File name:

tools.zip

Full analysis: https://app.any.run/tasks/053aca59-bffd-4e25-97ce-afe5516ea98a
Verdict: Malicious activity
Threats:

Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.

Analysis date: September 03, 2025, 17:55:00
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
arch-exec
neshta
stealer
anti-evasion
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract, compression method=store
MD5:

DE1D599F84FBD9416366654893A85C30

SHA1:

81F43CCEFF73D5F0BBBE62A978C6FD1D9C73B339

SHA256:

21880C2216C530058A7F63CD6C3FF5896D23000C40DDAADEF35146F2E0632ED4

SSDEEP:

49152:qEPHZi+bBqn7TaJO/jJQEEEWlXvfq9lY:qEPZi+FIWw7IEWhfL

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 2624)
    • NESHTA mutex has been found

      • NS.exe (PID: 2940)
    • Steals credentials from Web Browsers

      • readonly.exe (PID: 2992)
      • readonly.exe (PID: 2512)
    • Actions looks like stealing of personal data

      • readonly.exe (PID: 2992)
      • readonly.exe (PID: 2512)
    • Executing a file with an untrusted certificate

      • DefenderControl.exe (PID: 3232)
      • DefenderControl.exe (PID: 756)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • NS.exe (PID: 2940)
      • readonly.exe (PID: 2108)
      • DefenderControl.exe (PID: 3744)
      • readonly.exe (PID: 1568)
    • There is functionality for taking screenshot (YARA)

      • NS.exe (PID: 2940)
    • Reads the Internet Settings

      • NS.exe (PID: 2940)
      • readonly.exe (PID: 2108)
      • DefenderControl.exe (PID: 3744)
      • readonly.exe (PID: 1568)
    • Starts CMD.EXE for commands execution

      • NS.exe (PID: 2060)
    • Mutex name with non-standard characters

      • NS.exe (PID: 2940)
    • Reads security settings of Internet Explorer

      • NS.exe (PID: 2940)
      • readonly.exe (PID: 2108)
      • DefenderControl.exe (PID: 3744)
      • readonly.exe (PID: 1568)
    • Creates file in the systems drive root

      • readonly.exe (PID: 2992)
      • readonly.exe (PID: 2512)
    • Modifies hosts file to alter network resolution

      • readonly.exe (PID: 2992)
      • readonly.exe (PID: 2512)
    • The process checks if it is being run in the virtual environment

      • readonly.exe (PID: 2992)
      • readonly.exe (PID: 2512)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2624)
    • Create files in a temporary directory

      • NS.exe (PID: 2940)
      • readonly.exe (PID: 2108)
      • DefenderControl.exe (PID: 3744)
    • Checks supported languages

      • NS.exe (PID: 2940)
      • NS.exe (PID: 2060)
      • readonly.exe (PID: 2108)
      • readonly.exe (PID: 2992)
      • DefenderControl.exe (PID: 3744)
      • DefenderControl.exe (PID: 756)
      • readonly.exe (PID: 1568)
      • readonly.exe (PID: 2512)
    • Manual execution by a user

      • NS.exe (PID: 2940)
      • readonly.exe (PID: 2108)
      • DefenderControl.exe (PID: 3744)
      • readonly.exe (PID: 1568)
      • firefox.exe (PID: 3140)
    • Reads the computer name

      • NS.exe (PID: 2940)
      • readonly.exe (PID: 2108)
      • NS.exe (PID: 2060)
      • DefenderControl.exe (PID: 3744)
      • DefenderControl.exe (PID: 756)
      • readonly.exe (PID: 1568)
    • Failed to create an executable file in Windows directory

      • readonly.exe (PID: 2992)
      • readonly.exe (PID: 2512)
    • The sample compiled with english language support

      • DefenderControl.exe (PID: 3744)
    • Reads mouse settings

      • DefenderControl.exe (PID: 756)
    • Application launched itself

      • firefox.exe (PID: 3152)
      • firefox.exe (PID: 3140)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2021:10:04 11:46:02
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: tools/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
60
Monitored processes
20
Malicious processes
6
Suspicious processes
2

