| File name: | osiri_458241338 (1).zip |
| Full analysis: | https://app.any.run/tasks/84523779-b1aa-4c43-bf6f-5a6e7abfa297 |
| Verdict: | Malicious activity |
| Analysis date: | March 12, 2021, 18:24:17 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | 23F84503773CBCD58609A5C153F93FBC |
| SHA1: | F4019E80D4A5927047FB9DE01F4B5461E53BAEAC |
| SHA256: | 1AEFEF43D5B1A6A3EFBED83F3190201E3D8F9A0ECD1564E6644D8C0F5BE0D79F |
| SSDEEP: | 98304:SpWKUmSrRpKNsP3vV22IxYZq7JsvuM886S/5iTgUL+XIOAqpo:29IYlqq+uKFBIOAqpo |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2019:12:24 23:16:18 |
| ZipCRC: | 0xc2f14acd |
| ZipCompressedSize: | 3661082 |
| ZipUncompressedSize: | 4136792 |
| ZipFileName: | qw3xv0pn.04m.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 336 | "C:\Users\admin\Desktop\qw3xv0pn.04m.exe" /SPAWNWND=$20172 /NOTIFYWND=$3017C | C:\Users\admin\Desktop\qw3xv0pn.04m.exe | qw3xv0pn.04m.tmp | ||||||||||||
User: admin Company: KirySoft Integrity Level: HIGH Description: WSCC4 (x64) Exit code: 1 Version: 4.0.1.7 Modules
| |||||||||||||||
| 1272 | "C:\Users\admin\AppData\Local\Temp\is-9EM74.tmp\qw3xv0pn.04m.tmp" /SL5="$4016C,3403402,721408,C:\Users\admin\Desktop\qw3xv0pn.04m.exe" /SPAWNWND=$40170 /NOTIFYWND=$4017A | C:\Users\admin\AppData\Local\Temp\is-9EM74.tmp\qw3xv0pn.04m.tmp | — | qw3xv0pn.04m.exe | |||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 1 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 1280 | "C:\Users\admin\AppData\Local\Temp\is-7EDMK.tmp\qw3xv0pn.04m.tmp" /SL5="$4017A,3403402,721408,C:\Users\admin\Desktop\qw3xv0pn.04m.exe" | C:\Users\admin\AppData\Local\Temp\is-7EDMK.tmp\qw3xv0pn.04m.tmp | — | qw3xv0pn.04m.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 1 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 1316 | "C:\Users\admin\AppData\Local\Temp\is-M3KQ9.tmp\qw3xv0pn.04m.tmp" /SL5="$30170,3403402,721408,C:\Users\admin\Desktop\qw3xv0pn.04m.exe" /SPAWNWND=$20172 /NOTIFYWND=$3017C | C:\Users\admin\AppData\Local\Temp\is-M3KQ9.tmp\qw3xv0pn.04m.tmp | — | qw3xv0pn.04m.exe | |||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 1 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 1936 | "C:\Users\admin\AppData\Local\Temp\is-I33P9.tmp\qw3xv0pn.04m.tmp" /SL5="$3017C,3403402,721408,C:\Users\admin\Desktop\qw3xv0pn.04m.exe" | C:\Users\admin\AppData\Local\Temp\is-I33P9.tmp\qw3xv0pn.04m.tmp | — | qw3xv0pn.04m.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 1 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 2356 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\osiri_458241338 (1).zip" | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 2508 | "C:\Users\admin\Desktop\qw3xv0pn.04m.exe" | C:\Users\admin\Desktop\qw3xv0pn.04m.exe | explorer.exe | ||||||||||||
User: admin Company: KirySoft Integrity Level: MEDIUM Description: WSCC4 (x64) Exit code: 1 Version: 4.0.1.7 Modules
| |||||||||||||||
| 2816 | "C:\Users\admin\Desktop\qw3xv0pn.04m.exe" | C:\Users\admin\Desktop\qw3xv0pn.04m.exe | explorer.exe | ||||||||||||
User: admin Company: KirySoft Integrity Level: MEDIUM Description: WSCC4 (x64) Exit code: 1 Version: 4.0.1.7 Modules
| |||||||||||||||
| 3560 | "C:\Users\admin\Desktop\qw3xv0pn.04m.exe" /SPAWNWND=$40170 /NOTIFYWND=$4017A | C:\Users\admin\Desktop\qw3xv0pn.04m.exe | qw3xv0pn.04m.tmp | ||||||||||||
User: admin Company: KirySoft Integrity Level: HIGH Description: WSCC4 (x64) Exit code: 1 Version: 4.0.1.7 Modules
| |||||||||||||||
| (PID) Process: | (2356) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (2356) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (2356) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2356) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E |
| Operation: | write | Name: | @C:\Windows\system32\NetworkExplorer.dll,-1 |
Value: Network | |||
| (PID) Process: | (2356) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\osiri_458241338 (1).zip | |||
| (PID) Process: | (2356) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2356) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2356) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2356) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (1936) qw3xv0pn.04m.tmp | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2356 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2356.31776\qw3xv0pn.04m.exe | — | |
MD5:— | SHA256:— | |||
| 3560 | qw3xv0pn.04m.exe | C:\Users\admin\AppData\Local\Temp\is-9EM74.tmp\qw3xv0pn.04m.tmp | executable | |
MD5:84DB4B4205F705DA71471DC6ECC061F5 | SHA256:647983EBDE53E0501FF1AF8EF6190DFEEA5CCC64CAF7DCE808F1E3D98FB66A3C | |||
| 2508 | qw3xv0pn.04m.exe | C:\Users\admin\AppData\Local\Temp\is-7EDMK.tmp\qw3xv0pn.04m.tmp | executable | |
MD5:84DB4B4205F705DA71471DC6ECC061F5 | SHA256:647983EBDE53E0501FF1AF8EF6190DFEEA5CCC64CAF7DCE808F1E3D98FB66A3C | |||
| 2816 | qw3xv0pn.04m.exe | C:\Users\admin\AppData\Local\Temp\is-I33P9.tmp\qw3xv0pn.04m.tmp | executable | |
MD5:84DB4B4205F705DA71471DC6ECC061F5 | SHA256:647983EBDE53E0501FF1AF8EF6190DFEEA5CCC64CAF7DCE808F1E3D98FB66A3C | |||
| 336 | qw3xv0pn.04m.exe | C:\Users\admin\AppData\Local\Temp\is-M3KQ9.tmp\qw3xv0pn.04m.tmp | executable | |
MD5:84DB4B4205F705DA71471DC6ECC061F5 | SHA256:647983EBDE53E0501FF1AF8EF6190DFEEA5CCC64CAF7DCE808F1E3D98FB66A3C | |||