| File name: | tools.zip |
| Full analysis: | https://app.any.run/tasks/053aca59-bffd-4e25-97ce-afe5516ea98a |
| Verdict: | Malicious activity |
| Threats: | Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns. |
| Analysis date: | September 03, 2025, 17:55:00 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v1.0 to extract, compression method=store |
| MD5: | DE1D599F84FBD9416366654893A85C30 |
| SHA1: | 81F43CCEFF73D5F0BBBE62A978C6FD1D9C73B339 |
| SHA256: | 21880C2216C530058A7F63CD6C3FF5896D23000C40DDAADEF35146F2E0632ED4 |
| SSDEEP: | 49152:qEPHZi+bBqn7TaJO/jJQEEEWlXvfq9lY:qEPZi+FIWw7IEWhfL |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 10 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | None |
| ZipModifyDate: | 2021:10:04 11:46:02 |
| ZipCRC: | 0x00000000 |
| ZipCompressedSize: | - |
| ZipUncompressedSize: | - |
| ZipFileName: | tools/ |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 756 | "C:\Users\admin\AppData\Local\Temp\3582-490\DefenderControl.exe" | C:\Users\admin\AppData\Local\Temp\3582-490\DefenderControl.exe | DefenderControl.exe | ||||||||||||
User: admin Company: www.sordum.org Integrity Level: HIGH Description: Windows Defender Control Exit code: 0 Version: 1.6.0.0 Modules
| |||||||||||||||
| 1220 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3152.0.1597503765\710754723" -parentBuildID 20230710165010 -prefsHandle 1112 -prefMapHandle 1104 -prefsLen 28739 -prefMapSize 244371 -appDir "C:\Program Files\Mozilla Firefox\browser" - {7bebf1b5-61a6-4f36-9389-0ba0eef0af01} 3152 "\\.\pipe\gecko-crash-server-pipe.3152" 1184 d9b2f20 gpu | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 1 Version: 115.0.2 Modules
| |||||||||||||||
| 1568 | "C:\Users\admin\Desktop\readonly.exe" | C:\Users\admin\Desktop\readonly.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 2008 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3152.1.2048980237\1487848407" -parentBuildID 20230710165010 -prefsHandle 1304 -prefMapHandle 1300 -prefsLen 28816 -prefMapSize 244371 -appDir "C:\Program Files\Mozilla Firefox\browser" - {28954994-6841-46fe-961f-b6cc96ff64f4} 3152 "\\.\pipe\gecko-crash-server-pipe.3152" 1316 d920070 socket | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2060 | "C:\Users\admin\AppData\Local\Temp\3582-490\NS.exe" | C:\Users\admin\AppData\Local\Temp\3582-490\NS.exe | — | NS.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221225786 Modules
| |||||||||||||||
| 2108 | "C:\Users\admin\Desktop\readonly.exe" | C:\Users\admin\Desktop\readonly.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 2152 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3152.2.869500721\1845405338" -childID 1 -isForBrowser -prefsHandle 1852 -prefMapHandle 1848 -prefsLen 28928 -prefMapSize 244371 -jsInitHandle 880 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {5e83d801-f0e6-4e48-809a-2fc3f85a42f2} 3152 "\\.\pipe\gecko-crash-server-pipe.3152" 1864 12d4b6d0 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| 2512 | "C:\Users\admin\AppData\Local\Temp\3582-490\readonly.exe" | C:\Users\admin\AppData\Local\Temp\3582-490\readonly.exe | readonly.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 2624 | "C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\tools.zip | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 2744 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="3152.5.2103731780\24921067" -childID 4 -isForBrowser -prefsHandle 3576 -prefMapHandle 3580 -prefsLen 29245 -prefMapSize 244371 -jsInitHandle 880 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {e277d25d-cf2b-4299-bf83-183038479064} 3152 "\\.\pipe\gecko-crash-server-pipe.3152" 3536 207b5560 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 115.0.2 Modules
| |||||||||||||||
| (PID) Process: | (2624) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (2624) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (2624) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2624) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2624) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2624) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2624) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (2624) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (2624) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
