200
2.56.10.105:80
http://2.56.10.105/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/sqlite3.dll
NL
executable
1.05 Mb
unknown
3816
AppSetup.exe
GET
200
2.56.10.105:80
http://2.56.10.105/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/nss3.dll
NL
executable
1.95 Mb
unknown
3816
AppSetup.exe
GET
200
2.56.10.105:80
http://2.56.10.105/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/vcruntime140.dll
NL
executable
78.2 Kb
unknown
3816
AppSetup.exe
POST
200
2.56.10.105:80
http://2.56.10.105/1d2bbed7b83be82af5b79c50ba15347c
NL
text
8 b
unknown
2360
AppSetup.exe
POST
200
2.56.10.105:80
http://2.56.10.105/
NL
text
6.72 Kb
unknown
2360
AppSetup.exe
GET
2.56.10.105:80
http://2.56.10.105/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/freebl3.dll
NL
unknown
3816
AppSetup.exe
GET
200
2.56.10.105:80
http://2.56.10.105/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/mozglue.dll
NL
executable
612 Kb
unknown
3816
AppSetup.exe
POST
200
2.56.10.105:80
http://2.56.10.105/1d2bbed7b83be82af5b79c50ba15347c
NL
text
8 b
unknown
3816
AppSetup.exe
GET
200
2.56.10.105:80
http://2.56.10.105/aN7jD0qO6kT5bK5bQ4eR8fE1xP7hL2vK/softokn3.dll
NL
executable
248 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2360
AppSetup.exe
2.56.10.105:80
IP Connect Inc
NL
unknown
3816
AppSetup.exe
2.56.10.105:80
IP Connect Inc
NL
unknown

DNS requests

No data

Threats

No threats detected
No debug info