File name:

usbdriveinfo (1).zip

Full analysis: https://app.any.run/tasks/1a1e7e80-77b1-41e8-a363-1184b894021f
Verdict: Malicious activity
Analysis date: May 01, 2019, 14:11:46
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

BBF68F03A462A3277A8A69818A747A05

SHA1:

6F4B1DE4F37F5E541F5BB2964F0D7F2C3B2C8351

SHA256:

0D246A250D2669DD025DFFAAEBF3A4A68943F0B1DEB73E5D6ECC856B46042CC9

SSDEEP:

98304:BbduZbEK4zZP5bmg9mB4YMBd2Qb1Rd2r9goxhXhWDJT1K:9dGE5ZhOgBd2QJ+hMDR8

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • GetFlashInfo.exe (PID: 3620)
      • GetFlashInfo.exe (PID: 2500)
    • Loads dropped or rewritten executable

      • GetFlashInfo.exe (PID: 3620)
  • SUSPICIOUS

    • Uses RUNDLL32.EXE to load library

      • WinRAR.exe (PID: 2528)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2528)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0002
ZipCompression: None
ZipModifyDate: 2015:11:25 15:07:28
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: usbflashinfo/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
34
Monitored processes
4
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
drop and start drop and start start winrar.exe rundll32.exe no specs getflashinfo.exe getflashinfo.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2500"C:\Users\admin\AppData\Local\Temp\Rar$EXa2528.44091\usbflashinfo\GetFlashInfo.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2528.44091\usbflashinfo\GetFlashInfo.exeWinRAR.exe
User:
admin
Company:
ANTSpec Software
Integrity Level:
MEDIUM
Description:
Tool to get USB flash drive information.
Exit code:
0
Version:
8.2.0.570
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2528.44091\usbflashinfo\getflashinfo.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2528"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\usbdriveinfo (1).zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2816"C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\AppData\Local\Temp\Rar$DIa2528.43583\File_id.dizC:\Windows\system32\rundll32.exeWinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
3620"C:\Users\admin\AppData\Local\Temp\Rar$EXa2528.44030\usbflashinfo\GetFlashInfo.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2528.44030\usbflashinfo\GetFlashInfo.exe
WinRAR.exe
User:
admin
Company:
ANTSpec Software
Integrity Level:
MEDIUM
Description:
Tool to get USB flash drive information.
Exit code:
0
Version:
8.2.0.570
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2528.44030\usbflashinfo\getflashinfo.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
Total events
437
Read events
422
Write events
15
Delete events
0

Modification events

(PID) Process:(2528) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2528) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2528) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2528) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\usbdriveinfo (1).zip
(PID) Process:(2528) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2528) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2528) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2528) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2528) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
Operation:writeName:@C:\Windows\system32\notepad.exe,-469
Value:
Text Document
(PID) Process:(2528) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
Executable files
4
Suspicious files
0
Text files
5
Unknown types
0

Dropped files

PID
Process
Filename
Type
2528WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2528.44030\usbflashinfo\gfienc.dllexecutable
MD5:
SHA256:
2528WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DIa2528.43583\File_id.diztext
MD5:D643F060F87F4E8CA375D0B7662E251F
SHA256:37168040A84D6F73FBABD60EC1E4AD0DCD65048B57460F67ED655C160323774D
2528WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2528.44091\File_id.diztext
MD5:D643F060F87F4E8CA375D0B7662E251F
SHA256:37168040A84D6F73FBABD60EC1E4AD0DCD65048B57460F67ED655C160323774D
2528WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2528.44091\usbflashinfo\gfienc.dllexecutable
MD5:
SHA256:
2528WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2528.44030\File_id.diztext
MD5:D643F060F87F4E8CA375D0B7662E251F
SHA256:37168040A84D6F73FBABD60EC1E4AD0DCD65048B57460F67ED655C160323774D
2528WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2528.44030\usbflashinfo\GetFlashInfo.exeexecutable
MD5:EF46475224A17026846BCEC3CE42EFD3
SHA256:27C99C34AD4527D2CB4E9352DE536E7A03CAF69AFA25626850D2A05ABED1D29E
2528WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2528.44030\usbflashinfo\ReadMe.txttext
MD5:5D45315FFAB2C14A8EBB4620E910741C
SHA256:91D88EB4BE4CB1FFEE917A79869A698A8FA47D075CE3FDC80827CEB78C40BBFF
2528WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2528.44091\usbflashinfo\ReadMe.txttext
MD5:5D45315FFAB2C14A8EBB4620E910741C
SHA256:91D88EB4BE4CB1FFEE917A79869A698A8FA47D075CE3FDC80827CEB78C40BBFF
2528WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2528.44091\usbflashinfo\GetFlashInfo.exeexecutable
MD5:EF46475224A17026846BCEC3CE42EFD3
SHA256:27C99C34AD4527D2CB4E9352DE536E7A03CAF69AFA25626850D2A05ABED1D29E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
Process
Message
GetFlashInfo.exe
%s------------------------------------------------ --- Themida Professional --- --- (c)2012 Oreans Technologies --- ------------------------------------------------