File name:

CloneCD key.zip

Full analysis: https://app.any.run/tasks/49a1eb45-e0b0-41c6-b768-f51a306dbd0a
Verdict: Malicious activity
Analysis date: May 11, 2020, 14:49:07
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

6E35A0C5311312B825AAF4A2B4E28B35

SHA1:

C98BED464653AAE6379093F86423FE2B03F7AC46

SHA256:

353EA6C7216958094E2D9FF82DA825A2DA7ED52E2043D74F8DC987FD03CD5D4B

SSDEEP:

49152:/Vetxfvodt9gJeo0VrH9DJrgrdCo7kbZlOkZi5D4wavcws/ctgP1BLjKORE0h:NsfvSueoAdJkr8omOIs4wYZo9PDKORDh

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • SetupCloneCD5340.exe (PID: 2440)
      • nstC6BA.tmp (PID: 2472)
      • SetupCloneCD5340.exe (PID: 1524)
      • SetACL.exe (PID: 2672)
      • SetRegACL.exe (PID: 3744)
      • ExecuteWithUAC.exe (PID: 2948)
      • CloneCDTray.exe (PID: 2784)
      • RegCloneCD.exe (PID: 1332)
      • RegCloneCD.exe (PID: 3620)
      • ExecuteWithUAC.exe (PID: 1564)
      • RegCloneCD.exe (PID: 916)
      • RegCloneCD.exe (PID: 3384)
      • CloneCD.exe (PID: 4012)
      • CloneCD.exe (PID: 1168)
    • Loads dropped or rewritten executable

      • nstC6BA.tmp (PID: 2472)
      • CloneCDTray.exe (PID: 2784)
      • CloneCD.exe (PID: 4012)
      • CloneCD.exe (PID: 1168)
    • Changes the autorun value in the registry

      • nstC6BA.tmp (PID: 2472)
    • Loads the Task Scheduler COM API

      • ExecuteWithUAC.exe (PID: 2948)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2376)
      • SetupCloneCD5340.exe (PID: 1524)
      • nstC6BA.tmp (PID: 2472)
    • Modifies the open verb of a shell class

      • nstC6BA.tmp (PID: 2472)
    • Starts application with an unusual extension

      • SetupCloneCD5340.exe (PID: 1524)
    • Creates a software uninstall entry

      • nstC6BA.tmp (PID: 2472)
    • Creates files in the program directory

      • RegCloneCD.exe (PID: 3620)
      • nstC6BA.tmp (PID: 2472)
    • Creates files in the driver directory

      • nstC6BA.tmp (PID: 2472)
    • Creates or modifies windows services

      • nstC6BA.tmp (PID: 2472)
    • Creates files in the Windows directory

      • nstC6BA.tmp (PID: 2472)
    • Executed via Task Scheduler

      • ExecuteWithUAC.exe (PID: 1564)
  • INFO

    • Manual execution by user

      • SetupCloneCD5340.exe (PID: 2440)
      • SetupCloneCD5340.exe (PID: 1524)
      • RegCloneCD.exe (PID: 1332)
      • RegCloneCD.exe (PID: 3620)
      • RegCloneCD.exe (PID: 3384)
      • CloneCD.exe (PID: 4012)
      • CloneCD.exe (PID: 1168)
      • RegCloneCD.exe (PID: 916)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2020:05:11 16:47:28
ZipCRC: 0xe429bc40
ZipCompressedSize: 257
ZipUncompressedSize: 290
ZipFileName: 2Key.CloneCD
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
66
Monitored processes
15
Malicious processes
5
Suspicious processes
3

