| File name: | TFM Pgiex Client v6.zip |
| Full analysis: | https://app.any.run/tasks/24080cb3-e1bd-412c-8a38-de3712a8a4c7 |
| Verdict: | Malicious activity |
| Analysis date: | February 06, 2022, 19:56:22 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | CDBB36E31429222672198D13FA2ECF09 |
| SHA1: | 77310F77ACF474E8A2A2BFD55461EA4C7F6BAF32 |
| SHA256: | 23F9B243882F95EB2FB6EEA5DE1E63658F2395823F927568D50AAC8AEA8ACF35 |
| SSDEEP: | 196608:K6fZOUWT7cKSUFP94Vntzu2FT6Brx/33R4ikdV/20kRsgLlYRKCnnnphKlb3WZa5:KD7nSUFUnRpFeB9p4ljlktLlYQ6gWZuv |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipFileName: | AdobeAIR.exe |
|---|---|
| ZipUncompressedSize: | 7689512 |
| ZipCompressedSize: | 7351309 |
| ZipCRC: | 0xeaed1e2b |
| ZipModifyDate: | 2021:03:25 12:16:14 |
| ZipCompression: | Deflated |
| ZipBitFlag: | - |
| ZipRequiredVersion: | 20 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2068 | "c:\Program Files\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe" -installupdatecheck | c:\Program Files\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe | Adobe AIR Installer.exe | ||||||||||||
User: admin Company: Adobe Integrity Level: MEDIUM Description: Adobe AIR Installer Exit code: 0 Version: 33.1.1.385 Modules
| |||||||||||||||
| 2136 | "C:\Users\admin\Desktop\TFM Pgiex Client v6\TFMClient - Pgiex Tfm.exe" | C:\Users\admin\Desktop\TFM Pgiex Client v6\TFMClient - Pgiex Tfm.exe | Explorer.EXE | ||||||||||||
User: admin Integrity Level: MEDIUM Description: TFMClient - Pgiex Tfm Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 2824 | "C:\0343508a-1741-4891-84da-05c4846283be\TFMClient - Pgiex Tfm.exe" | C:\0343508a-1741-4891-84da-05c4846283be\TFMClient - Pgiex Tfm.exe | TFMClient - Pgiex Tfm.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 2940 | "C:\Users\admin\appdata\local\temp\air7bdd.tmp\adobe air installer.exe" -stdio \\.\pipe\AIR_3192_0 -ei | C:\Users\admin\appdata\local\temp\air7bdd.tmp\adobe air installer.exe | Adobe AIR Installer.exe | ||||||||||||
User: admin Company: Adobe Integrity Level: HIGH Description: Adobe AIR Installer Exit code: 0 Version: 33.1.1.385 Modules
| |||||||||||||||
| 2984 | "C:\Users\admin\Desktop\AdobeAIR.exe" | C:\Users\admin\Desktop\AdobeAIR.exe | Explorer.EXE | ||||||||||||
User: admin Company: Adobe Integrity Level: MEDIUM Description: Adobe AIR Installer Exit code: 0 Version: 33.1.1.385 Modules
| |||||||||||||||
| 3164 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\TFM Pgiex Client v6.zip" | C:\Program Files\WinRAR\WinRAR.exe | Explorer.EXE | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 3192 | "C:\Users\admin\AppData\Local\Temp\AIR7BDD.tmp\Adobe AIR Installer.exe" | C:\Users\admin\AppData\Local\Temp\AIR7BDD.tmp\Adobe AIR Installer.exe | AdobeAIR.exe | ||||||||||||
User: admin Company: Adobe Integrity Level: MEDIUM Description: Adobe AIR Installer Exit code: 0 Version: 33.1.1.385 Modules
| |||||||||||||||
| 3204 | "C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" | C:\Windows\system32\SearchProtocolHost.exe | — | SearchIndexer.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft Windows Search Protocol Host Exit code: 0 Version: 7.00.7601.24542 (win7sp1_ldr_escrow.191209-2211) Modules
| |||||||||||||||
| 3400 | "C:\0343508a-1741-4891-84da-05c4846283be\Pgiex - Transformice SWF Updater.exe" | C:\0343508a-1741-4891-84da-05c4846283be\Pgiex - Transformice SWF Updater.exe | TFMClient - Pgiex Tfm.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: Pgiex - Transformice SWF Updater Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 3696 | C:\Windows\system32\msiexec.exe /V | C:\Windows\system32\msiexec.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows� installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (3164) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3164) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3164) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3164) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (3164) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (3164) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\TFM Pgiex Client v6.zip | |||
