File name:

System32.zip

Full analysis: https://app.any.run/tasks/f35905b3-24c9-449a-b398-3ad4cc3a8d8b
Verdict: Malicious activity
Analysis date: August 13, 2024, 08:03:25
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
upx
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

F6C5E856B4177774B8395A2C3BC6677B

SHA1:

4E568CAA454A8D17E82AAA46BA25E9A716390F40

SHA256:

322B665B3411541D8BD6AB3E8C97D632D647E46A4BE5475E8F73EF0A95BB60A1

SSDEEP:

49152:hgyaedhcaT1xC7yBcKweZjJ8Wbu5ZmJq/Wt4JRKNHMVM7LY4FCm84JewT+riO/7s:zNhcaZxC7TeFqWbSQC+HMwRhewdO/7TI

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Runs injected code in another process

      • StarRailBase.exe (PID: 6052)
      • StarRailBase.exe (PID: 1168)
    • Application was injected by another process

      • svchost.exe (PID: 1316)
  • SUSPICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 6364)
    • Executable content was dropped or overwritten

      • svchost.exe (PID: 6640)
    • The process executes via Task Scheduler

      • StarRailBase.exe (PID: 6052)
      • svchost.exe (PID: 6180)
      • StarRailBase.exe (PID: 1168)
      • svchost.exe (PID: 6080)
  • INFO

    • Manual execution by a user

      • StarRailBase.exe (PID: 5988)
      • StarRailBase.exe (PID: 3044)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 6364)
    • Reads security settings of Internet Explorer

      • svchost.exe (PID: 6640)
    • Reads the computer name

      • StarRailBase.exe (PID: 5988)
      • StarRailBase.exe (PID: 6052)
      • StarRailBase.exe (PID: 3044)
      • StarRailBase.exe (PID: 1168)
    • Checks supported languages

      • StarRailBase.exe (PID: 5988)
      • StarRailBase.exe (PID: 6052)
      • StarRailBase.exe (PID: 3044)
      • StarRailBase.exe (PID: 1168)
    • UPX packer has been detected

      • svchost.exe (PID: 6180)
      • dllhost.exe (PID: 208)
      • svchost.exe (PID: 6080)
      • dllhost.exe (PID: 3272)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2024:08:13 09:31:18
ZipCRC: 0x84075924
ZipCompressedSize: 453
ZipUncompressedSize: 1152
ZipFileName: bcd.conf
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
148
Monitored processes
13
Malicious processes
1
Suspicious processes
2

Behavior graph

Click at the process to see the details
start winrar.exe starrailbase.exe svchost.exe starrailbase.exe no specs THREAT svchost.exe THREAT dllhost.exe rundll32.exe no specs starrailbase.exe svchost.exe no specs starrailbase.exe no specs THREAT svchost.exe THREAT dllhost.exe no specs svchost.exe

Process information

PID
CMD
Path
Indicators
Parent process
208C:\WINDOWS\system32\dllhost.exe /Processid:{F8284233-48F4-4680-ADDD-F8284233}C:\Windows\System32\dllhost.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
COM Surrogate
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\dllhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
1168"C:\WINDOWS\system32\StarRailBase.exe" -svcC:\Windows\System32\StarRailBase.exesvchost.exe
User:
SYSTEM
Company:
上海米哈游网络科技股份有限公司
Integrity Level:
SYSTEM
Description:
Star Rail
Exit code:
0
Version:
2019.4.34.1463972
Modules
Images
c:\windows\system32\starrailbase.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\starrailbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\combase.dll
c:\windows\system32\gdi32.dll
1316C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s ScheduleC:\Windows\System32\svchost.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
3044"C:\Windows\System32\StarRailBase.exe" C:\Windows\System32\StarRailBase.exe
explorer.exe
User:
admin
Company:
上海米哈游网络科技股份有限公司
Integrity Level:
HIGH
Description:
Star Rail
Exit code:
0
Version:
2019.4.34.1463972
Modules
Images
c:\windows\system32\starrailbase.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\starrailbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\combase.dll
3272C:\WINDOWS\system32\dllhost.exe /Processid:{F8284233-48F4-4680-ADDD-F8284233}C:\Windows\System32\dllhost.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
COM Surrogate
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\dllhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
3376C:\WINDOWS\system32\svchost.exe -InstallC:\Windows\System32\svchost.exeStarRailBase.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Host Process for Windows Services
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\advapi32.dll
4924C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
5988"C:\Users\admin\Desktop\StarRailBase.exe" C:\Users\admin\Desktop\StarRailBase.exe
explorer.exe
User:
admin
Company:
上海米哈游网络科技股份有限公司
Integrity Level:
HIGH
Description:
Star Rail
Exit code:
0
Version:
2019.4.34.1463972
Modules
Images
c:\users\admin\desktop\starrailbase.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\users\admin\desktop\starrailbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\combase.dll
6052"C:\WINDOWS\system32\StarRailBase.exe" -svcC:\Windows\System32\StarRailBase.exesvchost.exe
User:
SYSTEM
Company:
上海米哈游网络科技股份有限公司
Integrity Level:
SYSTEM
Description:
Star Rail
Exit code:
0
Version:
2019.4.34.1463972
Modules
Images
c:\windows\system32\starrailbase.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\starrailbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\combase.dll
c:\windows\system32\gdi32.dll
6080C:\WINDOWS\system32\svchost.exe -k netsvcsC:\Windows\System32\svchost.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
Total events
11 856
Read events
11 312
Write events
263
Delete events
281

