File name:

330cad3946f342bc821c328ae10808819053ff71707a989e36e9518e0c57c236

Full analysis: https://app.any.run/tasks/16145205-c442-45cf-b806-83c3e390d3d2
Verdict: Malicious activity
Analysis date: March 14, 2019, 21:53:51
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract
MD5:

5A28B4648928DD0C931C130648631EA6

SHA1:

54913F4451163921B599BAA69D9D635EB51FD71A

SHA256:

330CAD3946F342BC821C328AE10808819053FF71707A989E36E9518E0C57C236

SSDEEP:

768:bCIqdH/k1ZVcT194jp4HBQUYnDLnY29Tob/h9+rXlULi:bNqaLV8a6hinnY2Omwi

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • john@youtube2.com (PID: 2348)
    • Changes the autorun value in the registry

      • john@youtube2.com (PID: 2348)
  • SUSPICIOUS

    • Starts application with an unusual extension

      • WinRAR.exe (PID: 2856)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2856)
      • john@youtube2.com (PID: 2348)
    • Connects to SMTP port

      • john@youtube2.com (PID: 2348)
    • Connects to unusual port

      • john@youtube2.com (PID: 2348)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2004:03:13 01:10:17
ZipCRC: 0xbe2c57bb
ZipCompressedSize: 36976
ZipUncompressedSize: 36976
ZipFileName: john@youtube2.com
No data.
screenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
30
Monitored processes
2
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start winrar.exe john@youtube2.com

Process information

PID
CMD
Path
Indicators
Parent process
2348"C:\Users\admin\AppData\Local\Temp\Rar$DIa2856.45642\john@youtube2.com" C:\Users\admin\AppData\Local\Temp\Rar$DIa2856.45642\john@youtube2.com
WinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\rar$dia2856.45642\john@youtube2.com
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2856"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\330cad3946f342bc821c328ae10808819053ff71707a989e36e9518e0c57c236.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
464
Read events
437
Write events
27
Delete events
0

Modification events

(PID) Process:(2856) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2856) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2856) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2856) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\330cad3946f342bc821c328ae10808819053ff71707a989e36e9518e0c57c236.zip
(PID) Process:(2856) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2856) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2856) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2856) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2856) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(2856) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
Executable files
2
Suspicious files
1
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
2348john@youtube2.comC:\Users\admin\AppData\Local\Temp\tmpD19B.tmp
MD5:
SHA256:
2348john@youtube2.comC:\Users\admin\AppData\Local\Temp\tmpD1CB.tmp
MD5:
SHA256:
2348john@youtube2.comC:\Users\admin\AppData\Local\Temp\tmpD1DB.tmp
MD5:
SHA256:
2348john@youtube2.comC:\Users\admin\AppData\Local\Temp\tmpD21B.tmp
MD5:
SHA256:
2348john@youtube2.comC:\Users\admin\AppData\Local\Temp\tmpFDB0.tmp
MD5:
SHA256:
2348john@youtube2.comC:\Users\admin\AppData\Local\Temp\tmpFDD0.tmp
MD5:
SHA256:
2348john@youtube2.comC:\Users\admin\AppData\Local\Temp\tmpFE1F.tmp
MD5:
SHA256:
2348john@youtube2.comC:\Users\admin\AppData\Local\Temp\tmpFE30.tmp
MD5:
SHA256:
2348john@youtube2.comC:\Users\admin\AppData\Local\Temp\tmpFE31.tmp
MD5:
SHA256:
2348john@youtube2.comC:\Users\admin\AppData\Local\Temp\tmp1DB.tmp
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
71
DNS requests
96
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2348
john@youtube2.com
24.199.116.33:1042
Time Warner Cable Internet LLC
US
unknown
2348
john@youtube2.com
15.255.18.252:1042
Hewlett-Packard Company
US
unknown
2348
john@youtube2.com
15.228.173.202:1042
Hewlett-Packard Company
US
unknown
2348
john@youtube2.com
158.183.109.61:1042
US
unknown
2348
john@youtube2.com
17.151.62.66:25
nwk-aaemail-lapp01.apple.com
Apple Inc.
US
unknown
2348
john@youtube2.com
216.97.88.9:25
unicode.org
CoreSpace, Inc.
US
unknown
2348
john@youtube2.com
67.195.229.59:25
mta7.am0.yahoodns.net
Yahoo
US
unknown
2348
john@youtube2.com
212.227.17.8:25
mx-ha02.web.de
1&1 Internet SE
DE
unknown
2348
john@youtube2.com
185.199.217.140:25
j3e.de
SerNet Service Network GmbH
DE
unknown
2348
john@youtube2.com
193.40.113.55:25
ingrid.eki.ee
Hariduse Infotehnoloogia Sihtasutus
EE
unknown

DNS requests

Domain
IP
Reputation
dns.msftncsi.com
  • 131.107.255.255
shared
apple.com
whitelisted
unicode.org
  • 216.97.88.9
whitelisted
nwk-aaemail-lapp01.apple.com
  • 17.151.62.66
whitelisted
yahoo.com
  • 98.137.246.8
  • 72.30.35.10
  • 72.30.35.9
  • 98.138.219.231
  • 98.137.246.7
  • 98.138.219.232
whitelisted
mta7.am0.yahoodns.net
  • 67.195.229.59
  • 98.137.159.25
  • 74.6.137.63
  • 98.137.159.24
  • 67.195.228.141
  • 66.218.85.52
  • 74.6.137.64
  • 74.6.137.65
whitelisted
j3e.de
  • 185.199.217.140
unknown
web.de
  • 82.165.230.17
  • 82.165.229.138
shared
mail.j3e.de
  • 185.199.217.140
shared
mx-ha02.web.de
  • 212.227.17.8
unknown

Threats

No threats detected
No debug info