download:

/CryptoNickSoft/7z-SFX-Constructor/raw/master/upd/7zSFX%20Constructor.7z

Full analysis: https://app.any.run/tasks/778bc258-051e-4dee-9c4a-19d0e87bf832
Verdict: Malicious activity
Analysis date: April 13, 2025, 15:07:59
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
arch-exec
arch-doc
autoit
lua
Indicators:
MIME: application/x-7z-compressed
File info: 7-zip archive data, version 0.4
MD5:

D1D742B063729E155DCBC15822178647

SHA1:

60140553FBF80854E0807569958C742E3F8B6607

SHA256:

1060C7742E6883F4845D0B81D51A6957523C1C91B579A6BD7232F146982F0D5B

SSDEEP:

98304:/o91ukS5l6A0w4wiSjhKxIGeju+J6hvVRFfiDANk7j6HHVPr6CEqVyszmM7lM7O+:EEQAGekj1gVlcri4iiA

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • 7zSFX_Constructor.exe (PID: 568)
      • 7zSFX_Constructor.exe (PID: 312)
      • 7zSFX_Constructor.exe (PID: 3224)
    • Generic archive extractor

      • WinRAR.exe (PID: 2840)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • 7zSFX_Constructor.exe (PID: 568)
      • xcopy.exe (PID: 3108)
      • 7zSFX_Constructor.exe (PID: 3224)
      • ap14.dat (PID: 3276)
    • Drops 7-zip archiver for unpacking

      • 7zSFX_Constructor.exe (PID: 568)
      • xcopy.exe (PID: 3108)
      • 7zSFX_Constructor.exe (PID: 3224)
    • Reads the Internet Settings

      • 7zSFX_Constructor.exe (PID: 568)
      • 7zSFX_Constructor.exe (PID: 3224)
    • Reads security settings of Internet Explorer

      • 7zSFX_Constructor.exe (PID: 568)
    • Starts CMD.EXE for commands execution

      • 7zSFX_Constructor.exe (PID: 568)
    • Starts the AutoIt3 executable file

      • 7zSFX_Constructor.exe (PID: 3224)
    • Starts application with an unusual extension

      • 7zSFX_Constructor.exe (PID: 3224)
    • Reads the Windows owner or organization settings

      • 7zSFX_Constructor.exe (PID: 3224)
    • There is functionality for taking screenshot (YARA)

      • 7zSFX_Constructor.exe (PID: 3224)
  • INFO

    • Checks supported languages

      • 7zSFX_Constructor.exe (PID: 312)
      • 7zSFX_Constructor.exe (PID: 568)
      • 7zSFX_Constructor.exe (PID: 3224)
      • ap10.dat (PID: 3184)
      • ap30.dat (PID: 2780)
      • ap30.dat (PID: 3668)
      • ap14.dat (PID: 3276)
    • Manual execution by a user

      • cmd.exe (PID: 2568)
      • cmd.exe (PID: 672)
      • 7zSFX_Constructor.exe (PID: 3224)
    • The sample compiled with english language support

      • 7zSFX_Constructor.exe (PID: 568)
      • 7zSFX_Constructor.exe (PID: 3224)
      • xcopy.exe (PID: 3108)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2840)
    • Create files in a temporary directory

      • 7zSFX_Constructor.exe (PID: 568)
    • The sample compiled with turkish language support

      • 7zSFX_Constructor.exe (PID: 568)
      • xcopy.exe (PID: 3108)
    • The sample compiled with russian language support

      • 7zSFX_Constructor.exe (PID: 568)
      • xcopy.exe (PID: 3108)
    • Reads the computer name

      • 7zSFX_Constructor.exe (PID: 568)
      • ap10.dat (PID: 3184)
      • ap30.dat (PID: 2780)
      • ap30.dat (PID: 3668)
      • 7zSFX_Constructor.exe (PID: 3224)
    • Creates files in the program directory

