File name:

360zip_setup.exe

Full analysis: https://app.any.run/tasks/dc2289b8-1b31-41ff-8ee1-49b2703aaceb
Verdict: Malicious activity
Threats:

Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.

Analysis date: October 29, 2024, 13:26:24
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-doc
stealer
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections
MD5:

A5A77DD46371CA24D7DC6E8AC86E15FD

SHA1:

0D1337FBC378928B6E3E24730F4DC2D1BABC906B

SHA256:

32BE06A580EA8FD869B77560908C4790A01E523B68A437677DE72DF3BC4CFC35

SSDEEP:

98304:iAR73JY8uLiMozaDyoQbm6PZAZ3GewjUiTb7oAyWtBdTTEJ4r1Jj38P5pJ2IpDEH:5mAoh6nTX/P+TJ/18zpRv2g

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Actions looks like stealing of personal data

      • 360zip_setup.exe (PID: 5944)
    • Registers / Runs the DLL via REGSVR32.EXE

      • 360zip_setup.exe (PID: 5944)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • 360zip_setup.exe (PID: 5944)
    • Drops 7-zip archiver for unpacking

      • 360zip_setup.exe (PID: 5944)
    • Executable content was dropped or overwritten

      • 360zip_setup.exe (PID: 5944)
    • The process verifies whether the antivirus software is installed

      • 360zip_setup.exe (PID: 5944)
  • INFO

    • Create files in a temporary directory

      • 360zip_setup.exe (PID: 5944)
    • Checks supported languages

      • 360zip_setup.exe (PID: 5944)
    • Creates files in the program directory

      • 360zip_setup.exe (PID: 5944)
    • Reads the computer name

      • 360zip_setup.exe (PID: 5944)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:10:16 02:05:13+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 9
CodeSize: 596480
InitializedDataSize: 15040512
UninitializedDataSize: -
EntryPoint: 0x672b5
OSVersion: 5
ImageVersion: -
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 4.0.0.1540
ProductVersionNumber: 4.0.0.1540
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Dynamic link library
FileSubtype: -
LanguageCode: Chinese (Simplified)
CharacterSet: Unicode
Comments: 360压缩
CompanyName: 360.cn
FileDescription: 360压缩安装程序
FileVersion: 4, 0, 0, 1540
InternalName: 360zipsetup
LegalCopyright: 360.cn
OriginalFileName: 360zipsetup.exe
ProductName: 360压缩
ProductVersion: 4, 0, 0, 1540
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
135
Monitored processes
5
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start 360zip_setup.exe regsvr32.exe no specs 360zip.exe 360zip.exe 360zip_setup.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3128"C:\Users\admin\AppData\Local\Temp\360zip_setup.exe" C:\Users\admin\AppData\Local\Temp\360zip_setup.exeexplorer.exe
User:
admin
Company:
360.cn
Integrity Level:
MEDIUM
Description:
360压缩安装程序
Exit code:
3221226540
Version:
4, 0, 0, 1540
Modules
Images
c:\users\admin\appdata\local\temp\360zip_setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
5332C:\WINDOWS\Sysnative\regsvr32.exe /s "C:\Program Files (x86)\360\360zip\360ZipExt64.dll"C:\Windows\System32\regsvr32.exe360zip_setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
5944"C:\Users\admin\AppData\Local\Temp\360zip_setup.exe" C:\Users\admin\AppData\Local\Temp\360zip_setup.exe
explorer.exe
User:
admin
Company:
360.cn
Integrity Level:
HIGH
Description:
360压缩安装程序
Exit code:
0
Version:
4, 0, 0, 1540
Modules
Images
c:\users\admin\appdata\local\temp\360zip_setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
6992"C:\Program Files (x86)\360\360zip\360zip.exe" -install /newC:\Program Files (x86)\360\360zip\360zip.exe
360zip_setup.exe
User:
admin
Company:
360.cn
Integrity Level:
HIGH
Description:
360压缩
Exit code:
0
Version:
4, 0, 0, 1460
Modules
Images
c:\program files (x86)\360\360zip\360zip.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
7152"C:\Program Files (x86)\360\360zip\360zip.exe" /run_by_installerC:\Program Files (x86)\360\360zip\360zip.exe
360zip_setup.exe
User:
admin
Company:
360.cn
Integrity Level:
HIGH
Description:
360压缩
Version:
4, 0, 0, 1460
Modules
Images
c:\program files (x86)\360\360zip\360zip.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
Total events
5 685
Read events
4 106
Write events
1 301
Delete events
278

