File name:

P00037621_2024-11-26_07_19_46.659.zip

Full analysis: https://app.any.run/tasks/5be6cddf-6e73-4db3-8014-5065e6df0a0f
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: November 26, 2024, 07:22:37
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
adware
innosetup
loader
Indicators:
MIME: application/zip
File info: Zip archive data, at least v4.5 to extract, compression method=deflate
MD5:

1B38B5FA250F5C64841471BE53BB5626

SHA1:

C9A0D38E457011332ED0D23EE8F3E365EE017040

SHA256:

2F477278D63072C66CFCC439D43AC2CE7CBC9B3A6FACB51C41B9F942632347DA

SSDEEP:

98304:cmgNk4T82pV4zdCU7XRbNo1dm5+EB5wLv0qq4+dOaWzhP0tdrNYgT6CVCx/OlsQM:+yLgF

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • INNOSETUP has been detected (SURICATA)

      • inkscape-portable_u-snut1.tmp (PID: 628)
  • SUSPICIOUS

    • Access to an unwanted program domain was detected

      • inkscape-portable_u-snut1.tmp (PID: 628)
    • Executable content was dropped or overwritten

      • inkscape-portable_u-snut1.exe (PID: 6324)
      • inkscape-portable_u-snut1.tmp (PID: 628)
      • inkscape-portable_u-snut1.exe (PID: 2632)
    • Process requests binary or script from the Internet

      • inkscape-portable_u-snut1.tmp (PID: 628)
    • Potential Corporate Privacy Violation

      • inkscape-portable_u-snut1.tmp (PID: 628)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 6468)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0801
ZipCompression: Deflated
ZipModifyDate: 1980:00:00 00:00:00
ZipCRC: 0x21c8063c
ZipCompressedSize: 2114840
ZipUncompressedSize: 2650168
ZipFileName: Device/HarddiskVolume4/Users/philippe.gossiaux/Downloads/inkscape-portable_u-snut1.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
130
Monitored processes
5
Malicious processes
2
Suspicious processes
2

Behavior graph

Click at the process to see the details
start winrar.exe inkscape-portable_u-snut1.exe inkscape-portable_u-snut1.tmp no specs inkscape-portable_u-snut1.exe #INNOSETUP inkscape-portable_u-snut1.tmp

Process information

PID
CMD
Path
Indicators
Parent process
628"C:\Users\admin\AppData\Local\Temp\is-JSP0I.tmp\inkscape-portable_u-snut1.tmp" /SL5="$802C8,1598543,845824,C:\Users\admin\AppData\Local\Temp\Rar$EXb6468.7777\Device\HarddiskVolume4\Users\philippe.gossiaux\Downloads\inkscape-portable_u-snut1.exe" /SPAWNWND=$1202C6 /NOTIFYWND=$A01FE C:\Users\admin\AppData\Local\Temp\is-JSP0I.tmp\inkscape-portable_u-snut1.tmp
inkscape-portable_u-snut1.exe
User:
admin
Company:
Integrity Level:
HIGH
Description:
Setup/Uninstall
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-jsp0i.tmp\inkscape-portable_u-snut1.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
2632"C:\Users\admin\AppData\Local\Temp\Rar$EXb6468.7777\Device\HarddiskVolume4\Users\philippe.gossiaux\Downloads\inkscape-portable_u-snut1.exe" /SPAWNWND=$1202C6 /NOTIFYWND=$A01FE C:\Users\admin\AppData\Local\Temp\Rar$EXb6468.7777\Device\HarddiskVolume4\Users\philippe.gossiaux\Downloads\inkscape-portable_u-snut1.exe
inkscape-portable_u-snut1.tmp
User:
admin
Company:
Integrity Level:
HIGH
Description:
IMDownloader Installer
Version:
5.3.12.3318
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb6468.7777\device\harddiskvolume4\users\philippe.gossiaux\downloads\inkscape-portable_u-snut1.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comctl32.dll
6312"C:\Users\admin\AppData\Local\Temp\is-ANEPQ.tmp\inkscape-portable_u-snut1.tmp" /SL5="$A01FE,1598543,845824,C:\Users\admin\AppData\Local\Temp\Rar$EXb6468.7777\Device\HarddiskVolume4\Users\philippe.gossiaux\Downloads\inkscape-portable_u-snut1.exe" C:\Users\admin\AppData\Local\Temp\is-ANEPQ.tmp\inkscape-portable_u-snut1.tmpinkscape-portable_u-snut1.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-anepq.tmp\inkscape-portable_u-snut1.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\comdlg32.dll
c:\windows\syswow64\msvcrt.dll
6324"C:\Users\admin\AppData\Local\Temp\Rar$EXb6468.7777\Device\HarddiskVolume4\Users\philippe.gossiaux\Downloads\inkscape-portable_u-snut1.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb6468.7777\Device\HarddiskVolume4\Users\philippe.gossiaux\Downloads\inkscape-portable_u-snut1.exe
WinRAR.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
IMDownloader Installer
Version:
5.3.12.3318
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb6468.7777\device\harddiskvolume4\users\philippe.gossiaux\downloads\inkscape-portable_u-snut1.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\comctl32.dll
c:\windows\syswow64\advapi32.dll
6468"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\P00037621_2024-11-26_07_19_46.659.zipC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
Total events
3 669
Read events
3 660
Write events
9
Delete events
0

