| File name: | Remover-Virus-Acceso-Directo(By Pixel4brain.com).zip |
| Full analysis: | https://app.any.run/tasks/2596f1a0-59be-4ddb-9c7d-e06ac9b7ec89 |
| Verdict: | Malicious activity |
| Analysis date: | August 08, 2024, 21:49:29 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract, compression method=deflate |
| MD5: | 42510139D773823A103A7B35BB207BF5 |
| SHA1: | 774BCCF0A241FFEDEC3D74602E3D88CAF1BE281E |
| SHA256: | 1FCA7814AD5A9F1E2F361B1BE30EC5B6737A1D3A79E836C6E081C80CB2A1CFC7 |
| SSDEEP: | 98304:pU1E6+cYcA7IW6kLYvOHR6VXMDuBQMITyJf3fwOgs/hwc7qfAB3xuh0UWEz5XqTc:PBuCi6to8SXUjT |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | 0x0002 |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2014:09:29 07:02:58 |
| ZipCRC: | 0xfdf0abdb |
| ZipCompressedSize: | 515667 |
| ZipUncompressedSize: | 806717 |
| ZipFileName: | Shortcut Virus Remover v3.1.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1048 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa6252.12671\Shortcut Virus Remover v3.1.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa6252.12671\Shortcut Virus Remover v3.1.exe | WinRAR.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 1556 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --single-argument microsoft-edge:https://www.usb-antivirus.com/ | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | UsbFix.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft Edge Exit code: 1 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 1964 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=3464 --field-trial-handle=2332,i,14504564311404799722,18029439701523141267,262144 --variations-seed-version /prefetch:1 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 2508 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=4208 --field-trial-handle=2332,i,14504564311404799722,18029439701523141267,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 2960 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5228 --field-trial-handle=2332,i,14504564311404799722,18029439701523141267,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 2992 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=3636 --field-trial-handle=2332,i,14504564311404799722,18029439701523141267,262144 --variations-seed-version /prefetch:1 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 3028 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=2548 --field-trial-handle=2424,i,4636854826946629428,8461202765441588517,262144 --variations-seed-version /prefetch:3 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 4004 | "C:\Users\admin\AppData\Local\Temp\RarSFX0\Shortcut Virus Remover v3.1.exe" | C:\Users\admin\AppData\Local\Temp\RarSFX0\Shortcut Virus Remover v3.1.exe | — | Shortcut Virus Remover v3.1.exe | |||||||||||
User: admin Company: Cyber X Integrity Level: MEDIUM Description: Shortcut Virus Remover Exit code: 0 Version: 3.01.0012 Modules
| |||||||||||||||
| 4080 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --no-appcompat-clear --gpu-preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=2116 --field-trial-handle=2332,i,14504564311404799722,18029439701523141267,262144 --variations-seed-version /prefetch:2 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 4236 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --no-appcompat-clear --gpu-preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=2416 --field-trial-handle=2424,i,4636854826946629428,8461202765441588517,262144 --variations-seed-version /prefetch:2 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| (PID) Process: | (6252) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (6252) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (6252) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\GoogleChromeEnterpriseBundle64.zip | |||
| (PID) Process: | (6252) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Remover-Virus-Acceso-Directo(By Pixel4brain.com).zip | |||
| (PID) Process: | (6252) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (6252) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (6252) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (6252) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (6252) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (6252) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6444 | Shortcut Virus Remover v3.1.exe | C:\Users\admin\AppData\Local\Temp\RarSFX0\pskill.exe | executable | |
MD5:6F2F60AF33A5CAF03E1D0AC81A2DE892 | SHA256:ED8F3C368BA229043C8ACEF7AE4F4A0FDE62BF39FCE51522916B7DCE1E837F71 | |||
| 6252 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa6252.9458\Shortcut Virus Remover v3.1.exe | executable | |
MD5:BC1C264165EC26EDA413024AE079341E | SHA256:83C9829FB99DCB4A61BCFD6ECDF22791E1589418C26A2AA51B676EFFFC0B988E | |||
| 6252 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa6252.9458\UsbFix_9.018.exe | executable | |
MD5:7F72C1915DC932065294F62C96B8A79F | SHA256:CCE20E86DF16B3853E0AFA5E623F6B1E628FED3958B669A322345BF6D9C5BD77 | |||
| 6444 | Shortcut Virus Remover v3.1.exe | C:\Users\admin\AppData\Local\Temp\RarSFX0\Shortcut Virus Remover v3.1.exe | executable | |
MD5:A9FEC8AD17B80EF7C3D3A142BF58CBB2 | SHA256:B898EF094D66880BA27AFE8B4C61950059EB6B403832776FBE067F3B1D9DA49F | |||
| 6252 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa6252.10763\UsbFix_9.018.exe | executable | |
MD5:7F72C1915DC932065294F62C96B8A79F | SHA256:CCE20E86DF16B3853E0AFA5E623F6B1E628FED3958B669A322345BF6D9C5BD77 | |||
| 6532 | Shortcut Virus Remover v3.1.exe | C:\Users\admin\AppData\Local\Temp\~DFC1B8BC3FD2C0EA97.TMP | binary | |
MD5:2416B0A4F94219CA2190FFAD8D442E0E | SHA256:A9EEB8EE2EB97E0A2AD878F31A608D9BCF329872F45F8CADF7DA352E989B5C82 | |||
| 5880 | UsbFix_9.018.exe | C:\UsbFix\Res\Apply2.jpg | image | |
MD5:1D2DBB4273A5E717BC50D0485C8325F1 | SHA256:83608235287DF83712530EF2526269BB88929E7C042AA47A3BB51E209F18D7DC | |||
| 5880 | UsbFix_9.018.exe | C:\UsbFix\Res\AutoClean.png | image | |
MD5:5DFE56A16FEF1C0599426F575B3BF707 | SHA256:4959DAE2F8CB8494D09BD8771B1CB8205ECE92DB2BE85BC86468ADE1CB7DD3ED | |||
| 5880 | UsbFix_9.018.exe | C:\UsbFix\Res\Angle2.png | image | |
MD5:EC7B1BC95DA3B18F18ACB18EE157947D | SHA256:409398A8701008AEF28D844FADADB99802205A51F0643FB759736BDE6AB72C90 | |||
| 5880 | UsbFix_9.018.exe | C:\UsbFix\Res\Angle.png | image | |
MD5:41108867BA519CA76C88711DCE4FBFF0 | SHA256:58A56E197655D53886EA7BB483B21EE25E1B852925BF39D4A8393C4E8378695B | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
5336 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
5484 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
5484 | svchost.exe | GET | 304 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
6672 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
6712 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4056 | svchost.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
3972 | RUXIMICS.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
2120 | MoUsoCoreWorker.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
3888 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4056 | svchost.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
5336 | SearchApp.exe | 104.126.37.155:443 | www.bing.com | Akamai International B.V. | DE | unknown |
5336 | SearchApp.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
5484 | svchost.exe | 20.190.159.2:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
www.bing.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
login.live.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
th.bing.com |
| whitelisted |
fd.api.iris.microsoft.com |
| whitelisted |
arc.msn.com |
| whitelisted |
www.usb-antivirus.com |
| unknown |