| File name: | MDE_File_Sample_5f4485615c870b5ec03f0aa7591a04f330b3a2f6.zip |
| Full analysis: | https://app.any.run/tasks/722c86c9-2283-46ab-94e6-94c9b6a50e07 |
| Verdict: | Malicious activity |
| Analysis date: | September 15, 2022, 10:47:17 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | 67FF509F87F2BBBBDC5F4DB39FEC2293 |
| SHA1: | 84D3C61B0855989032C275D5022CAB8481380341 |
| SHA256: | 1BF7E23F0FA7A0BCD4F5A66DB9B20AB6323F485A61DD53C9FA9A874CEBD38CFF |
| SSDEEP: | 196608:4nozAcEWwr7nmdKYC05ZVtDyHpwP8thBpNerbhqkwmRZ8:PzAcEWSGC6KLfBuxqknH8 |
| .zip | | | ZIP compressed archive (100) |
|---|
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 712 | C:\Windows\system32\DllHost.exe /Processid:{2DB4F9B7-144E-4319-B14A-432AC74C0CEF} | C:\Windows\system32\DllHost.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: COM Surrogate Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 848 | "C:\Program Files\GRETECH\GomPlayer\GOM.exe" /regassoc | C:\Program Files\GRETECH\GomPlayer\GOM.exe | — | GOMPLAYERENSETUP.EXE | |||||||||||
User: admin Company: Gretech Corp. Integrity Level: HIGH Description: GOM Player Exit code: 0 Version: 2, 1, 33, 5071 Modules
| |||||||||||||||
| 948 | C:\Users\admin\AppData\Local\Temp\AskInstallChecker.exe GOM2 | C:\Users\admin\AppData\Local\Temp\AskInstallChecker.exe | GOMPLAYERENSETUP.EXE | ||||||||||||
User: admin Company: Ask.com Integrity Level: HIGH Description: Install Checker Exit code: 0 Version: 1.5.0.0 Modules
| |||||||||||||||
| 1324 | "C:\Program Files\GRETECH\GomPlayer\GOM.exe" | C:\Program Files\GRETECH\GomPlayer\GOM.exe | GomWiz.exe | ||||||||||||
User: admin Company: Gretech Corp. Integrity Level: MEDIUM Description: GOM Player Exit code: 0 Version: 2, 1, 33, 5071 Modules
| |||||||||||||||
| 1684 | "C:\Program Files\GRETECH\GomPlayer\ShellRegister.exe" | C:\Program Files\GRETECH\GomPlayer\ShellRegister.exe | — | GOMPLAYERENSETUP.EXE | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 1712 | C:\Windows\system32\svchost.exe -k RPCSS | C:\Windows\system32\svchost.exe | — | services.exe | |||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2060 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\MDE_File_Sample_5f4485615c870b5ec03f0aa7591a04f330b3a2f6.zip" | C:\Program Files\WinRAR\WinRAR.exe | Explorer.EXE | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 2696 | "C:\Program Files\GRETECH\GomPlayer\GrLauncher.exe"" <GRLAUNCHER_PARAM Command='checkversion' AgentName='GomPlayer 2, 1, 33, 5071 (ENG)' ProgramID='GOMPLAYER2' ForceCheck='0' CheckMinorVersion='1' RetWindowHandle='524688' LocalVersionFilePath='C:\Users\admin\AppData\Roaming\GRETECH\GomPlayer\GrVersion.ini' />" | C:\Program Files\GRETECH\GomPlayer\GrLauncher.exe | GOM.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 41 Modules
| |||||||||||||||
| 2732 | "C:\Program Files\GRETECH\GomPlayer\KillGom.exe" GOM.EXE | C:\Program Files\GRETECH\GomPlayer\KillGom.exe | — | GOMPLAYERENSETUP.EXE | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2888 | "C:\Program Files\GRETECH\GomPlayer\GOM.exe" | C:\Program Files\GRETECH\GomPlayer\GOM.exe | — | Explorer.EXE | |||||||||||
