File name:

#!SetUp_55820--!PassW0rdz#$.zip

Full analysis: https://app.any.run/tasks/f054bb0b-fcdf-4af1-8ca1-4c2414eb99ad
Verdict: Malicious activity
Analysis date: June 22, 2024, 02:59:07
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract, compression method=store
MD5:

97C5984FC16F3BD692A38377D3131C51

SHA1:

EDE461B5E8BC9F18AD8DC317264C67B7AC73C06B

SHA256:

1AF402DEC30401659D806FAD02364C3DF0F248E7279C2AC39734BA10D815C432

SSDEEP:

196608:Oa0fr7C7rFwmwPBn81rl1G8qaWyOZtEV+kLsnuKQY35Yhyr5:Oa0fr7yrimeBeL/OD4guKQsKyr5

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Setup.exe (PID: 3976)
      • Setup.exe (PID: 524)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 2428)
    • Executable content was dropped or overwritten

      • Setup.exe (PID: 3976)
      • Setup.exe (PID: 524)
    • Starts a Microsoft application from unusual location

      • VSLauncher_[0MB]_[1].exe (PID: 3840)
      • VSLauncher_[0MB]_[1].exe (PID: 1524)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2428)
    • Manual execution by a user

      • WinRAR.exe (PID: 3212)
      • Setup.exe (PID: 3976)
      • WinRAR.exe (PID: 2428)
      • Setup.exe (PID: 524)
      • VSLauncher_[0MB]_[1].exe (PID: 3840)
      • NvStereoUtilityOGL_[1MB]_[1].exe (PID: 1800)
      • VSLauncher_[0MB]_[1].exe (PID: 1524)
      • HDHelper_[0MB]_[1].exe (PID: 2620)
      • HDHelper_[0MB]_[1].exe (PID: 4004)
      • notepad.exe (PID: 900)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 2428)
    • Checks supported languages

      • Setup.exe (PID: 3976)
      • Setup.tmp (PID: 1596)
      • Setup.exe (PID: 524)
      • Setup.tmp (PID: 312)
      • NvStereoUtilityOGL_[1MB]_[1].exe (PID: 1800)
      • VSLauncher_[0MB]_[1].exe (PID: 1524)
      • HDHelper_[0MB]_[1].exe (PID: 2620)
      • HDHelper_[0MB]_[1].exe (PID: 4004)
      • VSLauncher_[0MB]_[1].exe (PID: 3840)
    • Create files in a temporary directory

      • Setup.exe (PID: 3976)
      • Setup.exe (PID: 524)
      • HDHelper_[0MB]_[1].exe (PID: 2620)
    • Reads the computer name

