| File name: | 4672cf66f3eeab147756012e3417b185.zip |
| Full analysis: | https://app.any.run/tasks/8bbdf1cd-25c3-4c15-8ba6-11c7871ffaef |
| Verdict: | Malicious activity |
| Analysis date: | May 29, 2024, 00:40:53 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract, compression method=deflate |
| MD5: | 4672CF66F3EEAB147756012E3417B185 |
| SHA1: | C30FA09BD52F09D2F665794117B8C890D490FB1F |
| SHA256: | 32A6200ACE3D87FF46F535A0055CB2D750DBC05ACFCD7C976C2071A2510375F0 |
| SSDEEP: | 6144:9HdV32pgEnAIT+e0b5u+1Xcm9J7MkKBB:BheAQ+e0cgM+okM |
| .xpi | | | Mozilla Firefox browser extension (66.6) |
|---|---|---|
| .zip | | | ZIP compressed archive (33.3) |
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | 0x0004 |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2009:04:15 00:09:16 |
| ZipCRC: | 0x446252ef |
| ZipCompressedSize: | 320 |
| ZipUncompressedSize: | 899 |
| ZipFileName: | RACE/Install.cmd |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 284 | DrvInst.exe "2" "211" "ROOT\DISPLAY\0000" "C:\Windows\INF\oem2.inf" "dfmirage.inf:DFMirage.Mfg.NTx86:DFMirage:2.0.105.0:dfmirage" "670102fe7" "000002B8" "000005B8" "000005E4" | C:\Windows\System32\drvinst.exe | svchost.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 336 | "C:\Users\admin\Desktop\RACE\MirrInst32.exe" -i "dfmirage" "Mirage Driver" "C:\Users\admin\Desktop\RACE\105\" "C:\Users\admin\Desktop\RACE\105\dfmirage.inf" | C:\Users\admin\Desktop\RACE\MirrInst32.exe | — | cmd.exe | |||||||||||
User: admin Company: DemoForge, LLC. Integrity Level: MEDIUM Description: DemoForge Mirror Driver Installer Exit code: 3221226540 Version: 2.0 (build 113) Modules
| |||||||||||||||
| 588 | DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{61acd38a-978b-1f8e-ad1e-6c0a0220d921}\dfmirage.inf" "0" "6d9889773" "000002B8" "WinSta0\Default" "00000064" "208" "C:\Users\admin\Desktop\RACE\105" | C:\Windows\System32\drvinst.exe | svchost.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 748 | C:\Windows\system32\cmd.exe /S /D /c" ver " | C:\Windows\System32\cmd.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1064 | find "5.0" | C:\Windows\System32\find.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Find String (grep) Utility Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1488 | "C:\Users\admin\Desktop\RACE\MirrInst32.exe" -i "dfmirage" "Mirage Driver" "C:\Users\admin\Desktop\RACE\105\" "C:\Users\admin\Desktop\RACE\105\dfmirage.inf" | C:\Users\admin\Desktop\RACE\MirrInst32.exe | cmd.exe | ||||||||||||
User: admin Company: DemoForge, LLC. Integrity Level: HIGH Description: DemoForge Mirror Driver Installer Exit code: 18874368 Version: 2.0 (build 113) Modules
| |||||||||||||||
| 1872 | "C:\Users\admin\Desktop\RACE\MirrInst32.exe" -i "dfmirage" "Mirage Driver" "C:\Users\admin\Desktop\RACE\105\" "C:\Users\admin\Desktop\RACE\105\dfmirage.inf" | C:\Users\admin\Desktop\RACE\MirrInst32.exe | — | cmd.exe | |||||||||||
User: admin Company: DemoForge, LLC. Integrity Level: MEDIUM Description: DemoForge Mirror Driver Installer Exit code: 3221226540 Version: 2.0 (build 113) Modules
| |||||||||||||||
| 2032 | C:\Windows\system32\cmd.exe /S /D /c" ver " | C:\Windows\System32\cmd.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2040 | find "5.1" | C:\Windows\System32\find.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Find String (grep) Utility Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2104 | C:\Windows\system32\cmd.exe /c ""C:\Users\admin\Desktop\RACE\Install.cmd" " | C:\Windows\System32\cmd.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| (PID) Process: | (3988) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3988) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3988) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3988) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (3988) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (3988) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
| (PID) Process: | (3988) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\4672cf66f3eeab147756012e3417b185.zip | |||
| (PID) Process: | (3988) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3988) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3988) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3988 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3988.8244\RACE\Install.cmd | text | |
MD5:E5B4D641C72C9938595A4FD224E6AD1F | SHA256:6DD2494E7619D54AB4C817B5F0933D0B0AC90A6781D79D0D76B9B190BBB1F74C | |||
| 3988 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3988.8244\RACE\MirrInst64.exe | executable | |
MD5:F6E2D04EE7BABDB2DFD80E6C5B79724C | SHA256:27E90FB741B042C3EA596B8323F42FEC9FD6432A24EFA0D3553CFCF381EEBCA9 | |||
| 3988 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3988.8244\RACE\105\x64\dfmirage.sys | executable | |
MD5:178A6E9A0DCE42959FC5AD129F60CBA9 | SHA256:215CB36C6178D47CAA6600B4CA7036DCEFF412141BE4511ED7220A1831820355 | |||
| 3988 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3988.8244\RACE\Uninstall.cmd | text | |
MD5:F0A37851F221A8BCCE03FCED4725946B | SHA256:4174D538E81AF357CE1381B533716D9DF926D6648EF40E8A0E4A02D6C5F49D33 | |||
| 1488 | MirrInst32.exe | C:\Users\admin\AppData\Local\Temp\{61acd38a-978b-1f8e-ad1e-6c0a0220d921}\SETA0E7.tmp | cat | |
MD5:964BD2583871D246F0A01CA9E51ABD9D | SHA256:28200FBD0236E2B1AB2D0D615D45C1672EE4F4B7521FCAAE52F7225EB124303C | |||
| 3988 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3988.8244\RACE\105\x86\dfmirage.dll | executable | |
MD5:B2B8D1C5A6F69B503AB639CD606448ED | SHA256:B9601A692824691DA15AE53747FA68E539044F2D0C60AFED0EB3996A54EBE7EC | |||
| 3988 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3988.8244\RACE\105\x86\dfmirage.sys | executable | |
MD5:699EF0FD9AE72B7F5AD756E382C73E0E | SHA256:18FDAD70917551B0051D4CD97A41174F2BE953FA9173E93410E680292B413870 | |||
| 1488 | MirrInst32.exe | C:\Windows\INF\setupapi.dev.log | text | |
MD5:F8D814901A68E212391E6E9C91164CED | SHA256:6C2D98DFA746335E0696DE65112E7B5C8F7FE4AFDB771F4742B22197EEE5D1F0 | |||
| 1488 | MirrInst32.exe | C:\Users\admin\AppData\Local\Temp\{61acd38a-978b-1f8e-ad1e-6c0a0220d921}\x86\SETA0D7.tmp | executable | |
MD5:699EF0FD9AE72B7F5AD756E382C73E0E | SHA256:18FDAD70917551B0051D4CD97A41174F2BE953FA9173E93410E680292B413870 | |||
| 1488 | MirrInst32.exe | C:\Users\admin\AppData\Local\Temp\{61acd38a-978b-1f8e-ad1e-6c0a0220d921}\x86\dfmirage.dll | executable | |
MD5:B2B8D1C5A6F69B503AB639CD606448ED | SHA256:B9601A692824691DA15AE53747FA68E539044F2D0C60AFED0EB3996A54EBE7EC | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1088 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |