| File name: | Consignment Document PL&BL Draft.r00 |
| Full analysis: | https://app.any.run/tasks/b449bd61-badd-464b-8aa0-82d85cc6c0da |
| Verdict: | Malicious activity |
| Threats: | MassLogger is a credential stealer and keylogger first identified in April 2020. It has been actively used in cyber campaigns to exfiltrate sensitive information from compromised systems. It is designed for easy use by less tech-savvy actors and is prominent for the capability of spreading via USB drives. It targets both individuals and organizations in various industries, mostly in Europe and the USA. |
| Analysis date: | May 30, 2020, 05:17:42 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v5 |
| MD5: | 58995681F9389BC36866624D772C6F9F |
| SHA1: | 87115E9C0074EC127D1D6778FB0F661834E001D3 |
| SHA256: | 28B68458109EBCD6633290C6CC79134295B506DABD415CBD677F73AE36CDF166 |
| SSDEEP: | 12288:k91+tFA0/iohlukhRYWt2CPonUvzjpCVqKN14xvpGBkv:kGFF/Lh/bEAoUO9mv |
| .rar | | | RAR compressed archive (v5.0) (61.5) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2720 | "cmd" /c start /b powershell Start-Sleep -Seconds 2; Remove-Item -path 'C:\Users\admin\AppData\Local\Temp\Rar$EXa2788.23071\Consignment Document PL&BL Draft.exe' & exit | C:\Windows\system32\cmd.exe | — | Consignment Document PL&BL Draft.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 9009 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2788 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Consignment Document PL&BL Draft.r00.rar" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 3284 | powershell Start-Sleep -Seconds 2; Remove-Item -path 'C:\Users\admin\AppData\Local\Temp\Rar$EXa2788.23071\Consignment Document PL | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3684 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2788.23071\Consignment Document PL&BL Draft.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2788.23071\Consignment Document PL&BL Draft.exe | — | WinRAR.exe | |||||||||||
User: admin Company: 6Lw!i4$D2Rj@(p9 Integrity Level: MEDIUM Description: Mw4$i3@Y6Rx_Dc#78K Exit code: 0 Version: 9.14.19.24 Modules
| |||||||||||||||
| 3880 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2788.23071\Consignment Document PL&BL Draft.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2788.23071\Consignment Document PL&BL Draft.exe | Consignment Document PL&BL Draft.exe | ||||||||||||
User: admin Company: 6Lw!i4$D2Rj@(p9 Integrity Level: MEDIUM Description: Mw4$i3@Y6Rx_Dc#78K Exit code: 0 Version: 9.14.19.24 Modules
| |||||||||||||||
| (PID) Process: | (2788) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (2788) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (2788) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12F\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2788) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12F\52C64B7E |
| Operation: | write | Name: | @C:\Windows\system32\NetworkExplorer.dll,-1 |
Value: Network | |||
| (PID) Process: | (2788) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Consignment Document PL&BL Draft.r00.rar | |||
| (PID) Process: | (2788) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2788) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2788) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2788) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (2788) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3284 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\XTUI1BOBA3I8KBQDOW8W.temp | — | |
MD5:— | SHA256:— | |||
| 2788 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2788.23071\Consignment Document PL&BL Draft.exe | executable | |
MD5:— | SHA256:— | |||
| 3284 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms~RF8aa91.TMP | binary | |
MD5:— | SHA256:— | |||
| 3284 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms | binary | |
MD5:— | SHA256:— | |||