File name:

Odin3 v3.14.1.zip

Full analysis: https://app.any.run/tasks/11338113-312b-4d73-a440-cc0678db1b1d
Verdict: Malicious activity
Analysis date: April 02, 2021, 04:42:42
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

9B1CE70D79DB8CF0E83D19FB85B720A7

SHA1:

967BC985984E967C62C6D1222C27471FBDAC2779

SHA256:

2CC560F72F38C3FE77AD8F2B1DB19F530D3ED83BE49A84F30748A36AB01200B0

SSDEEP:

49152:x7p1I2M6M9XJOmjZiWg7TLzA+ymfDYyGyTHRjEEsn7gxfeX6q5ewgcrZ3LAz:hpXeZ39s7TL/ymkoTxju7gxfeXCERE

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Odin3 v3.14.1.exe (PID: 2184)
      • Odin3 v3.14.1.exe (PID: 3564)
  • SUSPICIOUS

    • Drops a file that was compiled in debug mode

      • WinRAR.exe (PID: 1148)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1148)
  • INFO

    • Manual execution by user

      • explorer.exe (PID: 600)
      • explorer.exe (PID: 1548)
      • Odin3 v3.14.1.exe (PID: 2184)
      • Odin3 v3.14.1.exe (PID: 3564)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2019:09:03 17:01:02
ZipCRC: 0x2eded816
ZipCompressedSize: 1201202
ZipUncompressedSize: 2550784
ZipFileName: SS_DL.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
41
Monitored processes
5
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe explorer.exe no specs explorer.exe no specs odin3 v3.14.1.exe no specs odin3 v3.14.1.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
600"C:\Windows\explorer.exe" C:\Windows\explorer.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1148"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Odin3 v3.14.1.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
1548"C:\Windows\explorer.exe" C:\Windows\explorer.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2184"C:\Users\admin\Downloads\Odin3 v3.14.1.exe" C:\Users\admin\Downloads\Odin3 v3.14.1.exeexplorer.exe
User:
admin
Company:
Samsung Electronics Co., Ltd.
Integrity Level:
MEDIUM
Description:
Odin Downloader
Exit code:
2
Version:
2019.5.1.0
Modules
Images
c:\users\admin\downloads\odin3 v3.14.1.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msimg32.dll
3564"C:\Users\admin\Downloads\Odin3 v3.14.1.exe" C:\Users\admin\Downloads\Odin3 v3.14.1.exeexplorer.exe
User:
admin
Company:
Samsung Electronics Co., Ltd.
Integrity Level:
MEDIUM
Description:
Odin Downloader
Exit code:
0
Version:
2019.5.1.0
Modules
Images
c:\users\admin\downloads\odin3 v3.14.1.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msimg32.dll
Total events
510
Read events
481
Write events
29
Delete events
0

Modification events

(PID) Process:(1148) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1148) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1148) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1148) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E
Operation:writeName:@C:\Windows\system32\NetworkExplorer.dll,-1
Value:
Network
(PID) Process:(1148) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Odin3 v3.14.1.zip
(PID) Process:(1148) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1148) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1148) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1148) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1148) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E
Operation:writeName:@C:\Program Files\Common Files\system\wab32res.dll,-10100
Value:
Contacts
Executable files
2
Suspicious files
0
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
1148WinRAR.exeC:\Users\admin\Downloads\Odin3.initext
MD5:DB6CDA4A0F475A15600C24CB9C6D1F8F
SHA256:1181873C445E19C2DF8633717550C02571490217674CA121C830F9140630F1BF
1148WinRAR.exeC:\Users\admin\Downloads\Odin3 v3.14.1.exeexecutable
MD5:DB19B40D7F161B41EC50700952B706CC
SHA256:93E57DAB07F008FE4C2AB2BE1B6559D86AAF1308D32B5B2F5CBB6BC12F3848F7
1148WinRAR.exeC:\Users\admin\Downloads\SS_DL.dllexecutable
MD5:89B7EA72413881E5F86CB14618A2BD11
SHA256:A308B924626DEA58C98B3BA0C2BE393071CF559CB97B62C3B3B12B6E6048E9B2
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info