File name:

Outlook Recovery ToolBox 4.7.15.77.zip

Full analysis: https://app.any.run/tasks/10b9c7d4-4789-4c4d-bb42-1beae664d36b
Verdict: Suspicious activity
Analysis date: August 12, 2020, 14:49:02
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

438C3113D1A69007F52F079A44C5C748

SHA1:

339B9F582104DF51457F890E9FEDA9151344F801

SHA256:

2BB2EFB515F5E3E2A732AD1C81661EA13AE5098CE374C466FB6A4F002D289699

SSDEEP:

12288:FsMevDeRMAWpUn2maJDZrzPf4l2I1rMvR/PpgKQ3nxVDH5SGfCnP:FdADebcU/aJDZHfX0MBp7Q3xNi

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Outlook Recovery ToolBox 4.7.15.77.exe (PID: 2096)
      • Outlook Recovery ToolBox 4.7.15.77.exe (PID: 3904)
      • sihost.exe (PID: 2488)
    • Uses Task Scheduler to run other applications

      • sihost.exe (PID: 2488)
    • Loads the Task Scheduler COM API

      • schtasks.exe (PID: 3824)
      • schtasks.exe (PID: 2700)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Outlook Recovery ToolBox 4.7.15.77.exe (PID: 2096)
      • Outlook Recovery ToolBox 4.7.15.77.exe (PID: 3904)
      • Outlook Recovery ToolBox 4.7.15.77.tmp (PID: 2304)
      • 7za.exe (PID: 3804)
    • Reads the Windows organization settings

      • Outlook Recovery ToolBox 4.7.15.77.tmp (PID: 2304)
    • Reads Windows owner or organization settings

      • Outlook Recovery ToolBox 4.7.15.77.tmp (PID: 2304)
    • Creates files in the user directory

      • sihost.exe (PID: 2488)
      • Outlook Recovery ToolBox 4.7.15.77.tmp (PID: 2304)
    • Executed via COM

      • explorer.exe (PID: 3248)
  • INFO

    • Manual execution by user

      • Outlook Recovery ToolBox 4.7.15.77.exe (PID: 3904)
      • NOTEPAD.EXE (PID: 2836)
    • Application was dropped or rewritten from another process

      • 7za.exe (PID: 3804)
      • 7za.exe (PID: 952)
      • 7za.exe (PID: 2188)
      • Outlook Recovery ToolBox 4.7.15.77.tmp (PID: 2104)
      • Outlook Recovery ToolBox 4.7.15.77.tmp (PID: 2304)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0001
ZipCompression: Deflated
ZipModifyDate: 2020:08:12 17:41:19
ZipCRC: 0x86259aad
ZipCompressedSize: 684999
ZipUncompressedSize: 758849
ZipFileName: Outlook Recovery ToolBox 4.7.15.77.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
60
Monitored processes
14
Malicious processes
3
Suspicious processes
2