| (PID) Process: | (3164) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3164) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3164) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3164) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2984 | AdobeAIR.exe | C:\Users\admin\AppData\Local\Temp\AIR7BDD.tmp\Adobe AIR\Versions\1.0\Resources\Licenses\pixman\COPYING | text | |
MD5:1168F6DA9F901D48731A7D51940FECAD | SHA256:6E9F39A63E6E8AE87DE8AFDF5E7E9571B964A52717614EDB84675016042F6AFC | |||
| 2984 | AdobeAIR.exe | C:\Users\admin\AppData\Local\Temp\AIR7BDD.tmp\Adobe AIR\Versions\1.0\Resources\template.msi | executable | |
MD5:32FF6AEB858F568659329935919BA4BB | SHA256:6F71B263DA13DFD79E16CA35C49CA39AD0EC370F902FB87E9C8F9395FA9A41E8 | |||
| 2984 | AdobeAIR.exe | C:\Users\admin\AppData\Local\Temp\AIR7BDD.tmp\Adobe AIR\sentinel | text | |
MD5:A5C11CA014FE30B8085EA2E95F7196C4 | SHA256:096E4BFD9F7E1FAF15058C0A0FE45E6DBD00E3E1360F21F2CA92BCE16A9A919A | |||
| 2984 | AdobeAIR.exe | C:\Users\admin\AppData\Local\Temp\AIR7BDD.tmp\Adobe AIR\Versions\1.0\Resources\setup.swf | swf | |
MD5:60CB4BC16891B669EDD5D7094CE403F1 | SHA256:3DDC574F0DB25A3C18EF30A448057FA48851F7CCA195258347CAB156C5BB7673 | |||
| 2984 | AdobeAIR.exe | C:\Users\admin\AppData\Local\Temp\AIR7BDD.tmp\Adobe AIR\Versions\1.0\Adobe AIR Application Installer.swf | swf | |
MD5:9C9D13B4EBCE6056466C3ECED7A60631 | SHA256:54C854CB8DE91C1FCC05BF9ACE5EE71E98E7ECDC80D234EFF54AC1318C43CC9F | |||
| 2984 | AdobeAIR.exe | C:\Users\admin\AppData\Local\Temp\AIR7BDD.tmp\Adobe AIR\Versions\1.0\Resources\WebKit\LGPL License.txt | text | |
MD5:8C2A8D5DB686D0E41323611A1DCABB67 | SHA256:98B84A0EF7B265DFD8C4796BC03EFF27EBCE5491026798C14508D80049434FEB | |||
| 2984 | AdobeAIR.exe | C:\Users\admin\AppData\Local\Temp\AIR7BDD.tmp\Adobe AIR\Versions\1.0\Resources\Licenses\pcre2\COPYING | text | |
MD5:1F800C179F381B72E818AAB4BA25C504 | SHA256:4F8DEFD8B03D6E0DF53C3A37FD37CAF2BD8A5E8E77F7886FE3557BA4CDA45E8C | |||
| 3164 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3164.5707\AdobeAIR.exe | executable | |
MD5:CE0059C94FD5F8099E54F85FF204B511 | SHA256:D5C8659A712145CC19B4E23FF0C731C87FEFC5C100D98C963A2689C5FD97A96C | |||
| 2984 | AdobeAIR.exe | C:\Users\admin\AppData\Local\Temp\AIR7BDD.tmp\Adobe AIR\Versions\1.0\Resources\Adobe Root Certificate.cer | der | |
MD5:BF70913FF8D6D60A47FE825330815DB4 | SHA256:944E66AA967BD390952D22426BF1DFCD379A2C87A21B942FBCA79F41F0354AAC | |||
| 3164 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3164.5179\TFM Pgiex Client v6\TFMClient - Pgiex Tfm.exe | executable | |
MD5:08773F1A4562128900D33D360BCE85E1 | SHA256:AD479BF73BD329475B843C4A1786796C3F202D71F5D1C41CA8E5DA3B40CDED7E | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2136 | TFMClient - Pgiex Tfm.exe | GET | 204 | 142.250.186.78:80 | http://google.com/generate_204 | US | — | — | malicious |
2068 | Adobe AIR Updater.exe | GET | 200 | 52.222.206.67:80 | http://ocsp.rootg2.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBSIfaREXmfqfJR3TkMYnD7O5MhzEgQUnF8A36oB1zArOIiiuG1KnPIRkYMCEwZ%2FlEoqJ83z%2BsKuKwH5CO65xMY%3D | US | der | 1.51 Kb | whitelisted |
2068 | Adobe AIR Updater.exe | GET | 200 | 18.66.92.28:80 | http://o.ss2.us//MEowSDBGMEQwQjAJBgUrDgMCGgUABBSLwZ6EW5gdYc9UaSEaaLjjETNtkAQUv1%2B30c7dH4b0W1Ws3NcQwg6piOcCCQCnDkpMNIK3fw%3D%3D | US | der | 1.70 Kb | whitelisted |
2824 | TFMClient - Pgiex Tfm.exe | GET | 200 | 51.75.128.119:80 | http://www.transformice.com/langues/tfm-pl.gz?d=695 | GB | pz | 52.8 Kb | suspicious |