Modification events

(PID) Process:(5944) 360zip_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{1A893393-71A8-4a50-95A1-2B89DE87B24C}
Operation:delete keyName:(default)
Value:
(PID) Process:(5944) 360zip_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\360Safe\Liveup
Operation:writeName:mid
Value:
80342cb959da2233832ae840f019ccba8b56b331eb673be97c52113eab1cd1bc
(PID) Process:(5332) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9179176E-B763-3200-8500-BB1B90B3D5DE}\InprocServer32
Operation:writeName:ThreadingModel
Value:
Apartment
(PID) Process:(5332) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
Operation:writeName:{9179176E-B763-3200-8500-BB1B90B3D5DE}
Value:
360ѹËõ Shell Extension
(PID) Process:(5944) 360zip_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{9179176E-B763-3200-8500-BB1B90B3D5DE}\InprocServer32
Operation:writeName:ThreadingModel
Value:
Apartment
(PID) Process:(6992) 360zip.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\360Safe\Liveup
Operation:writeName:m2
Value:
fe9694f777e256d0cc4755a6dd1f6ad7651f60d32bec
(PID) Process:(6992) 360zip.exeKey:HKEY_CURRENT_USER\SOFTWARE\360zip\FileAssoc
Operation:writeName:AssocFileType
Value:
001;7z;arj;bz2;bzip2;cab;cpio;deb;dmg;fat;gz;gzip;hfs;lha;lzh;lzma;ntfs;rar;rpm;squashfs;swm;tar;taz;tbz;tbz2;tgz;tpz;txz;vhd;wim;xar;xz;z;zip;
(PID) Process:(6992) 360zip.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\360zip.exe
Operation:writeName:Path
Value:
C:\Program Files (x86)\360\360zip
(PID) Process:(6992) 360zip.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\360zip\Capabilities
Operation:writeName:ApplicationDescription
Value:
360压缩
(PID) Process:(6992) 360zip.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\360zip\Capabilities\FileAssociations
Operation:writeName:.001
Value:
360zip
Executable files
113
Suspicious files
28
Text files
92
Unknown types
4

