File name:

iz3lne.zip

Full analysis: https://app.any.run/tasks/933d3ce6-e22b-4f8b-92d7-6650368b7079
Verdict: Malicious activity
Analysis date: November 08, 2024, 00:43:05
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-exec
arch-doc
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

6B104BA9DEB749A6B6CE88B9C6997DAE

SHA1:

19D9B52477606B78BDCE568235C0ACB9321C1BC4

SHA256:

14CE93AE01D50B9D2FF3C36C3EDD574A9F8BCEC56451F3A865FCC210C617A77B

SSDEEP:

49152:vaAW1JvfJzxpH5gntvVxsO/vXYoFA1N4VrBBXYt621Vrmt7a7wWn7/YmO:vaAWnN2lnvXXFFA1N4VG6GVrmt7a7zBO

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 6304)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • GenP-3.4.14.1.exe (PID: 7112)
      • GenP-3.4.14.1.exe (PID: 6336)
    • Application launched itself

      • GenP-3.4.14.1.exe (PID: 6232)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3532)
    • Manual execution by a user

      • WinRAR.exe (PID: 3532)
      • GenP-3.4.14.1.exe (PID: 6232)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2024:08:02 14:32:54
ZipCRC: 0xb9323b01
ZipCompressedSize: 703043
ZipUncompressedSize: 1285632
ZipFileName: GenP-3.4.14.1.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
143
Monitored processes
7
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs winrar.exe rundll32.exe no specs genp-3.4.14.1.exe no specs genp-3.4.14.1.exe nsudolg.exe no specs genp-3.4.14.1.exe

Process information

PID
CMD
Path
Indicators
Parent process
1588C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
3532"C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Desktop\iz3lne.zip" C:\Users\admin\Desktop\iz3lne\C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
6232"C:\Users\admin\Desktop\iz3lne\GenP-3.4.14.1.exe" C:\Users\admin\Desktop\iz3lne\GenP-3.4.14.1.exeexplorer.exe
User:
admin
Company:
GenP
Integrity Level:
MEDIUM
Description:
GenP v3.4.14.1
Exit code:
0
Version:
3.4.14.1
Modules
Images
c:\users\admin\desktop\iz3lne\genp-3.4.14.1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\psapi.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\msvcrt.dll
6304"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\iz3lne.zipC:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
6336"C:\Users\admin\Desktop\iz3lne\GenP-3.4.14.1.exe"C:\Users\admin\Desktop\iz3lne\GenP-3.4.14.1.exe
NSudoLG.exe
User:
SYSTEM
Company:
GenP
Integrity Level:
SYSTEM
Description:
GenP v3.4.14.1
Version:
3.4.14.1
Modules
Images
c:\users\admin\desktop\iz3lne\genp-3.4.14.1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\psapi.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
7096C:\Users\admin\AppData\Local\Temp\NSudoLG.exe -U:T -P:E -M:S "C:\Users\admin\Desktop\iz3lne\GenP-3.4.14.1.exe"C:\Users\admin\AppData\Local\Temp\NSudoLG.exeGenP-3.4.14.1.exe
User:
admin
Company:
M2-Team
Integrity Level:
HIGH
Description:
NSudo Launcher
Exit code:
0
Version:
8.2.0.0
Modules
Images
c:\users\admin\appdata\local\temp\nsudolg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
7112"C:\Users\admin\Desktop\iz3lne\GenP-3.4.14.1.exe" !C:\Users\admin\Desktop\iz3lne\GenP-3.4.14.1.exe
GenP-3.4.14.1.exe
User:
admin
Company:
GenP
Integrity Level:
HIGH
Description:
GenP v3.4.14.1
Exit code:
7096
Version:
3.4.14.1
Modules
Images
c:\users\admin\desktop\iz3lne\genp-3.4.14.1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\psapi.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
Total events
7 300
Read events
7 225
Write events
67
Delete events
8

Modification events

(PID) Process:(6304) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\GoogleChromeEnterpriseBundle64.zip
(PID) Process:(6304) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\iz3lne.zip
(PID) Process:(6304) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(6304) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(6304) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(6304) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(6304) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:name
Value:
256
(PID) Process:(6304) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(6304) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:psize
Value:
80
(PID) Process:(6304) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:type
Value:
120
Executable files
5
Suspicious files
11
Text files
5
Unknown types
0