Modification events

(PID) Process:(6364) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(6364) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(6364) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\GoogleChromeEnterpriseBundle64.zip
(PID) Process:(6364) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\System32.zip
(PID) Process:(6364) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(6364) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(6364) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(6364) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1316) svchost.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C2AF3602-9179-4BAE-85B3-74A4EF5CF51F}
Operation:writeName:DynamicInfo
Value:
03000000BDCB09F80A59DA014054E44757EDDA0100000000000000001491014A57EDDA01
(PID) Process:(1316) svchost.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F93AD50A-2FB2-4A34-88EF-786903C710ED}
Operation:writeName:DynamicInfo
Value:
03000000C09775A51C59DA014054E44757EDDA0100000000054000809BA17C4B57EDDA01
Executable files
4
Suspicious files
8
Text files
8
Unknown types
0

Dropped files

PID
Process
Filename
Type
6364WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6364.6751\perfh009.datbinary
MD5:830E0470C77AB6C96A0F2E49BF00D32A
SHA256:AA00D6A73AFF078FC487342278FA3203383FF5931DF7FF88F7BC98A5802AAB1F
1316svchost.exeC:\Windows\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Schedule Wake To Workxml
MD5:C6086D02F8CE044F5FA07A98303DC7EB
SHA256:8901D9C9AEA465DA4EA7AA874610A90B8CF0A71EBA0E321CF9675FCEEE0B54A0
1316svchost.exeC:\Windows\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Schedule Scanxml
MD5:11954764DE4745B35A42219A7C5E2DCA
SHA256:997FCF971A38394C30D9E5CA0C6B36E782630E83B52D2664C56F1DEFBA54CB6C
1316svchost.exeC:\Windows\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Schedule Workxml
MD5:5FADF13CCFBDCC5DD728380F7A615B28
SHA256:FF1F73395F6B5B22D5FDA367521FE0DCC31FF252849B7FA85FA346B953A40451
6364WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6364.6751\bcd.conftext
MD5:3070A4022FABDB0FB594469A0AF263A2
SHA256:645CDDDCD378E413734F1B040B1F28F5657751A2E16585A15D27CD40CE9402A8
6364WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6364.6751\prfc0804.datbinary
MD5:F2F7A145B4335E9F5C4AD04C65980C37
SHA256:83DC9CA565FA0B245EFFBC595DFD1A64BA9CFE81B4FD0FA422C1B2FE5EB68925
6364WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6364.6751\perfc009.datbinary
MD5:890C11269D82D7D28C6B243FBAE7A80C
SHA256:05A268381632DF1D8F955BD0E53ED1AB932F2F7030048859042A944671901046
1316svchost.exeC:\Windows\System32\Tasks\Microsoft\Windows\WindowsUpdate\RUXIM\PLUGSchedulerxml
MD5:1E0FD17505DF7FDD52708C59FCD5284C
SHA256:B374CE865F05A467798DE01B77F9AEEA861325CF274390D4C06753E77CDA564D
6364WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6364.6751\PerfStringBackup.INIbinary
MD5:0B892301C2B2CAE9385C8EBF98395EE1
SHA256:88A87A363131F8203B71C1EB3FBF5670778298C9B866393D8B9C8A0A0640399F
6364WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6364.6751\StarRailBase.exeexecutable
MD5:09CBEBE3306F81DBB1498E2C214B897D
SHA256:2AA3366883B707C1FEA777156417F4BE0B5C90F209FDA1AFAC1C8544ACAB702C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
47
DNS requests
16
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5336
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
640
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6892
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
6856
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
3888
svchost.exe
239.255.255.250:1900
whitelisted
1536
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2120
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
876
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
5336
SearchApp.exe
204.79.197.200:443
www.bing.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5336
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
640
svchost.exe
20.190.159.0:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
3260
svchost.exe
20.197.71.89:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
SG
unknown

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.238
whitelisted
settings-win.data.microsoft.com
  • 4.231.128.59
  • 40.127.240.158
whitelisted
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 20.190.159.0
  • 40.126.31.73
  • 20.190.159.75
  • 40.126.31.67
  • 40.126.31.71
  • 20.190.159.71
  • 20.190.159.68
  • 20.190.159.2
whitelisted
client.wns.windows.com
  • 20.197.71.89
whitelisted
th.bing.com
  • 92.123.104.36
  • 92.123.104.46
  • 92.123.104.42
  • 92.123.104.52
  • 92.123.104.37
  • 92.123.104.49
  • 92.123.104.45
  • 92.123.104.43
  • 92.123.104.38
whitelisted
fd.api.iris.microsoft.com
  • 20.223.35.26
whitelisted
arc.msn.com
  • 20.31.169.57
whitelisted
slscr.update.microsoft.com
  • 20.114.59.183
whitelisted

Threats

No threats detected
No debug info