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
756"C:\Users\admin\AppData\Local\Temp\3582-490\DefenderControl.exe" C:\Users\admin\AppData\Local\Temp\3582-490\DefenderControl.exe
DefenderControl.exe
User:
admin
Company:
www.sordum.org
Integrity Level:
HIGH
Description:
Windows Defender Control
Exit code:
0
Version:
1.6.0.0
Modules
Images
c:\users\admin\appdata\local\temp\3582-490\defendercontrol.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\version.dll
1220"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3152.0.1597503765\710754723" -parentBuildID 20230710165010 -prefsHandle 1112 -prefMapHandle 1104 -prefsLen 28739 -prefMapSize 244371 -appDir "C:\Program Files\Mozilla Firefox\browser" - {7bebf1b5-61a6-4f36-9389-0ba0eef0af01} 3152 "\\.\pipe\gecko-crash-server-pipe.3152" 1184 d9b2f20 gpuC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
1
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
1568"C:\Users\admin\Desktop\readonly.exe" C:\Users\admin\Desktop\readonly.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\readonly.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2008"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3152.1.2048980237\1487848407" -parentBuildID 20230710165010 -prefsHandle 1304 -prefMapHandle 1300 -prefsLen 28816 -prefMapSize 244371 -appDir "C:\Program Files\Mozilla Firefox\browser" - {28954994-6841-46fe-961f-b6cc96ff64f4} 3152 "\\.\pipe\gecko-crash-server-pipe.3152" 1316 d920070 socketC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
2060"C:\Users\admin\AppData\Local\Temp\3582-490\NS.exe" C:\Users\admin\AppData\Local\Temp\3582-490\NS.exeNS.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221225786
Modules
Images
c:\users\admin\appdata\local\temp\3582-490\ns.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\mpr.dll
2108"C:\Users\admin\Desktop\readonly.exe" C:\Users\admin\Desktop\readonly.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\readonly.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2152"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3152.2.869500721\1845405338" -childID 1 -isForBrowser -prefsHandle 1852 -prefMapHandle 1848 -prefsLen 28928 -prefMapSize 244371 -jsInitHandle 880 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {5e83d801-f0e6-4e48-809a-2fc3f85a42f2} 3152 "\\.\pipe\gecko-crash-server-pipe.3152" 1864 12d4b6d0 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
2512"C:\Users\admin\AppData\Local\Temp\3582-490\readonly.exe" C:\Users\admin\AppData\Local\Temp\3582-490\readonly.exe
readonly.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\3582-490\readonly.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
2624"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\tools.zipC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2744"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3152.5.2103731780\24921067" -childID 4 -isForBrowser -prefsHandle 3576 -prefMapHandle 3580 -prefsLen 29245 -prefMapSize 244371 -jsInitHandle 880 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {e277d25d-cf2b-4299-bf83-183038479064} 3152 "\\.\pipe\gecko-crash-server-pipe.3152" 3536 207b5560 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
Total events
13 904
Read events
13 804
Write events
95
Delete events
5

Modification events

(PID) Process:(2624) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2624) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2624) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2624) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2624) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2624) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2624) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2624) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2624) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(2624) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
Executable files
49
Suspicious files
202
Text files
30
Unknown types
0

