File name:

P00037621_2024-11-26_07_19_46.659.zip

Full analysis: https://app.any.run/tasks/3c4f0ddc-2c32-4744-ba17-1017da679f72
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: November 26, 2024, 07:24:30
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
adware
innosetup
Indicators:
MIME: application/zip
File info: Zip archive data, at least v4.5 to extract, compression method=deflate
MD5:

1B38B5FA250F5C64841471BE53BB5626

SHA1:

C9A0D38E457011332ED0D23EE8F3E365EE017040

SHA256:

2F477278D63072C66CFCC439D43AC2CE7CBC9B3A6FACB51C41B9F942632347DA

SSDEEP:

98304:cmgNk4T82pV4zdCU7XRbNo1dm5+EB5wLv0qq4+dOaWzhP0tdrNYgT6CVCx/OlsQM:+yLgF

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • INNOSETUP has been detected (SURICATA)

      • inkscape-portable_u-snut1.tmp (PID: 236)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • inkscape-portable_u-snut1.tmp (PID: 236)
      • inkscape-portable_u-snut1.exe (PID: 3420)
      • inkscape-portable_u-snut1.exe (PID: 7156)
    • Access to an unwanted program domain was detected

      • inkscape-portable_u-snut1.tmp (PID: 236)
    • Potential Corporate Privacy Violation

      • inkscape-portable_u-snut1.tmp (PID: 236)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 5732)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0801
ZipCompression: Deflated
ZipModifyDate: 1980:00:00 00:00:00
ZipCRC: 0x21c8063c
ZipCompressedSize: 2114840
ZipUncompressedSize: 2650168
ZipFileName: Device/HarddiskVolume4/Users/philippe.gossiaux/Downloads/inkscape-portable_u-snut1.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
132
Monitored processes
5
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe inkscape-portable_u-snut1.exe inkscape-portable_u-snut1.tmp no specs inkscape-portable_u-snut1.exe #INNOSETUP inkscape-portable_u-snut1.tmp

Process information

PID
CMD
Path
Indicators
Parent process
236"C:\Users\admin\AppData\Local\Temp\is-G8QBD.tmp\inkscape-portable_u-snut1.tmp" /SL5="$B0298,1598543,845824,C:\Users\admin\AppData\Local\Temp\Rar$EXb5732.20070\Device\HarddiskVolume4\Users\philippe.gossiaux\Downloads\inkscape-portable_u-snut1.exe" /SPAWNWND=$702C2 /NOTIFYWND=$7035C C:\Users\admin\AppData\Local\Temp\is-G8QBD.tmp\inkscape-portable_u-snut1.tmp
inkscape-portable_u-snut1.exe
User:
admin
Company:
Integrity Level:
HIGH
Description:
Setup/Uninstall
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-g8qbd.tmp\inkscape-portable_u-snut1.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
1944"C:\Users\admin\AppData\Local\Temp\is-OGAO3.tmp\inkscape-portable_u-snut1.tmp" /SL5="$7035C,1598543,845824,C:\Users\admin\AppData\Local\Temp\Rar$EXb5732.20070\Device\HarddiskVolume4\Users\philippe.gossiaux\Downloads\inkscape-portable_u-snut1.exe" C:\Users\admin\AppData\Local\Temp\is-OGAO3.tmp\inkscape-portable_u-snut1.tmpinkscape-portable_u-snut1.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-ogao3.tmp\inkscape-portable_u-snut1.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\comdlg32.dll
c:\windows\syswow64\msvcrt.dll
3420"C:\Users\admin\AppData\Local\Temp\Rar$EXb5732.20070\Device\HarddiskVolume4\Users\philippe.gossiaux\Downloads\inkscape-portable_u-snut1.exe" /SPAWNWND=$702C2 /NOTIFYWND=$7035C C:\Users\admin\AppData\Local\Temp\Rar$EXb5732.20070\Device\HarddiskVolume4\Users\philippe.gossiaux\Downloads\inkscape-portable_u-snut1.exe
inkscape-portable_u-snut1.tmp
User:
admin
Company:
Integrity Level:
HIGH
Description:
IMDownloader Installer
Version:
5.3.12.3318
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb5732.20070\device\harddiskvolume4\users\philippe.gossiaux\downloads\inkscape-portable_u-snut1.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comctl32.dll
5732"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\P00037621_2024-11-26_07_19_46.659.zipC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
7156"C:\Users\admin\AppData\Local\Temp\Rar$EXb5732.20070\Device\HarddiskVolume4\Users\philippe.gossiaux\Downloads\inkscape-portable_u-snut1.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb5732.20070\Device\HarddiskVolume4\Users\philippe.gossiaux\Downloads\inkscape-portable_u-snut1.exe
WinRAR.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
IMDownloader Installer
Version:
5.3.12.3318
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb5732.20070\device\harddiskvolume4\users\philippe.gossiaux\downloads\inkscape-portable_u-snut1.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\comctl32.dll
c:\windows\syswow64\advapi32.dll
Total events
3 654
Read events
3 645
Write events
9
Delete events
0

Modification events

(PID) Process:(5732) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(5732) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(5732) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(5732) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\P00037621_2024-11-26_07_19_46.659.zip
(PID) Process:(5732) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(5732) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(5732) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(5732) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(5732) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
1
Executable files
6
Suspicious files
0
Text files
7
Unknown types
0