2824 | TFMClient - Pgiex Tfm.exe | GET | 200 | 51.75.128.119:80 | http://www.transformice.com/images/x_bibliotheques/x_meli_costumes.swf?d=685.695?d=685 | GB | swf | 599 Kb | suspicious |
2824 | TFMClient - Pgiex Tfm.exe | GET | 200 | 51.75.128.119:80 | http://www.transformice.com/images/x_bibliotheques/costume1.swf?d=685.695?d=685 | GB | swf | 28.8 Kb | suspicious |
2068 | Adobe AIR Updater.exe | GET | 200 | 13.32.118.159:80 | http://ocsp.sca1b.amazontrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQz9arGHWbnBV0DFzpNHz4YcTiFDQQUWaRmBlKge5WSPKOUByeWdFv5PdACEArnLp9awM69gd%2BIe6rguv0%3D | US | der | 471 b | whitelisted |
2824 | TFMClient - Pgiex Tfm.exe | GET | 200 | 51.75.128.119:80 | http://www.transformice.com/images/x_bibliotheques/fourrures/f222.swf?d=685.695?d=685 | GB | swf | 8.47 Kb | suspicious |
2824 | TFMClient - Pgiex Tfm.exe | GET | 200 | 212.47.246.230:80 | http://audio.atelier801.com/transformice/musique/intro.mp3 | FR | mp3 | 931 Kb | suspicious |
2824 | TFMClient - Pgiex Tfm.exe | GET | 200 | 51.75.128.119:80 | http://www.transformice.com/images/x_bibliotheques/fourrures/f223.swf?d=685.695?d=685 | GB | swf | 9.12 Kb | suspicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2136 | TFMClient - Pgiex Tfm.exe | 142.250.186.78:80 | google.com | Google Inc. | US | whitelisted |
2068 | Adobe AIR Updater.exe | 54.144.96.229:443 | airsdk.harman.com | Amazon.com, Inc. | US | unknown |
2068 | Adobe AIR Updater.exe | 67.27.233.254:80 | ctldl.windowsupdate.com | Level 3 Communications, Inc. | US | suspicious |
2136 | TFMClient - Pgiex Tfm.exe | 140.82.36.185:443 | bolcorp.icu | — | US | suspicious |
2068 | Adobe AIR Updater.exe | 13.32.118.159:80 | ocsp.sca1b.amazontrust.com | Amazon.com, Inc. | US | whitelisted |
2824 | TFMClient - Pgiex Tfm.exe | 140.82.36.185:80 | bolcorp.icu | — | US | suspicious |
2136 | TFMClient - Pgiex Tfm.exe | 162.159.134.233:443 | discordapp.com | Cloudflare Inc | — | shared |
2824 | TFMClient - Pgiex Tfm.exe | 37.187.29.8:11801 | — | OVH SAS | FR | malicious |
2824 | TFMClient - Pgiex Tfm.exe | 51.75.128.119:80 | www.transformice.com | — | GB | suspicious |
2824 | TFMClient - Pgiex Tfm.exe | 51.158.113.197:80 | — | — | GB | suspicious |
Domain | IP | Reputation |
|---|---|---|
airsdk.harman.com |
| suspicious |
ctldl.windowsupdate.com |
| whitelisted |
google.com |
| malicious |
bolcorp.icu |
| malicious |
o.ss2.us |
| whitelisted |
ocsp.rootg2.amazontrust.com |
| whitelisted |
ocsp.rootca1.amazontrust.com |
| shared |
ocsp.sca1b.amazontrust.com |
| whitelisted |
transformice.bolcorp.icu |
| suspicious |
discordapp.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
— | — | Potentially Bad Traffic | ET INFO DNS Query for Suspicious .icu Domain |
2136 | TFMClient - Pgiex Tfm.exe | Potentially Bad Traffic | ET INFO Suspicious Domain (*.icu) in TLS SNI |
2136 | TFMClient - Pgiex Tfm.exe | Potentially Bad Traffic | ET INFO Observed Let's Encrypt Certificate for Suspicious TLD (.icu) |
2136 | TFMClient - Pgiex Tfm.exe | Potentially Bad Traffic | ET INFO Observed Let's Encrypt Certificate for Suspicious TLD (.icu) |
2136 | TFMClient - Pgiex Tfm.exe | Potentially Bad Traffic | ET INFO Observed Let's Encrypt Certificate for Suspicious TLD (.icu) |
3400 | Pgiex - Transformice SWF Updater.exe | Potentially Bad Traffic | ET INFO Observed Let's Encrypt Certificate for Suspicious TLD (.icu) |
3400 | Pgiex - Transformice SWF Updater.exe | Potentially Bad Traffic | ET INFO Observed Let's Encrypt Certificate for Suspicious TLD (.icu) |
2824 | TFMClient - Pgiex Tfm.exe | Potential Corporate Privacy Violation | ET POLICY Outdated Flash Version M1 |
2824 | TFMClient - Pgiex Tfm.exe | Potential Corporate Privacy Violation | ET INFO Observed Interesting Content-Type Inbound (application/x-sh) |
2824 | TFMClient - Pgiex Tfm.exe | Potential Corporate Privacy Violation | ET INFO Observed Interesting Content-Type Inbound (application/x-sh) |