analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

malware.zip

Full analysis: https://app.any.run/tasks/63223e34-aa1e-40a4-83f0-c1a6d63a07f3
Verdict: Malicious activity
Threats:

Remote access trojans (RATs) are a type of malware that enables attackers to establish complete to partial control over infected computers. Such malicious programs often have a modular design, offering a wide range of functionalities for conducting illicit activities on compromised systems. Some of the most common features of RATs include access to the users’ data, webcam, and keystrokes. This malware is often distributed through phishing emails and links.

Analysis date: October 20, 2020, 10:43:49
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
rat
remcos
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

01441DB5F268BFBD514554CCFC7145B0

SHA1:

06B224577A39031E27FECDB1BB961A7E5F01727B

SHA256:

14AEAC4E7BDFD1E68C5DF60501DBAD08E1A1C370FEFF718A0A8C71B54D9A201E

SSDEEP:

12288:fS1bt5Uk9ZdYPUSb6WcabdtbASHiR9mJkIFfa+9LXVuT:fS1btyiYcSb6WJdtdCDmr9LXVuT

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • IM0006163819_pdf.exe (PID: 4008)
    • Uses Task Scheduler to run other applications

      • IM0006163819_pdf.exe (PID: 4008)
    • REMCOS was detected

      • RegSvcs.exe (PID: 3148)
    • Loads the Task Scheduler COM API

      • schtasks.exe (PID: 2328)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2516)
      • IM0006163819_pdf.exe (PID: 4008)
    • Creates files in the user directory

      • IM0006163819_pdf.exe (PID: 4008)
  • INFO

    • Manual execution by user

      • IM0006163819_pdf.exe (PID: 4008)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0001
ZipCompression: Deflated
ZipModifyDate: 2020:10:19 08:08:21
ZipCRC: 0x9adfd1fb
ZipCompressedSize: 457080
ZipUncompressedSize: 805376
ZipFileName: IM0006163819_pdf.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
42
Monitored processes
4
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe im0006163819_pdf.exe schtasks.exe no specs #REMCOS regsvcs.exe

Process information

PID
CMD
Path
Indicators
Parent process
2516"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\malware.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
4008"C:\Users\admin\Desktop\IM0006163819_pdf.exe" C:\Users\admin\Desktop\IM0006163819_pdf.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Scale Detect
Exit code:
0
Version:
2.0.0.6
2328"C:\Windows\System32\schtasks.exe" /Create /TN "Updates\RACUfltu" /XML "C:\Users\admin\AppData\Local\Temp\tmp55D1.tmp"C:\Windows\System32\schtasks.exeIM0006163819_pdf.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Manages scheduled tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
3148"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe
IM0006163819_pdf.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft .NET Services Installation Utility
Version:
4.7.3062.0 built by: NET472REL1
Total events
394
Read events
368
Write events
26
Delete events
0

Modification events

(PID) Process:(2516) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2516) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2516) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2516) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\malware.zip
(PID) Process:(2516) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2516) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2516) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2516) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2516) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
(PID) Process:(2516) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
Executable files
2
Suspicious files
0
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
4008IM0006163819_pdf.exeC:\Users\admin\AppData\Local\Temp\tmp55D1.tmpxml
MD5:06C3B5C716FAC5F5BD60C1122F913E30
SHA256:D967DBEE65D3A60EEA4575A22133115C1C4BFC03C521DE31CF873E7203521ACB
2516WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb2516.48313\IM0006163819_pdf.exeexecutable
MD5:BC56FCAB79CA2CA1744076E7A8F5605F
SHA256:F4B4B96E89BDCDA8AEC894EE2A0047914218B9CBEECDDBCDD878C7224004D299
4008IM0006163819_pdf.exeC:\Users\admin\AppData\Roaming\RACUfltu.exeexecutable
MD5:BC56FCAB79CA2CA1744076E7A8F5605F
SHA256:F4B4B96E89BDCDA8AEC894EE2A0047914218B9CBEECDDBCDD878C7224004D299
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
11
DNS requests
8
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3148
RegSvcs.exe
185.244.30.201:2265
moremoneypls.trickip.net
malicious

DNS requests

Domain
IP
Reputation
moremoneypls.trickip.net
  • 185.244.30.201
malicious
dns.msftncsi.com
  • 131.107.255.255
shared

Threats

No threats detected
No debug info