File name:

systools-export-notes.exe_AD8B996DE1C116B34FBF248FEA455CE0.zip

Full analysis: https://app.any.run/tasks/17f9a50c-f8c2-46ef-a4c2-16cc2f7f03d5
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: June 19, 2019, 14:24:19
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
adware
installcore
pup
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

592DA385C8A85FD1953C8FA7CAF171E9

SHA1:

3E037793925F98B5D8D66A4ADA208FAACF435B46

SHA256:

0FD7BF3BD3B3D30BECD817B360679852B51294EDB173FF6639F6C4FF5B27A252

SSDEEP:

49152:BcG5w8Nhv23Om3t55cguqNyt9Wo52i6TQJseohhHBlGaCz:KGj++m3FD3N4L68Js9hHDbq

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • systools-export-notes.exe (PID: 3280)
      • systools-export-notes.exe (PID: 3020)
      • systools-export-notes.exe (PID: 1452)
      • systools-export-notes.exe (PID: 3948)
      • systools-export-notes.exe (PID: 3124)
      • systools-export-notes.exe (PID: 2604)
      • systools-export-notes.exe (PID: 1548)
    • Connects to CnC server

      • systools-export-notes.exe (PID: 3280)
      • systools-export-notes.exe (PID: 3948)
      • systools-export-notes.exe (PID: 1548)
    • INSTALLCORE was detected

      • systools-export-notes.exe (PID: 3280)
      • systools-export-notes.exe (PID: 3948)
      • systools-export-notes.exe (PID: 1548)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3620)
    • Reads Environment values

      • systools-export-notes.exe (PID: 3280)
      • systools-export-notes.exe (PID: 3948)
      • systools-export-notes.exe (PID: 1548)
    • Application launched itself

      • systools-export-notes.exe (PID: 3020)
      • systools-export-notes.exe (PID: 3280)
      • systools-export-notes.exe (PID: 3948)
      • systools-export-notes.exe (PID: 2604)
    • Reads internet explorer settings

      • systools-export-notes.exe (PID: 3280)
      • systools-export-notes.exe (PID: 3948)
      • systools-export-notes.exe (PID: 1548)
  • INFO

    • Manual execution by user

      • systools-export-notes.exe (PID: 3948)
      • systools-export-notes.exe (PID: 2604)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0009
ZipCompression: Deflated
ZipModifyDate: 2019:06:19 16:01:14
ZipCRC: 0x71f4e917
ZipCompressedSize: 2100619
ZipUncompressedSize: 2139040
ZipFileName: systools-export-notes.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
50
Monitored processes
8
Malicious processes
5
Suspicious processes
1

Behavior graph

Click at the process to see the details
drop and start start winrar.exe systools-export-notes.exe no specs #INSTALLCORE systools-export-notes.exe systools-export-notes.exe no specs #INSTALLCORE systools-export-notes.exe systools-export-notes.exe no specs systools-export-notes.exe no specs #INSTALLCORE systools-export-notes.exe

Process information

PID
CMD
Path
Indicators
Parent process
1452"C:\Users\admin\AppData\Local\Temp\Rar$EXb3620.30969\systools-export-notes.exe" /RSF /ppn:VPluUxWrQDZtznaRkw /_ShowProgress /mnlC:\Users\admin\AppData\Local\Temp\Rar$EXb3620.30969\systools-export-notes.exesystools-export-notes.exe
User:
admin
Company:
Integrity Level:
HIGH
Description:
Hotesahe Setup
Exit code:
259
Version:
4.5.4.1
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb3620.30969\systools-export-notes.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
1548"C:\Users\admin\Desktop\systools-export-notes.exe" /RSF /ppn:YyhwYgxaFRAiP211FM5W /mnlC:\Users\admin\Desktop\systools-export-notes.exe
systools-export-notes.exe
User:
admin
Company:
Integrity Level:
HIGH
Description:
Hotesahe Setup
Exit code:
4294967206
Version:
4.5.4.1
Modules
Images
c:\users\admin\desktop\systools-export-notes.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
2604"C:\Users\admin\Desktop\systools-export-notes.exe" C:\Users\admin\Desktop\systools-export-notes.exeexplorer.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Hotesahe Setup
Exit code:
0
Version:
4.5.4.1
Modules
Images
c:\users\admin\desktop\systools-export-notes.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
3020"C:\Users\admin\AppData\Local\Temp\Rar$EXb3620.30969\systools-export-notes.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb3620.30969\systools-export-notes.exeWinRAR.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Hotesahe Setup
Exit code:
0
Version:
4.5.4.1
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb3620.30969\systools-export-notes.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\usp10.dll
3124"C:\Users\admin\Desktop\systools-export-notes.exe" /_ShowProgress /mnlC:\Users\admin\Desktop\systools-export-notes.exesystools-export-notes.exe
User:
admin
Company:
Integrity Level:
HIGH
Description:
Hotesahe Setup
Exit code:
259
Version:
4.5.4.1
Modules
Images
c:\users\admin\desktop\systools-export-notes.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
3280"C:\Users\admin\AppData\Local\Temp\Rar$EXb3620.30969\systools-export-notes.exe" /RSF /ppn:VPluUxWrQDZtznaRkw /mnlC:\Users\admin\AppData\Local\Temp\Rar$EXb3620.30969\systools-export-notes.exe
systools-export-notes.exe
User:
admin
Company:
Integrity Level:
HIGH
Description:
Hotesahe Setup
Exit code:
4294967206
Version:
4.5.4.1
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb3620.30969\systools-export-notes.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\oleaut32.dll
3620"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\systools-export-notes.exe_AD8B996DE1C116B34FBF248FEA455CE0.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3948"C:\Users\admin\Desktop\systools-export-notes.exe" C:\Users\admin\Desktop\systools-export-notes.exe
explorer.exe
User:
admin
Company:
Integrity Level:
HIGH
Description:
Hotesahe Setup
Exit code:
4294967206
Version:
4.5.4.1
Modules
Images
c:\users\admin\desktop\systools-export-notes.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
Total events
1 233
Read events
1 138
Write events
95
Delete events
0

