| File name: | MDE_File_Sample_5f4485615c870b5ec03f0aa7591a04f330b3a2f6.zip |
| Full analysis: | https://app.any.run/tasks/722c86c9-2283-46ab-94e6-94c9b6a50e07 |
| Verdict: | Malicious activity |
| Analysis date: | September 15, 2022, 10:47:17 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | 67FF509F87F2BBBBDC5F4DB39FEC2293 |
| SHA1: | 84D3C61B0855989032C275D5022CAB8481380341 |
| SHA256: | 1BF7E23F0FA7A0BCD4F5A66DB9B20AB6323F485A61DD53C9FA9A874CEBD38CFF |
| SSDEEP: | 196608:4nozAcEWwr7nmdKYC05ZVtDyHpwP8thBpNerbhqkwmRZ8:PzAcEWSGC6KLfBuxqknH8 |
| .zip | | | ZIP compressed archive (100) |
|---|
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 712 | C:\Windows\system32\DllHost.exe /Processid:{2DB4F9B7-144E-4319-B14A-432AC74C0CEF} | C:\Windows\system32\DllHost.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: COM Surrogate Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 848 | "C:\Program Files\GRETECH\GomPlayer\GOM.exe" /regassoc | C:\Program Files\GRETECH\GomPlayer\GOM.exe | — | GOMPLAYERENSETUP.EXE | |||||||||||
User: admin Company: Gretech Corp. Integrity Level: HIGH Description: GOM Player Exit code: 0 Version: 2, 1, 33, 5071 Modules
| |||||||||||||||
| 948 | C:\Users\admin\AppData\Local\Temp\AskInstallChecker.exe GOM2 | C:\Users\admin\AppData\Local\Temp\AskInstallChecker.exe | GOMPLAYERENSETUP.EXE | ||||||||||||
User: admin Company: Ask.com Integrity Level: HIGH Description: Install Checker Exit code: 0 Version: 1.5.0.0 Modules
| |||||||||||||||
| 1324 | "C:\Program Files\GRETECH\GomPlayer\GOM.exe" | C:\Program Files\GRETECH\GomPlayer\GOM.exe | GomWiz.exe | ||||||||||||
User: admin Company: Gretech Corp. Integrity Level: MEDIUM Description: GOM Player Exit code: 0 Version: 2, 1, 33, 5071 Modules
| |||||||||||||||
| 1684 | "C:\Program Files\GRETECH\GomPlayer\ShellRegister.exe" | C:\Program Files\GRETECH\GomPlayer\ShellRegister.exe | — | GOMPLAYERENSETUP.EXE | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 1712 | C:\Windows\system32\svchost.exe -k RPCSS | C:\Windows\system32\svchost.exe | — | services.exe | |||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2060 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\MDE_File_Sample_5f4485615c870b5ec03f0aa7591a04f330b3a2f6.zip" | C:\Program Files\WinRAR\WinRAR.exe | Explorer.EXE | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 2696 | "C:\Program Files\GRETECH\GomPlayer\GrLauncher.exe"" <GRLAUNCHER_PARAM Command='checkversion' AgentName='GomPlayer 2, 1, 33, 5071 (ENG)' ProgramID='GOMPLAYER2' ForceCheck='0' CheckMinorVersion='1' RetWindowHandle='524688' LocalVersionFilePath='C:\Users\admin\AppData\Roaming\GRETECH\GomPlayer\GrVersion.ini' />" | C:\Program Files\GRETECH\GomPlayer\GrLauncher.exe | GOM.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 41 Modules
| |||||||||||||||
| 2732 | "C:\Program Files\GRETECH\GomPlayer\KillGom.exe" GOM.EXE | C:\Program Files\GRETECH\GomPlayer\KillGom.exe | — | GOMPLAYERENSETUP.EXE | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2888 | "C:\Program Files\GRETECH\GomPlayer\GOM.exe" | C:\Program Files\GRETECH\GomPlayer\GOM.exe | — | Explorer.EXE | |||||||||||