      • Setup.tmp (PID: 1596)
      • Setup.tmp (PID: 312)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2024:06:22 01:57:14
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: 0pen___files/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
59
Monitored processes
14
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs winrar.exe no specs winrar.exe setup.exe setup.tmp no specs setup.exe setup.tmp no specs vslauncher_[0mb]_[1].exe no specs nvstereoutilityogl_[1mb]_[1].exe vslauncher_[0mb]_[1].exe no specs hdhelper_[0mb]_[1].exe no specs hdhelper_[0mb]_[1].exe no specs notepad.exe no specs wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
312"C:\Users\admin\AppData\Local\Temp\is-FA6SK.tmp\Setup.tmp" /SL5="$601CA,31167586,791040,C:\Users\admin\Desktop\#!SetUp_55820--!PassW0rdz#$\0pen___files\!ŞetUp_55820--#PaSꞨKḙy#$\Setup.exe" C:\Users\admin\AppData\Local\Temp\is-FA6SK.tmp\Setup.tmpSetup.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
1
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-fa6sk.tmp\setup.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
524"C:\Users\admin\Desktop\#!SetUp_55820--!PassW0rdz#$\0pen___files\!ŞetUp_55820--#PaSꞨKḙy#$\Setup.exe" C:\Users\admin\Desktop\#!SetUp_55820--!PassW0rdz#$\0pen___files\!ŞetUp_55820--#PaSꞨKḙy#$\Setup.exe
explorer.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Tgt_Cli_debug Setup
Exit code:
1
Version:
4.2131.88.1
Modules
Images
c:\users\admin\desktop\#!setup_55820--!passw0rdz#$\0pen___files\!şetup_55820--#pasꞩkḙy#$\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
900"C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\#!SetUp_55820--!PassW0rdz#$\0pen___files\!ŞetUp_55820--#PaSꞨKḙy#$\updater\manager\ks_tyres.iniC:\Windows\System32\notepad.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1524"C:\Users\admin\Desktop\#!SetUp_55820--!PassW0rdz#$\0pen___files\!ŞetUp_55820--#PaSꞨKḙy#$\x86\VSLauncher_[0MB]_[1].exe" C:\Users\admin\Desktop\#!SetUp_55820--!PassW0rdz#$\0pen___files\!ŞetUp_55820--#PaSꞨKḙy#$\x86\VSLauncher_[0MB]_[1].exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Visual Studio Version Selector
Exit code:
4294967295
Version:
17.0.34205.65 built by: CBA-1005_101930_1
Modules
Images
c:\users\admin\desktop\#!setup_55820--!passw0rdz#$\0pen___files\!şetup_55820--#pasꞩkḙy#$\x86\vslauncher_[0mb]_[1].exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1596"C:\Users\admin\AppData\Local\Temp\is-ML9VC.tmp\Setup.tmp" /SL5="$50206,31167586,791040,C:\Users\admin\Desktop\#!SetUp_55820--!PassW0rdz#$\0pen___files\!ŞetUp_55820--#PaSꞨKḙy#$\Setup.exe" C:\Users\admin\AppData\Local\Temp\is-ML9VC.tmp\Setup.tmpSetup.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
1
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-ml9vc.tmp\setup.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1800"C:\Users\admin\Desktop\#!SetUp_55820--!PassW0rdz#$\0pen___files\!ŞetUp_55820--#PaSꞨKḙy#$\x86\NvStereoUtilityOGL_[1MB]_[1].exe" C:\Users\admin\Desktop\#!SetUp_55820--!PassW0rdz#$\0pen___files\!ŞetUp_55820--#PaSꞨKḙy#$\x86\NvStereoUtilityOGL_[1MB]_[1].exe
explorer.exe
User:
admin
Company:
NVIDIA Corporation
Integrity Level:
MEDIUM
Description:
OpenGL Stereo Sample
Exit code:
3221225477
Version:
1, 2, 2, 0
Modules
Images
c:\users\admin\desktop\#!setup_55820--!passw0rdz#$\0pen___files\!şetup_55820--#pasꞩkḙy#$\x86\nvstereoutilityogl_[1mb]_[1].exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\opengl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
2428"C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Desktop\#!SetUp_55820--!PassW0rdz#$\0pen___files\!ŞetUp_55820--#PaSꞨKḙy#$.rar" C:\Users\admin\Desktop\#!SetUp_55820--!PassW0rdz#$\0pen___files\!ŞetUp_55820--#PaSꞨKḙy#$\C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2620"C:\Users\admin\Desktop\#!SetUp_55820--!PassW0rdz#$\0pen___files\!ŞetUp_55820--#PaSꞨKḙy#$\x86\HDHelper_[0MB]_[1].exe" C:\Users\admin\Desktop\#!SetUp_55820--!PassW0rdz#$\0pen___files\!ŞetUp_55820--#PaSꞨKḙy#$\x86\HDHelper_[0MB]_[1].exeexplorer.exe
User:
admin
Company:
Adobe Inc.
Integrity Level:
MEDIUM
Description:
HD Helper
Exit code:
4294967295
Version:
5.9.0.372
Modules
Images
c:\users\admin\desktop\#!setup_55820--!passw0rdz#$\0pen___files\!şetup_55820--#pasꞩkḙy#$\x86\hdhelper_[0mb]_[1].exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3212"C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Desktop\#!SetUp_55820--!PassW0rdz#$.zip" C:\Users\admin\Desktop\#!SetUp_55820--!PassW0rdz#$\C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3396"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\Desktop\#!SetUp_55820--!PassW0rdz#$.zipC:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
1
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
3 708
Read events
3 684
Write events
24
Delete events
0

Modification events

(PID) Process:(3396) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3396) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3396) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3396) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\General
Operation:writeName:LastFolder
Value:
C:\Users\admin\Desktop
(PID) Process:(3396) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3396) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3396) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3396) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3396) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\General\Toolbar\Layout
Operation:writeName:Band56_0
Value:
38000000730100000402000000000000D4D0C800000000000000000000000000420106000000000039000000B40200000000000001000000
(PID) Process:(3396) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\General\Toolbar\Layout
Operation:writeName:Band56_1
Value:
38000000730100000500000000000000D4D0C8000000000000000000000000005401050000000000160000002A0000000000000002000000
Executable files
27
Suspicious files
0
Text files
3
Unknown types
0