Behavior graph

Click at the process to see the details
start drop and start drop and start drop and start drop and start drop and start drop and start winrar.exe no specs outlook recovery toolbox 4.7.15.77.exe outlook recovery toolbox 4.7.15.77.tmp no specs outlook recovery toolbox 4.7.15.77.exe outlook recovery toolbox 4.7.15.77.tmp 7za.exe no specs 7za.exe 7za.exe no specs notepad.exe no specs sihost.exe no specs schtasks.exe no specs schtasks.exe no specs explorer.exe no specs explorer.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
876"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Outlook Recovery ToolBox 4.7.15.77.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
952"C:\Users\admin\AppData\Local\Temp\is-6988V.tmp\7za.exe" x "C:\Users\admin\AppData\Local\Temp\is-6988V.tmp\sub.res" -p"b1lig@n_vl"C:\Users\admin\AppData\Local\Temp\is-6988V.tmp\7za.exeOutlook Recovery ToolBox 4.7.15.77.tmp
User:
admin
Company:
Igor Pavlov
Integrity Level:
HIGH
Description:
7-Zip Standalone Console
Exit code:
0
Version:
4.65
Modules
Images
c:\users\admin\appdata\local\temp\is-6988v.tmp\7za.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
1700"explorer.exe" "C:\Users\admin\Desktop\Outlook Recovery ToolBox 4.7.15.77"C:\Windows\explorer.exeOutlook Recovery ToolBox 4.7.15.77.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2096"C:\Users\admin\Desktop\Outlook Recovery ToolBox 4.7.15.77.exe" /SPAWNWND=$7012E /NOTIFYWND=$30158 C:\Users\admin\Desktop\Outlook Recovery ToolBox 4.7.15.77.exe
Outlook Recovery ToolBox 4.7.15.77.tmp
User:
admin
Company:
Integrity Level:
HIGH
Description:
Exit code:
0
Version:
14.38
Modules
Images
c:\users\admin\desktop\outlook recovery toolbox 4.7.15.77.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2104"C:\Users\admin\AppData\Local\Temp\is-J0HC3.tmp\Outlook Recovery ToolBox 4.7.15.77.tmp" /SL5="$30158,368831,121344,C:\Users\admin\Desktop\Outlook Recovery ToolBox 4.7.15.77.exe" C:\Users\admin\AppData\Local\Temp\is-J0HC3.tmp\Outlook Recovery ToolBox 4.7.15.77.tmpOutlook Recovery ToolBox 4.7.15.77.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-j0hc3.tmp\outlook recovery toolbox 4.7.15.77.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2188"C:\Users\admin\AppData\Local\Temp\is-6988V.tmp\7za.exe" x "C:\Users\admin\AppData\Local\Temp\is-6988V.tmp\misc.res" -p"b1lig@n_vl"C:\Users\admin\AppData\Local\Temp\is-6988V.tmp\7za.exeOutlook Recovery ToolBox 4.7.15.77.tmp
User:
admin
Company:
Igor Pavlov
Integrity Level:
HIGH
Description:
7-Zip Standalone Console
Exit code:
0
Version:
4.65
Modules
Images
c:\users\admin\appdata\local\temp\is-6988v.tmp\7za.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
2304"C:\Users\admin\AppData\Local\Temp\is-P38LL.tmp\Outlook Recovery ToolBox 4.7.15.77.tmp" /SL5="$70132,368831,121344,C:\Users\admin\Desktop\Outlook Recovery ToolBox 4.7.15.77.exe" /SPAWNWND=$7012E /NOTIFYWND=$30158 C:\Users\admin\AppData\Local\Temp\is-P38LL.tmp\Outlook Recovery ToolBox 4.7.15.77.tmp
Outlook Recovery ToolBox 4.7.15.77.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-p38ll.tmp\outlook recovery toolbox 4.7.15.77.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2488"C:\Users\admin\AppData\Roaming\ToolSysHost\sihost.exe" -cr -tu 5C:\Users\admin\AppData\Roaming\ToolSysHost\sihost.exeOutlook Recovery ToolBox 4.7.15.77.tmp
User:
admin
Integrity Level:
HIGH
Description:
System Info Host
Exit code:
0
Version:
2.0.72.38
Modules
Images
c:\users\admin\appdata\roaming\toolsyshost\sihost.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2700"C:\Windows\system32\schtasks.exe" /Create /f /XML "C:\Users\admin\AppData\Roaming\ToolSysHost\data.xml" /tn "Microsoft\Windows\Windows Error Reporting\SysInfo"C:\Windows\system32\schtasks.exesihost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Manages scheduled tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
2836"C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\Outlook Recovery ToolBox 4.7.15.77\license.txtC:\Windows\system32\NOTEPAD.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
1 152
Read events
1 085
Write events
67
Delete events
0