Modification events

(PID) Process:(3620) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3620) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3620) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3620) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\systools-export-notes.exe_AD8B996DE1C116B34FBF248FEA455CE0.zip
(PID) Process:(3620) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3620) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3620) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3620) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3620) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
(PID) Process:(3620) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
Executable files
2
Suspicious files
9
Text files
195
Unknown types
0

Dropped files

PID
Process
Filename
Type
3280systools-export-notes.exeC:\Users\admin\AppData\Local\Temp\001264EC.log
MD5:
SHA256:
3620WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb3620.30969\systools-export-notes.exeexecutable
MD5:
SHA256:
3280systools-export-notes.exeC:\Users\admin\AppData\Local\Temp\inH120548448654\css\main.csstext
MD5:
SHA256:
3280systools-export-notes.exeC:\Users\admin\AppData\Local\Temp\inH120548448654\css\main.scsstext
MD5:
SHA256:
3280systools-export-notes.exeC:\Users\admin\AppData\Local\Temp\inH120548448654\form.bmp.Maskbinary
MD5:D2FC989F9C2043CD32332EC0FAD69C70
SHA256:27DD029405CBFB0C3BF8BAC517BE5DB9AA83E981B1DC2BD5C5D6C549FA514101
3280systools-export-notes.exeC:\Users\admin\AppData\Local\Temp\inH120548448654\css\ie6_main.csstext
MD5:AD234E6A62580F62019C78B2A718DE00
SHA256:C4F2684F16C8E4553CC29C604A2F505399039638A34E652A7A1ACDEB157A0861
3280systools-export-notes.exeC:\Users\admin\AppData\Local\Temp\inH120548448654\csshover3.htchtml
MD5:52FA0DA50BF4B27EE625C80D36C67941
SHA256:E37E99DDFC73AC7BA774E23736B2EF429D9A0CB8C906453C75B14C029BDD5493
3280systools-export-notes.exeC:\Users\admin\AppData\Local\Temp\inH120548448654\css\ie6_main.scsstext
MD5:D10348D17ADF8A90670696728F54562D
SHA256:E8A3D15CF32009B01B9145B6E62FF6CAA9C2981F81CE063578C73C7ADFF08DFC
3280systools-export-notes.exeC:\Users\admin\AppData\Local\Temp\inH120548448654\css\swAgent.csstext
MD5:2543E3AF757C7D7C8A26C7CF57795F60
SHA256:C38892A06C8F50C6386ED794AF4F1EA3E1897AD5F0C7E19594D9EA7B20CFB3F1
3280systools-export-notes.exeC:\Users\admin\AppData\Local\Temp\inH120548448654\css\helpers\_backgrounds.scsstext
MD5:6092A3768F84CFBC6E5C52301F5B63EA
SHA256:8A22A3285F3C7D82AA1A4273BDD62729DA241723507C1ECD5D2FD0A24C12E23B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
3
DNS requests
2
Threats
9

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3280
systools-export-notes.exe
POST
200
52.214.73.247:80
http://gw.tufonawotsotic.com/
IE
malicious
3280
systools-export-notes.exe
POST
200
52.214.73.247:80
http://gw.tufonawotsotic.com/
IE
malicious
3948
systools-export-notes.exe
POST
200
52.214.73.247:80
http://gw.tufonawotsotic.com/
IE
malicious
3948
systools-export-notes.exe
POST
200
52.214.73.247:80
http://gw.tufonawotsotic.com/
IE
malicious
1548
systools-export-notes.exe
POST
200
54.194.149.175:80
http://gw.tufonawotsotic.com/
IE
malicious
1548
systools-export-notes.exe
POST
200
54.194.149.175:80
http://gw.tufonawotsotic.com/
IE
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1548
systools-export-notes.exe
54.194.149.175:80
gw.tufonawotsotic.com
Amazon.com, Inc.
IE
malicious
3280
systools-export-notes.exe
52.214.73.247:80
gw.tufonawotsotic.com
Amazon.com, Inc.
IE
malicious
3948
systools-export-notes.exe
52.214.73.247:80
gw.tufonawotsotic.com
Amazon.com, Inc.
IE
malicious

DNS requests

Domain
IP
Reputation
gw.tufonawotsotic.com
  • 52.214.73.247
  • 54.194.149.175
malicious

Threats

PID
Process
Class
Message
3280
systools-export-notes.exe
Misc activity
ADWARE [PTsecurity] PUP.Optional.InstallCore Artifact M2
3280
systools-export-notes.exe
Misc activity
ADWARE [PTsecurity] PUP.Optional.InstallCore Artifact M1
3948
systools-export-notes.exe
Misc activity
ADWARE [PTsecurity] PUP.Optional.InstallCore Artifact M2
3948
systools-export-notes.exe
Misc activity
ADWARE [PTsecurity] PUP.Optional.InstallCore Artifact M1
1548
systools-export-notes.exe
Misc activity
ADWARE [PTsecurity] PUP.Optional.InstallCore Artifact M2
1548
systools-export-notes.exe
Misc activity
ADWARE [PTsecurity] PUP.Optional.InstallCore Artifact M1
3 ETPRO signatures available at the full report
No debug info