| File name: | FACtU653728075438FHGFJDHGOGIF.zip |
| Full analysis: | https://app.any.run/tasks/515387d7-0e86-422a-8da8-bac309c30dd7 |
| Verdict: | Malicious activity |
| Analysis date: | September 30, 2020, 06:39:15 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | 7B2FC89B3F6DB29B8F6900F9A5CEFDFB |
| SHA1: | E6E783C9B67C1C1637B97CC2196D99C811F83693 |
| SHA256: | 1F0873BC6A084C59538433F3BDD9D067C25F69E2B82AB3369EA92BF5F5434603 |
| SSDEEP: | 24576:Oi1pME2vq9GUAGNfJfKCy/xoFAouYPq406scFPwX7ExQ9e/CrsaHVk5:+E2vqlAmJcxmoYPq40tCtKrlo |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | None |
| ZipModifyDate: | 2020:09:23 01:55:01 |
| ZipCRC: | 0x00000000 |
| ZipCompressedSize: | - |
| ZipUncompressedSize: | - |
| ZipFileName: | FACtU653728075438FHGFJDHGOGIF/0/ |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 308 | C:\Users\admin\AppData\Local\Temp\GUMD7.tmp\GoogleUpdate.exe /installsource taggedmi /install "appguid={8A69D345-D564-463C-AFF1-A69D9E530F96}&iid={E3F64318-E7BD-80EB-6FC7-D053B4A556A2}&lang=pt-PT&browser=4&usagestats=1&appname=Google%20Chrome&needsadmin=prefers&ap=x64-stable-statsdef_1&brand=CHBF&installdataindex=empty" | C:\Users\admin\AppData\Local\Temp\GUMD7.tmp\GoogleUpdate.exe | — | ChromeSetup.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Installer Exit code: 0 Version: 1.3.35.451 Modules
| |||||||||||||||
| 1712 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2116.32191\FACtU653728075438FHGFJDHGOGIF\0\ChromeSetup.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2116.32191\FACtU653728075438FHGFJDHGOGIF\0\ChromeSetup.exe | WinRAR.exe | ||||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Update Setup Exit code: 0 Version: 1.3.35.452 Modules
| |||||||||||||||
| 1916 | "C:\Program Files\Google\Update\GoogleUpdate.exe" /svc | C:\Program Files\Google\Update\GoogleUpdate.exe | services.exe | ||||||||||||
User: SYSTEM Company: Google Inc. Integrity Level: SYSTEM Description: Google Installer Exit code: 0 Version: 1.3.33.23 Modules
| |||||||||||||||
| 2116 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\FACtU653728075438FHGFJDHGOGIF.zip" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 2552 | "C:\Users\admin\AppData\Local\Temp\GUMD7.tmp\GoogleUpdateSetup.exe" /installsource taggedmi /install "appguid={8A69D345-D564-463C-AFF1-A69D9E530F96}&iid={E3F64318-E7BD-80EB-6FC7-D053B4A556A2}&lang=pt-PT&browser=4&usagestats=1&appname=Google%20Chrome&needsadmin=prefers&ap=x64-stable-statsdef_1&brand=CHBF&installdataindex=empty" /installelevated /nomitag | C:\Users\admin\AppData\Local\Temp\GUMD7.tmp\GoogleUpdateSetup.exe | GoogleUpdate.exe | ||||||||||||
User: admin Company: Google LLC Integrity Level: HIGH Description: Google Update Setup Exit code: 0 Version: 1.3.35.452 Modules
| |||||||||||||||
| 2644 | "C:\Program Files\Google\Update\GoogleUpdate.exe" /regserver | C:\Program Files\Google\Update\GoogleUpdate.exe | — | GoogleUpdate.exe | |||||||||||
User: admin Company: Google Inc. Integrity Level: HIGH Description: Google Installer Exit code: 0 Version: 1.3.33.23 Modules
| |||||||||||||||
| 2696 | C:\Windows\system32\msiexec.exe /V | C:\Windows\system32\msiexec.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2884 | "C:\Windows\System32\WScript.exe" "C:\Users\Public\U85.vbs" | C:\Windows\System32\WScript.exe | MsiExec.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft ® Windows Based Script Host Exit code: 0 Version: 5.8.7600.16385 Modules
| |||||||||||||||
| 2924 | "C:\Program Files\Google\Temp\GUM740.tmp\GoogleUpdate.exe" /installsource taggedmi /install "appguid={8A69D345-D564-463C-AFF1-A69D9E530F96}&iid={E3F64318-E7BD-80EB-6FC7-D053B4A556A2}&lang=pt-PT&browser=4&usagestats=1&appname=Google%20Chrome&needsadmin=prefers&ap=x64-stable-statsdef_1&brand=CHBF&installdataindex=empty" /installelevated | C:\Program Files\Google\Temp\GUM740.tmp\GoogleUpdate.exe | GoogleUpdateSetup.exe | ||||||||||||
User: admin Company: Google LLC Integrity Level: HIGH Description: Google Installer Exit code: 0 Version: 1.3.35.451 Modules
| |||||||||||||||
| 2992 | C:\Windows\system32\MsiExec.exe -Embedding D9F85903A78574F10ECFA412B199FCC0 C | C:\Windows\system32\MsiExec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (2116) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (2116) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (2116) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2116) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\FACtU653728075438FHGFJDHGOGIF.zip | |||
