download:

Windows.zip

Full analysis: https://app.any.run/tasks/a4d75013-be05-4a28-8bc9-6b3494aed813
Verdict: Malicious activity
Analysis date: February 08, 2019, 14:08:31
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

BC422930F80138DC2B6155BF919FB1BF

SHA1:

C75F02855433D7D8047604B94094FD986FEE25EE

SHA256:

32AE965A0B8EA94499FFB0368AE4D5A349F84C5B37BA3CBA1874D0BD73DC650C

SSDEEP:

393216:MezlcNnJXiTw/0Yfl9Via+7OMFrkdQyWpq9pUNK:inJXr/0Y99QrkdQpHK

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • laZagne_x86.exe (PID: 2984)
      • laZagne_x86.exe (PID: 4024)
      • laZagne_x86.exe (PID: 3824)
      • laZagne_x86.exe (PID: 2844)
      • laZagne_x86.exe (PID: 3296)
      • laZagne_x86.exe (PID: 2260)
      • laZagne_x86.exe (PID: 2304)
      • laZagne_x86.exe (PID: 2892)
      • laZagne_x86.exe (PID: 3488)
      • laZagne_x86.exe (PID: 2748)
      • laZagne_x86.exe (PID: 3640)
      • laZagne_x86.exe (PID: 2548)
    • Loads dropped or rewritten executable

      • laZagne_x86.exe (PID: 2984)
      • laZagne_x86.exe (PID: 2844)
      • laZagne_x86.exe (PID: 2260)
      • laZagne_x86.exe (PID: 3640)
      • laZagne_x86.exe (PID: 2892)
      • laZagne_x86.exe (PID: 2548)
  • SUSPICIOUS

    • Loads Python modules

      • laZagne_x86.exe (PID: 2984)
      • laZagne_x86.exe (PID: 2844)
      • laZagne_x86.exe (PID: 2260)
      • laZagne_x86.exe (PID: 2892)
      • laZagne_x86.exe (PID: 3640)
      • laZagne_x86.exe (PID: 2548)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3912)
      • laZagne_x86.exe (PID: 4024)
      • laZagne_x86.exe (PID: 3824)
      • laZagne_x86.exe (PID: 3296)
      • laZagne_x86.exe (PID: 2304)
      • laZagne_x86.exe (PID: 2748)
      • laZagne_x86.exe (PID: 3488)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 788
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2018:03:22 13:11:09
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: Windows/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
49
Monitored processes
13
Malicious processes
12
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe lazagne_x86.exe lazagne_x86.exe no specs lazagne_x86.exe lazagne_x86.exe no specs lazagne_x86.exe lazagne_x86.exe no specs lazagne_x86.exe lazagne_x86.exe no specs lazagne_x86.exe lazagne_x86.exe no specs lazagne_x86.exe lazagne_x86.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2260"C:\Users\admin\Desktop\laZagne_x86.exe" C:\Users\admin\Desktop\laZagne_x86.exelaZagne_x86.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1
Modules
Images
c:\users\admin\desktop\lazagne_x86.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\users\admin\appdata\local\temp\_mei32962\python27.dll
2304"C:\Users\admin\Desktop\laZagne_x86.exe" C:\Users\admin\Desktop\laZagne_x86.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1
Modules
Images
c:\users\admin\desktop\lazagne_x86.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\nsi.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\apphelp.dll
2548"C:\Users\admin\Desktop\laZagne_x86.exe" C:\Users\admin\Desktop\laZagne_x86.exelaZagne_x86.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1
Modules
Images
c:\users\admin\desktop\lazagne_x86.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\users\admin\appdata\local\temp\_mei34882\python27.dll
2748"C:\Users\admin\Desktop\laZagne_x86.exe" C:\Users\admin\Desktop\laZagne_x86.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1
Modules
Images
c:\users\admin\desktop\lazagne_x86.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\apphelp.dll
2844"C:\Users\admin\Desktop\laZagne_x86.exe" C:\Users\admin\Desktop\laZagne_x86.exelaZagne_x86.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1
Modules
Images
c:\users\admin\desktop\lazagne_x86.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\users\admin\appdata\local\temp\_mei38242\python27.dll
2892"C:\Users\admin\Desktop\laZagne_x86.exe" C:\Users\admin\Desktop\laZagne_x86.exelaZagne_x86.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1
Modules
Images
c:\users\admin\desktop\lazagne_x86.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\users\admin\appdata\local\temp\_mei23042\python27.dll
2984"C:\Users\admin\Desktop\laZagne_x86.exe" C:\Users\admin\Desktop\laZagne_x86.exelaZagne_x86.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1
Modules
Images
c:\users\admin\desktop\lazagne_x86.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\users\admin\appdata\local\temp\_mei40242\python27.dll
3296"C:\Users\admin\Desktop\laZagne_x86.exe" C:\Users\admin\Desktop\laZagne_x86.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1
Modules
Images
c:\users\admin\desktop\lazagne_x86.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\apphelp.dll
3488"C:\Users\admin\Desktop\laZagne_x86.exe" C:\Users\admin\Desktop\laZagne_x86.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1
Modules
Images
c:\users\admin\desktop\lazagne_x86.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\apphelp.dll
3640"C:\Users\admin\Desktop\laZagne_x86.exe" C:\Users\admin\Desktop\laZagne_x86.exelaZagne_x86.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1
Modules
Images
c:\users\admin\desktop\lazagne_x86.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\users\admin\appdata\local\temp\_mei27482\python27.dll
Total events
439
Read events
416
Write events
23
Delete events
0