User: admin Company: Gretech Corp. Integrity Level: MEDIUM Description: GOM Player Exit code: 0 Version: 2, 1, 33, 5071 Modules
| |||||||||||||||
| (PID) Process: | (2060) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (2060) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (2060) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2060) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (2060) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (2060) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\MDE_File_Sample_5f4485615c870b5ec03f0aa7591a04f330b3a2f6.zip | |||
| (PID) Process: | (2060) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2060) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2060) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2060) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2060 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb2060.1329\GOMPLAYERENSETUP.EXE | executable | |
MD5:— | SHA256:— | |||
| 3824 | GOMPLAYERENSETUP.EXE | C:\Users\admin\AppData\Local\Temp\NSISPromotionEx.dll | executable | |
MD5:— | SHA256:— | |||
| 3824 | GOMPLAYERENSETUP.EXE | C:\Program Files\GRETECH\GomPlayer\GOM.exe | executable | |
MD5:— | SHA256:— | |||
| 3824 | GOMPLAYERENSETUP.EXE | C:\Users\admin\AppData\Local\Temp\nstF169.tmp\System.dll | executable | |
MD5:C17103AE9072A06DA581DEC998343FC1 | SHA256:DC58D8AD81CACB0C1ED72E33BFF8F23EA40B5252B5BB55D393A0903E6819AE2F | |||
| 3824 | GOMPLAYERENSETUP.EXE | C:\Users\admin\AppData\Local\Temp\NSISPromotionEx.ini | text | |
MD5:FF5F0C84C510C5D69F7FA5774C8BAC7E | SHA256:56DDBB25A7FEAE8DA47A3DADE69A8F513E99AC5E1AB010DC1DEB94105745F0A8 | |||
| 3824 | GOMPLAYERENSETUP.EXE | C:\Users\admin\AppData\Local\Temp\spltmp.bmp | image | |
MD5:D4C147D4EEBA482BA53F9A6FF6101E31 | SHA256:1C33A2C72449468A285E183ED9E71C81D439FD7F6CE67DA51F50CA8D1631D665 | |||
| 3824 | GOMPLAYERENSETUP.EXE | C:\Users\admin\AppData\Local\Temp\nstF169.tmp\InstallOptions.dll | executable | |
MD5:325B008AEC81E5AAA57096F05D4212B5 | SHA256:C9CD5C9609E70005926AE5171726A4142FFBCCCC771D307EFCD195DAFC1E6B4B | |||
| 3824 | GOMPLAYERENSETUP.EXE | C:\Program Files\GRETECH\GomPlayer\GomX.dll | executable | |
MD5:C892F82FDA41C02904242E6B2CA991BE | SHA256:1A57659DE2DD38DA23DB4AD39AEA25EEA32980F5EA910E077F8B4D7199EB295A | |||
| 3824 | GOMPLAYERENSETUP.EXE | C:\Users\admin\AppData\Local\Temp\nstF169.tmp\SkinKidslock.ini | ini | |
MD5:BDEE298E2F72ABB6C2E6D4AC4E3A436E | SHA256:7226614E56D843B447EEA362FDF14787A7B02778546517214E27F7610DCB64EA | |||
| 3824 | GOMPLAYERENSETUP.EXE | C:\Users\admin\AppData\Local\Temp\nstF169.tmp\AdvSplash.dll | executable | |
MD5:C098AF110A7935DE4100BFAFA3065635 | SHA256:B475C7C4CA8293E785D845C9D4886DC5B6D6EC994E01FC781EFE2FAE180DEA7B | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
948 | AskInstallChecker.exe | GET | — | 34.102.132.13:80 | http://websearch.ask.com/preinstall?client=ic&tb=GOM2&r=0&ipid=&npid=GOM2&iev=9&ielu=0&fflu=0&iv=&nv=1.8.0.0&clientv=1.5.0.0&rep=0 | US | — | — | suspicious |
3824 | GOMPLAYERENSETUP.EXE | GET | 200 | 54.84.188.188:80 | http://app.gomlab.com/eng/gom/PromotionCheck.php | US | text | 495 b | unknown |
3824 | GOMPLAYERENSETUP.EXE | GET | 302 | 18.66.127.70:80 | http://www.gomlab.com/ | US | html | 206 b | malicious |