User: admin Company: Gretech Corp. Integrity Level: MEDIUM Description: GOM Player Exit code: 0 Version: 2, 1, 33, 5071 Modules
| |||||||||||||||
| (PID) Process: | (2060) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (2060) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (2060) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2060) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (2060) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (2060) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\MDE_File_Sample_5f4485615c870b5ec03f0aa7591a04f330b3a2f6.zip | |||
| (PID) Process: | (2060) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2060) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2060) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2060) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3824 | GOMPLAYERENSETUP.EXE | C:\Users\admin\AppData\Local\Temp\NSISPromotionEx.dll | executable | |
MD5:— | SHA256:— | |||
| 2060 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb2060.1329\GOMPLAYERENSETUP.EXE | executable | |
MD5:— | SHA256:— | |||
| 3824 | GOMPLAYERENSETUP.EXE | C:\Users\admin\AppData\Local\Temp\nstF169.tmp\System.dll | executable | |
MD5:C17103AE9072A06DA581DEC998343FC1 | SHA256:DC58D8AD81CACB0C1ED72E33BFF8F23EA40B5252B5BB55D393A0903E6819AE2F | |||
| 3824 | GOMPLAYERENSETUP.EXE | C:\Program Files\GRETECH\GomPlayer\libavcodec.dll | executable | |
MD5:— | SHA256:— | |||
| 3824 | GOMPLAYERENSETUP.EXE | C:\Program Files\GRETECH\GomPlayer\GomWiz.exe | executable | |
MD5:— | SHA256:— | |||
| 3824 | GOMPLAYERENSETUP.EXE | C:\Program Files\GRETECH\GomPlayer\GOM.exe | executable | |
MD5:— | SHA256:— | |||
| 3824 | GOMPLAYERENSETUP.EXE | C:\Users\admin\AppData\Local\Temp\nstF169.tmp\SkinKidslock.ini | ini | |
MD5:BDEE298E2F72ABB6C2E6D4AC4E3A436E | SHA256:7226614E56D843B447EEA362FDF14787A7B02778546517214E27F7610DCB64EA | |||
| 3824 | GOMPLAYERENSETUP.EXE | C:\Users\admin\AppData\Local\Temp\NSISPromotionEx.ini | text | |
MD5:FF5F0C84C510C5D69F7FA5774C8BAC7E | SHA256:56DDBB25A7FEAE8DA47A3DADE69A8F513E99AC5E1AB010DC1DEB94105745F0A8 | |||
| 3824 | GOMPLAYERENSETUP.EXE | C:\Users\admin\AppData\Local\Temp\GomEncDnInstaller.exe | executable | |
MD5:D0103DA25CEF21CDC1591683FB96F5FC | SHA256:4A7B15CC88A2F8B97F7BB91C12E23B4E7506A6C50E52C855B953C7184907940A | |||
| 3824 | GOMPLAYERENSETUP.EXE | C:\Users\admin\AppData\Local\Temp\spltmp.bmp | image | |
MD5:D4C147D4EEBA482BA53F9A6FF6101E31 | SHA256:1C33A2C72449468A285E183ED9E71C81D439FD7F6CE67DA51F50CA8D1631D665 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
948 | AskInstallChecker.exe | GET | — | 34.102.132.13:80 | http://websearch.ask.com/preinstall?client=ic&tb=GOM2&r=0&ipid=&npid=GOM2&iev=9&ielu=0&fflu=0&iv=&nv=1.8.0.0&clientv=1.5.0.0&rep=0 | US | — | — | suspicious |
3824 | GOMPLAYERENSETUP.EXE | GET | 302 | 18.66.127.70:80 | http://www.gomlab.com/ | US | html | 206 b | malicious |