      • xcopy.exe (PID: 3108)
      • cmd.exe (PID: 3076)
      • xcopy.exe (PID: 2952)
      • cmd.exe (PID: 2652)
      • ap10.dat (PID: 3184)
      • ap30.dat (PID: 2780)
      • ap14.dat (PID: 3276)
      • 7zSFX_Constructor.exe (PID: 3224)
    • Creates a new folder

      • cmd.exe (PID: 3076)
    • Creates files or folders in the user directory

      • 7zSFX_Constructor.exe (PID: 568)
      • 7zSFX_Constructor.exe (PID: 3224)
    • Reads mouse settings

      • ap14.dat (PID: 3276)
    • The process uses Lua

      • 7zSFX_Constructor.exe (PID: 3224)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.7z | 7-Zip compressed archive (v0.4) (57.1)
.7z | 7-Zip compressed archive (gen) (42.8)

EXIF

ZIP

FileVersion: 7z v0.04
ModifyDate: 2018:12:09 11:50:31+00:00
ArchivedFileName: APPS
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
66
Monitored processes
21
Malicious processes
2
Suspicious processes
2

Behavior graph

Click at the process to see the details
start winrar.exe cmd.exe no specs 7zsfx_constructor.exe no specs cmd.exe no specs 7zsfx_constructor.exe cmd.exe no specs xcopy.exe cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs xcopy.exe no specs cmd.exe no specs 7zsfx_constructor.exe ap10.dat no specs ap30.dat no specs ap30.dat no specs ap14.dat

Process information

PID
CMD
Path
Indicators
Parent process
312"7zSFX_Constructor.exe" /hC:\Users\admin\Desktop\7zSFX_Constructor.execmd.exe
User:
admin
Company:
CryptoNick
Integrity Level:
MEDIUM
Description:
7z SFX Constructor
Exit code:
0
Version:
4.5.0.0
Modules
Images
c:\users\admin\desktop\7zsfx_constructor.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
5687zSFX_Constructor.exe -aiSC:\Users\admin\Desktop\7zSFX_Constructor.exe
cmd.exe
User:
admin
Company:
CryptoNick
Integrity Level:
MEDIUM
Description:
7z SFX Constructor
Exit code:
0
Version:
4.5.0.0
Modules
Images
c:\users\admin\desktop\7zsfx_constructor.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
672C:\Windows\system32\cmd.exe /c ""C:\Users\admin\Desktop\Install.cmd" "C:\Windows\System32\cmd.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
988"C:\Windows\System32\cmd.exe" /c if not exist "C:\ProgramData\7zSFX_Constructor\APPS\Settings\Sert.pfx.old" (copy /y "C:\ProgramData\7zSFX_Constructor\APPS\Sert\Sert.pfx" "C:\ProgramData\7zSFX_Constructor\APPS\Sert\Sert.pfx.old")C:\Windows\System32\cmd.exe7zSFX_Constructor.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1268"C:\Windows\System32\cmd.exe" /c if not exist "C:\ProgramData\7zSFX_Constructor\APPS\Settings\Sert.cer.old" (copy /y "C:\ProgramData\7zSFX_Constructor\APPS\Sert\Sert.cer" "C:\ProgramData\7zSFX_Constructor\APPS\Sert\Sert.cer.old")C:\Windows\System32\cmd.exe7zSFX_Constructor.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1996"C:\Windows\System32\cmd.exe" /c if not exist "C:\ProgramData\7zSFX_Constructor\APPS\Settings\Settings.old" (copy /y "C:\ProgramData\7zSFX_Constructor\APPS\Settings\Settings.cfg" "C:\ProgramData\7zSFX_Constructor\APPS\Settings\Settings.old")C:\Windows\System32\cmd.exe7zSFX_Constructor.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2464"C:\Windows\System32\cmd.exe" /c xcopy "C:\Users\admin\Desktop\APPS" "C:\ProgramData\7zSFX_Constructor\APPS" /c /i /s /e /r /h /yC:\Windows\System32\cmd.exe7zSFX_Constructor.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2568C:\Windows\system32\cmd.exe /c ""C:\Users\admin\Desktop\Help.cmd" "C:\Windows\System32\cmd.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2604"C:\Windows\System32\cmd.exe" /c if not exist "C:\ProgramData\7zSFX_Constructor\APPS\Settings\VerIcon.old" (copy /y "C:\ProgramData\7zSFX_Constructor\APPS\Settings\VerIcon.dll" "C:\ProgramData\7zSFX_Constructor\APPS\Settings\VerIcon.old")C:\Windows\System32\cmd.exe7zSFX_Constructor.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2652"C:\Windows\System32\cmd.exe" /c @echo Install Date: %date%>>"C:\ProgramData\7zSFX_Constructor\Install.log"C:\Windows\System32\cmd.exe7zSFX_Constructor.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
5 188
Read events
5 140
Write events
35
Delete events
13