3824 | GOMPLAYERENSETUP.EXE | GET | 302 | 18.66.127.70:80 | http://www.gomlab.com/ipCheck/ipCheck.php | US | html | 206 b | malicious |
3824 | GOMPLAYERENSETUP.EXE | GET | 200 | 54.84.188.188:80 | http://app.gomlab.com/eng/gomaudio/promo/audio.jpg | US | image | 119 Kb | unknown |
2972 | GrLauncherTempSetup.exe | GET | 200 | 18.66.248.88:80 | http://playinfo.gomlab.com/cms/bundle/index.gom?version=1&mode=upgrade | US | html | 4.85 Kb | whitelisted |
948 | AskInstallChecker.exe | GET | 200 | 34.117.224.112:80 | http://img.apnanalytics.com/images/nocache/apn/tr.gif?ev=eichk&cb=&encb=&chk=sucof&ts=Uciha&guid= | US | image | 46 b | suspicious |
2696 | GrLauncher.exe | GET | 200 | 54.84.188.188:80 | http://app.gomlab.com/eng/gom/GrVersionEN.ini | US | text | 843 b | unknown |
3824 | GOMPLAYERENSETUP.EXE | GET | 200 | 52.222.250.174:80 | http://ocsp.rootg2.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBSIfaREXmfqfJR3TkMYnD7O5MhzEgQUnF8A36oB1zArOIiiuG1KnPIRkYMCEwZ%2FlEoqJ83z%2BsKuKwH5CO65xMY%3D | US | der | 1.51 Kb | whitelisted |
3824 | GOMPLAYERENSETUP.EXE | GET | 200 | 108.138.2.107:80 | http://o.ss2.us//MEowSDBGMEQwQjAJBgUrDgMCGgUABBSLwZ6EW5gdYc9UaSEaaLjjETNtkAQUv1%2B30c7dH4b0W1Ws3NcQwg6piOcCCQCnDkpMNIK3fw%3D%3D | US | der | 1.70 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
948 | AskInstallChecker.exe | 34.102.132.13:80 | websearch.ask.com | — | US | suspicious |
3824 | GOMPLAYERENSETUP.EXE | 54.84.188.188:80 | app.gomlab.com | Amazon.com, Inc. | US | unknown |
948 | AskInstallChecker.exe | 34.117.224.112:80 | img.apnanalytics.com | — | US | suspicious |
3824 | GOMPLAYERENSETUP.EXE | 18.66.127.70:80 | www.gomlab.com | Massachusetts Institute of Technology | US | unknown |
3824 | GOMPLAYERENSETUP.EXE | 18.66.127.70:443 | www.gomlab.com | Massachusetts Institute of Technology | US | unknown |
3824 | GOMPLAYERENSETUP.EXE | 23.216.77.69:80 | ctldl.windowsupdate.com | NTT DOCOMO, INC. | US | suspicious |
3824 | GOMPLAYERENSETUP.EXE | 108.138.2.107:80 | o.ss2.us | BellSouth.net Inc. | US | whitelisted |
3824 | GOMPLAYERENSETUP.EXE | 52.222.250.174:80 | ocsp.rootg2.amazontrust.com | Amazon.com, Inc. | US | whitelisted |
2696 | GrLauncher.exe | 54.84.188.188:80 | app.gomlab.com | Amazon.com, Inc. | US | unknown |
3824 | GOMPLAYERENSETUP.EXE | 52.222.250.185:80 | ocsp.rootg2.amazontrust.com | Amazon.com, Inc. | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
websearch.ask.com |
| suspicious |
img.apnanalytics.com |
| suspicious |
app.gomlab.com |
| unknown |
www.gomlab.com |
| malicious |
ctldl.windowsupdate.com |
| whitelisted |
o.ss2.us |
| whitelisted |
ocsp.rootg2.amazontrust.com |
| whitelisted |
ocsp.rootca1.amazontrust.com |
| shared |
info.gomplayer.com |
| unknown |
geo2.adobe.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
948 | AskInstallChecker.exe | Potential Corporate Privacy Violation | ET POLICY Suspicious User Agent (AskInstallChecker) |
948 | AskInstallChecker.exe | Potential Corporate Privacy Violation | ET POLICY Suspicious User Agent (AskInstallChecker) |
2972 | GrLauncherTempSetup.exe | Potentially Bad Traffic | ET USER_AGENTS Observed Suspicious UA (NSIS_Inetc (Mozilla)) |