analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

Archive.zip

Full analysis: https://app.any.run/tasks/a48ad189-409c-4791-9b0d-300a8ab3692c
Verdict: Malicious activity
Analysis date: April 23, 2019, 14:38:40
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
macros
macros-on-open
maldoc-5
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

916A8D4DBB024E76000A0B11BF297DA2

SHA1:

9A7B75DAEED84BD1C3180E7B05EE4FAEA8A1138D

SHA256:

285170BABB05D05FFFA8702D442643DD0884E136D26704C3852AA6FFE001A2EA

SSDEEP:

1536:gaMSJ+zrIg3w8RviIuko75jM6cgF1bhthGpyyz:gbzrIYwPIHcQ6VF1NGz

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Unusual execution from Microsoft Office

      • EXCEL.EXE (PID: 3816)
      • EXCEL.EXE (PID: 3856)
    • Starts CMD.EXE for commands execution

      • EXCEL.EXE (PID: 3816)
      • EXCEL.EXE (PID: 3856)
    • Executes PowerShell scripts

      • cmD.exe (PID: 4088)
      • cmD.exe (PID: 3900)
  • SUSPICIOUS

    • Starts CMD.EXE for commands execution

      • cmD.exe (PID: 4088)
      • cmD.exe (PID: 3900)
    • Creates files in the user directory

      • powershell.exe (PID: 608)
      • powershell.exe (PID: 3336)
  • INFO

    • Creates files in the user directory

      • EXCEL.EXE (PID: 3816)
      • EXCEL.EXE (PID: 3856)
    • Reads Microsoft Office registry keys

      • EXCEL.EXE (PID: 3816)
      • EXCEL.EXE (PID: 3856)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2008:09:24 13:29:15
ZipCRC: 0x5c7c8e5f
ZipCompressedSize: 1140
ZipUncompressedSize: 2253
ZipFileName: Italiano.bat
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
56
Monitored processes
15
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs cmd.exe no specs tzutil.exe no specs certutil.exe no specs regedit.exe no specs regedit.exe no specs regedit.exe excel.exe no specs cmd.exe no specs cmd.exe no specs powershell.exe no specs excel.exe no specs cmd.exe no specs cmd.exe no specs powershell.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2832"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\Archive.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.60.0
2920cmd /c ""C:\Users\admin\Desktop\Italiano.bat" "C:\Windows\system32\cmd.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
3660tzutil /s "W. Europe Standard Time"C:\Windows\system32\tzutil.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Time Zone Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
2104certutil /decode "C:\Users\admin\AppData\Local\Temp\b64" "C:\Users\admin\AppData\Local\Temp\decoded" C:\Windows\system32\certutil.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
CertUtil.exe
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
3032regedit.exe /s "C:\Users\admin\AppData\Local\Temp\decoded"C:\Windows\regedit.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Registry Editor
Exit code:
3221226540
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
3508"C:\Windows\regedit.exe" /s "C:\Users\admin\AppData\Local\Temp\decoded"C:\Windows\regedit.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Registry Editor
Exit code:
3221226540
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
236"C:\Windows\regedit.exe" /s "C:\Users\admin\AppData\Local\Temp\decoded"C:\Windows\regedit.exe
cmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Registry Editor
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
3816"C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /ddeC:\Program Files\Microsoft Office\Office14\EXCEL.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Excel
Exit code:
0
Version:
14.0.6024.1000
4088cmD /C " EchO/^^^&( $Env:COMSPec[4,15,25]-jOiN'') (NEw-oBJEct IO.COMpREsSION.DeflAtEsTREAm( [syStem.Io.MeMoRysTrEaM] [conVeRt]::FROMbasE64sTrINg( '' ), [SYsTeM.io.coMPReSsIoN.COmPreSsIOnModE]::deCOmPreSS )^^^| fOReAch-OBjECt{NEw-oBJEct iO.stREAmREADeR( $_,[TexT.eNCoDiNg]::aSCiI )}).readtOEnd() | pOwerShEll -exeCutioNp bypASs -nOprOFIle -NOnIntE -WinD hidDEN ${execUTIonCOnteXt}.InvokeCoMmAnd.InVokEsCripT( ${iNput} )"C:\Windows\system32\cmD.exeEXCEL.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
3076C:\Windows\system32\cmd.exe /S /D /c" EchO/^&( $Env:COMSPec[4,15,25]-jOiN'') (NEw-oBJEct IO.COMpREsSION.DeflAtEsTREAm( [syStem.Io.MeMoRysTrEaM] [conVeRt]::FROMbasE64sTrINg( '' ), [SYsTeM.io.coMPReSsIoN.COmPreSsIOnModE]::deCOmPreSS )^| fOReAch-OBjECt{NEw-oBJEct iO.stREAmREADeR( $_,[TexT.eNCoDiNg]::aSCiI )}).readtOEnd() "C:\Windows\system32\cmd.execmD.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Total events
1 771
Read events
1 528
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
6
Text files
11
Unknown types
4

Dropped files

PID
Process
Filename
Type
3816EXCEL.EXEC:\Users\admin\AppData\Local\Temp\CVR41BF.tmp.cvr
MD5:
SHA256:
608powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\JCIX6XLVOT5RAAJ9Z4BQ.temp
MD5:
SHA256:
3816EXCEL.EXEC:\Users\admin\AppData\Local\Temp\~DFC85DAC1BFB406524.TMP
MD5:
SHA256:
3816EXCEL.EXEC:\Users\admin\AppData\Local\Temp\~DF7DBACBDE6DDBDEAA.TMP
MD5:
SHA256:
3856EXCEL.EXEC:\Users\admin\AppData\Local\Temp\CVRE4C1.tmp.cvr
MD5:
SHA256:
3336powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\M6T2AYVRG5UXQQ1CNHEH.temp
MD5:
SHA256:
3816EXCEL.EXEC:\Users\admin\Desktop\doc. n. 735-(5)_19 del 23-04-2019 CA 0054.xlsdocument
MD5:28D0A7CCD9A10B757E73987CE20A4F13
SHA256:37C892618E8FBAC96447755F7E534C28B21B8F607E226EEF3FAE8626E7DC4155
2920cmd.exeC:\Users\admin\AppData\Local\Temp\b64text
MD5:76B1CB245BB8EFC84B95B1A28FA8CAE0
SHA256:64CDFA15E887F48785B5E2AD3966AFB00CE35B88CD5176A7659950884C6A3CCB
2832WinRAR.exeC:\Users\admin\Desktop\Italiano.battext
MD5:A23A6695360512AA6664FA404D2A98A5
SHA256:5DEC32B67112693409931B60AC89843C2EA08460900F61B609BD9D0DA23B933C
3816EXCEL.EXEC:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\doc. n. 735-(5)_19 del 23-04-2019 CA 0054.xls.LNKlnk
MD5:CC555B3D23A04D450E9597CA69A148EC
SHA256:415CC4A33F1EDD217A598D24663E3D53DDECCAC97AEB23FE5FC0254836D35C4F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info