| (PID) Process: | (2116) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2116) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2116) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2116) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (2116) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E |
| Operation: | write | Name: | @C:\Windows\System32\msimsg.dll,-34 |
Value: Windows Installer Package | |||
| (PID) Process: | (2116) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2116 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2116.32191\FACtU653728075438FHGFJDHGOGIF\0\ChromeSetup.exe | executable | |
MD5:— | SHA256:— | |||
| 2116 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2116.32191\FACtU653728075438FHGFJDHGOGIF\FacT89HJKFVVBVKSFN GDHGRUIYHEWGH765HG.msi | executable | |
MD5:— | SHA256:— | |||
| 1712 | ChromeSetup.exe | C:\Users\admin\AppData\Local\Temp\GUMD7.tmp\GoogleCrashHandler.exe | executable | |
MD5:74CDA8051136B80DC3AE4BF86623003C | SHA256:3C05CAF977003005770BCA7CD4C4586A3C2C2B749A5BB8659AF50B8637F5AC5E | |||
| 1712 | ChromeSetup.exe | C:\Users\admin\AppData\Local\Temp\GUMD7.tmp\GoogleUpdateHelper.msi | executable | |
MD5:1766B021B0BAB4F82259974154C5A920 | SHA256:4016DFF47234FF9031B634C5EC931783402EA3F7E40CBDA8CC9637EB947CC6C7 | |||
| 1712 | ChromeSetup.exe | C:\Users\admin\AppData\Local\Temp\GUMD7.tmp\psmachine.dll | executable | |
MD5:146A84692C2B149D170359DD716B0AF0 | SHA256:4ABA9A08E281DD328A4094D5EDC4C1F672391BA049A3C9DC682B283CE83D006F | |||
| 1712 | ChromeSetup.exe | C:\Users\admin\AppData\Local\Temp\GUMD7.tmp\GoogleUpdateOnDemand.exe | executable | |
MD5:9020315BBE57A2F88EFF3BE4BF04F349 | SHA256:C070E09AC50C460A33CEA55CCADB66413ABD53EBE871F549597DEF8A719B9CB1 | |||
| 1712 | ChromeSetup.exe | C:\Users\admin\AppData\Local\Temp\GUMD7.tmp\goopdate.dll | executable | |
MD5:423A3E9172B85D03B338067A14E23A00 | SHA256:DEA45DD3A35A5D92EFA2726B52B0275121DCEAFDC7717A406F4CD294B10CD67E | |||
| 2116 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2116.32191\FACtU653728075438FHGFJDHGOGIF\0\- | executable | |
MD5:1152D8A0B208B371FB64BF02A67C8732 | SHA256:AEA16D34C312EB8706705CB3751FE7A56FA1E97B2974FCABE89555DF9AD0A250 | |||
| 1712 | ChromeSetup.exe | C:\Users\admin\AppData\Local\Temp\GUMD7.tmp\GoogleUpdate.exe | executable | |
MD5:0BCA3F16DD527B4150648EC1E36CB22A | SHA256:B60E92004D394D0B14A8953A2BA29951C79F2F8A6C94F495E3153DFBBEF115B6 | |||
| 1712 | ChromeSetup.exe | C:\Users\admin\AppData\Local\Temp\GUMD7.tmp\psmachine_64.dll | executable | |
MD5:719B0BCBD5A62428455175971C32466D | SHA256:1371C51CD108934EB2345039639ABE54B673AA84BCE1CF7176F3E7194A5BE641 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | HEAD | 200 | 159.148.69.141:80 | http://r2---sn-a5uoxu-gpme.gvt1.com/edgedl/release2/chrome/ALgibAjT0Zy8wIzHqPUFTQ0_85.0.4183.121/85.0.4183.121_chrome_installer.exe?cms_redirect=yes&mh=Gz&mip=80.233.134.134&mm=28&mn=sn-a5uoxu-gpme&ms=nvh&mt=1601447893&mv=m&mvi=2&pl=24&shardbypass=yes | LV | — | — | whitelisted |
— | — | GET | — | 159.148.69.141:80 | http://r2---sn-a5uoxu-gpme.gvt1.com/edgedl/release2/chrome/ALgibAjT0Zy8wIzHqPUFTQ0_85.0.4183.121/85.0.4183.121_chrome_installer.exe?cms_redirect=yes&mh=Gz&mip=80.233.134.134&mm=28&mn=sn-a5uoxu-gpme&ms=nvh&mt=1601447893&mv=m&mvi=2&pl=24&shardbypass=yes | LV | — | — | whitelisted |
— | — | HEAD | 302 | 216.58.207.78:80 | http://redirector.gvt1.com/edgedl/release2/chrome/ALgibAjT0Zy8wIzHqPUFTQ0_85.0.4183.121/85.0.4183.121_chrome_installer.exe | US | — | — | whitelisted |
2884 | WScript.exe | POST | — | 165.22.67.118:80 | http://165.22.67.118/nj42.php | US | — | — | malicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3252 | GoogleUpdate.exe | 216.58.206.3:443 | update.googleapis.com | Google Inc. | US | whitelisted |
1916 | GoogleUpdate.exe | 216.58.206.3:443 | update.googleapis.com | Google Inc. | US | whitelisted |
— | — | 216.58.207.78:80 | redirector.gvt1.com | Google Inc. | US | whitelisted |
— | — | 159.148.69.141:80 | r2---sn-a5uoxu-gpme.gvt1.com | LATNET SERVISS Ltd. | LV | whitelisted |
2884 | WScript.exe | 165.22.67.118:80 | — | — | US | malicious |
Domain | IP | Reputation |
|---|---|---|
update.googleapis.com |
| whitelisted |
redirector.gvt1.com |
| whitelisted |
r2---sn-a5uoxu-gpme.gvt1.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
— | — | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
— | — | Misc activity | ET INFO EXE - Served Attached HTTP |