analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

Order PCT1086586 - Project Commercial Conditions.zip

Full analysis: https://app.any.run/tasks/a214c84d-e99f-4a70-98ef-3fefd82993d5
Verdict: Malicious activity
Threats:

A keylogger is a type of spyware that infects a system and has the ability to record every keystroke made on the device. This lets attackers collect personal information of victims, which may include their online banking credentials, as well as personal conversations. The most widespread vector of attack leading to a keylogger infection begins with a phishing email or link. Keylogging is also often present in remote access trojans as part of an extended set of malicious tools.

Analysis date: July 18, 2019, 07:42:28
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
rat
remcos
trojan
keylogger
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

D08C78C2052432CA6ECA13C79EF6DF1A

SHA1:

A6EF2828EA27BAA756B243B16C815F03C9D19B8F

SHA256:

1AA27D6164A04A5F1713ED89353B4F6DBA19617C94B88E91813F3E7F29C1613C

SSDEEP:

6144:rcK1z/TDjOpEYQ7uQycOAAcekZ5qCGkN2XR8VS9cS84zaMgwSDNkQZ:gCT/JYdjxA9LXGklVS9cSPOMi5hZ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Order PCT1086586 - Project Commercial Conditions.exe (PID: 3892)
      • Order PCT1086586 - Project Commercial Conditions.exe (PID: 3948)
      • Order PCT1086586 - Project Commercial Conditions.exe (PID: 3896)
      • Order PCT1086586 - Project Commercial Conditions.exe (PID: 2904)
      • Order PCT1086586 - Project Commercial Conditions.exe (PID: 1528)
      • Order PCT1086586 - Project Commercial Conditions.exe (PID: 4020)
      • Order PCT1086586 - Project Commercial Conditions.exe (PID: 3048)
      • Order PCT1086586 - Project Commercial Conditions.exe (PID: 3872)
      • hpsupport.exe (PID: 3236)
      • hpsupport.exe (PID: 4040)
    • Changes the autorun value in the registry

      • Order PCT1086586 - Project Commercial Conditions.exe (PID: 3892)
      • hpsupport.exe (PID: 4040)
    • REMCOS was detected

      • hpsupport.exe (PID: 4040)
    • Detected logs from REMCOS RAT

      • hpsupport.exe (PID: 4040)
    • Connects to CnC server

      • hpsupport.exe (PID: 4040)
  • SUSPICIOUS

    • Application launched itself

      • Order PCT1086586 - Project Commercial Conditions.exe (PID: 4020)
      • Order PCT1086586 - Project Commercial Conditions.exe (PID: 3872)
      • Order PCT1086586 - Project Commercial Conditions.exe (PID: 2904)
      • Order PCT1086586 - Project Commercial Conditions.exe (PID: 3048)
      • hpsupport.exe (PID: 3236)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3012)
      • Order PCT1086586 - Project Commercial Conditions.exe (PID: 3892)
    • Creates files in the user directory

      • Order PCT1086586 - Project Commercial Conditions.exe (PID: 3892)
      • hpsupport.exe (PID: 4040)
    • Executes scripts

      • Order PCT1086586 - Project Commercial Conditions.exe (PID: 3892)
    • Starts CMD.EXE for commands execution

      • WScript.exe (PID: 1420)
    • Writes files like Keylogger logs

      • hpsupport.exe (PID: 4040)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: Order PCT1086586 - Project Commercial Conditions.exe
ZipUncompressedSize: 544768
ZipCompressedSize: 290356
ZipCRC: 0xe99659d7
ZipModifyDate: 2005:01:27 01:09:26
ZipCompression: Deflated
ZipBitFlag: -
ZipRequiredVersion: 20
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
51
Monitored processes
13
Malicious processes
8
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start drop and start drop and start drop and start start winrar.exe order pct1086586 - project commercial conditions.exe no specs order pct1086586 - project commercial conditions.exe no specs order pct1086586 - project commercial conditions.exe no specs order pct1086586 - project commercial conditions.exe no specs order pct1086586 - project commercial conditions.exe no specs order pct1086586 - project commercial conditions.exe order pct1086586 - project commercial conditions.exe no specs order pct1086586 - project commercial conditions.exe no specs wscript.exe no specs cmd.exe no specs hpsupport.exe no specs #REMCOS hpsupport.exe

