File name:

malware.zip

Full analysis: https://app.any.run/tasks/63223e34-aa1e-40a4-83f0-c1a6d63a07f3
Verdict: Malicious activity
Threats:

Remote access trojans (RATs) are a type of malware that enables attackers to establish complete to partial control over infected computers. Such malicious programs often have a modular design, offering a wide range of functionalities for conducting illicit activities on compromised systems. Some of the most common features of RATs include access to the users’ data, webcam, and keystrokes. This malware is often distributed through phishing emails and links.

Analysis date: October 20, 2020, 10:43:49
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
rat
remcos
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

01441DB5F268BFBD514554CCFC7145B0

SHA1:

06B224577A39031E27FECDB1BB961A7E5F01727B

SHA256:

14AEAC4E7BDFD1E68C5DF60501DBAD08E1A1C370FEFF718A0A8C71B54D9A201E

SSDEEP:

12288:fS1bt5Uk9ZdYPUSb6WcabdtbASHiR9mJkIFfa+9LXVuT:fS1btyiYcSb6WJdtdCDmr9LXVuT

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • IM0006163819_pdf.exe (PID: 4008)
    • REMCOS was detected

      • RegSvcs.exe (PID: 3148)
    • Loads the Task Scheduler COM API

      • schtasks.exe (PID: 2328)
    • Uses Task Scheduler to run other applications

      • IM0006163819_pdf.exe (PID: 4008)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • IM0006163819_pdf.exe (PID: 4008)
      • WinRAR.exe (PID: 2516)
    • Creates files in the user directory

      • IM0006163819_pdf.exe (PID: 4008)
  • INFO

    • Manual execution by user

      • IM0006163819_pdf.exe (PID: 4008)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0001
ZipCompression: Deflated
ZipModifyDate: 2020:10:19 08:08:21
ZipCRC: 0x9adfd1fb
ZipCompressedSize: 457080
ZipUncompressedSize: 805376
ZipFileName: IM0006163819_pdf.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
42
Monitored processes
4
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe im0006163819_pdf.exe schtasks.exe no specs #REMCOS regsvcs.exe

Process information

PID
CMD
Path
Indicators
Parent process
2328"C:\Windows\System32\schtasks.exe" /Create /TN "Updates\RACUfltu" /XML "C:\Users\admin\AppData\Local\Temp\tmp55D1.tmp"C:\Windows\System32\schtasks.exeIM0006163819_pdf.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Manages scheduled tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
2516"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\malware.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\comdlg32.dll
3148"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe
IM0006163819_pdf.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft .NET Services Installation Utility
Exit code:
0
Version:
4.7.3062.0 built by: NET472REL1
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\regsvcs.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
4008"C:\Users\admin\Desktop\IM0006163819_pdf.exe" C:\Users\admin\Desktop\IM0006163819_pdf.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Scale Detect
Exit code:
0
Version:
2.0.0.6
Modules
Images
c:\users\admin\desktop\im0006163819_pdf.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
394
Read events
368
Write events
26
Delete events
0

Modification events

(PID) Process:(2516) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2516) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2516) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2516) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\malware.zip
(PID) Process:(2516) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2516) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2516) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2516) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2516) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
(PID) Process:(2516) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
Executable files
2
Suspicious files
0
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
4008IM0006163819_pdf.exeC:\Users\admin\AppData\Roaming\RACUfltu.exeexecutable
MD5:
SHA256:
2516WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb2516.48313\IM0006163819_pdf.exeexecutable
MD5:
SHA256:
4008IM0006163819_pdf.exeC:\Users\admin\AppData\Local\Temp\tmp55D1.tmpxml
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
11
DNS requests
8
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3148
RegSvcs.exe
185.244.30.201:2265
moremoneypls.trickip.net
malicious

DNS requests

Domain
IP
Reputation
moremoneypls.trickip.net
  • 185.244.30.201
malicious
dns.msftncsi.com
  • 131.107.255.255
shared

Threats

No threats detected
No debug info