| File name: | TFM Pgiex Client v6.zip |
| Full analysis: | https://app.any.run/tasks/24080cb3-e1bd-412c-8a38-de3712a8a4c7 |
| Verdict: | Malicious activity |
| Analysis date: | February 06, 2022, 19:56:22 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | CDBB36E31429222672198D13FA2ECF09 |
| SHA1: | 77310F77ACF474E8A2A2BFD55461EA4C7F6BAF32 |
| SHA256: | 23F9B243882F95EB2FB6EEA5DE1E63658F2395823F927568D50AAC8AEA8ACF35 |
| SSDEEP: | 196608:K6fZOUWT7cKSUFP94Vntzu2FT6Brx/33R4ikdV/20kRsgLlYRKCnnnphKlb3WZa5:KD7nSUFUnRpFeB9p4ljlktLlYQ6gWZuv |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipFileName: | AdobeAIR.exe |
|---|---|
| ZipUncompressedSize: | 7689512 |
| ZipCompressedSize: | 7351309 |
| ZipCRC: | 0xeaed1e2b |
| ZipModifyDate: | 2021:03:25 12:16:14 |
| ZipCompression: | Deflated |
| ZipBitFlag: | - |
| ZipRequiredVersion: | 20 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2068 | "c:\Program Files\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe" -installupdatecheck | c:\Program Files\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe | Adobe AIR Installer.exe | ||||||||||||
User: admin Company: Adobe Integrity Level: MEDIUM Description: Adobe AIR Installer Exit code: 0 Version: 33.1.1.385 Modules
| |||||||||||||||
| 2136 | "C:\Users\admin\Desktop\TFM Pgiex Client v6\TFMClient - Pgiex Tfm.exe" | C:\Users\admin\Desktop\TFM Pgiex Client v6\TFMClient - Pgiex Tfm.exe | Explorer.EXE | ||||||||||||
User: admin Integrity Level: MEDIUM Description: TFMClient - Pgiex Tfm Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 2824 | "C:\0343508a-1741-4891-84da-05c4846283be\TFMClient - Pgiex Tfm.exe" | C:\0343508a-1741-4891-84da-05c4846283be\TFMClient - Pgiex Tfm.exe | TFMClient - Pgiex Tfm.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 2940 | "C:\Users\admin\appdata\local\temp\air7bdd.tmp\adobe air installer.exe" -stdio \\.\pipe\AIR_3192_0 -ei | C:\Users\admin\appdata\local\temp\air7bdd.tmp\adobe air installer.exe | Adobe AIR Installer.exe | ||||||||||||
User: admin Company: Adobe Integrity Level: HIGH Description: Adobe AIR Installer Exit code: 0 Version: 33.1.1.385 Modules
| |||||||||||||||
| 2984 | "C:\Users\admin\Desktop\AdobeAIR.exe" | C:\Users\admin\Desktop\AdobeAIR.exe | Explorer.EXE | ||||||||||||
User: admin Company: Adobe Integrity Level: MEDIUM Description: Adobe AIR Installer Exit code: 0 Version: 33.1.1.385 Modules
| |||||||||||||||
| 3164 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\TFM Pgiex Client v6.zip" | C:\Program Files\WinRAR\WinRAR.exe | Explorer.EXE | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 3192 | "C:\Users\admin\AppData\Local\Temp\AIR7BDD.tmp\Adobe AIR Installer.exe" | C:\Users\admin\AppData\Local\Temp\AIR7BDD.tmp\Adobe AIR Installer.exe | AdobeAIR.exe | ||||||||||||
User: admin Company: Adobe Integrity Level: MEDIUM Description: Adobe AIR Installer Exit code: 0 Version: 33.1.1.385 Modules
| |||||||||||||||
| 3204 | "C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" | C:\Windows\system32\SearchProtocolHost.exe | — | SearchIndexer.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft Windows Search Protocol Host Exit code: 0 Version: 7.00.7601.24542 (win7sp1_ldr_escrow.191209-2211) Modules
| |||||||||||||||
| 3400 | "C:\0343508a-1741-4891-84da-05c4846283be\Pgiex - Transformice SWF Updater.exe" | C:\0343508a-1741-4891-84da-05c4846283be\Pgiex - Transformice SWF Updater.exe | TFMClient - Pgiex Tfm.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: Pgiex - Transformice SWF Updater Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 3696 | C:\Windows\system32\msiexec.exe /V | C:\Windows\system32\msiexec.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows� installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (3164) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3164) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3164) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3164) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (3164) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (3164) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\TFM Pgiex Client v6.zip | |||
