File name:

#!SetUp_55820--!PassW0rdz#$.zip

Full analysis: https://app.any.run/tasks/f054bb0b-fcdf-4af1-8ca1-4c2414eb99ad
Verdict: Malicious activity
Analysis date: June 22, 2024, 02:59:07
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract, compression method=store
MD5:

97C5984FC16F3BD692A38377D3131C51

SHA1:

EDE461B5E8BC9F18AD8DC317264C67B7AC73C06B

SHA256:

1AF402DEC30401659D806FAD02364C3DF0F248E7279C2AC39734BA10D815C432

SSDEEP:

196608:Oa0fr7C7rFwmwPBn81rl1G8qaWyOZtEV+kLsnuKQY35Yhyr5:Oa0fr7yrimeBeL/OD4guKQsKyr5

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Setup.exe (PID: 3976)
      • Setup.exe (PID: 524)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 2428)
    • Starts a Microsoft application from unusual location

      • VSLauncher_[0MB]_[1].exe (PID: 3840)
      • VSLauncher_[0MB]_[1].exe (PID: 1524)
    • Executable content was dropped or overwritten

      • Setup.exe (PID: 524)
      • Setup.exe (PID: 3976)
  • INFO

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 2428)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2428)
    • Manual execution by a user

      • WinRAR.exe (PID: 2428)
      • WinRAR.exe (PID: 3212)
      • Setup.exe (PID: 524)
      • VSLauncher_[0MB]_[1].exe (PID: 3840)
      • NvStereoUtilityOGL_[1MB]_[1].exe (PID: 1800)
      • VSLauncher_[0MB]_[1].exe (PID: 1524)
      • HDHelper_[0MB]_[1].exe (PID: 2620)
      • HDHelper_[0MB]_[1].exe (PID: 4004)
      • notepad.exe (PID: 900)
      • Setup.exe (PID: 3976)
    • Checks supported languages

      • Setup.tmp (PID: 312)
      • Setup.tmp (PID: 1596)
      • Setup.exe (PID: 524)
      • VSLauncher_[0MB]_[1].exe (PID: 3840)
      • NvStereoUtilityOGL_[1MB]_[1].exe (PID: 1800)
      • HDHelper_[0MB]_[1].exe (PID: 2620)
      • VSLauncher_[0MB]_[1].exe (PID: 1524)
      • HDHelper_[0MB]_[1].exe (PID: 4004)
      • Setup.exe (PID: 3976)
    • Reads the computer name

      • Setup.tmp (PID: 1596)
      • Setup.tmp (PID: 312)
    • Create files in a temporary directory

