download:

/CryptoNickSoft/7z-SFX-Constructor/raw/master/upd/7zSFX%20Constructor.7z

Full analysis: https://app.any.run/tasks/778bc258-051e-4dee-9c4a-19d0e87bf832
Verdict: Malicious activity
Analysis date: April 13, 2025, 15:07:59
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
arch-exec
arch-doc
autoit
lua
Indicators:
MIME: application/x-7z-compressed
File info: 7-zip archive data, version 0.4
MD5:

D1D742B063729E155DCBC15822178647

SHA1:

60140553FBF80854E0807569958C742E3F8B6607

SHA256:

1060C7742E6883F4845D0B81D51A6957523C1C91B579A6BD7232F146982F0D5B

SSDEEP:

98304:/o91ukS5l6A0w4wiSjhKxIGeju+J6hvVRFfiDANk7j6HHVPr6CEqVyszmM7lM7O+:EEQAGekj1gVlcri4iiA

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 2840)
    • Executing a file with an untrusted certificate

      • 7zSFX_Constructor.exe (PID: 312)
      • 7zSFX_Constructor.exe (PID: 568)
      • 7zSFX_Constructor.exe (PID: 3224)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • 7zSFX_Constructor.exe (PID: 568)
      • xcopy.exe (PID: 3108)
      • 7zSFX_Constructor.exe (PID: 3224)
      • ap14.dat (PID: 3276)
    • Drops 7-zip archiver for unpacking

      • 7zSFX_Constructor.exe (PID: 568)
      • xcopy.exe (PID: 3108)
      • 7zSFX_Constructor.exe (PID: 3224)
    • Reads the Internet Settings

      • 7zSFX_Constructor.exe (PID: 568)
      • 7zSFX_Constructor.exe (PID: 3224)
    • Reads security settings of Internet Explorer

      • 7zSFX_Constructor.exe (PID: 568)
    • Starts CMD.EXE for commands execution

      • 7zSFX_Constructor.exe (PID: 568)
    • There is functionality for taking screenshot (YARA)

      • 7zSFX_Constructor.exe (PID: 3224)
    • Reads the Windows owner or organization settings

      • 7zSFX_Constructor.exe (PID: 3224)
    • Starts application with an unusual extension

      • 7zSFX_Constructor.exe (PID: 3224)
    • Starts the AutoIt3 executable file

      • 7zSFX_Constructor.exe (PID: 3224)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2840)
    • Manual execution by a user

      • cmd.exe (PID: 2568)
      • cmd.exe (PID: 672)
      • 7zSFX_Constructor.exe (PID: 3224)
    • Checks supported languages

      • 7zSFX_Constructor.exe (PID: 312)
      • 7zSFX_Constructor.exe (PID: 568)
      • ap10.dat (PID: 3184)
      • ap30.dat (PID: 3668)
      • ap30.dat (PID: 2780)
      • ap14.dat (PID: 3276)
      • 7zSFX_Constructor.exe (PID: 3224)
    • Create files in a temporary directory

      • 7zSFX_Constructor.exe (PID: 568)
    • The sample compiled with english language support

      • 7zSFX_Constructor.exe (PID: 568)
      • xcopy.exe (PID: 3108)
      • 7zSFX_Constructor.exe (PID: 3224)
    • The sample compiled with turkish language support

      • 7zSFX_Constructor.exe (PID: 568)
      • xcopy.exe (PID: 3108)
    • Creates files in the program directory

      • xcopy.exe (PID: 3108)
      • cmd.exe (PID: 3076)
      • xcopy.exe (PID: 2952)
      • cmd.exe (PID: 2652)
      • ap30.dat (PID: 2780)
      • ap10.dat (PID: 3184)
      • 7zSFX_Constructor.exe (PID: 3224)
      • ap14.dat (PID: 3276)
    • The sample compiled with russian language support

      • xcopy.exe (PID: 3108)
      • 7zSFX_Constructor.exe (PID: 568)
    • Creates a new folder