| (PID) Process: | (2624) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\omni_23_10_2024_.zip | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2940 | NS.exe | C:\Users\admin\AppData\Local\Temp\3582-490\NS.exe | executable | |
MD5:6BFFC6C7CAA2EB2FA90FAC0317F63338 | SHA256:92C65B58C4925534C2CE78E54B0E11ECAF45ED8CF0344EBFF46CDFC4F2FE0D84 | |||
| 2624 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2624.25426\tools\NS.exe | executable | |
MD5:B16522C76D4129C5381C2568B1E31581 | SHA256:21F78B4D9829DB5E3E7D21FF3AD03991B9D00DF9D05518FF49B8CDFB2D46E282 | |||
| 2940 | NS.exe | C:\MSOCache\All Users\{90140000-006E-0416-0000-0000000FF1CE}-C\DW20.EXE | executable | |
MD5:02EE6A3424782531461FB2F10713D3C1 | SHA256:EAD58C483CB20BCD57464F8A4929079539D634F469B213054BF737D227C026DC | |||
| 2940 | NS.exe | C:\MSOCache\All Users\{90140000-006E-0412-0000-0000000FF1CE}-C\DW20.EXE | executable | |
MD5:02EE6A3424782531461FB2F10713D3C1 | SHA256:EAD58C483CB20BCD57464F8A4929079539D634F469B213054BF737D227C026DC | |||
| 2940 | NS.exe | C:\MSOCache\All Users\{90140000-006E-0410-0000-0000000FF1CE}-C\DW20.EXE | executable | |
MD5:02EE6A3424782531461FB2F10713D3C1 | SHA256:EAD58C483CB20BCD57464F8A4929079539D634F469B213054BF737D227C026DC | |||
| 2624 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2624.26437\tools\DefenderControl.ini | text | |
MD5:436BA365F9847A17824226930A0A8C7D | SHA256:294C26956691C3512FFC20C621AD95125341042683BBCE806EEAA33C12E8BBEE | |||
| 2940 | NS.exe | C:\MSOCache\All Users\{90140000-003D-0000-0000-0000000FF1CE}-C\ose.exe | executable | |
MD5:58B58875A50A0D8B5E7BE7D6AC685164 | SHA256:2A0AA0763FDEF9C38C5DD4D50703F0C7E27F4903C139804EC75E55F8388139AE | |||
| 2624 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2624.25940\tools\DefenderControl.exe | executable | |
MD5:D4531EFA4966994018145F9150545649 | SHA256:CE162D2D3649A13A48510E79EF0046F9A194F9609C5EE0EE340766ABE1D1B565 | |||
| 2624 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2624.25031\tools\readonly.exe | executable | |
MD5:05009F4A981B86A26073E40E358FD1A8 | SHA256:23FA9076055DF20D9D8EE26A2597D850FF2B539014031F27210FC8C34D048F5F | |||
| 2940 | NS.exe | C:\MSOCache\All Users\{90140000-003D-0000-0000-0000000FF1CE}-C\setup.exe | executable | |
MD5:566ED4F62FDC96F175AFEDD811FA0370 | SHA256:E17CD94C08FC0E001A49F43A0801CEA4625FB9AEE211B6DFEBEBEC446C21F460 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3152 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/success.txt?ipv4 | US | text | 8 b | whitelisted |
3152 | firefox.exe | POST | 200 | 172.217.16.195:80 | http://o.pki.goog/we2 | US | binary | 281 b | whitelisted |
3152 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/canonical.html | US | text | 90 b | whitelisted |
3152 | firefox.exe | POST | 200 | 172.217.16.195:80 | http://o.pki.goog/s/wr3/W6c | US | binary | 471 b | whitelisted |
3152 | firefox.exe | POST | 200 | 172.217.16.195:80 | http://o.pki.goog/s/wr3/vbw | US | binary | 472 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 224.0.0.252:5355 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
3152 | firefox.exe | 34.107.221.82:80 | detectportal.firefox.com | GOOGLE | US | whitelisted |
3152 | firefox.exe | 34.36.137.203:443 | contile.services.mozilla.com | GOOGLE-CLOUD-PLATFORM | US | unknown |
3152 | firefox.exe | 172.217.16.195:80 | o.pki.goog | GOOGLE | US | whitelisted |
3152 | firefox.exe | 34.107.243.93:443 | push.services.mozilla.com | GOOGLE | US | whitelisted |
3152 | firefox.exe | 151.101.1.91:443 | firefox.settings.services.mozilla.com | FASTLY | US | whitelisted |
3152 | firefox.exe | 34.160.144.191:443 | content-signature-2.cdn.mozilla.net | GOOGLE | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
detectportal.firefox.com |
| whitelisted |
prod.detectportal.prod.cloudops.mozgcp.net |
| whitelisted |
example.org |
| whitelisted |
contile.services.mozilla.com |
| whitelisted |
spocs.getpocket.com |
| whitelisted |
ipv4only.arpa |
| whitelisted |
firefox.settings.services.mozilla.com |
| whitelisted |
mc.prod.ads.prod.webservices.mozgcp.net |
| unknown |
mozilla.map.fastly.net |
| unknown |