Modification events

(PID) Process:(6468) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(6468) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(6468) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(6468) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\P00037621_2024-11-26_07_19_46.659.zip
(PID) Process:(6468) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(6468) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(6468) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(6468) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(6468) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
1
Executable files
6
Suspicious files
0
Text files
9
Unknown types
0

Dropped files

PID
Process
Filename
Type
628inkscape-portable_u-snut1.tmpC:\Users\admin\AppData\Local\Temp\is-QNA2U.tmp\is-VQ8EK.tmpimage
MD5:4CFFF8DC30D353CD3D215FD3A5DBAC24
SHA256:0C430E56D69435D8AB31CBB5916A73A47D11EF65B37D289EE7D11130ADF25856
6324inkscape-portable_u-snut1.exeC:\Users\admin\AppData\Local\Temp\is-ANEPQ.tmp\inkscape-portable_u-snut1.tmpexecutable
MD5:B01517D2BE6AD802367A2B1F9C87DB61
SHA256:38458574B19F9357BEDC0848B102F42A88F4C1E22002BF9FB387729E7AD2A01E
628inkscape-portable_u-snut1.tmpC:\Users\admin\AppData\Local\Temp\is-QNA2U.tmp\AVG_AV.pngimage
MD5:AEE8E80B35DCB3CF2A5733BA99231560
SHA256:35BBD8F390865173D65BA2F38320A04755541A0783E9F825FDB9862F80D97AA9
628inkscape-portable_u-snut1.tmpC:\Users\admin\AppData\Local\Temp\is-QNA2U.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
628inkscape-portable_u-snut1.tmpC:\Users\admin\AppData\Local\Temp\is-QNA2U.tmp\is-JJKR6.tmpimage
MD5:C226428FCC7E2E29F917E2324FA23577
SHA256:C8EB1F9A15EFFDF74FE6E4D8A50249943B3AEEC689EDC99F462D4E3EC28CB8AB
628inkscape-portable_u-snut1.tmpC:\Users\admin\AppData\Local\Temp\is-QNA2U.tmp\is-7Q7J1.tmpimage
MD5:AEE8E80B35DCB3CF2A5733BA99231560
SHA256:35BBD8F390865173D65BA2F38320A04755541A0783E9F825FDB9862F80D97AA9
628inkscape-portable_u-snut1.tmpC:\Users\admin\AppData\Local\Temp\is-QNA2U.tmp\mainlogo.pngimage
MD5:C226428FCC7E2E29F917E2324FA23577
SHA256:C8EB1F9A15EFFDF74FE6E4D8A50249943B3AEEC689EDC99F462D4E3EC28CB8AB
628inkscape-portable_u-snut1.tmpC:\Users\admin\AppData\Local\Temp\is-QNA2U.tmp\WebAdvisor.pngimage
MD5:4CFFF8DC30D353CD3D215FD3A5DBAC24
SHA256:0C430E56D69435D8AB31CBB5916A73A47D11EF65B37D289EE7D11130ADF25856
6468WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb6468.7777\manifest.jsontext
MD5:C174FDE8EE9A91FFB4FBFEAE2D4493C3
SHA256:BB2E785E49F5C47046FE934306E2C4C85C1B5D08F02553C34DC6E3A1689B0AEA
628inkscape-portable_u-snut1.tmpC:\Users\admin\AppData\Local\Temp\is-QNA2U.tmp\Helper.dllexecutable
MD5:4EB0347E66FA465F602E52C03E5C0B4B
SHA256:C73E53CBB7B98FEAFE27CC7DE8FDAD51DF438E2235E91891461C5123888F73CC
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
11
TCP/UDP connections
37
DNS requests
19
Threats
3

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
2.16.241.19:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
2.16.241.19:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
1412
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6672
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
1412
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
628
inkscape-portable_u-snut1.tmp
GET
95.168.168.24:80
http://dl.jalecdn.com/FR/inkscape-portable.exe
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4712
MoUsoCoreWorker.exe
2.16.241.19:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
2.16.241.19:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4712
MoUsoCoreWorker.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
5064
SearchApp.exe
92.123.104.16:443
www.bing.com
Akamai International B.V.
DE
whitelisted
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
4
System
192.168.100.255:138
whitelisted
1176
svchost.exe
40.126.32.133:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 20.73.194.208
whitelisted
crl.microsoft.com
  • 2.16.241.19
  • 2.16.241.12
whitelisted
google.com
  • 142.250.186.174
whitelisted
www.microsoft.com
  • 95.101.149.131
  • 23.35.229.160
whitelisted
www.bing.com
  • 92.123.104.16
  • 92.123.104.9
  • 92.123.104.12
  • 92.123.104.11
  • 92.123.104.4
  • 92.123.104.67
  • 92.123.104.15
  • 92.123.104.5
  • 92.123.104.14
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 40.126.32.133
  • 40.126.32.140
  • 40.126.32.136
  • 40.126.32.68
  • 40.126.32.138
  • 20.190.160.14
  • 20.190.160.20
  • 40.126.32.72
whitelisted
go.microsoft.com
  • 184.28.89.167
whitelisted
arc.msn.com
  • 20.199.58.43
whitelisted
fd.api.iris.microsoft.com
  • 20.74.47.205
whitelisted

Threats

PID
Process
Class
Message
628
inkscape-portable_u-snut1.tmp
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] InnoSetup Installer
628
inkscape-portable_u-snut1.tmp
Possibly Unwanted Program Detected
ADWARE [ANY.RUN] InnoSetup Installer
628
inkscape-portable_u-snut1.tmp
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
No debug info