Modification events

(PID) Process:(2840) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2840) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2840) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2840) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2840) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(2840) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(2840) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\778bc258-051e-4dee-9c4a-19d0e87bf832.7z
(PID) Process:(2840) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2840) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2840) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
69
Suspicious files
158
Text files
314
Unknown types
0

Dropped files

PID
Process
Filename
Type
2840WinRAR.exeC:\Users\admin\Desktop\APPS\Changelog.txttext
MD5:A42B1D33FC08C288477B38ACD696430F
SHA256:007D561CFB13F6914FE37AA2DCD1412A9BB1C38D9526489AB3271A3D96F2D07E
2840WinRAR.exeC:\Users\admin\Desktop\APPS\Icon\08.icoimage
MD5:38DFDD10BC80F987BE67A5FB0C553B7D
SHA256:7F48F3E63AE9BE28ED4A8FFBB0217C67B0C32C74C5628B4764719A810DB388D0
2840WinRAR.exeC:\Users\admin\Desktop\APPS\Icon\03.icobinary
MD5:9CCE39CC41B45137E1DF26C80500888B
SHA256:A7857DAFE02CD91699ED67CBDC329623A72BB5D5C5355EFE81C0828DD7538AD1
2840WinRAR.exeC:\Users\admin\Desktop\APPS\Icon\107.icoimage
MD5:9F8B4FB338503FC90874DD561E9D7C4C
SHA256:9108F20BDC4ED66CA0A15F627CCF382CADB99148E9E965F416D3565851EC117C
2840WinRAR.exeC:\Users\admin\Desktop\APPS\Icon\07.icoimage
MD5:1FF38F61C271CC99B67655CD9B004239
SHA256:B264602D8348EF5538F7D8ACB9ACDF90A88C84A75E13D83E3BBACBE7CDA660F1
2840WinRAR.exeC:\Users\admin\Desktop\APPS\Icon\05.icoimage
MD5:7935317E09A754BD1D7AB8E20A8550CE
SHA256:1ECDE30857AC47F3AB1C58D302F435F0E99598AC0140CCBD6CE4C4E1A302424F
2840WinRAR.exeC:\Users\admin\Desktop\APPS\Icon\04.icoimage
MD5:7FB4DA969F150C834A3B4DE251E27928
SHA256:47C7D32CE8F8BB3C1751551EC7C62E8A1F851D0853A004653387C92140C54EA6
2840WinRAR.exeC:\Users\admin\Desktop\APPS\Icon\01.icoimage
MD5:3802F70CAA8594D31EE3010E48ABC252
SHA256:D5CB9C5494A059B37FE7402838001F2F33EE536430ACEF01887D84806A1C9AB2
2840WinRAR.exeC:\Users\admin\Desktop\APPS\Icon\22.icobinary
MD5:4C77C30650E4C5EC389980129C82A095
SHA256:A229C336F4FC0E64E662E1200EA327716F35BF6928F2C9E59BA39B67BC3A616F
2840WinRAR.exeC:\Users\admin\Desktop\APPS\Icon\11.icoimage
MD5:284B99343AAE097F2D9E9D779FB539C1
SHA256:916ABAAE31E56CAAF467920CA7AB5A8610172C6A854C6AE53FA8FF172E710240
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
6
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:138
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 216.58.206.46
whitelisted

Threats

No threats detected
No debug info