      • cmd.exe (PID: 3076)
    • Reads the computer name

      • 7zSFX_Constructor.exe (PID: 568)
      • ap10.dat (PID: 3184)
      • ap30.dat (PID: 2780)
      • ap30.dat (PID: 3668)
      • 7zSFX_Constructor.exe (PID: 3224)
    • Reads mouse settings

      • ap14.dat (PID: 3276)
    • Creates files or folders in the user directory

      • 7zSFX_Constructor.exe (PID: 568)
      • 7zSFX_Constructor.exe (PID: 3224)
    • The process uses Lua

      • 7zSFX_Constructor.exe (PID: 3224)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.7z | 7-Zip compressed archive (v0.4) (57.1)
.7z | 7-Zip compressed archive (gen) (42.8)

EXIF

ZIP

FileVersion: 7z v0.04
ModifyDate: 2018:12:09 11:50:31+00:00
ArchivedFileName: APPS
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
66
Monitored processes
21
Malicious processes
2
Suspicious processes
2

Behavior graph

Click at the process to see the details
start winrar.exe cmd.exe no specs 7zsfx_constructor.exe no specs cmd.exe no specs 7zsfx_constructor.exe cmd.exe no specs xcopy.exe cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs xcopy.exe no specs cmd.exe no specs 7zsfx_constructor.exe ap10.dat no specs ap30.dat no specs ap30.dat no specs ap14.dat

Process information

PID
CMD
Path
Indicators
Parent process
312"7zSFX_Constructor.exe" /hC:\Users\admin\Desktop\7zSFX_Constructor.execmd.exe
User:
admin
Company:
CryptoNick
Integrity Level:
MEDIUM
Description:
7z SFX Constructor
Exit code:
0
Version:
4.5.0.0
Modules
Images
c:\users\admin\desktop\7zsfx_constructor.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
5687zSFX_Constructor.exe -aiSC:\Users\admin\Desktop\7zSFX_Constructor.exe
cmd.exe
User:
admin
Company:
CryptoNick
Integrity Level:
MEDIUM
Description:
7z SFX Constructor
Exit code:
0
Version:
4.5.0.0
Modules
Images
c:\users\admin\desktop\7zsfx_constructor.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
672C:\Windows\system32\cmd.exe /c ""C:\Users\admin\Desktop\Install.cmd" "C:\Windows\System32\cmd.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
988"C:\Windows\System32\cmd.exe" /c if not exist "C:\ProgramData\7zSFX_Constructor\APPS\Settings\Sert.pfx.old" (copy /y "C:\ProgramData\7zSFX_Constructor\APPS\Sert\Sert.pfx" "C:\ProgramData\7zSFX_Constructor\APPS\Sert\Sert.pfx.old")C:\Windows\System32\cmd.exe7zSFX_Constructor.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1268"C:\Windows\System32\cmd.exe" /c if not exist "C:\ProgramData\7zSFX_Constructor\APPS\Settings\Sert.cer.old" (copy /y "C:\ProgramData\7zSFX_Constructor\APPS\Sert\Sert.cer" "C:\ProgramData\7zSFX_Constructor\APPS\Sert\Sert.cer.old")C:\Windows\System32\cmd.exe7zSFX_Constructor.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1996"C:\Windows\System32\cmd.exe" /c if not exist "C:\ProgramData\7zSFX_Constructor\APPS\Settings\Settings.old" (copy /y "C:\ProgramData\7zSFX_Constructor\APPS\Settings\Settings.cfg" "C:\ProgramData\7zSFX_Constructor\APPS\Settings\Settings.old")C:\Windows\System32\cmd.exe7zSFX_Constructor.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2464"C:\Windows\System32\cmd.exe" /c xcopy "C:\Users\admin\Desktop\APPS" "C:\ProgramData\7zSFX_Constructor\APPS" /c /i /s /e /r /h /yC:\Windows\System32\cmd.exe7zSFX_Constructor.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2568C:\Windows\system32\cmd.exe /c ""C:\Users\admin\Desktop\Help.cmd" "C:\Windows\System32\cmd.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2604"C:\Windows\System32\cmd.exe" /c if not exist "C:\ProgramData\7zSFX_Constructor\APPS\Settings\VerIcon.old" (copy /y "C:\ProgramData\7zSFX_Constructor\APPS\Settings\VerIcon.dll" "C:\ProgramData\7zSFX_Constructor\APPS\Settings\VerIcon.old")C:\Windows\System32\cmd.exe7zSFX_Constructor.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2652"C:\Windows\System32\cmd.exe" /c @echo Install Date: %date%>>"C:\ProgramData\7zSFX_Constructor\Install.log"C:\Windows\System32\cmd.exe7zSFX_Constructor.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
5 188
Read events
5 140
Write events
35
Delete events
13

