File name:

FACtU653728075438FHGFJDHGOGIF.zip

Full analysis: https://app.any.run/tasks/515387d7-0e86-422a-8da8-bac309c30dd7
Verdict: Malicious activity
Analysis date: September 30, 2020, 06:39:15
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

7B2FC89B3F6DB29B8F6900F9A5CEFDFB

SHA1:

E6E783C9B67C1C1637B97CC2196D99C811F83693

SHA256:

1F0873BC6A084C59538433F3BDD9D067C25F69E2B82AB3369EA92BF5F5434603

SSDEEP:

24576:Oi1pME2vq9GUAGNfJfKCy/xoFAouYPq406scFPwX7ExQ9e/CrsaHVk5:+E2vqlAmJcxmoYPq40tCtKrlo

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • GoogleUpdateSetup.exe (PID: 2552)
      • ChromeSetup.exe (PID: 1712)
      • GoogleUpdate.exe (PID: 308)
      • GoogleUpdate.exe (PID: 2924)
    • Loads dropped or rewritten executable

      • GoogleUpdate.exe (PID: 308)
      • GoogleUpdate.exe (PID: 2924)
      • GoogleUpdate.exe (PID: 2644)
      • GoogleUpdate.exe (PID: 3252)
      • GoogleUpdate.exe (PID: 3520)
      • GoogleUpdate.exe (PID: 3776)
      • GoogleUpdate.exe (PID: 1916)
    • Loads the Task Scheduler COM API

      • GoogleUpdate.exe (PID: 2924)
    • Changes settings of System certificates

      • GoogleUpdate.exe (PID: 3252)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • ChromeSetup.exe (PID: 1712)
      • WinRAR.exe (PID: 2116)
      • GoogleUpdateSetup.exe (PID: 2552)
      • GoogleUpdate.exe (PID: 2924)
    • Creates files in the program directory

      • GoogleUpdateSetup.exe (PID: 2552)
      • GoogleUpdate.exe (PID: 2924)
    • Creates COM task schedule object

      • GoogleUpdate.exe (PID: 2644)
    • Executed as Windows Service

      • GoogleUpdate.exe (PID: 1916)
      • vssvc.exe (PID: 3336)
    • Adds / modifies Windows certificates

      • GoogleUpdate.exe (PID: 3252)
    • Starts Microsoft Installer

      • WinRAR.exe (PID: 2116)
    • Executes scripts

      • MsiExec.exe (PID: 2992)
    • Reads Internet Cache Settings

      • WScript.exe (PID: 2884)
    • Connects to server without host name

      • WScript.exe (PID: 2884)
    • Disables SEHOP

      • GoogleUpdate.exe (PID: 2924)
  • INFO

    • Low-level read access rights to disk partition

      • vssvc.exe (PID: 3336)
    • Application launched itself

      • msiexec.exe (PID: 2696)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2020:09:23 01:55:01
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: FACtU653728075438FHGFJDHGOGIF/0/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
52
Monitored processes
15
Malicious processes
5
Suspicious processes
4