Modification events

(PID) Process:(876) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(876) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(876) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\136\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(876) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\136\52C64B7E
Operation:writeName:@C:\Windows\system32\NetworkExplorer.dll,-1
Value:
Network
(PID) Process:(876) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Outlook Recovery ToolBox 4.7.15.77.zip
(PID) Process:(876) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(876) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(876) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(876) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(876) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
Executable files
5
Suspicious files
3
Text files
5
Unknown types
0

Dropped files

PID
Process
Filename
Type
876WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb876.9739\Outlook Recovery ToolBox 4.7.15.77.exe
MD5:
SHA256:
2304Outlook Recovery ToolBox 4.7.15.77.tmpC:\Users\admin\AppData\Local\Temp\{95A2F6E1-E3AD-4289-A931-33ED31DF7A37}\is-AVVSO.tmp
MD5:
SHA256:
2304Outlook Recovery ToolBox 4.7.15.77.tmpC:\Users\admin\AppData\Local\Temp\{95A2F6E1-E3AD-4289-A931-33ED31DF7A37}\license.txt
MD5:
SHA256:
2488sihost.exeC:\Users\admin\AppData\Roaming\ToolSysHost\data.xml
MD5:
SHA256:
2304Outlook Recovery ToolBox 4.7.15.77.tmpC:\Users\admin\Desktop\Outlook Recovery ToolBox 4.7.15.77\license.txttext
MD5:
SHA256:
3904Outlook Recovery ToolBox 4.7.15.77.exeC:\Users\admin\AppData\Local\Temp\is-J0HC3.tmp\Outlook Recovery ToolBox 4.7.15.77.tmpexecutable
MD5:34ACC2BDB45A9C436181426828C4CB49
SHA256:9C81817ACD4982632D8C7F1DF3898FCA1477577738184265D735F49FC5480F07
9527za.exeC:\Users\admin\AppData\Local\Temp\is-6988V.tmp\sub.xmlxml
MD5:C047508A4A1F583B7ED31EC7B0DF9695
SHA256:CD999BAA036D44D442FE43A541D69F04BA206C58938F3C22EC0F226493C63E35
2304Outlook Recovery ToolBox 4.7.15.77.tmpC:\Users\admin\AppData\Local\Temp\is-6988V.tmp\misc.rescompressed
MD5:4276E4182A04700263891F395FD74B65
SHA256:436DB65389AFD9020211E47F28A090AB12A5D0E2AF5961BB6C491074F73E30D6
21887za.exeC:\Users\admin\AppData\Local\Temp\is-6988V.tmp\misc.xmlxml
MD5:D54DA888E3C5FD5BA749EC296E0C0FD9
SHA256:EC58F7E5FE7C18248BF4B987DD3D16A8A67508EAE035DF5A25F2643E0E53BEBF
2304Outlook Recovery ToolBox 4.7.15.77.tmpC:\Users\admin\AppData\Local\Temp\is-6988V.tmp\sub.rescompressed
MD5:AE50AD46B7EF3517F5DF5EDF2B96443E
SHA256:F4A2B3FA7460606D58AD078D320AFCEAD400285304DC49E8F2BA3FA9800854DC
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
2
DNS requests
2
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2304
Outlook Recovery ToolBox 4.7.15.77.tmp
POST
200
216.58.212.142:80
http://www.google-analytics.com/collect
US
image
35 b
whitelisted
2304
Outlook Recovery ToolBox 4.7.15.77.tmp
POST
200
216.58.212.142:80
http://www.google-analytics.com/collect
US
image
35 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2304
Outlook Recovery ToolBox 4.7.15.77.tmp
216.58.212.142:80
www.google-analytics.com
Google Inc.
US
whitelisted
2304
Outlook Recovery ToolBox 4.7.15.77.tmp
172.67.133.234:80
video-box.org
US
suspicious

DNS requests

Domain
IP
Reputation
www.google-analytics.com
  • 216.58.212.142
whitelisted
video-box.org
  • 172.67.133.234
  • 104.28.31.94
  • 104.28.30.94
malicious

Threats

No threats detected
No debug info