Dropped files

PID
Process
Filename
Type
5944360zip_setup.exeC:\Users\admin\AppData\Local\Temp\{C4946140-844C-499c-AB13-23B7D2EAC4DB}.tmp
MD5:
SHA256:
5944360zip_setup.exeC:\Users\admin\AppData\Local\Temp\{75895521-736F-4348-9B64-B361CD63D9E6}.tmpexecutable
MD5:6CF0E704C7AE3EA3452D3C0457D58E3A
SHA256:36C27DC744F871142FEA6D6345916EE04121BCD6D119B0CBD2F0D6DD6D20E14B
5944360zip_setup.exeC:\Users\admin\AppData\Local\Temp\{B496F840-3B7B-4d2a-894A-74C900D98CB8}.tmp\config\defaultskin\Skin.jpgimage
MD5:5D1059252A64312D62181DAE70A16EDE
SHA256:C3283EAEBA5DB93FD5A4F6EF457080C86822BC7B51A85284F46C98E1E6C45338
5944360zip_setup.exeC:\Users\admin\AppData\Local\Temp\{23471782-6EEB-4593-8A04-EA10DCE2D224}.tmp\7z.dllexecutable
MD5:6CF0E704C7AE3EA3452D3C0457D58E3A
SHA256:36C27DC744F871142FEA6D6345916EE04121BCD6D119B0CBD2F0D6DD6D20E14B
5944360zip_setup.exeC:\Users\admin\AppData\Local\Temp\{B496F840-3B7B-4d2a-894A-74C900D98CB8}.tmp\config\zcomment\skin\skin1.jpgimage
MD5:254F08B459F9586B5F396E1FD0BCF83E
SHA256:DC75FDCDADA93E82EA23C4E7F5481C77208325804824C574CC6F7591E4044ADA
5944360zip_setup.exeC:\Program Files (x86)\360\360zip\config\defaultskin\Skin.jpgimage
MD5:5D1059252A64312D62181DAE70A16EDE
SHA256:C3283EAEBA5DB93FD5A4F6EF457080C86822BC7B51A85284F46C98E1E6C45338
5944360zip_setup.exeC:\Program Files (x86)\360\360zip\config\zcomment\skin\skin1.jpgimage
MD5:254F08B459F9586B5F396E1FD0BCF83E
SHA256:DC75FDCDADA93E82EA23C4E7F5481C77208325804824C574CC6F7591E4044ADA
5944360zip_setup.exeC:\Users\admin\AppData\Local\Temp\{B496F840-3B7B-4d2a-894A-74C900D98CB8}.tmp\config\zcomment\skin\skin2.jpgimage
MD5:8CAB43852A5677C00E949B92E9D8EFB5
SHA256:D73FA1136D46266C7A2B5E418E1ADEC9281B0E42CAA7741040CB7DB8F7274D4E
5944360zip_setup.exeC:\Users\admin\AppData\Local\Temp\{3FA901A0-971F-4c51-85C2-F2850D015EC8}.tmpcompressed
MD5:2A01DCD8CFA940462D8A2BB22B6792B0
SHA256:2E39283B88F014EEB4A7188A3FB39C3CDC8D110E0C8DED3745A37F9FC3441F62
5944360zip_setup.exeC:\Users\admin\AppData\Local\Temp\{B496F840-3B7B-4d2a-894A-74C900D98CB8}.tmp\config\zcomment\skin\skin5.jpgimage
MD5:F686C8FB34D556023DDC6B2258234A2D
SHA256:2EF010C2074CD0F5A21133AE532FE9B81639DB00B6646E1D6121C3FE41D361A6
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
16
TCP/UDP connections
44
DNS requests
21
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6364
SIHClient.exe
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
4360
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
5944
360zip_setup.exe
POST
200
1.192.137.22:80
http://s.f.360.cn/scan
unknown
whitelisted
5488
MoUsoCoreWorker.exe
GET
200
2.16.164.43:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5488
MoUsoCoreWorker.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4700
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5944
360zip_setup.exe
POST
200
1.192.137.22:80
http://s.f.360.cn/scan
unknown
whitelisted
5944
360zip_setup.exe
POST
200
1.192.137.22:80
http://s.f.360.cn/scan
unknown
whitelisted
6992
360zip.exe
POST
200
1.192.137.22:80
http://s.f.360.cn/scan
unknown
whitelisted
6992
360zip.exe
POST
200
1.192.137.22:80
http://s.f.360.cn/scan
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
5488
MoUsoCoreWorker.exe
2.16.164.43:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
5488
MoUsoCoreWorker.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6944
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1584
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4020
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
5944
360zip_setup.exe
1.192.137.22:80
s.f.360.cn
Luoyang, Henan Province, P.R.China.
CN
whitelisted
4360
SearchApp.exe
2.23.209.133:443
www.bing.com
Akamai International B.V.
GB
whitelisted

DNS requests

Domain
IP
Reputation
crl.microsoft.com
  • 2.16.164.43
  • 2.16.164.9
  • 2.16.164.49
  • 2.16.164.106
  • 2.16.164.18
whitelisted
www.microsoft.com
  • 95.101.149.131
  • 23.52.120.96
whitelisted
google.com
  • 142.250.185.110
whitelisted
settings-win.data.microsoft.com
  • 51.104.136.2
  • 20.73.194.208
whitelisted
s.f.360.cn
  • 1.192.137.22
  • 36.99.172.78
whitelisted
www.bing.com
  • 2.23.209.133
  • 2.23.209.131
  • 2.23.209.185
  • 2.23.209.187
  • 2.23.209.186
  • 2.23.209.130
  • 2.23.209.135
  • 2.23.209.189
  • 2.23.209.132
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 20.190.160.22
  • 40.126.32.136
  • 40.126.32.133
  • 40.126.32.72
  • 20.190.160.20
  • 20.190.160.17
  • 40.126.32.74
  • 40.126.32.68
whitelisted
th.bing.com
  • 2.23.209.132
  • 2.23.209.140
  • 2.23.209.135
  • 2.23.209.131
  • 2.23.209.187
  • 2.23.209.130
  • 2.23.209.137
  • 2.23.209.189
  • 2.23.209.133
whitelisted
go.microsoft.com
  • 184.28.89.167
whitelisted

Threats

No threats detected
No debug info