Behavior graph

Click at the process to see the details
drop and start start drop and start drop and start winrar.exe chromesetup.exe googleupdate.exe no specs googleupdatesetup.exe googleupdate.exe googleupdate.exe no specs googleupdate.exe no specs googleupdate.exe googleupdate.exe no specs googleupdate.exe msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs wscript.exe vssvc.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
308C:\Users\admin\AppData\Local\Temp\GUMD7.tmp\GoogleUpdate.exe /installsource taggedmi /install "appguid={8A69D345-D564-463C-AFF1-A69D9E530F96}&iid={E3F64318-E7BD-80EB-6FC7-D053B4A556A2}&lang=pt-PT&browser=4&usagestats=1&appname=Google%20Chrome&needsadmin=prefers&ap=x64-stable-statsdef_1&brand=CHBF&installdataindex=empty"C:\Users\admin\AppData\Local\Temp\GUMD7.tmp\GoogleUpdate.exeChromeSetup.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Installer
Exit code:
0
Version:
1.3.35.451
Modules
Images
c:\users\admin\appdata\local\temp\gumd7.tmp\googleupdate.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
1712"C:\Users\admin\AppData\Local\Temp\Rar$EXa2116.32191\FACtU653728075438FHGFJDHGOGIF\0\ChromeSetup.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2116.32191\FACtU653728075438FHGFJDHGOGIF\0\ChromeSetup.exe
WinRAR.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Update Setup
Exit code:
0
Version:
1.3.35.452
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2116.32191\factu653728075438fhgfjdhgogif\0\chromesetup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
1916"C:\Program Files\Google\Update\GoogleUpdate.exe" /svcC:\Program Files\Google\Update\GoogleUpdate.exe
services.exe
User:
SYSTEM
Company:
Google Inc.
Integrity Level:
SYSTEM
Description:
Google Installer
Exit code:
0
Version:
1.3.33.23
Modules
Images
c:\program files\google\update\googleupdate.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
2116"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\FACtU653728075438FHGFJDHGOGIF.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2552"C:\Users\admin\AppData\Local\Temp\GUMD7.tmp\GoogleUpdateSetup.exe" /installsource taggedmi /install "appguid={8A69D345-D564-463C-AFF1-A69D9E530F96}&iid={E3F64318-E7BD-80EB-6FC7-D053B4A556A2}&lang=pt-PT&browser=4&usagestats=1&appname=Google%20Chrome&needsadmin=prefers&ap=x64-stable-statsdef_1&brand=CHBF&installdataindex=empty" /installelevated /nomitagC:\Users\admin\AppData\Local\Temp\GUMD7.tmp\GoogleUpdateSetup.exe
GoogleUpdate.exe
User:
admin
Company:
Google LLC
Integrity Level:
HIGH
Description:
Google Update Setup
Exit code:
0
Version:
1.3.35.452
Modules
Images
c:\users\admin\appdata\local\temp\gumd7.tmp\googleupdatesetup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2644"C:\Program Files\Google\Update\GoogleUpdate.exe" /regserverC:\Program Files\Google\Update\GoogleUpdate.exeGoogleUpdate.exe
User:
admin
Company:
Google Inc.
Integrity Level:
HIGH
Description:
Google Installer
Exit code:
0
Version:
1.3.33.23
Modules
Images
c:\program files\google\update\googleupdate.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
2696C:\Windows\system32\msiexec.exe /VC:\Windows\system32\msiexec.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2884"C:\Windows\System32\WScript.exe" "C:\Users\Public\U85.vbs" C:\Windows\System32\WScript.exe
MsiExec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Windows Based Script Host
Exit code:
0
Version:
5.8.7600.16385
Modules
Images
c:\windows\system32\wscript.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2924"C:\Program Files\Google\Temp\GUM740.tmp\GoogleUpdate.exe" /installsource taggedmi /install "appguid={8A69D345-D564-463C-AFF1-A69D9E530F96}&iid={E3F64318-E7BD-80EB-6FC7-D053B4A556A2}&lang=pt-PT&browser=4&usagestats=1&appname=Google%20Chrome&needsadmin=prefers&ap=x64-stable-statsdef_1&brand=CHBF&installdataindex=empty" /installelevatedC:\Program Files\Google\Temp\GUM740.tmp\GoogleUpdate.exe
GoogleUpdateSetup.exe
User:
admin
Company:
Google LLC
Integrity Level:
HIGH
Description:
Google Installer
Exit code:
0
Version:
1.3.35.451
Modules
Images
c:\program files\google\temp\gum740.tmp\googleupdate.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
2992C:\Windows\system32\MsiExec.exe -Embedding D9F85903A78574F10ECFA412B199FCC0 CC:\Windows\system32\MsiExec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
2 890
Read events
1 401
Write events
1 367
Delete events
122

