analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

330cad3946f342bc821c328ae10808819053ff71707a989e36e9518e0c57c236

Full analysis: https://app.any.run/tasks/16145205-c442-45cf-b806-83c3e390d3d2
Verdict: Malicious activity
Analysis date: March 14, 2019, 21:53:51
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract
MD5:

5A28B4648928DD0C931C130648631EA6

SHA1:

54913F4451163921B599BAA69D9D635EB51FD71A

SHA256:

330CAD3946F342BC821C328AE10808819053FF71707A989E36E9518E0C57C236

SSDEEP:

768:bCIqdH/k1ZVcT194jp4HBQUYnDLnY29Tob/h9+rXlULi:bNqaLV8a6hinnY2Omwi

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

  • SUSPICIOUS

  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: [email protected]
ZipUncompressedSize: 36976
ZipCompressedSize: 36976
ZipCRC: 0xbe2c57bb
ZipModifyDate: 2004:03:13 01:10:17
ZipCompression: None
ZipBitFlag: -
ZipRequiredVersion: 10
No data.
screenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
30
Monitored processes
2
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start winrar.exe [email protected]

Process information

PID
CMD
Path
Indicators
Parent process
2856"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\330cad3946f342bc821c328ae10808819053ff71707a989e36e9518e0c57c236.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2348"C:\Users\admin\AppData\Local\Temp\Rar$DIa2856.45642\[email protected]" C:\Users\admin\AppData\Local\Temp\Rar$DIa2856.45642\[email protected]
WinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\users\admin\appdata\local\temp\rar$dia2856.45642\[email protected]
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
464
Read events
437
Write events
27
Delete events
0

Modification events

(PID) Process:(2856) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2856) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2856) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2856) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\330cad3946f342bc821c328ae10808819053ff71707a989e36e9518e0c57c236.zip
(PID) Process:(2856) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2856) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2856) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2856) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2856) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(2856) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
Executable files
2
Suspicious files
1
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
2348[email protected]C:\Users\admin\AppData\Local\Temp\tmpD19B.tmp
MD5:
SHA256:
2348[email protected]C:\Users\admin\AppData\Local\Temp\tmpD1CB.tmp
MD5:
SHA256:
2348[email protected]C:\Users\admin\AppData\Local\Temp\tmpD1DB.tmp
MD5:
SHA256:
2348[email protected]C:\Users\admin\AppData\Local\Temp\tmpD21B.tmp
MD5:
SHA256:
2348[email protected]C:\Users\admin\AppData\Local\Temp\tmpFDB0.tmp
MD5:
SHA256:
2348[email protected]C:\Users\admin\AppData\Local\Temp\tmpFDD0.tmp
MD5:
SHA256:
2348[email protected]C:\Users\admin\AppData\Local\Temp\tmpFE1F.tmp
MD5:
SHA256:
2348[email protected]C:\Users\admin\AppData\Local\Temp\tmpFE30.tmp
MD5:
SHA256:
2348[email protected]C:\Users\admin\AppData\Local\Temp\tmpFE31.tmp
MD5:
SHA256:
2348[email protected]C:\Users\admin\AppData\Local\Temp\tmp1DB.tmp
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
71
DNS requests
96
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2348
10.21.141.83:1042
unknown
2348
16.115.196.82:1042
Hewlett-Packard Company
US
unknown
2348
15.255.18.252:1042
Hewlett-Packard Company
US
unknown
2348
24.199.116.33:1042
Time Warner Cable Internet LLC
US
unknown
2348
15.228.173.202:1042
Hewlett-Packard Company
US
unknown
2348
10.16.37.204:1042
unknown
2348
16.115.194.223:1042
Hewlett-Packard Company
US
unknown
2348
158.183.109.61:1042
US
unknown
2348
17.151.62.66:25
nwk-aaemail-lapp01.apple.com
Apple Inc.
US
unknown
2348
67.195.229.59:25
mta7.am0.yahoodns.net
Yahoo
US
unknown

DNS requests

Domain
IP
Reputation
dns.msftncsi.com
  • 131.107.255.255
shared
apple.com
whitelisted
unicode.org
  • 216.97.88.9
whitelisted
nwk-aaemail-lapp01.apple.com
  • 17.151.62.66
whitelisted
yahoo.com
  • 98.137.246.8
  • 72.30.35.10
  • 72.30.35.9
  • 98.138.219.231
  • 98.137.246.7
  • 98.138.219.232
whitelisted
mta7.am0.yahoodns.net
  • 67.195.229.59
  • 98.137.159.25
  • 74.6.137.63
  • 98.137.159.24
  • 67.195.228.141
  • 66.218.85.52
  • 74.6.137.64
  • 74.6.137.65
whitelisted
j3e.de
  • 185.199.217.140
unknown
web.de
  • 82.165.230.17
  • 82.165.229.138
shared
mail.j3e.de
  • 185.199.217.140
shared
mx-ha02.web.de
  • 212.227.17.8
unknown

Threats

No threats detected
No debug info