Process information

PID
CMD
Path
Indicators
Parent process
3012"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Order PCT1086586 - Project Commercial Conditions.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.60.0
3872"C:\Users\admin\AppData\Local\Temp\Rar$EXa3012.37035\Order PCT1086586 - Project Commercial Conditions.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3012.37035\Order PCT1086586 - Project Commercial Conditions.exeWinRAR.exe
User:
admin
Company:
Reva
Integrity Level:
MEDIUM
Description:
CYNODONT10
Exit code:
0
Version:
1.07.0009
4020"C:\Users\admin\AppData\Local\Temp\Rar$EXa3012.37040\Order PCT1086586 - Project Commercial Conditions.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3012.37040\Order PCT1086586 - Project Commercial Conditions.exeWinRAR.exe
User:
admin
Company:
Reva
Integrity Level:
MEDIUM
Description:
CYNODONT10
Exit code:
0
Version:
1.07.0009
2904"C:\Users\admin\AppData\Local\Temp\Rar$EXa3012.37071\Order PCT1086586 - Project Commercial Conditions.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3012.37071\Order PCT1086586 - Project Commercial Conditions.exeWinRAR.exe
User:
admin
Company:
Reva
Integrity Level:
MEDIUM
Description:
CYNODONT10
Exit code:
0
Version:
1.07.0009
3048"C:\Users\admin\AppData\Local\Temp\Rar$EXa3012.37079\Order PCT1086586 - Project Commercial Conditions.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3012.37079\Order PCT1086586 - Project Commercial Conditions.exeWinRAR.exe
User:
admin
Company:
Reva
Integrity Level:
MEDIUM
Description:
CYNODONT10
Exit code:
0
Version:
1.07.0009
1528C:\Users\admin\AppData\Local\Temp\Rar$EXa3012.37040\Order PCT1086586 - Project Commercial Conditions.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3012.37040\Order PCT1086586 - Project Commercial Conditions.exeOrder PCT1086586 - Project Commercial Conditions.exe
User:
admin
Company:
Reva
Integrity Level:
MEDIUM
Description:
CYNODONT10
Exit code:
1
Version:
1.07.0009
3892C:\Users\admin\AppData\Local\Temp\Rar$EXa3012.37079\Order PCT1086586 - Project Commercial Conditions.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3012.37079\Order PCT1086586 - Project Commercial Conditions.exe
Order PCT1086586 - Project Commercial Conditions.exe
User:
admin
Company:
Reva
Integrity Level:
MEDIUM
Description:
CYNODONT10
Exit code:
0
Version:
1.07.0009
3896C:\Users\admin\AppData\Local\Temp\Rar$EXa3012.37035\Order PCT1086586 - Project Commercial Conditions.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3012.37035\Order PCT1086586 - Project Commercial Conditions.exeOrder PCT1086586 - Project Commercial Conditions.exe
User:
admin
Company:
Reva
Integrity Level:
MEDIUM
Description:
CYNODONT10
Exit code:
1
Version:
1.07.0009
3948C:\Users\admin\AppData\Local\Temp\Rar$EXa3012.37071\Order PCT1086586 - Project Commercial Conditions.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3012.37071\Order PCT1086586 - Project Commercial Conditions.exeOrder PCT1086586 - Project Commercial Conditions.exe
User:
admin
Company:
Reva
Integrity Level:
MEDIUM
Description:
CYNODONT10
Exit code:
1
Version:
1.07.0009
1420"C:\Windows\System32\WScript.exe" "C:\Users\admin\AppData\Local\Temp\install.vbs" C:\Windows\System32\WScript.exeOrder PCT1086586 - Project Commercial Conditions.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Windows Based Script Host
Exit code:
0
Version:
5.8.7600.16385
Total events
871
Read events
847
Write events
24
Delete events
0

