| File name: | cbsidlm-tr1_10a-Advanced_Serial_Port_Monitor-SEO-10187293.zip |
| Full analysis: | https://app.any.run/tasks/cfbba486-ceda-4a64-adaf-29ff7df8e4de |
| Verdict: | Malicious activity |
| Analysis date: | September 25, 2019, 08:03:45 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | 56063A459B7DBA87F4D5384D09C440E8 |
| SHA1: | 0DBF220B50C70E917A79A6A6D8B31426B578F8DF |
| SHA256: | 34B3E238664964B792D324CB65C1FF7FE706AF79CA8786A297BEB53E0947838B |
| SSDEEP: | 12288:wmgyBmK+c9rF9/yeW+3ZfkNdo/mWAndqNFS2cl32MYvTkZ:YyRBqA3ZfkjWAnYNBclcvTe |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | 0x0003 |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2013:01:14 10:47:16 |
| ZipCRC: | 0x311a4909 |
| ZipCompressedSize: | 600811 |
| ZipUncompressedSize: | 635864 |
| ZipFileName: | cbsidlm-tr1_10a-Advanced_Serial_Port_Monitor-SEO-10187293.txt |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2112 | "C:\Program Files\WinRAR\WinRAR.exe" -elevate2764 | C:\Program Files\WinRAR\WinRAR.exe | WinRAR.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: HIGH Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 2764 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\cbsidlm-tr1_10a-Advanced_Serial_Port_Monitor-SEO-10187293.zip" | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 3540 | "C:\cbsidlm-tr1_10a-Advanced_Serial_Port_Monitor-SEO-10187293.exe" | C:\cbsidlm-tr1_10a-Advanced_Serial_Port_Monitor-SEO-10187293.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 3576 | C:\Windows\system32\DllHost.exe /Processid:{3AD05575-8857-4850-9277-11B85BDB8E09} | C:\Windows\system32\DllHost.exe | svchost.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: COM Surrogate Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3624 | "C:\cbsidlm-tr1_10a-Advanced_Serial_Port_Monitor-SEO-10187293.exe" | C:\cbsidlm-tr1_10a-Advanced_Serial_Port_Monitor-SEO-10187293.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| 3852 | "C:\Windows\explorer.exe" | C:\Windows\explorer.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (2764) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (2764) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (2764) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2764) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\cbsidlm-tr1_10a-Advanced_Serial_Port_Monitor-SEO-10187293.zip | |||
| (PID) Process: | (2764) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2764) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2764) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2764) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (2764) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath |
| Operation: | write | Name: | 0 |
Value: C:\ | |||
| (PID) Process: | (2764) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3540 | cbsidlm-tr1_10a-Advanced_Serial_Port_Monitor-SEO-10187293.exe | C:\Users\admin\AppData\Local\Temp\nst9C29.tmp\lua51.dll | executable | |
MD5:13C3A33C1F6E43F38DE533FD0B766C98 | SHA256:4158063B0A868431F6430F54C1192BF20E58A43A6D3D03B740E090951E2F4427 | |||
| 3540 | cbsidlm-tr1_10a-Advanced_Serial_Port_Monitor-SEO-10187293.exe | C:\Users\admin\AppData\Local\Temp\nst9C29.tmp\LuaBridge.dll | executable | |
MD5:CBE3E9D256B05308737716EF87F407E9 | SHA256:979352B90822DF00178C00FA836C76EF3E86EC79B99B61D06D43274EE9351990 | |||
| 2112 | WinRAR.exe | C:\cbsidlm-tr1_10a-Advanced_Serial_Port_Monitor-SEO-10187293.txt | executable | |
MD5:9F5119B4D8EAB88EC8B7CB2804EA7AF5 | SHA256:85096A31802F5BD3279391D1CD2BDE58624D6E1C19DFA965B17683F3BBD118C9 | |||
| 3540 | cbsidlm-tr1_10a-Advanced_Serial_Port_Monitor-SEO-10187293.exe | C:\Users\admin\AppData\Local\Temp\nst9C29.tmp\LuaXml_lib.dll | executable | |
MD5:7292B642BD958AEB7FD7CFD19E45B068 | SHA256:90F1BB98E034FCF7BFDDB8CB0A85B27A9C9DDB01B926B4E139E1E8FC53D41D09 | |||
| 3540 | cbsidlm-tr1_10a-Advanced_Serial_Port_Monitor-SEO-10187293.exe | C:\Users\admin\AppData\Local\Temp\nst9C29.tmp\System.dll | executable | |
MD5:7E3C808299AA2C405DFFA864471DDB7F | SHA256:91C47A9A54A3A8C359E89A8B4E133E6B7296586748ED3E8F4FE566ABD6C81DDD | |||
| 3540 | cbsidlm-tr1_10a-Advanced_Serial_Port_Monitor-SEO-10187293.exe | C:\Users\admin\AppData\Local\Temp\nst9C29.tmp\LuaSocket\lua\socket\tp.lua | text | |
MD5:2CAD406E591CADE482C7F16F39C21481 | SHA256:343AFA62F69C7C140FBBF02B4BA2F7B2F711B6201BB6671C67A3744394084269 | |||
| 3540 | cbsidlm-tr1_10a-Advanced_Serial_Port_Monitor-SEO-10187293.exe | C:\Users\admin\AppData\Local\Temp\nst9C29.tmp\LuaSocket\socket\core.dll | executable | |
MD5:4BF7DB111ACFA7C28AD36606107B3322 | SHA256:BFE8445C38EE71240E856F85D79E94123D7179BF43688DE0E2A14E32E6EF21B0 | |||
| 3540 | cbsidlm-tr1_10a-Advanced_Serial_Port_Monitor-SEO-10187293.exe | C:\Users\admin\AppData\Local\Temp\nst9C29.tmp\LuaSocket\lua\ltn12.lua | text | |
MD5:E440044AFE6C761507A996B5B45AB0F9 | SHA256:B1864AED85C114354B04FBE9B3F41C5EBC4DF6D129E08EF65A0C413D0DAABD29 | |||
| 3540 | cbsidlm-tr1_10a-Advanced_Serial_Port_Monitor-SEO-10187293.exe | C:\Users\admin\AppData\Local\Temp\nst9C29.tmp\LuaXml.lua | text | |
MD5:A34EED4E795D1A7F8F26AF91994B2785 | SHA256:6345B8A47F378416CBD31E543410FA5B03C914219DED2A51C2D3C858F281D6CD | |||
| 3540 | cbsidlm-tr1_10a-Advanced_Serial_Port_Monitor-SEO-10187293.exe | C:\Users\admin\AppData\Local\Temp\nst9C29.tmp\LuaSocket\lua\socket\ftp.lua | text | |
MD5:7309F4294AE4ABB4F6AE657B2A98D488 | SHA256:9BA5DF91091C46F0FFE0A93ACE577A4833C92CBEC1742113D0A2DA9E568F9A10 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3540 | cbsidlm-tr1_10a-Advanced_Serial_Port_Monitor-SEO-10187293.exe | GET | — | 50.22.63.141:80 | http://50.22.63.141:80/dlcom-install?filename=cbsidlm%2dtr1_10a%2dAdvanced_Serial_Port_Monitor%2dSEO%2d10187293%2eexe | US | — | — | malicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3540 | cbsidlm-tr1_10a-Advanced_Serial_Port_Monitor-SEO-10187293.exe | 50.22.63.141:80 | download.webinstall.com | SoftLayer Technologies Inc. | US | malicious |
Domain | IP | Reputation |
|---|---|---|
download.webinstall.com |
| malicious |