| (PID) Process: | (3164) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3164) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3164) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3164) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2984 | AdobeAIR.exe | C:\Users\admin\AppData\Local\Temp\AIR7BDD.tmp\Adobe AIR\Versions\1.0\Resources\Licenses\cairo\COPYING | text | |
MD5:EF5A4E944085278EB1A7B7A881CCEAF6 | SHA256:4FDCDE2E1F6AEB1DF3D767A8330AFF6ED6E6C0031D3C8EA72E95620613B4F827 | |||
| 2984 | AdobeAIR.exe | C:\Users\admin\AppData\Local\Temp\AIR7BDD.tmp\Adobe AIR\sentinel | text | |
MD5:A5C11CA014FE30B8085EA2E95F7196C4 | SHA256:096E4BFD9F7E1FAF15058C0A0FE45E6DBD00E3E1360F21F2CA92BCE16A9A919A | |||
| 2984 | AdobeAIR.exe | C:\Users\admin\AppData\Local\Temp\AIR7BDD.tmp\Adobe AIR\Versions\1.0\Resources\Licenses\pixman\COPYING | text | |
MD5:1168F6DA9F901D48731A7D51940FECAD | SHA256:6E9F39A63E6E8AE87DE8AFDF5E7E9571B964A52717614EDB84675016042F6AFC | |||
| 2984 | AdobeAIR.exe | C:\Users\admin\AppData\Local\Temp\AIR7BDD.tmp\Adobe AIR\Versions\1.0\Adobe AIR Application Installer.swf | swf | |
MD5:9C9D13B4EBCE6056466C3ECED7A60631 | SHA256:54C854CB8DE91C1FCC05BF9ACE5EE71E98E7ECDC80D234EFF54AC1318C43CC9F | |||
| 2984 | AdobeAIR.exe | C:\Users\admin\AppData\Local\Temp\AIR7BDD.tmp\Adobe AIR\Versions\1.0\Resources\template.msi | executable | |
MD5:32FF6AEB858F568659329935919BA4BB | SHA256:6F71B263DA13DFD79E16CA35C49CA39AD0EC370F902FB87E9C8F9395FA9A41E8 | |||
| 2984 | AdobeAIR.exe | C:\Users\admin\AppData\Local\Temp\AIR7BDD.tmp\Adobe AIR\Versions\1.0\Resources\setup.swf | swf | |
MD5:60CB4BC16891B669EDD5D7094CE403F1 | SHA256:3DDC574F0DB25A3C18EF30A448057FA48851F7CCA195258347CAB156C5BB7673 | |||
| 2984 | AdobeAIR.exe | C:\Users\admin\AppData\Local\Temp\AIR7BDD.tmp\setup.swf | swf | |
MD5:60CB4BC16891B669EDD5D7094CE403F1 | SHA256:3DDC574F0DB25A3C18EF30A448057FA48851F7CCA195258347CAB156C5BB7673 | |||
| 3164 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3164.5179\TFM Pgiex Client v6\TFMClient - Pgiex Tfm.exe | executable | |
MD5:08773F1A4562128900D33D360BCE85E1 | SHA256:AD479BF73BD329475B843C4A1786796C3F202D71F5D1C41CA8E5DA3B40CDED7E | |||
| 3164 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3164.5179\TFM Pgiex Client v6\Interop.ShockwaveFlashObjects.dll | executable | |
MD5:06A3F066769840D59803A363E4085C18 | SHA256:71F163FDCBF8E488F27005B4AEF2667F94EB6528BEF549B90AB215F50672F3B3 | |||
| 2984 | AdobeAIR.exe | C:\Users\admin\AppData\Local\Temp\AIR7BDD.tmp\setup.msi | executable | |
MD5:381D4D2D2BAD85B27BE8D46E9692679C | SHA256:7194FBE6883C6D4535CF7EF80CF7CC9349523C1DBF71B84564FA702A425DE216 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2136 | TFMClient - Pgiex Tfm.exe | GET | 204 | 142.250.186.78:80 | http://google.com/generate_204 | US | — | — | malicious |
2824 | TFMClient - Pgiex Tfm.exe | GET | 200 | 51.75.128.119:80 | http://www.transformice.com/images/x_bibliotheques/x_meli_costumes.swf?d=685.695?d=685 | GB | swf | 599 Kb | suspicious |
2824 | TFMClient - Pgiex Tfm.exe | GET | 200 | 51.75.128.119:80 | http://www.transformice.com/images/x_bibliotheques/costume1.swf?d=685.695?d=685 | GB | swf | 28.8 Kb | suspicious |
2068 | Adobe AIR Updater.exe | GET | 200 | 52.222.206.73:80 | http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwZ%2FlFeFh%2Bisd96yUzJbvJmLVg0%3D | US | der | 1.39 Kb | shared |
2068 | Adobe AIR Updater.exe | GET | 200 | 13.32.118.159:80 | http://ocsp.sca1b.amazontrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQz9arGHWbnBV0DFzpNHz4YcTiFDQQUWaRmBlKge5WSPKOUByeWdFv5PdACEArnLp9awM69gd%2BIe6rguv0%3D | US | der | 471 b | whitelisted |