Modification events

(PID) Process:(3012) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3012) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3012) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\70\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3012) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Order PCT1086586 - Project Commercial Conditions.zip
(PID) Process:(3012) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3012) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3012) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3012) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3012) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(3012) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
Executable files
5
Suspicious files
1
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
3012WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3012.37035\Order PCT1086586 - Project Commercial Conditions.exeexecutable
MD5:F2ECAAD95EB5C1EC560456807507554E
SHA256:6B67C78359A721A5D973706792105EB2E108F2C24B1E195C85E517AB32AA0FA5
4040hpsupport.exeC:\Users\admin\AppData\Roaming\hpsupport\logs.dattext
MD5:741D3F59B03144F17912A6A42F863889
SHA256:113D8074A692B9C30AEF8D424F7BE10F2E1B326F50959B05F970B8ED455213C2
3892Order PCT1086586 - Project Commercial Conditions.exeC:\Users\admin\AppData\Roaming\hpsupport\hpsupport.exeexecutable
MD5:F2ECAAD95EB5C1EC560456807507554E
SHA256:6B67C78359A721A5D973706792105EB2E108F2C24B1E195C85E517AB32AA0FA5
3012WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3012.37079\Order PCT1086586 - Project Commercial Conditions.exeexecutable
MD5:F2ECAAD95EB5C1EC560456807507554E
SHA256:6B67C78359A721A5D973706792105EB2E108F2C24B1E195C85E517AB32AA0FA5
3012WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3012.37040\Order PCT1086586 - Project Commercial Conditions.exeexecutable
MD5:F2ECAAD95EB5C1EC560456807507554E
SHA256:6B67C78359A721A5D973706792105EB2E108F2C24B1E195C85E517AB32AA0FA5
3012WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3012.37071\Order PCT1086586 - Project Commercial Conditions.exeexecutable
MD5:F2ECAAD95EB5C1EC560456807507554E
SHA256:6B67C78359A721A5D973706792105EB2E108F2C24B1E195C85E517AB32AA0FA5
3892Order PCT1086586 - Project Commercial Conditions.exeC:\Users\admin\AppData\Local\Temp\install.vbsbinary
MD5:B4DD0E6DED24F260B85FEAFCBF394F64
SHA256:41DCAD305F95F49F5B3528711D01C80B86C5DAD0DD247751620033F746AE56AB
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
1
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4040
hpsupport.exe
185.247.228.250:5001
dubaidhllee.ddns.net
malicious

DNS requests

Domain
IP
Reputation
dubaidhllee.ddns.net
  • 185.247.228.250
malicious

Threats

PID
Process
Class
Message
4040
hpsupport.exe
A Network Trojan was detected
MALWARE [PTsecurity] Win32/Remcos RAT Checkin
4040
hpsupport.exe
A Network Trojan was detected
MALWARE [PTsecurity] Remcos RAT
4040
hpsupport.exe
A Network Trojan was detected
ET TROJAN Remcos RAT Checkin 23
4040
hpsupport.exe
A Network Trojan was detected
MALWARE [PTsecurity] Win32/Remcos RAT Checkin
4040
hpsupport.exe
A Network Trojan was detected
MALWARE [PTsecurity] Remcos RAT
4040
hpsupport.exe
A Network Trojan was detected
MALWARE [PTsecurity] Backdoor.Win32/Remcos RAT connection
4040
hpsupport.exe
A Network Trojan was detected
MALWARE [PTsecurity] Win32/Remcos RAT Checkin
4040
hpsupport.exe
A Network Trojan was detected
MALWARE [PTsecurity] Remcos RAT
4040
hpsupport.exe
A Network Trojan was detected
ET TROJAN Remcos RAT Checkin 23
4040
hpsupport.exe
A Network Trojan was detected
MALWARE [PTsecurity] Win32/Remcos RAT Checkin
No debug info