      • Setup.exe (PID: 524)
      • HDHelper_[0MB]_[1].exe (PID: 2620)
      • Setup.exe (PID: 3976)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2024:06:22 01:57:14
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: 0pen___files/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
59
Monitored processes
14
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs winrar.exe no specs winrar.exe setup.exe setup.tmp no specs setup.exe setup.tmp no specs vslauncher_[0mb]_[1].exe no specs nvstereoutilityogl_[1mb]_[1].exe vslauncher_[0mb]_[1].exe no specs hdhelper_[0mb]_[1].exe no specs hdhelper_[0mb]_[1].exe no specs notepad.exe no specs wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
312"C:\Users\admin\AppData\Local\Temp\is-FA6SK.tmp\Setup.tmp" /SL5="$601CA,31167586,791040,C:\Users\admin\Desktop\#!SetUp_55820--!PassW0rdz#$\0pen___files\!ŞetUp_55820--#PaSꞨKḙy#$\Setup.exe" C:\Users\admin\AppData\Local\Temp\is-FA6SK.tmp\Setup.tmpSetup.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
1
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-fa6sk.tmp\setup.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
524"C:\Users\admin\Desktop\#!SetUp_55820--!PassW0rdz#$\0pen___files\!ŞetUp_55820--#PaSꞨKḙy#$\Setup.exe" C:\Users\admin\Desktop\#!SetUp_55820--!PassW0rdz#$\0pen___files\!ŞetUp_55820--#PaSꞨKḙy#$\Setup.exe
explorer.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Tgt_Cli_debug Setup
Exit code:
1
Version:
4.2131.88.1
Modules
Images
c:\users\admin\desktop\#!setup_55820--!passw0rdz#$\0pen___files\!şetup_55820--#pasꞩkḙy#$\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
900"C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\#!SetUp_55820--!PassW0rdz#$\0pen___files\!ŞetUp_55820--#PaSꞨKḙy#$\updater\manager\ks_tyres.iniC:\Windows\System32\notepad.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1524"C:\Users\admin\Desktop\#!SetUp_55820--!PassW0rdz#$\0pen___files\!ŞetUp_55820--#PaSꞨKḙy#$\x86\VSLauncher_[0MB]_[1].exe" C:\Users\admin\Desktop\#!SetUp_55820--!PassW0rdz#$\0pen___files\!ŞetUp_55820--#PaSꞨKḙy#$\x86\VSLauncher_[0MB]_[1].exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Visual Studio Version Selector
Exit code:
4294967295
Version:
17.0.34205.65 built by: CBA-1005_101930_1
Modules
Images
c:\users\admin\desktop\#!setup_55820--!passw0rdz#$\0pen___files\!şetup_55820--#pasꞩkḙy#$\x86\vslauncher_[0mb]_[1].exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1596"C:\Users\admin\AppData\Local\Temp\is-ML9VC.tmp\Setup.tmp" /SL5="$50206,31167586,791040,C:\Users\admin\Desktop\#!SetUp_55820--!PassW0rdz#$\0pen___files\!ŞetUp_55820--#PaSꞨKḙy#$\Setup.exe" C:\Users\admin\AppData\Local\Temp\is-ML9VC.tmp\Setup.tmpSetup.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
1
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-ml9vc.tmp\setup.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1800"C:\Users\admin\Desktop\#!SetUp_55820--!PassW0rdz#$\0pen___files\!ŞetUp_55820--#PaSꞨKḙy#$\x86\NvStereoUtilityOGL_[1MB]_[1].exe" C:\Users\admin\Desktop\#!SetUp_55820--!PassW0rdz#$\0pen___files\!ŞetUp_55820--#PaSꞨKḙy#$\x86\NvStereoUtilityOGL_[1MB]_[1].exe
explorer.exe
User:
admin
Company:
NVIDIA Corporation
Integrity Level:
MEDIUM
Description:
OpenGL Stereo Sample
Exit code:
3221225477
Version:
1, 2, 2, 0
Modules
Images
c:\users\admin\desktop\#!setup_55820--!passw0rdz#$\0pen___files\!şetup_55820--#pasꞩkḙy#$\x86\nvstereoutilityogl_[1mb]_[1].exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\opengl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
2428"C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Desktop\#!SetUp_55820--!PassW0rdz#$\0pen___files\!ŞetUp_55820--#PaSꞨKḙy#$.rar" C:\Users\admin\Desktop\#!SetUp_55820--!PassW0rdz#$\0pen___files\!ŞetUp_55820--#PaSꞨKḙy#$\C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2620"C:\Users\admin\Desktop\#!SetUp_55820--!PassW0rdz#$\0pen___files\!ŞetUp_55820--#PaSꞨKḙy#$\x86\HDHelper_[0MB]_[1].exe" C:\Users\admin\Desktop\#!SetUp_55820--!PassW0rdz#$\0pen___files\!ŞetUp_55820--#PaSꞨKḙy#$\x86\HDHelper_[0MB]_[1].exeexplorer.exe
User:
admin
Company:
Adobe Inc.
Integrity Level:
MEDIUM
Description:
HD Helper
Exit code:
4294967295
Version:
5.9.0.372
Modules
Images
c:\users\admin\desktop\#!setup_55820--!passw0rdz#$\0pen___files\!şetup_55820--#pasꞩkḙy#$\x86\hdhelper_[0mb]_[1].exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3212"C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Desktop\#!SetUp_55820--!PassW0rdz#$.zip" C:\Users\admin\Desktop\#!SetUp_55820--!PassW0rdz#$\C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3396"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\Desktop\#!SetUp_55820--!PassW0rdz#$.zipC:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
1
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
3 708
Read events
3 684
Write events
24
Delete events
0

Modification events

(PID) Process:(3396) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3396) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3396) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3396) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\General
Operation:writeName:LastFolder
Value:
C:\Users\admin\Desktop
(PID) Process:(3396) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3396) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3396) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3396) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3396) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\General\Toolbar\Layout
Operation:writeName:Band56_0
Value:
38000000730100000402000000000000D4D0C800000000000000000000000000420106000000000039000000B40200000000000001000000
(PID) Process:(3396) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\General\Toolbar\Layout
Operation:writeName:Band56_1
Value:
38000000730100000500000000000000D4D0C8000000000000000000000000005401050000000000160000002A0000000000000002000000
Executable files
27
Suspicious files
0
Text files
3
Unknown types
0

