| File name: | Win32.zip |
| Full analysis: | https://app.any.run/tasks/48aa0e24-13d1-4922-b59e-a54731b72246 |
| Verdict: | Malicious activity |
| Analysis date: | March 10, 2024, 23:28:50 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v4.5 to extract, compression method=deflate |
| MD5: | B251B30E1035C263C629C320F2C372E3 |
| SHA1: | A2B0C01EB6FCBB92FC6335ABB1522BA344651673 |
| SHA256: | 2B480727BE5CBF562BC6CBC8F4D840292451B703D20934B6C78DE8D2BF744E9C |
| SSDEEP: | 24576:JAzqvDYufXiUGYt3fYIeaYz9nhb8DOzVOiwjFmj/BtuGy6OkRS:JAzqvDYufXiUGYt3fYIeaYZnhb8DOzV8 |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 45 |
|---|---|
| ZipBitFlag: | 0x0800 |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2024:03:10 21:41:18 |
| ZipCRC: | 0x00000000 |
| ZipCompressedSize: | 2 |
| ZipUncompressedSize: | - |
| ZipFileName: | Win32/ |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 664 | "C:\Users\admin\AppData\Local\Temp\Win32\Win32\Trojan.Win32.IconDance\IconDance.exe" | C:\Users\admin\AppData\Local\Temp\Win32\Win32\Trojan.Win32.IconDance\IconDance.exe | — | explorer.exe | |||||||||||
User: admin Company: Xavier LAURENT Integrity Level: MEDIUM Description: Danse des icônes Exit code: 1073807364 Version: 1.0.0.30 Modules
| |||||||||||||||
| 668 | "C:\Users\admin\AppData\Local\Temp\Win32\Win32\Virus.Win32.Winfig\Winfig.exe" | C:\Users\admin\AppData\Local\Temp\Win32\Win32\Virus.Win32.Winfig\Winfig.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221225595 Version: 1.00 Modules
| |||||||||||||||
| 712 | "C:\Users\admin\AppData\Local\Temp\Win32\Win32\Trojan.Win32.Whiter\Whiter.exe" | C:\Users\admin\AppData\Local\Temp\Win32\Win32\Trojan.Win32.Whiter\Whiter.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221225786 | |||||||||||||||
| 796 | NET STOP AVPCC | C:\Windows\System32\net.exe | — | Opaserv.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Net Command Exit code: 2 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 848 | NET STOP PERSFW | C:\Windows\System32\net.exe | — | Opaserv.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Net Command Exit code: 2 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1112 | C:\Windows\system32\net1 STOP SWEEPSRV.SYS | C:\Windows\System32\net1.exe | — | net.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Net Command Exit code: 2 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1188 | "C:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXE" /SetPreload /KOR /Log | C:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXE | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office IME 2010 Exit code: 1 Version: 14.0.4734.1000 | |||||||||||||||
| 1448 | C:\Windows\system32\sipnotify.exe -LogonOrUnlock | C:\Windows\System32\sipnotify.exe | — | taskeng.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: sipnotify Exit code: 0 Version: 6.1.7602.20480 (win7sp1_ldr_escrow.191010-1716) | |||||||||||||||
| 1504 | "C:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXE" /SetPreload /JPN /Log | C:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXE | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office IME 2010 Exit code: 1 Version: 14.0.4734.1000 | |||||||||||||||
| 1572 | C:\Windows\system32\net1 STOP AVPCC | C:\Windows\System32\net1.exe | — | net.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Net Command Exit code: 2 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| (PID) Process: | (3864) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3864) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3864) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3864) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (3864) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (3864) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
| (PID) Process: | (3864) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Win32.zip | |||
| (PID) Process: | (3864) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3864) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3864) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3864 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Win32\Win32\Net-Worm.Win32.Opaserv\Opaserv.exe | executable | |
MD5:71C981D4F5316C3AD1DEEFE48FDDB94A | SHA256:DE709DACAC623C637448DC91F6DFD441A49C89372AF2C53E2027E4AF5310B95D | |||
| 3864 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Win32\Win32\Joke.Win32.FakePetya\FakePetya.exe | executable | |
MD5:C01399C30E8744681251164FAE8DCA01 | SHA256:4146805A52DB2D4FDB1183BB45F0CD4D90CF184CBD0D5EC2CF370E2FA2813CD7 | |||
| 3864 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Win32\Win32\Virus.Win32.Antares\Antares.exe | executable | |
MD5:EDD7A751B4676DCD2065D7D44DD4C902 | SHA256:5BC2D85780A31474C02E92A9A5EA73A82C8EEAFE483197CDDF1D2FFEE473266B | |||
| 3864 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Win32\Win32\Trojan.Win32.Sevgi\Sevgi.exe | executable | |
MD5:B28505A8050446AF4638319060E006E9 | SHA256:750E37D1FDD64E9EA015272A0DB6720AC9A8D803DC0CAAD29D0653756A8E5B17 | |||
| 3864 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Win32\Win32\Trojan.Win32.IconDance\IconDance.exe | executable | |
MD5:7AD8C84DEA7BD1E9CBB888734DB28961 | SHA256:A4B6E53453D1874A6F78F0D7AA14DFAFBA778062F4B85B42B4C1001E1FC17095 | |||
| 3864 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Win32\Win32\Virus.VBS.Karma\karma.vbs | text | |
MD5:1B2FD919726C83AA8D47BF7F3C523628 | SHA256:F29077CE315731F78BD1DBA3FF166A155D7D4CA5581455B28349D91266F5C9E0 | |||
| 3864 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Win32\Win32\Virus.Win32.Winfig\Winfig.exe | executable | |
MD5:C82B6D5A8496064ABB5E66A26AA6717B | SHA256:50AED187373623BE982BCAC479CF729F08BF945B0976ECC48BC4047FF67A938D | |||
| 3864 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Win32\Win32\Trojan.Win32.Alerta\Alerta.exe | executable | |
MD5:E8ED8AAF35E6059BA28504C19FF50BAB | SHA256:2D2A22DB20A44474AFBD7B0E6488690BAD584DCAE9789A5DB776CC1A00B98728 | |||
| 3864 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Win32\Win32\Joke.Win32.Badgame\not-virus_Joke.Win32.Badgame.exe | executable | |
MD5:EBFBD478A8CFC0FB645B8559973690CB | SHA256:62C99EA25FEA9D3E5917114ADA0406A333B1506697BD2BC28E9D676655232A59 | |||
| 3864 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Win32\Win32\Virus.VBS.Karma\Readme.txt | text | |
MD5:93A258C5DA185B408B40CC0CCD84F4B4 | SHA256:EA3A3D3CF7CAB9043145DCE2B3EA7584CCB12CB03C1F862C4FC83E65A11FCC50 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | HEAD | 200 | 23.207.104.5:80 | http://query.prod.cms.rt.microsoft.com/cms/api/am/binary/RE2JgkA?v=133545871188280000 | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
— | — | 224.0.0.252:5355 | — | — | — | unknown |
— | — | 23.207.104.5:80 | query.prod.cms.rt.microsoft.com | AKAMAI-AS | JP | unknown |
Domain | IP | Reputation |
|---|---|---|
query.prod.cms.rt.microsoft.com |
| whitelisted |