Modification events

(PID) Process:(3912) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3912) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3912) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3912) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Windows.zip
(PID) Process:(3912) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3912) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3912) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3912) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3912) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(3912) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
Executable files
188
Suspicious files
0
Text files
12
Unknown types
0

Dropped files

PID
Process
Filename
Type
3912WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3912.44950\Windows\laZagne_x86.exe
MD5:
SHA256:
4024laZagne_x86.exeC:\Users\admin\AppData\Local\Temp\_MEI40242\Crypto.Util.strxor.pydexecutable
MD5:9A54EFCC5C341D85A40BC1EB8778404C
SHA256:54F0903C422D01D770F706F8143F5D841DEEA3EFCD17BCCDF001617EF8FA1177
3912WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3912.44267\Windows\laZagne_x64.exeexecutable
MD5:0B86D572F837AF0209C27392FC2BA7E3
SHA256:D5FA28CBF3A73AC20D908ACEDFCE3849477648E37391E8E926EC2E7933F175A0
4024laZagne_x86.exeC:\Users\admin\AppData\Local\Temp\_MEI40242\Crypto.Cipher._DES.pydexecutable
MD5:998B516BD0348ABFB87FBB578D5D8B93
SHA256:284D0297889D41E0272D09031AC4B2E911836547704B91CE6B1B70C072883CF2
4024laZagne_x86.exeC:\Users\admin\AppData\Local\Temp\_MEI40242\Crypto.Cipher._ARC4.pydexecutable
MD5:2D36279B873B799C39275E823E311230
SHA256:BB97B7D777746E1BCD36DD80A3DA57EC6558F63D431255829BE9CE0A7EA74475
4024laZagne_x86.exeC:\Users\admin\AppData\Local\Temp\_MEI40242\Crypto.Util._counter.pydexecutable
MD5:5E08037C576D0EE18E18F8AE6F827D74
SHA256:92955FA3BCC4B4732F45422131912A3BAEBCC1C30E1EF4484355B8AAF209510C
4024laZagne_x86.exeC:\Users\admin\AppData\Local\Temp\_MEI40242\Crypto.Hash._SHA256.pydexecutable
MD5:0D38A35419B3D5675AB6C4200927BC28
SHA256:1C9F3A66476BE9A46F84BC36BB02B1587202A616E55BBC0B6570A7AA7FEF6EDE
4024laZagne_x86.exeC:\Users\admin\AppData\Local\Temp\_MEI40242\Crypto.Random.OSRNG.winrandom.pydexecutable
MD5:5C35A468F12A53A7F6E8DD281F042DA8
SHA256:F9705903CAA966EEDAE0BDE4DD20E7B44E26A66E60F805CC0ECD718D17C5E8AB
4024laZagne_x86.exeC:\Users\admin\AppData\Local\Temp\_MEI40242\Crypto.Cipher._AES.pydexecutable
MD5:052643DA8529E74F179B0308923AE6F1
SHA256:430844D99AE87C99FD78B83256E228B7E77C80F88C529030C28CAF6063E02358
4024laZagne_x86.exeC:\Users\admin\AppData\Local\Temp\_MEI40242\Crypto.Cipher._DES3.pydexecutable
MD5:0DB4BD1129984067D51C2B2556B6976B
SHA256:044D4E2137706B41A121A01A6F1EA78488AE3AA0B9F61744CB2DAFB0400F55EF
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info