Modification events

(PID) Process:(2116) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2116) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2116) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2116) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\FACtU653728075438FHGFJDHGOGIF.zip
(PID) Process:(2116) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2116) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2116) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2116) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2116) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E
Operation:writeName:@C:\Windows\System32\msimsg.dll,-34
Value:
Windows Installer Package
(PID) Process:(2116) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
Executable files
213
Suspicious files
2
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
2116WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2116.32191\FACtU653728075438FHGFJDHGOGIF\0\ChromeSetup.exeexecutable
MD5:
SHA256:
2116WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2116.32191\FACtU653728075438FHGFJDHGOGIF\FacT89HJKFVVBVKSFN GDHGRUIYHEWGH765HG.msiexecutable
MD5:
SHA256:
1712ChromeSetup.exeC:\Users\admin\AppData\Local\Temp\GUMD7.tmp\GoogleCrashHandler.exeexecutable
MD5:74CDA8051136B80DC3AE4BF86623003C
SHA256:3C05CAF977003005770BCA7CD4C4586A3C2C2B749A5BB8659AF50B8637F5AC5E
1712ChromeSetup.exeC:\Users\admin\AppData\Local\Temp\GUMD7.tmp\GoogleUpdateHelper.msiexecutable
MD5:1766B021B0BAB4F82259974154C5A920
SHA256:4016DFF47234FF9031B634C5EC931783402EA3F7E40CBDA8CC9637EB947CC6C7
1712ChromeSetup.exeC:\Users\admin\AppData\Local\Temp\GUMD7.tmp\psmachine.dllexecutable
MD5:146A84692C2B149D170359DD716B0AF0
SHA256:4ABA9A08E281DD328A4094D5EDC4C1F672391BA049A3C9DC682B283CE83D006F
1712ChromeSetup.exeC:\Users\admin\AppData\Local\Temp\GUMD7.tmp\GoogleUpdateOnDemand.exeexecutable
MD5:9020315BBE57A2F88EFF3BE4BF04F349
SHA256:C070E09AC50C460A33CEA55CCADB66413ABD53EBE871F549597DEF8A719B9CB1
1712ChromeSetup.exeC:\Users\admin\AppData\Local\Temp\GUMD7.tmp\goopdate.dllexecutable
MD5:423A3E9172B85D03B338067A14E23A00
SHA256:DEA45DD3A35A5D92EFA2726B52B0275121DCEAFDC7717A406F4CD294B10CD67E
2116WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2116.32191\FACtU653728075438FHGFJDHGOGIF\0\-executable
MD5:1152D8A0B208B371FB64BF02A67C8732
SHA256:AEA16D34C312EB8706705CB3751FE7A56FA1E97B2974FCABE89555DF9AD0A250
1712ChromeSetup.exeC:\Users\admin\AppData\Local\Temp\GUMD7.tmp\GoogleUpdate.exeexecutable
MD5:0BCA3F16DD527B4150648EC1E36CB22A
SHA256:B60E92004D394D0B14A8953A2BA29951C79F2F8A6C94F495E3153DFBBEF115B6
1712ChromeSetup.exeC:\Users\admin\AppData\Local\Temp\GUMD7.tmp\psmachine_64.dllexecutable
MD5:719B0BCBD5A62428455175971C32466D
SHA256:1371C51CD108934EB2345039639ABE54B673AA84BCE1CF7176F3E7194A5BE641
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
5
DNS requests
3
Threats
3

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
HEAD
200
159.148.69.141:80
http://r2---sn-a5uoxu-gpme.gvt1.com/edgedl/release2/chrome/ALgibAjT0Zy8wIzHqPUFTQ0_85.0.4183.121/85.0.4183.121_chrome_installer.exe?cms_redirect=yes&mh=Gz&mip=80.233.134.134&mm=28&mn=sn-a5uoxu-gpme&ms=nvh&mt=1601447893&mv=m&mvi=2&pl=24&shardbypass=yes
LV
whitelisted
GET
159.148.69.141:80
http://r2---sn-a5uoxu-gpme.gvt1.com/edgedl/release2/chrome/ALgibAjT0Zy8wIzHqPUFTQ0_85.0.4183.121/85.0.4183.121_chrome_installer.exe?cms_redirect=yes&mh=Gz&mip=80.233.134.134&mm=28&mn=sn-a5uoxu-gpme&ms=nvh&mt=1601447893&mv=m&mvi=2&pl=24&shardbypass=yes
LV
whitelisted
HEAD
302
216.58.207.78:80
http://redirector.gvt1.com/edgedl/release2/chrome/ALgibAjT0Zy8wIzHqPUFTQ0_85.0.4183.121/85.0.4183.121_chrome_installer.exe
US
whitelisted
2884
WScript.exe
POST
165.22.67.118:80
http://165.22.67.118/nj42.php
US
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3252
GoogleUpdate.exe
216.58.206.3:443
update.googleapis.com
Google Inc.
US
whitelisted
1916
GoogleUpdate.exe
216.58.206.3:443
update.googleapis.com
Google Inc.
US
whitelisted
216.58.207.78:80
redirector.gvt1.com
Google Inc.
US
whitelisted
159.148.69.141:80
r2---sn-a5uoxu-gpme.gvt1.com
LATNET SERVISS Ltd.
LV
whitelisted
2884
WScript.exe
165.22.67.118:80
US
malicious

DNS requests

Domain
IP
Reputation
update.googleapis.com
  • 216.58.206.3
whitelisted
redirector.gvt1.com
  • 216.58.207.78
whitelisted
r2---sn-a5uoxu-gpme.gvt1.com
  • 159.148.69.141
whitelisted

Threats

PID
Process
Class
Message
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
Misc activity
ET INFO EXE - Served Attached HTTP
1 ETPRO signatures available at the full report
No debug info