2068 | Adobe AIR Updater.exe | GET | 200 | 52.222.206.67:80 | http://ocsp.rootg2.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBSIfaREXmfqfJR3TkMYnD7O5MhzEgQUnF8A36oB1zArOIiiuG1KnPIRkYMCEwZ%2FlEoqJ83z%2BsKuKwH5CO65xMY%3D | US | der | 1.51 Kb | whitelisted |
2824 | TFMClient - Pgiex Tfm.exe | GET | 200 | 140.82.36.185:80 | http://transformice.bolcorp.icu/Client/files/php/checkA.php?hbid=0343508a-1741-4891-84da-05c4846283be&pID=true&pgc=5422712378355&vb=27218939289784977846818752897139931&sl=null&d=1644177467589 | US | text | 2.16 Kb | suspicious |
2824 | TFMClient - Pgiex Tfm.exe | GET | 200 | 51.75.128.119:80 | http://www.transformice.com/images/x_bibliotheques/fourrures/f223.swf?d=685.695?d=685 | GB | swf | 9.12 Kb | suspicious |
2824 | TFMClient - Pgiex Tfm.exe | GET | 200 | 51.75.128.119:80 | http://www.transformice.com/images/x_bibliotheques/x_fourrures.swf?d=685.695?d=685 | GB | swf | 152 Kb | suspicious |
2824 | TFMClient - Pgiex Tfm.exe | GET | 200 | 51.75.128.119:80 | http://www.transformice.com/images/drapeaux/64/PL.png?d=695 | GB | image | 1.45 Kb | suspicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2136 | TFMClient - Pgiex Tfm.exe | 142.250.186.78:80 | google.com | Google Inc. | US | whitelisted |
2068 | Adobe AIR Updater.exe | 54.144.96.229:443 | airsdk.harman.com | Amazon.com, Inc. | US | unknown |
2068 | Adobe AIR Updater.exe | 67.27.233.254:80 | ctldl.windowsupdate.com | Level 3 Communications, Inc. | US | suspicious |
2136 | TFMClient - Pgiex Tfm.exe | 140.82.36.185:443 | bolcorp.icu | — | US | suspicious |
2068 | Adobe AIR Updater.exe | 18.66.92.28:80 | o.ss2.us | Massachusetts Institute of Technology | US | suspicious |
2136 | TFMClient - Pgiex Tfm.exe | 67.27.233.254:80 | ctldl.windowsupdate.com | Level 3 Communications, Inc. | US | suspicious |
2068 | Adobe AIR Updater.exe | 52.222.206.73:80 | ocsp.rootg2.amazontrust.com | Amazon.com, Inc. | US | whitelisted |
2068 | Adobe AIR Updater.exe | 13.32.118.159:80 | ocsp.sca1b.amazontrust.com | Amazon.com, Inc. | US | whitelisted |
2068 | Adobe AIR Updater.exe | 52.222.206.67:80 | ocsp.rootg2.amazontrust.com | Amazon.com, Inc. | US | whitelisted |
3400 | Pgiex - Transformice SWF Updater.exe | 140.82.36.185:443 | bolcorp.icu | — | US | suspicious |
Domain | IP | Reputation |
|---|---|---|
airsdk.harman.com |
| suspicious |
ctldl.windowsupdate.com |
| whitelisted |
google.com |
| malicious |
bolcorp.icu |
| malicious |
o.ss2.us |
| whitelisted |
ocsp.rootg2.amazontrust.com |
| whitelisted |
ocsp.rootca1.amazontrust.com |
| shared |
ocsp.sca1b.amazontrust.com |
| whitelisted |
transformice.bolcorp.icu |
| suspicious |
discordapp.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
— | — | Potentially Bad Traffic | ET INFO DNS Query for Suspicious .icu Domain |
2136 | TFMClient - Pgiex Tfm.exe | Potentially Bad Traffic | ET INFO Suspicious Domain (*.icu) in TLS SNI |
2136 | TFMClient - Pgiex Tfm.exe | Potentially Bad Traffic | ET INFO Observed Let's Encrypt Certificate for Suspicious TLD (.icu) |
2136 | TFMClient - Pgiex Tfm.exe | Potentially Bad Traffic | ET INFO Observed Let's Encrypt Certificate for Suspicious TLD (.icu) |
2136 | TFMClient - Pgiex Tfm.exe | Potentially Bad Traffic | ET INFO Observed Let's Encrypt Certificate for Suspicious TLD (.icu) |
3400 | Pgiex - Transformice SWF Updater.exe | Potentially Bad Traffic | ET INFO Observed Let's Encrypt Certificate for Suspicious TLD (.icu) |
3400 | Pgiex - Transformice SWF Updater.exe | Potentially Bad Traffic | ET INFO Observed Let's Encrypt Certificate for Suspicious TLD (.icu) |
2824 | TFMClient - Pgiex Tfm.exe | Potential Corporate Privacy Violation | ET POLICY Outdated Flash Version M1 |
2824 | TFMClient - Pgiex Tfm.exe | Potential Corporate Privacy Violation | ET INFO Observed Interesting Content-Type Inbound (application/x-sh) |
2824 | TFMClient - Pgiex Tfm.exe | Potential Corporate Privacy Violation | ET INFO Observed Interesting Content-Type Inbound (application/x-sh) |