Dropped files

PID
Process
Filename
Type
3212WinRAR.exeC:\Users\admin\Desktop\#!SetUp_55820--!PassW0rdz#$\0pen___files\!ŞetUp_55820--#PaSꞨKḙy#$.rar
MD5:
SHA256:
2428WinRAR.exeC:\Users\admin\Desktop\#!SetUp_55820--!PassW0rdz#$\0pen___files\!ŞetUp_55820--#PaSꞨKḙy#$\x86\NvStereoUtilityOGL_[1MB]_[1].exeexecutable
MD5:017CD77D01314E72A973FF0C7882453D
SHA256:C2C71318A17F7F767E5D203D22B48F27EECAE46A4F37082D7B413C51DA6183B3
2428WinRAR.exeC:\Users\admin\Desktop\#!SetUp_55820--!PassW0rdz#$\0pen___files\!ŞetUp_55820--#PaSꞨKḙy#$\updater\manager\ks_tyres.initext
MD5:47F6571C7884DA6C743551AC724186D4
SHA256:894D3C57598ECB22C769CC3EA8219859A95E22740E72394A474012EA2119B3D9
2428WinRAR.exeC:\Users\admin\Desktop\#!SetUp_55820--!PassW0rdz#$\0pen___files\!ŞetUp_55820--#PaSꞨKḙy#$\x86\updater.initext
MD5:6499B6EC03C720C897B9BBE4CADA2647
SHA256:EDD1A68585EBAC3872B7AB0A085B0A5C92F58F7DC59B926B6C647CC172F69AC4
2428WinRAR.exeC:\Users\admin\Desktop\#!SetUp_55820--!PassW0rdz#$\0pen___files\!ŞetUp_55820--#PaSꞨKḙy#$\x86\api-ms-win-core-rtlsupport-l1-1-0.dllexecutable
MD5:0069FD29263C0DD90314C48BBCE852EF
SHA256:D11093FDC1D5C9213B9B2886CE91DB3DED17EF8DAE1615A8C7FFBC55B8E3F79B
2428WinRAR.exeC:\Users\admin\Desktop\#!SetUp_55820--!PassW0rdz#$\0pen___files\!ŞetUp_55820--#PaSꞨKḙy#$\x86\api-ms-win-core-profile-l1-1-0.dllexecutable
MD5:6EE66DCA31C5CCE57740D677C85B4CE7
SHA256:D00A0EDACE14715BF79DBD17B715D8A74A2300F0ADB1F3FC137EDFB7074C9B0A
2428WinRAR.exeC:\Users\admin\Desktop\#!SetUp_55820--!PassW0rdz#$\0pen___files\!ŞetUp_55820--#PaSꞨKḙy#$\x86\VSLauncher_[0MB]_[1].exeexecutable
MD5:7A7BB3B0E57E4FB32C57B74E78E657AD
SHA256:87048CFF2227D2901314760618D23917CFBC5CC15FC22DC355E803C5EE5FB211
2428WinRAR.exeC:\Users\admin\Desktop\#!SetUp_55820--!PassW0rdz#$\0pen___files\!ŞetUp_55820--#PaSꞨKḙy#$\x86\api-ms-win-core-string-l1-1-0.dllexecutable
MD5:2E5C29FC652F432B89A1AFE187736C4D
SHA256:3807DB7ACF1B40C797E4D4C14A12C3806346AE56B25E205E600BE3E635C18D4F
2428WinRAR.exeC:\Users\admin\Desktop\#!SetUp_55820--!PassW0rdz#$\0pen___files\!ŞetUp_55820--#PaSꞨKḙy#$\x86\api-ms-win-core-processthreads-l1-1-1.dllexecutable
MD5:29001F316CCFC800E2246743DF9B15B3
SHA256:E5EA2C21FB225090F7D0DB6C6990D67B1558D8E834E86513BC8BA7A43C4E7B36
2428WinRAR.exeC:\Users\admin\Desktop\#!SetUp_55820--!PassW0rdz#$\0pen___files\!ŞetUp_55820--#PaSꞨKḙy#$\x86\api-ms-win-core-synch-l1-2-0.dllexecutable
MD5:659E4FEBC208545A2E23C0C8B881A30D
SHA256:9AC63682E03D55A5D18405D336634AF080DD0003B565D12A39D6D71AAA989F48
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
12
DNS requests
6
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1372
svchost.exe
GET
304
199.232.214.172:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?33775f6043c93e33
unknown
unknown
1372
svchost.exe
GET
200
23.211.242.170:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
unknown
1372
svchost.exe
GET
200
92.122.89.124:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
unknown
1060
svchost.exe
GET
304
199.232.210.172:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?fbe613066ac7852b
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1372
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
224.0.0.252:5355
unknown
2564
svchost.exe
239.255.255.250:3702
whitelisted
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1060
svchost.exe
224.0.0.252:5355
unknown
1372
svchost.exe
199.232.214.172:80
ctldl.windowsupdate.com
FASTLY
US
unknown
1372
svchost.exe
23.211.242.170:80
crl.microsoft.com
Akamai International B.V.
US
unknown
1372
svchost.exe
92.122.89.124:80
www.microsoft.com
Akamai International B.V.
NL
unknown
1060
svchost.exe
199.232.210.172:80
ctldl.windowsupdate.com
FASTLY
US
unknown

DNS requests

Domain
IP
Reputation
dns.msftncsi.com
  • 131.107.255.255
shared
settings-win.data.microsoft.com
  • 20.73.194.208
whitelisted
ctldl.windowsupdate.com
  • 199.232.214.172
  • 199.232.210.172
whitelisted
crl.microsoft.com
  • 23.211.242.170
  • 23.211.242.138
whitelisted
www.microsoft.com
  • 92.122.89.124
whitelisted

Threats

No threats detected
No debug info