Dropped files

PID
Process
Filename
Type
5732WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb5732.20070\manifest.jsontext
MD5:C174FDE8EE9A91FFB4FBFEAE2D4493C3
SHA256:BB2E785E49F5C47046FE934306E2C4C85C1B5D08F02553C34DC6E3A1689B0AEA
3420inkscape-portable_u-snut1.exeC:\Users\admin\AppData\Local\Temp\is-G8QBD.tmp\inkscape-portable_u-snut1.tmpexecutable
MD5:B01517D2BE6AD802367A2B1F9C87DB61
SHA256:38458574B19F9357BEDC0848B102F42A88F4C1E22002BF9FB387729E7AD2A01E
236inkscape-portable_u-snut1.tmpC:\Users\admin\AppData\Local\Temp\is-1EIT8.tmp\is-HU3BS.tmpimage
MD5:C226428FCC7E2E29F917E2324FA23577
SHA256:C8EB1F9A15EFFDF74FE6E4D8A50249943B3AEEC689EDC99F462D4E3EC28CB8AB
7156inkscape-portable_u-snut1.exeC:\Users\admin\AppData\Local\Temp\is-OGAO3.tmp\inkscape-portable_u-snut1.tmpexecutable
MD5:B01517D2BE6AD802367A2B1F9C87DB61
SHA256:38458574B19F9357BEDC0848B102F42A88F4C1E22002BF9FB387729E7AD2A01E
236inkscape-portable_u-snut1.tmpC:\Users\admin\AppData\Local\Temp\is-1EIT8.tmp\loader.gifimage
MD5:12D7FD91A06CEE2D0E76ABE0485036EE
SHA256:A6192B9A3FA5DB9917AEF72D651B7AD8FD8CCB9B53F3AD99D7C46701D00C78CB
5732WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb5732.20070\Device\HarddiskVolume4\Users\philippe.gossiaux\Downloads\inkscape-portable_u-snut1.exeexecutable
MD5:39771E814581EC4E0270E8137CFA417A
SHA256:6C37F547BCA41C2DE31701412239AFC1BE138C3ADE945F86462A4D0403EB65B2
236inkscape-portable_u-snut1.tmpC:\Users\admin\AppData\Local\Temp\is-1EIT8.tmp\mainlogo.pngimage
MD5:C226428FCC7E2E29F917E2324FA23577
SHA256:C8EB1F9A15EFFDF74FE6E4D8A50249943B3AEEC689EDC99F462D4E3EC28CB8AB
236inkscape-portable_u-snut1.tmpC:\Users\admin\AppData\Local\Temp\is-1EIT8.tmp\Helper.dllexecutable
MD5:4EB0347E66FA465F602E52C03E5C0B4B
SHA256:C73E53CBB7B98FEAFE27CC7DE8FDAD51DF438E2235E91891461C5123888F73CC
236inkscape-portable_u-snut1.tmpC:\Users\admin\AppData\Local\Temp\is-1EIT8.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
236inkscape-portable_u-snut1.tmpC:\Users\admin\AppData\Local\Temp\is-1EIT8.tmp\is-AI549.tmpimage
MD5:9FD278B8F33757D6BF36E0A86CFA4C1F
SHA256:70D1A84C73E28667AA56263CD31CC6145AECB1A834FCD9AF1D7623D56497F0AC
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
37
DNS requests
20
Threats
3

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.216.77.25:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
2.19.217.218:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
6200
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
7024
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
236
inkscape-portable_u-snut1.tmp
GET
95.168.168.24:80
http://dl.jalecdn.com/FR/inkscape-portable.exe
unknown
unknown
236
inkscape-portable_u-snut1.tmp
GET
301
104.22.56.224:80
http://static.download.it/gen/inkscape-portable-100x100.png
unknown
unknown
7024
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1380
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
4712
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
23.216.77.25:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
2.19.217.218:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
5064
SearchApp.exe
23.212.110.203:443
www.bing.com
Akamai International B.V.
CZ
whitelisted
4
System
192.168.100.255:138
whitelisted
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
1076
svchost.exe
23.213.166.81:443
go.microsoft.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 40.127.240.158
whitelisted
google.com
  • 142.250.186.110
whitelisted
crl.microsoft.com
  • 23.216.77.25
  • 23.216.77.36
whitelisted
www.microsoft.com
  • 2.19.217.218
  • 95.101.149.131
whitelisted
www.bing.com
  • 23.212.110.203
  • 23.212.110.200
  • 23.212.110.179
  • 23.212.110.201
  • 23.212.110.208
  • 23.212.110.187
  • 23.212.110.184
  • 23.212.110.186
  • 23.212.110.185
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
go.microsoft.com
  • 23.213.166.81
whitelisted
login.live.com
  • 40.126.31.73
  • 20.190.159.4
  • 20.190.159.73
  • 40.126.31.69
  • 40.126.31.71
  • 20.190.159.75
  • 20.190.159.68
  • 20.190.159.23
whitelisted
arc.msn.com
  • 20.199.58.43
whitelisted
fd.api.iris.microsoft.com
  • 20.105.99.58
whitelisted

Threats

PID
Process
Class
Message
236
inkscape-portable_u-snut1.tmp
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] InnoSetup Installer
236
inkscape-portable_u-snut1.tmp
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] InnoSetup Installer
236
inkscape-portable_u-snut1.tmp
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
No debug info