File name:

XB36Hazards_Installer_3000.zip

Full analysis: https://app.any.run/tasks/c98c67d6-a7de-4a3a-9da2-1b5a774d13d1
Verdict: Malicious activity
Analysis date: December 29, 2019, 15:26:28
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

0C008E6FDF0A83B1FB56387BCEB2C25C

SHA1:

455F5CC1C2AA9C2B17ED3989643BBE73ADA09378

SHA256:

13EE303403B908A134A1C738F6F8BCAA86450E9357DAD8C2B0DE45974ABDC764

SSDEEP:

49152:I6DBAwkxbdCIpXSxbRQt7TyL5g+SY1nnq1GLLxclXVY3lxVUrCW3:KwkCeXSxb6q9nZxcPQxVyh3

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • XB36Hazards Installer.exe (PID: 1048)
      • XB36Hazards Installer.exe (PID: 2732)
      • Red Dead Redemption Save Editor.exe (PID: 3624)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1600)
      • XB36Hazards Installer.exe (PID: 1048)
    • Creates files in the program directory

      • XB36Hazards Installer.exe (PID: 1048)
    • Creates a software uninstall entry

      • XB36Hazards Installer.exe (PID: 1048)
  • INFO

    • Reads settings of System Certificates

      • XB36Hazards Installer.exe (PID: 1048)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2019:12:18 12:11:28
ZipCRC: 0xc3a07ca8
ZipCompressedSize: 2544429
ZipUncompressedSize: 3169792
ZipFileName: XB36Hazards Installer.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
41
Monitored processes
4
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start drop and start start drop and start winrar.exe xb36hazards installer.exe no specs xb36hazards installer.exe red dead redemption save editor.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1048"C:\Users\admin\AppData\Local\Temp\Rar$EXa1600.21514\XB36Hazards Installer.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa1600.21514\XB36Hazards Installer.exe
WinRAR.exe
User:
admin
Company:
XB36Hazard
Integrity Level:
HIGH
Description:
XB36Hazard's Installer
Exit code:
0
Version:
3.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa1600.21514\xb36hazards installer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1600"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\XB36Hazards_Installer_3000.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2732"C:\Users\admin\AppData\Local\Temp\Rar$EXa1600.21514\XB36Hazards Installer.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa1600.21514\XB36Hazards Installer.exeWinRAR.exe
User:
admin
Company:
XB36Hazard
Integrity Level:
MEDIUM
Description:
XB36Hazard's Installer
Exit code:
3221226540
Version:
3.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa1600.21514\xb36hazards installer.exe
c:\systemroot\system32\ntdll.dll
3624"C:\Program Files\Red Dead Redemption Save Editor\Red Dead Redemption Save Editor.exe" C:\Program Files\Red Dead Redemption Save Editor\Red Dead Redemption Save Editor.exeXB36Hazards Installer.exe
User:
admin
Company:
XB36Hazard
Integrity Level:
HIGH
Description:
Red Dead Redemption Save Editor
Exit code:
0
Version:
0.1.3.1
Modules
Images
c:\program files\red dead redemption save editor\red dead redemption save editor.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
736
Read events
685
Write events
51
Delete events
0

Modification events

(PID) Process:(1600) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1600) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1600) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1600) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\XB36Hazards_Installer_3000.zip
(PID) Process:(1600) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1600) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1600) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1600) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1600) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(1600) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
Executable files
2
Suspicious files
0
Text files
16
Unknown types
0

Dropped files

PID
Process
Filename
Type
1048XB36Hazards Installer.exeC:\Users\admin\AppData\Local\Temp\tmpD173.tmp
MD5:
SHA256:
1048XB36Hazards Installer.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1600.21514\DataFile.ins
MD5:
SHA256:
1048XB36Hazards Installer.exeC:\Users\admin\AppData\Local\Temp\tmp72C5.tmp
MD5:
SHA256:
1048XB36Hazards Installer.exeC:\Users\admin\AppData\Local\Temp\4D3752EB
MD5:
SHA256:
1048XB36Hazards Installer.exeC:\Users\admin\AppData\Local\Temp\tmp7576.tmp
MD5:
SHA256:
1600WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1600.21514\XB36Hazards Installer.exeexecutable
MD5:
SHA256:
1048XB36Hazards Installer.exeC:\Users\admin\AppData\Local\XInstaller\966B69A695690EEFE9194593AE26C8A291DA84A9.xiiimage
MD5:
SHA256:
1048XB36Hazards Installer.exeC:\Users\admin\AppData\Local\XInstaller\02268FBE059B6C20B1DC73D32C78C16C53927CD4.xiiimage
MD5:
SHA256:
1048XB36Hazards Installer.exeC:\Users\admin\AppData\Local\XInstaller\BA5D08430CEFFE24F61A0086E6C6CE418763A627.xiiimage
MD5:
SHA256:
1048XB36Hazards Installer.exeC:\Users\admin\AppData\Local\XInstaller\11C75A1519A06839C45FEE76C233DFE843B99506.xiiimage
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
20
DNS requests
20
Threats
1

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1048
XB36Hazards Installer.exe
162.125.66.6:443
uc99752100070e3fcb20f4195622.dl.dropboxusercontent.com
Dropbox, Inc.
DE
shared
1048
XB36Hazards Installer.exe
162.125.66.1:443
www.dropbox.com
Dropbox, Inc.
DE
shared
1048
XB36Hazards Installer.exe
216.58.210.14:80
google.com
Google Inc.
US
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 216.58.210.14
malicious
www.dropbox.com
  • 162.125.66.1
shared
uc99752100070e3fcb20f4195622.dl.dropboxusercontent.com
  • 162.125.66.6
suspicious
uc298e0024efc39f970f6be98f8f.dl.dropboxusercontent.com
  • 162.125.66.6
suspicious
uc0cd09e40ce89d23dd2c2bf45cf.dl.dropboxusercontent.com
  • 162.125.66.6
suspicious
uc41b2922df7a313f2772392aa5d.dl.dropboxusercontent.com
  • 162.125.66.6
suspicious
uceb6c3be6217b029135cff1b25a.dl.dropboxusercontent.com
  • 162.125.66.6
suspicious
uc09efcd92df68f2e9c759a86d42.dl.dropboxusercontent.com
  • 162.125.66.6
suspicious
uc0ac7d30b7f23db8332ae1b955f.dl.dropboxusercontent.com
  • 162.125.66.6
suspicious
uc0f93e2eb3e366cfa793db129da.dl.dropboxusercontent.com
  • 162.125.66.6
suspicious

Threats

PID
Process
Class
Message
1048
XB36Hazards Installer.exe
Potential Corporate Privacy Violation
SUSPICIOUS [PTsecurity] Dropbox SSL Payload Request
No debug info