Dropped files

PID
Process
Filename
Type
3532WinRAR.exeC:\Users\admin\Desktop\iz3lne\SOURCE\COMPILE.txttext
MD5:B089647B4BFE6964655CB784D4F1AE38
SHA256:87B24B13BAA368A62E7F5E377BFA1551CCE0BB2224AA350309F571C24452AC30
7112GenP-3.4.14.1.exeC:\Users\admin\Desktop\iz3lne\config.iniini
MD5:ADD427035968BC6F8BCDF0C5D7580495
SHA256:66232A4D8677CD50612EAEBC664B2F2F3556B497D5BF8657967C259EF4723B68
7112GenP-3.4.14.1.exeC:\Users\admin\AppData\Local\Temp\autFCF6.tmpbinary
MD5:C8974BCA42D238986F542ECE4EBA859A
SHA256:1AE68F2E79AA2072FFD717E58B162CABF31785D341A398FBF3D9C67BB07332F1
7112GenP-3.4.14.1.exeC:\Users\admin\AppData\Local\Temp\autFD07.tmpbinary
MD5:6F040B192B47D1D0860045AA30C102A0
SHA256:A85D89E380CBF4929EE5B6E7D91BE71AF1C3A727A91CF30AFFB414B98E912180
3532WinRAR.exeC:\Users\admin\Desktop\iz3lne\SOURCE\README.txttext
MD5:7C8C065A6D1563CCE7A73C3D3FA66FAE
SHA256:4AE4BC30641801C603C0EB36B2DDFC06081B91CF2E614E6565F489187EF1B027
3532WinRAR.exeC:\Users\admin\Desktop\iz3lne\SOURCE\NSudoLG.exeexecutable
MD5:7AACFD85B8DFF0AA6867BEDE82CFD147
SHA256:871E4F28FE39BCAD8D295AE46E148BE458778C0195ED660B7DB18EB595D00BD8
3532WinRAR.exeC:\Users\admin\Desktop\iz3lne\SOURCE\GenP-3.4.14.1.au3text
MD5:42C434F0A040132E37EDDB5B1D886F8E
SHA256:3DD6CF96E38768110C8F0E64AE8C698E43931FF9FB57B4A1476B63F4E5D45554
3532WinRAR.exeC:\Users\admin\Desktop\iz3lne\GenP-3.4.14.1.exeexecutable
MD5:5AA73CE6297B35AAC0067529A47B44C5
SHA256:3BDDB83344219A07A43E53F68A0F6920FDD51B7412540D0DAAEAC353B6AB11A2
7112GenP-3.4.14.1.exeC:\Users\admin\AppData\Local\Temp\NSudoLG.exeexecutable
MD5:7AACFD85B8DFF0AA6867BEDE82CFD147
SHA256:871E4F28FE39BCAD8D295AE46E148BE458778C0195ED660B7DB18EB595D00BD8
3532WinRAR.exeC:\Users\admin\Desktop\iz3lne\SOURCE\ICONS\Logo.icoimage
MD5:C383035A57C2E7A39803F71096011CA6
SHA256:71DE01801146E8DBE1EA5771A80B5F8E39693A58AD12987022DDE335B9D7CA86
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
39
DNS requests
19
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6944
svchost.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
624
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6944
svchost.exe
GET
200
2.19.198.194:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4360
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
7080
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
7080
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6192
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
6944
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
1584
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5488
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
6944
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6944
svchost.exe
2.19.198.194:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
6944
svchost.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4360
SearchApp.exe
104.126.37.161:443
www.bing.com
Akamai International B.V.
DE
whitelisted
4360
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 20.73.194.208
whitelisted
google.com
  • 142.250.184.206
whitelisted
crl.microsoft.com
  • 2.19.198.194
  • 23.32.238.34
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
www.bing.com
  • 104.126.37.161
  • 104.126.37.171
  • 104.126.37.176
  • 104.126.37.169
  • 104.126.37.162
  • 104.126.37.128
  • 104.126.37.170
  • 104.126.37.129
  • 104.126.37.131
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 20.190.159.64
  • 20.190.159.75
  • 20.190.159.23
  • 40.126.31.71
  • 20.190.159.4
  • 20.190.159.71
  • 20.190.159.2
  • 40.126.31.67
whitelisted
th.bing.com
  • 104.126.37.145
  • 104.126.37.155
  • 104.126.37.136
  • 104.126.37.178
  • 104.126.37.161
  • 104.126.37.169
  • 104.126.37.153
  • 104.126.37.185
  • 104.126.37.146
whitelisted
go.microsoft.com
  • 184.30.17.189
whitelisted
slscr.update.microsoft.com
  • 52.149.20.212
whitelisted

Threats

No threats detected
Process
Message
GenP-3.4.14.1.exe
Unable to get NTFS id
GenP-3.4.14.1.exe
Unable to get NTFS id
GenP-3.4.14.1.exe
Unable to get NTFS id
GenP-3.4.14.1.exe
Unable to get NTFS id
GenP-3.4.14.1.exe
Unable to get NTFS id
GenP-3.4.14.1.exe
Unable to get NTFS id
GenP-3.4.14.1.exe
Unable to get NTFS id
GenP-3.4.14.1.exe
Unable to get NTFS id