download:

Windows.zip

Full analysis: https://app.any.run/tasks/a4d75013-be05-4a28-8bc9-6b3494aed813
Verdict: Malicious activity
Analysis date: February 08, 2019, 14:08:31
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

BC422930F80138DC2B6155BF919FB1BF

SHA1:

C75F02855433D7D8047604B94094FD986FEE25EE

SHA256:

32AE965A0B8EA94499FFB0368AE4D5A349F84C5B37BA3CBA1874D0BD73DC650C

SSDEEP:

393216:MezlcNnJXiTw/0Yfl9Via+7OMFrkdQyWpq9pUNK:inJXr/0Y99QrkdQpHK

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • laZagne_x86.exe (PID: 4024)
      • laZagne_x86.exe (PID: 2984)
      • laZagne_x86.exe (PID: 3824)
      • laZagne_x86.exe (PID: 2844)
      • laZagne_x86.exe (PID: 3296)
      • laZagne_x86.exe (PID: 2260)
      • laZagne_x86.exe (PID: 2748)
      • laZagne_x86.exe (PID: 3640)
      • laZagne_x86.exe (PID: 2892)
      • laZagne_x86.exe (PID: 3488)
      • laZagne_x86.exe (PID: 2548)
      • laZagne_x86.exe (PID: 2304)
    • Loads dropped or rewritten executable

      • laZagne_x86.exe (PID: 2984)
      • laZagne_x86.exe (PID: 2844)
      • laZagne_x86.exe (PID: 2260)
      • laZagne_x86.exe (PID: 3640)
      • laZagne_x86.exe (PID: 2548)
      • laZagne_x86.exe (PID: 2892)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3912)
      • laZagne_x86.exe (PID: 4024)
      • laZagne_x86.exe (PID: 3824)
      • laZagne_x86.exe (PID: 3296)
      • laZagne_x86.exe (PID: 2748)
      • laZagne_x86.exe (PID: 2304)
      • laZagne_x86.exe (PID: 3488)
    • Loads Python modules

      • laZagne_x86.exe (PID: 2984)
      • laZagne_x86.exe (PID: 2844)
      • laZagne_x86.exe (PID: 2260)
      • laZagne_x86.exe (PID: 3640)
      • laZagne_x86.exe (PID: 2892)
      • laZagne_x86.exe (PID: 2548)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 788
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2018:03:22 13:11:09
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: Windows/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
49
Monitored processes
13
Malicious processes
12
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe lazagne_x86.exe lazagne_x86.exe no specs lazagne_x86.exe lazagne_x86.exe no specs lazagne_x86.exe lazagne_x86.exe no specs lazagne_x86.exe lazagne_x86.exe no specs lazagne_x86.exe lazagne_x86.exe no specs lazagne_x86.exe lazagne_x86.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2260"C:\Users\admin\Desktop\laZagne_x86.exe" C:\Users\admin\Desktop\laZagne_x86.exelaZagne_x86.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1
Modules
Images
c:\users\admin\desktop\lazagne_x86.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\users\admin\appdata\local\temp\_mei32962\python27.dll
2304"C:\Users\admin\Desktop\laZagne_x86.exe" C:\Users\admin\Desktop\laZagne_x86.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1
Modules
Images
c:\users\admin\desktop\lazagne_x86.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\nsi.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\apphelp.dll
2548"C:\Users\admin\Desktop\laZagne_x86.exe" C:\Users\admin\Desktop\laZagne_x86.exelaZagne_x86.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1
Modules
Images
c:\users\admin\desktop\lazagne_x86.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\users\admin\appdata\local\temp\_mei34882\python27.dll
2748"C:\Users\admin\Desktop\laZagne_x86.exe" C:\Users\admin\Desktop\laZagne_x86.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1
Modules
Images
c:\users\admin\desktop\lazagne_x86.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\apphelp.dll
2844"C:\Users\admin\Desktop\laZagne_x86.exe" C:\Users\admin\Desktop\laZagne_x86.exelaZagne_x86.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1
Modules
Images
c:\users\admin\desktop\lazagne_x86.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\users\admin\appdata\local\temp\_mei38242\python27.dll
2892"C:\Users\admin\Desktop\laZagne_x86.exe" C:\Users\admin\Desktop\laZagne_x86.exelaZagne_x86.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1
Modules
Images
c:\users\admin\desktop\lazagne_x86.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\users\admin\appdata\local\temp\_mei23042\python27.dll
2984"C:\Users\admin\Desktop\laZagne_x86.exe" C:\Users\admin\Desktop\laZagne_x86.exelaZagne_x86.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1
Modules
Images
c:\users\admin\desktop\lazagne_x86.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\users\admin\appdata\local\temp\_mei40242\python27.dll
3296"C:\Users\admin\Desktop\laZagne_x86.exe" C:\Users\admin\Desktop\laZagne_x86.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1
Modules
Images
c:\users\admin\desktop\lazagne_x86.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\apphelp.dll
3488"C:\Users\admin\Desktop\laZagne_x86.exe" C:\Users\admin\Desktop\laZagne_x86.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1
Modules
Images
c:\users\admin\desktop\lazagne_x86.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\apphelp.dll
3640"C:\Users\admin\Desktop\laZagne_x86.exe" C:\Users\admin\Desktop\laZagne_x86.exelaZagne_x86.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1
Modules
Images
c:\users\admin\desktop\lazagne_x86.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\users\admin\appdata\local\temp\_mei27482\python27.dll
Total events
439
Read events
416
Write events
23
Delete events
0