3824 | GOMPLAYERENSETUP.EXE | GET | 302 | 18.66.127.70:80 | http://www.gomlab.com/ipCheck/ipCheck.php | US | html | 206 b | malicious |
3824 | GOMPLAYERENSETUP.EXE | GET | 200 | 54.84.188.188:80 | http://app.gomlab.com/eng/gom/PromotionCheck.php | US | text | 495 b | unknown |
2892 | GrLauncher.exe | GET | 200 | 18.66.121.29:80 | http://ocsp.sca1b.amazontrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQz9arGHWbnBV0DFzpNHz4YcTiFDQQUWaRmBlKge5WSPKOUByeWdFv5PdACEAFwoews%2FqqcdnN6bRFXvDU%3D | US | der | 471 b | whitelisted |
3824 | GOMPLAYERENSETUP.EXE | GET | 200 | 23.216.77.69:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?82e2d41089eb0964 | US | compressed | 4.70 Kb | whitelisted |
1324 | GOM.exe | POST | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/ | US | der | 471 b | whitelisted |
2696 | GrLauncher.exe | GET | 200 | 54.84.188.188:80 | http://app.gomlab.com/eng/gom/GrVersionEN.ini | US | text | 843 b | unknown |
1324 | GOM.exe | POST | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/ | US | der | 471 b | whitelisted |
2972 | GrLauncherTempSetup.exe | GET | 200 | 18.66.248.88:80 | http://playinfo.gomlab.com/cms/bundle/index.gom?version=1&mode=upgrade | US | html | 4.85 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3824 | GOMPLAYERENSETUP.EXE | 54.84.188.188:80 | app.gomlab.com | Amazon.com, Inc. | US | unknown |
3824 | GOMPLAYERENSETUP.EXE | 18.66.127.70:443 | www.gomlab.com | Massachusetts Institute of Technology | US | unknown |
3824 | GOMPLAYERENSETUP.EXE | 18.66.127.70:80 | www.gomlab.com | Massachusetts Institute of Technology | US | unknown |
3824 | GOMPLAYERENSETUP.EXE | 52.222.250.174:80 | ocsp.rootg2.amazontrust.com | Amazon.com, Inc. | US | whitelisted |
3824 | GOMPLAYERENSETUP.EXE | 52.222.250.185:80 | ocsp.rootg2.amazontrust.com | Amazon.com, Inc. | US | whitelisted |
948 | AskInstallChecker.exe | 34.117.224.112:80 | img.apnanalytics.com | — | US | suspicious |
948 | AskInstallChecker.exe | 34.102.132.13:80 | websearch.ask.com | — | US | suspicious |
2696 | GrLauncher.exe | 54.84.188.188:80 | app.gomlab.com | Amazon.com, Inc. | US | unknown |
1324 | GOM.exe | 23.32.59.230:443 | fpdownload.macromedia.com | Akamai International B.V. | US | suspicious |
1324 | GOM.exe | 93.184.220.29:80 | ocsp.digicert.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
websearch.ask.com |
| suspicious |
img.apnanalytics.com |
| suspicious |
app.gomlab.com |
| unknown |
www.gomlab.com |
| malicious |
ctldl.windowsupdate.com |
| whitelisted |
o.ss2.us |
| whitelisted |
ocsp.rootg2.amazontrust.com |
| whitelisted |
ocsp.rootca1.amazontrust.com |
| shared |
info.gomplayer.com |
| unknown |
geo2.adobe.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
948 | AskInstallChecker.exe | Potential Corporate Privacy Violation | ET POLICY Suspicious User Agent (AskInstallChecker) |
948 | AskInstallChecker.exe | Potential Corporate Privacy Violation | ET POLICY Suspicious User Agent (AskInstallChecker) |
2972 | GrLauncherTempSetup.exe | Potentially Bad Traffic | ET USER_AGENTS Observed Suspicious UA (NSIS_Inetc (Mozilla)) |