| File name: | Fix pc-lap.zip.zip |
| Full analysis: | https://app.any.run/tasks/775af82f-23c1-4f60-8de5-8ed4c2f04cb2 |
| Verdict: | Malicious activity |
| Analysis date: | October 20, 2023, 22:33:20 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | C01AA6D95CB41E05A8CF798E92EF181C |
| SHA1: | 276B0F08FA3DCFD56720FBACBDD0DD28C0A49BB1 |
| SHA256: | 348CB8392D41FE66A72482CA97AF770083888864BC592CDE9BA689F0D7ABDEA6 |
| SSDEEP: | 196608:WnfuVTP+abTGte15kRwCpXo/wQzHHJGqyp2W7hvdeQjF+JjywzFhv4kvFmzcQMFR:WnfuVTXAgSRZoTMF2WV1LjFaHYkIPt6x |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipFileName: | Fix pc-lap.zip |
|---|---|
| ZipUncompressedSize: | 13509850 |
| ZipCompressedSize: | 13511221 |
| ZipCRC: | 0xb3df2218 |
| ZipModifyDate: | 2023:10:19 22:21:42 |
| ZipCompression: | Deflated |
| ZipBitFlag: | 0x0009 |
| ZipRequiredVersion: | 20 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 632 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3576 --field-trial-handle=1296,i,14396177915336481163,17552431446446489026,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 820 | "C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe6_ Global\UsGthrCtrlFltPipeMssGthrPipe6 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" | C:\Windows\System32\SearchProtocolHost.exe | — | SearchIndexer.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft Windows Search Protocol Host Exit code: 0 Version: 7.00.7601.24542 (win7sp1_ldr_escrow.191209-2211) Modules
| |||||||||||||||
| 1176 | "C:\Users\admin\Desktop\Winrar v5_40-x86_x64.exe" | C:\Users\admin\Desktop\Winrar v5_40-x86_x64.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 1336 | cmd /v:on /c echo(^!param^! | C:\Windows\System32\cmd.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1536 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1188 --field-trial-handle=1296,i,14396177915336481163,17552431446446489026,131072 /prefetch:2 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1576 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3592 --field-trial-handle=1296,i,14396177915336481163,17552431446446489026,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1740 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3640 --field-trial-handle=1296,i,14396177915336481163,17552431446446489026,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1840 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3532 --field-trial-handle=1296,i,14396177915336481163,17552431446446489026,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 2196 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3840 --field-trial-handle=1296,i,14396177915336481163,17552431446446489026,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 2212 | "C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\AppData\Local\Temp\Rar$DIa2440.41047\Serial.txt | C:\Windows\System32\notepad.exe | — | WinRAR.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Notepad Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (2752) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2752) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (2752) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (2752) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (2752) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2752) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2752) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2752) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (2752) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2752) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 4060 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa4060.21855\Fix pc-lap\Acti1vad0r W10 OFFICE.rar | compressed | |
MD5:0CDA81B6DF6E2551FD023138B8128CD0 | SHA256:C8C3D16BC4ECB3E5A2E94FEAB4322FB5DF3530D58EE0BCC9F80EB772489A776A | |||
| 4060 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa4060.21855\Fix pc-lap\KMS_VL_ALL-41r\$OEM$\$\Setup\Scripts\bin\cleanosppx64.exe | executable | |
MD5:162AB955CB2F002A73C1530AA796477F | SHA256:5CE462E5F34065FC878362BA58617FAB28C22D631B9D836DDDCF43FB1AD4DE6E | |||
| 2752 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DIb2752.20353\Fix pc-lap.zip | compressed | |
MD5:36460C8240DDACF944CA82C24159D1AB | SHA256:5F3E55C7B57B353B9C2C311339FDF616779ABC0D78D1D26441AF31175CBA5E9B | |||
| 4060 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa4060.21855\Fix pc-lap\your_uninstaller_pro_2011.rar | — | |
MD5:— | SHA256:— | |||
| 4060 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa4060.21855\Fix pc-lap\KMS_VL_ALL-41r\$OEM$\$\Setup\Scripts\bin\A64.dll | executable | |
MD5:92C55495ECDC742B434D6B28827873A3 | SHA256:719FC76A343B9F07A10CB61FF620E5C56A41CD8A9305C5573DA52560E2F7A9C5 | |||
| 4060 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa4060.21855\Fix pc-lap\KMS_VL_ALL-41r\$OEM$\$\Setup\Scripts\bin\x64.dll | executable | |
MD5:C1B097EDE269EF5941C27B66621105EB | SHA256:A1FE9948E692B1FA2EBBA3C3D6FB2B88F7D97B418398369AD3865418C4E3CB88 | |||
| 4060 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa4060.21855\Fix pc-lap\KMS_VL_ALL-41r\$OEM$\$\Setup\Scripts\bin\SvcTrigger.xml | xml | |
MD5:ADE0007995DA8218A924EAE18DD5FFA4 | SHA256:6C4C7816D99652A6248E8877AC24D341B3D87BB1E7A6BE159EACBB6B6BC61352 | |||
| 4060 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa4060.21855\Fix pc-lap\KMS_VL_ALL-41r\bin\cleanosppx64.exe | executable | |
MD5:162AB955CB2F002A73C1530AA796477F | SHA256:5CE462E5F34065FC878362BA58617FAB28C22D631B9D836DDDCF43FB1AD4DE6E | |||
| 4060 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa4060.21855\Fix pc-lap\KMS_VL_ALL-41r\bin\cleanosppx86.exe | executable | |
MD5:5FD363D52D04AC200CD24F3BCC903200 | SHA256:3FDEFE2AD092A9A7FE0EDF0AC4DC2DE7E5B9CE6A0804F6511C06564194966CF9 | |||
| 4060 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa4060.21855\Fix pc-lap\KMS_VL_ALL-41r\bin\SvcTrigger.xml | xml | |
MD5:ADE0007995DA8218A924EAE18DD5FFA4 | SHA256:6C4C7816D99652A6248E8877AC24D341B3D87BB1E7A6BE159EACBB6B6BC61352 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2516 | cc.exe | GET | 403 | 172.67.172.233:80 | http://www.ursoftware.com/sc/getcountry.php | unknown | text | 16 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
3404 | msedge.exe | 13.107.42.16:443 | config.edge.skype.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
2844 | msedge.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
3404 | msedge.exe | 204.79.197.239:443 | edge.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
3404 | msedge.exe | 13.107.21.200:443 | www.bing.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
3404 | msedge.exe | 13.107.21.239:443 | edge.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
3404 | msedge.exe | 67.27.159.252:443 | msedgeextensions.sf.tlu.dl.delivery.mp.microsoft.com | LEVEL3 | US | unknown |
2844 | msedge.exe | 224.0.0.251:5353 | — | — | — | unknown |
3404 | msedge.exe | 40.74.98.195:443 | self.events.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | JP | unknown |
Domain | IP | Reputation |
|---|---|---|
config.edge.skype.com |
| whitelisted |
edge.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
msedgeextensions.sf.tlu.dl.delivery.mp.microsoft.com |
| whitelisted |
self.events.data.microsoft.com |
| whitelisted |
dns.msftncsi.com |
| shared |
www.ursoftware.com |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
2516 | cc.exe | A Network Trojan was detected | ET USER_AGENTS Suspicious User-Agent (Mozilla/3.0 (compatible)) |