Dropped files

PID
Process
Filename
Type
2940NS.exeC:\Users\admin\AppData\Local\Temp\3582-490\NS.exeexecutable
MD5:6BFFC6C7CAA2EB2FA90FAC0317F63338
SHA256:92C65B58C4925534C2CE78E54B0E11ECAF45ED8CF0344EBFF46CDFC4F2FE0D84
2624WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2624.25426\tools\NS.exeexecutable
MD5:B16522C76D4129C5381C2568B1E31581
SHA256:21F78B4D9829DB5E3E7D21FF3AD03991B9D00DF9D05518FF49B8CDFB2D46E282
2940NS.exeC:\MSOCache\All Users\{90140000-006E-0416-0000-0000000FF1CE}-C\DW20.EXEexecutable
MD5:02EE6A3424782531461FB2F10713D3C1
SHA256:EAD58C483CB20BCD57464F8A4929079539D634F469B213054BF737D227C026DC
2940NS.exeC:\MSOCache\All Users\{90140000-006E-0412-0000-0000000FF1CE}-C\DW20.EXEexecutable
MD5:02EE6A3424782531461FB2F10713D3C1
SHA256:EAD58C483CB20BCD57464F8A4929079539D634F469B213054BF737D227C026DC
2940NS.exeC:\MSOCache\All Users\{90140000-006E-0410-0000-0000000FF1CE}-C\DW20.EXEexecutable
MD5:02EE6A3424782531461FB2F10713D3C1
SHA256:EAD58C483CB20BCD57464F8A4929079539D634F469B213054BF737D227C026DC
2624WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2624.26437\tools\DefenderControl.initext
MD5:436BA365F9847A17824226930A0A8C7D
SHA256:294C26956691C3512FFC20C621AD95125341042683BBCE806EEAA33C12E8BBEE
2940NS.exeC:\MSOCache\All Users\{90140000-003D-0000-0000-0000000FF1CE}-C\ose.exeexecutable
MD5:58B58875A50A0D8B5E7BE7D6AC685164
SHA256:2A0AA0763FDEF9C38C5DD4D50703F0C7E27F4903C139804EC75E55F8388139AE
2624WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2624.25940\tools\DefenderControl.exeexecutable
MD5:D4531EFA4966994018145F9150545649
SHA256:CE162D2D3649A13A48510E79EF0046F9A194F9609C5EE0EE340766ABE1D1B565
2624WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2624.25031\tools\readonly.exeexecutable
MD5:05009F4A981B86A26073E40E358FD1A8
SHA256:23FA9076055DF20D9D8EE26A2597D850FF2B539014031F27210FC8C34D048F5F
2940NS.exeC:\MSOCache\All Users\{90140000-003D-0000-0000-0000000FF1CE}-C\setup.exeexecutable
MD5:566ED4F62FDC96F175AFEDD811FA0370
SHA256:E17CD94C08FC0E001A49F43A0801CEA4625FB9AEE211B6DFEBEBEC446C21F460
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
39
DNS requests
92
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3152
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
US
text
8 b
whitelisted
3152
firefox.exe
POST
200
172.217.16.195:80
http://o.pki.goog/we2
US
binary
281 b
whitelisted
3152
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
US
text
90 b
whitelisted
3152
firefox.exe
POST
200
172.217.16.195:80
http://o.pki.goog/s/wr3/W6c
US
binary
471 b
whitelisted
3152
firefox.exe
POST
200
172.217.16.195:80
http://o.pki.goog/s/wr3/vbw
US
binary
472 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:138
whitelisted
3152
firefox.exe
34.107.221.82:80
detectportal.firefox.com
GOOGLE
US
whitelisted
3152
firefox.exe
34.36.137.203:443
contile.services.mozilla.com
GOOGLE-CLOUD-PLATFORM
US
unknown
3152
firefox.exe
172.217.16.195:80
o.pki.goog
GOOGLE
US
whitelisted
3152
firefox.exe
34.107.243.93:443
push.services.mozilla.com
GOOGLE
US
whitelisted
3152
firefox.exe
151.101.1.91:443
firefox.settings.services.mozilla.com
FASTLY
US
whitelisted
3152
firefox.exe
34.160.144.191:443
content-signature-2.cdn.mozilla.net
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.186.46
whitelisted
detectportal.firefox.com
  • 34.107.221.82
whitelisted
prod.detectportal.prod.cloudops.mozgcp.net
  • 34.107.221.82
  • 2600:1901:0:38d7::
whitelisted
example.org
  • 23.215.0.132
  • 23.220.75.238
  • 23.215.0.133
  • 23.220.75.235
whitelisted
contile.services.mozilla.com
  • 34.36.137.203
whitelisted
spocs.getpocket.com
  • 34.36.137.203
whitelisted
ipv4only.arpa
  • 192.0.0.171
  • 192.0.0.170
whitelisted
firefox.settings.services.mozilla.com
  • 151.101.1.91
  • 151.101.129.91
  • 151.101.193.91
  • 151.101.65.91
whitelisted
mc.prod.ads.prod.webservices.mozgcp.net
  • 34.36.137.203
unknown
mozilla.map.fastly.net
  • 151.101.1.91
  • 151.101.129.91
  • 151.101.193.91
  • 151.101.65.91
  • 2a04:4e42:400::347
  • 2a04:4e42:200::347
  • 2a04:4e42:600::347
  • 2a04:4e42::347
unknown

Threats

No threats detected
No debug info