Dropped files

PID
Process
Filename
Type
3212WinRAR.exeC:\Users\admin\Desktop\#!SetUp_55820--!PassW0rdz#$\0pen___files\!ŞetUp_55820--#PaSꞨKḙy#$.rar
MD5:
SHA256:
2428WinRAR.exeC:\Users\admin\Desktop\#!SetUp_55820--!PassW0rdz#$\0pen___files\!ŞetUp_55820--#PaSꞨKḙy#$\updater\manager\ks_tyres.initext
MD5:47F6571C7884DA6C743551AC724186D4
SHA256:894D3C57598ECB22C769CC3EA8219859A95E22740E72394A474012EA2119B3D9
2428WinRAR.exeC:\Users\admin\Desktop\#!SetUp_55820--!PassW0rdz#$\0pen___files\!ŞetUp_55820--#PaSꞨKḙy#$\Setup.exeexecutable
MD5:DE75DD40E78D454DB2166B7D9A11EAB5
SHA256:B0FCFA67D92B6213B7E1BF6A14673ED46456F48D2BDA6E308363FB54808F4C60
2428WinRAR.exeC:\Users\admin\Desktop\#!SetUp_55820--!PassW0rdz#$\0pen___files\!ŞetUp_55820--#PaSꞨKḙy#$\x86\VSLauncher_[0MB]_[1].exeexecutable
MD5:7A7BB3B0E57E4FB32C57B74E78E657AD
SHA256:87048CFF2227D2901314760618D23917CFBC5CC15FC22DC355E803C5EE5FB211
2428WinRAR.exeC:\Users\admin\Desktop\#!SetUp_55820--!PassW0rdz#$\0pen___files\!ŞetUp_55820--#PaSꞨKḙy#$\x86\api-ms-win-core-processthreads-l1-1-1.dllexecutable
MD5:29001F316CCFC800E2246743DF9B15B3
SHA256:E5EA2C21FB225090F7D0DB6C6990D67B1558D8E834E86513BC8BA7A43C4E7B36
2428WinRAR.exeC:\Users\admin\Desktop\#!SetUp_55820--!PassW0rdz#$\0pen___files\!ŞetUp_55820--#PaSꞨKḙy#$\x86\api-ms-win-core-sysinfo-l1-1-0.dllexecutable
MD5:CEF4B9F680FAAE322170B961A3421C5B
SHA256:1FE918979F1653D63BB713D4716910D192CD09F50017A6ECB4CE026ED6285DF9
2428WinRAR.exeC:\Users\admin\Desktop\#!SetUp_55820--!PassW0rdz#$\0pen___files\!ŞetUp_55820--#PaSꞨKḙy#$\x86\api-ms-win-core-synch-l1-2-0.dllexecutable
MD5:659E4FEBC208545A2E23C0C8B881A30D
SHA256:9AC63682E03D55A5D18405D336634AF080DD0003B565D12A39D6D71AAA989F48
2428WinRAR.exeC:\Users\admin\Desktop\#!SetUp_55820--!PassW0rdz#$\0pen___files\!ŞetUp_55820--#PaSꞨKḙy#$\x86\api-ms-win-core-profile-l1-1-0.dllexecutable
MD5:6EE66DCA31C5CCE57740D677C85B4CE7
SHA256:D00A0EDACE14715BF79DBD17B715D8A74A2300F0ADB1F3FC137EDFB7074C9B0A
2428WinRAR.exeC:\Users\admin\Desktop\#!SetUp_55820--!PassW0rdz#$\0pen___files\!ŞetUp_55820--#PaSꞨKḙy#$\x86\api-ms-win-core-rtlsupport-l1-1-0.dllexecutable
MD5:0069FD29263C0DD90314C48BBCE852EF
SHA256:D11093FDC1D5C9213B9B2886CE91DB3DED17EF8DAE1615A8C7FFBC55B8E3F79B
2428WinRAR.exeC:\Users\admin\Desktop\#!SetUp_55820--!PassW0rdz#$\0pen___files\!ŞetUp_55820--#PaSꞨKḙy#$\x86\api-ms-win-core-synch-l1-1-0.dllexecutable
MD5:979C67BA244E5328A1A2E588FF748E86
SHA256:8BB38A7A59FBAA792B3D5F34F94580429588C8C592929CBD307AFD5579762ABC
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
12
DNS requests
6
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1372
svchost.exe
GET
304
199.232.214.172:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?33775f6043c93e33
unknown
unknown
1372
svchost.exe
GET
200
92.122.89.124:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
unknown
1372
svchost.exe
GET
200
23.211.242.170:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
unknown
1060
svchost.exe
GET
304
199.232.210.172:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?fbe613066ac7852b
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1372
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
224.0.0.252:5355
unknown
2564
svchost.exe
239.255.255.250:3702
whitelisted
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1060
svchost.exe
224.0.0.252:5355
unknown
1372
svchost.exe
199.232.214.172:80
ctldl.windowsupdate.com
FASTLY
US
unknown
1372
svchost.exe
23.211.242.170:80
crl.microsoft.com
Akamai International B.V.
US
unknown
1372
svchost.exe
92.122.89.124:80
www.microsoft.com
Akamai International B.V.
NL
unknown
1060
svchost.exe
199.232.210.172:80
ctldl.windowsupdate.com
FASTLY
US
unknown

DNS requests

Domain
IP
Reputation
dns.msftncsi.com
  • 131.107.255.255
shared
settings-win.data.microsoft.com
  • 20.73.194.208
whitelisted
ctldl.windowsupdate.com
  • 199.232.214.172
  • 199.232.210.172
whitelisted
crl.microsoft.com
  • 23.211.242.170
  • 23.211.242.138
whitelisted
www.microsoft.com
  • 92.122.89.124
whitelisted

Threats

No threats detected
No debug info