File name: | 0efd95e4d3502e20b7120685050abae2.zip |
Full analysis: | https://app.any.run/tasks/f78ae84a-417e-43c0-bcc6-b9dbc704074e |
Verdict: | Malicious activity |
Analysis date: | May 21, 2022, 04:31:24 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/zip |
File info: | Zip archive data, at least v2.0 to extract |
MD5: | 7C5AE7CCCF850D72F2DFA17799290F00 |
SHA1: | D5D8F78230DB88F44CAD88935E10AC428044C456 |
SHA256: | 22D0F3491EC9FDEF84151E70A706EBCD4324298E1EFC5228CAE1DB4D1010B8DD |
SSDEEP: | 768:rT/VnUtLLSG+/uk1S84RBPsVBld4ALmiLQ2f:PWtV+/uk1bcPEBkBi3f |
.zip | | | ZIP compressed archive (100) |
---|
ZipFileName: | 0efd95e4d3502e20b7120685050abae2 |
---|---|
ZipUncompressedSize: | 44032 |
ZipCompressedSize: | 28909 |
ZipCRC: | 0x60c4e6c4 |
ZipModifyDate: | 2012:10:13 14:26:15 |
ZipCompression: | Deflated |
ZipBitFlag: | 0x0001 |
ZipRequiredVersion: | 20 |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
2832 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\0efd95e4d3502e20b7120685050abae2.zip" | C:\Program Files\WinRAR\WinRAR.exe | Explorer.EXE | |
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 | ||||
3356 | "C:\Users\admin\Desktop\0efd95e4d3502e20b7120685050abae2.exe" | C:\Users\admin\Desktop\0efd95e4d3502e20b7120685050abae2.exe | — | Explorer.EXE |
User: admin Company: mst software GmbH, Germany Integrity Level: MEDIUM Description: mst Defrag SDK Service Exit code: 0 Version: 3,6,0,6165 | ||||
2232 | "C:\Users\admin\Desktop\0efd95e4d3502e20b7120685050abae2.exe" | C:\Users\admin\Desktop\0efd95e4d3502e20b7120685050abae2.exe | — | Explorer.EXE |
User: admin Company: mst software GmbH, Germany Integrity Level: MEDIUM Description: mst Defrag SDK Service Exit code: 0 Version: 3,6,0,6165 | ||||
2540 | "C:\Users\admin\Desktop\0efd95e4d3502e20b7120685050abae2.exe" | C:\Users\admin\Desktop\0efd95e4d3502e20b7120685050abae2.exe | Explorer.EXE | |
User: admin Company: mst software GmbH, Germany Integrity Level: HIGH Description: mst Defrag SDK Service Exit code: 0 Version: 3,6,0,6165 | ||||
2496 | "C:\Windows\System32\control.exe" "C:\Windows\System32\timedate.cpl", | C:\Windows\System32\control.exe | — | Explorer.EXE |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Control Panel Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
3660 | "C:\Windows\system32\rundll32.exe" Shell32.dll,Control_RunDLL "C:\Windows\System32\timedate.cpl", | C:\Windows\system32\rundll32.exe | — | control.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
3516 | C:\Windows\system32\DllHost.exe /Processid:{9DF523B0-A6C0-4EA9-B5F1-F4565C3AC8B8} | C:\Windows\system32\DllHost.exe | — | svchost.exe |
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: COM Surrogate Version: 6.1.7600.16385 (win7_rtm.090713-1255) |
(PID) Process: | (2832) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtBMP |
Value: | |||
(PID) Process: | (2832) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtIcon |
Value: | |||
(PID) Process: | (2832) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (2832) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
(PID) Process: | (2832) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
(PID) Process: | (2832) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\0efd95e4d3502e20b7120685050abae2.zip | |||
(PID) Process: | (2832) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | name |
Value: 120 | |||
(PID) Process: | (2832) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | size |
Value: 80 | |||
(PID) Process: | (2832) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | type |
Value: 120 | |||
(PID) Process: | (2832) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | mtime |
Value: 100 |
PID | Process | Filename | Type | |
---|---|---|---|---|
2832 | WinRAR.exe | C:\Users\admin\Desktop\0efd95e4d3502e20b7120685050abae2 | executable | |
MD5:0EFD95E4D3502E20B7120685050ABAE2 | SHA256:E19C8F1EA80D6CF9D3348A07C7428BBCDFC66EA5A192F63E22A8E29CFDA5AAF0 |
Domain | IP | Reputation |
---|---|---|
destromas.com |
| unknown |
alexdecorris.com |
| unknown |
bowsessexifid.com |
| unknown |
ferchogaetz.com |
| unknown |
toffieconciati.com |
| unknown |
mostestwaes.com |
| unknown |