Modification events

(PID) Process:(3912) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3912) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3912) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3912) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Windows.zip
(PID) Process:(3912) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3912) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3912) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3912) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3912) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(3912) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
Executable files
188
Suspicious files
0
Text files
12
Unknown types
0

Dropped files

PID
Process
Filename
Type
3912WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3912.44950\Windows\laZagne_x86.exe
MD5:
SHA256:
3912WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3912.44267\Windows\laZagne_x64.exeexecutable
MD5:0B86D572F837AF0209C27392FC2BA7E3
SHA256:D5FA28CBF3A73AC20D908ACEDFCE3849477648E37391E8E926EC2E7933F175A0
4024laZagne_x86.exeC:\Users\admin\AppData\Local\Temp\_MEI40242\Crypto.Util.strxor.pydexecutable
MD5:9A54EFCC5C341D85A40BC1EB8778404C
SHA256:54F0903C422D01D770F706F8143F5D841DEEA3EFCD17BCCDF001617EF8FA1177
4024laZagne_x86.exeC:\Users\admin\AppData\Local\Temp\_MEI40242\_ctypes.pydexecutable
MD5:98638A1BFDECDCECF4D7D47B521AC903
SHA256:11C739D28227773D70C3941D2E979B9D4CEE12F1D53CC94DAF77B62A4D3A0327
4024laZagne_x86.exeC:\Users\admin\AppData\Local\Temp\_MEI40242\Crypto.Random.OSRNG.winrandom.pydexecutable
MD5:5C35A468F12A53A7F6E8DD281F042DA8
SHA256:F9705903CAA966EEDAE0BDE4DD20E7B44E26A66E60F805CC0ECD718D17C5E8AB
4024laZagne_x86.exeC:\Users\admin\AppData\Local\Temp\_MEI40242\_bsddb.pydexecutable
MD5:FB7783A4F5F2A91D7B295F4066F7B6C6
SHA256:C43AF5D936F8EBC7C747AE965EA835D9CD47F6D43A35C8221E9FCF9EE252CACB
4024laZagne_x86.exeC:\Users\admin\AppData\Local\Temp\_MEI40242\Microsoft.VC90.CRT.manifestxml
MD5:FEDFDF2256720BADEFF9205E784B5DC8
SHA256:6373FB8261AF01506DC57DEE535A0BE800F3A59B18B0CC1E276807C746329FF6
4024laZagne_x86.exeC:\Users\admin\AppData\Local\Temp\_MEI40242\bz2.pydexecutable
MD5:0B1688C02640EC14D85E1CC3C93F7276
SHA256:753EA279675EEB34FE58908F10CB15886955C865B49C01B533A5930E6B326038
4024laZagne_x86.exeC:\Users\admin\AppData\Local\Temp\_MEI40242\_elementtree.pydexecutable
MD5:5C5B156BF6745E8F5B35B20847028A54
SHA256:781FA154CC862A73C2D3D9B2589B33ED9B5C601F0690F79C182E4F1951D7A82F
4024laZagne_x86.exeC:\Users\admin\AppData\Local\Temp\_MEI40242\_hashlib.pydexecutable
MD5:22071845DAF8C1F6E87F006673EED4FD
SHA256:51C47389782BC2DE8E401D231233E2E7F1A4B3AFCE7DF4DDF4AD533184DAD407
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info