Modification events

(PID) Process:(2840) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2840) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2840) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2840) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2840) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(2840) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(2840) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\778bc258-051e-4dee-9c4a-19d0e87bf832.7z
(PID) Process:(2840) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2840) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2840) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
69
Suspicious files
158
Text files
314
Unknown types
0

Dropped files

PID
Process
Filename
Type
2840WinRAR.exeC:\Users\admin\Desktop\APPS\Icon\128.icoimage
MD5:F125D75087C3DF3326E64D31F6E2B731
SHA256:199FDCC2688CD54B356CB11135EBB3B4655183B93E32D30FCBF763EE53C92CF9
2840WinRAR.exeC:\Users\admin\Desktop\APPS\Icon\08.icoimage
MD5:38DFDD10BC80F987BE67A5FB0C553B7D
SHA256:7F48F3E63AE9BE28ED4A8FFBB0217C67B0C32C74C5628B4764719A810DB388D0
2840WinRAR.exeC:\Users\admin\Desktop\APPS\Icon\01.icoimage
MD5:3802F70CAA8594D31EE3010E48ABC252
SHA256:D5CB9C5494A059B37FE7402838001F2F33EE536430ACEF01887D84806A1C9AB2
2840WinRAR.exeC:\Users\admin\Desktop\APPS\Icon\101.icoimage
MD5:1705BCCAE5C5A08D9273BCDEA7853565
SHA256:582542657D66CB5DD5E009995254FF3CDB8BF0C624EA849E1662DA28E31BD217
2840WinRAR.exeC:\Users\admin\Desktop\APPS\Icon\1.icoimage
MD5:2AD4EC3AFE3B0FD7E8E5DB395EE06DC1
SHA256:C46F08BB646DC3BE5C8FE75DFD926427F35D7F2F2D55E0C58166F21FFE325C5B
2840WinRAR.exeC:\Users\admin\Desktop\APPS\Icon\09.icobinary
MD5:C48D18018157B6C25CF38A78E0C7E742
SHA256:991F627239A110744C30E8BE8A447C7C9B10913D9B96AEE7F50B01ECC5DD4292
2840WinRAR.exeC:\Users\admin\Desktop\APPS\Icon\107.icoimage
MD5:9F8B4FB338503FC90874DD561E9D7C4C
SHA256:9108F20BDC4ED66CA0A15F627CCF382CADB99148E9E965F416D3565851EC117C
2840WinRAR.exeC:\Users\admin\Desktop\APPS\Icon\11.icoimage
MD5:284B99343AAE097F2D9E9D779FB539C1
SHA256:916ABAAE31E56CAAF467920CA7AB5A8610172C6A854C6AE53FA8FF172E710240
2840WinRAR.exeC:\Users\admin\Desktop\APPS\Icon\14.icobinary
MD5:F76185693A0A8B74163EEF9E658552B4
SHA256:15E836D0ED8AA9724304C29E3A32EEAE99310642CBE0A83B7EF8B64B2197ADC2
2840WinRAR.exeC:\Users\admin\Desktop\APPS\Icon\138.icoimage
MD5:F42C6A54594B38EA0C43210D53EA1654
SHA256:8FA77E2DE8774D0DCF247D4DFAF08820D7273C7AFA5979BA45BBF2B19748AB89
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
6
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:138
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 216.58.206.46
whitelisted

Threats

No threats detected
No debug info