Behavior graph

Click at the process to see the details
start drop and start drop and start drop and start drop and start winrar.exe setupclonecd5340.exe no specs setupclonecd5340.exe nstc6ba.tmp setregacl.exe no specs setacl.exe no specs executewithuac.exe no specs executewithuac.exe no specs clonecdtray.exe no specs regclonecd.exe no specs regclonecd.exe clonecd.exe no specs regclonecd.exe no specs regclonecd.exe clonecd.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
916"C:\Program Files\RedFox\CloneCD\RegCloneCD.exe" "C:\Users\admin\Desktop\2Key.CloneCD"C:\Program Files\RedFox\CloneCD\RegCloneCD.exeexplorer.exe
User:
admin
Company:
RedFox
Integrity Level:
MEDIUM
Description:
CloneCD Registration Tool
Exit code:
3221226540
Version:
5, 1, 1, 0
Modules
Images
c:\program files\redfox\clonecd\regclonecd.exe
c:\systemroot\system32\ntdll.dll
1168"C:\Program Files\RedFox\CloneCD\CloneCD.exe" C:\Program Files\RedFox\CloneCD\CloneCD.exeexplorer.exe
User:
admin
Company:
RedFox
Integrity Level:
MEDIUM
Description:
CloneCD Replicator Program
Exit code:
0
Version:
5.3.4.0
Modules
Images
c:\program files\redfox\clonecd\clonecd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\elbycdio.dll
c:\program files\redfox\clonecd\elbyecc.dll
c:\program files\redfox\clonecd\ccddriver.dll
c:\program files\redfox\clonecd\writedvd.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1332"C:\Program Files\RedFox\CloneCD\RegCloneCD.exe" "C:\Users\admin\Desktop\Key.CloneCD"C:\Program Files\RedFox\CloneCD\RegCloneCD.exeexplorer.exe
User:
admin
Company:
RedFox
Integrity Level:
MEDIUM
Description:
CloneCD Registration Tool
Exit code:
3221226540
Version:
5, 1, 1, 0
Modules
Images
c:\program files\redfox\clonecd\regclonecd.exe
c:\systemroot\system32\ntdll.dll
1524"C:\Users\admin\Desktop\SetupCloneCD5340.exe" C:\Users\admin\Desktop\SetupCloneCD5340.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\setupclonecd5340.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
1564"C:\Program Files\RedFox\CloneCD\ExecuteWithUAC.exe" /eC:\Program Files\RedFox\CloneCD\ExecuteWithUAC.exetaskeng.exe
User:
admin
Integrity Level:
MEDIUM
Description:
ElbyCDIO install helper process
Exit code:
0
Version:
1, 0, 0, 1
Modules
Images
c:\program files\redfox\clonecd\executewithuac.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2376"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\CloneCD key.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2440"C:\Users\admin\Desktop\SetupCloneCD5340.exe" C:\Users\admin\Desktop\SetupCloneCD5340.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\setupclonecd5340.exe
c:\systemroot\system32\ntdll.dll
2472nstC6BA.tmp /DOITC:\Users\admin\AppData\Local\Temp\nstC6AA.tmp\nstC6BA.tmp
SetupCloneCD5340.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\nstc6aa.tmp\nstc6ba.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2672"C:\Users\admin\AppData\Local\Temp\nstC794.tmp\SetACL.exe" "C:\ProgramData\SlySoft" /dir /grant S-1-5-32-545 /full /sid /silentC:\Users\admin\AppData\Local\Temp\nstC794.tmp\SetACL.exenstC6BA.tmp
User:
admin
Company:
Helge Klein
Integrity Level:
HIGH
Description:
SetACL
Exit code:
0
Version:
0, 9, 0, 4
Modules
Images
c:\users\admin\appdata\local\temp\nstc794.tmp\setacl.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wkscli.dll
2784"C:\Program Files\RedFox\CloneCD\CloneCDTray.exe" /sC:\Program Files\RedFox\CloneCD\CloneCDTray.exeExecuteWithUAC.exe
User:
admin
Company:
RedFox
Integrity Level:
MEDIUM
Description:
CloneCD Tray
Exit code:
0
Version:
5, 3, 3, 0
Modules
Images
c:\program files\redfox\clonecd\clonecdtray.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
Total events
692
Read events
584
Write events
107
Delete events
1

Modification events

(PID) Process:(2376) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2376) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2376) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12D\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2376) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12D\52C64B7E
Operation:writeName:@C:\Windows\system32\NetworkExplorer.dll,-1
Value:
Network
(PID) Process:(2376) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\CloneCD key.zip
(PID) Process:(2376) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2376) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2376) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2376) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2472) nstC6BA.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\SlySoft\CloneCD
Operation:writeName:Affiliate
Value:
0
Executable files
20
Suspicious files
70
Text files
320
Unknown types
20

Dropped files

PID
Process
Filename
Type
2376WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2376.41180\Key.CloneCDtext
MD5:
SHA256:
2472nstC6BA.tmpC:\Program Files\RedFox\CloneCD\ccd-uninst.initext
MD5:
SHA256:
2472nstC6BA.tmpC:\ProgramData\Microsoft\Windows\Start Menu\Programs\RedFox\CloneCD\Uninstall.lnklnk
MD5:
SHA256:
2376WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2376.41180\2Key.CloneCDtext
MD5:
SHA256:
2472nstC6BA.tmpC:\Program Files\RedFox\CloneCD\ccd-uninst.exeexecutable
MD5:47A7301CA52F4FC4EE4E14DC528AF0D6
SHA256:2C60E6175B20F216205A15FFA7A9D634365A35A62749EC56E10F001085D8A8DA
2472nstC6BA.tmpC:\Program Files\RedFox\CloneCD\InstallHelp.dllexecutable
MD5:95E69C3058EEDF7C848CFBED4A89E99B
SHA256:4647E65063EF6A3CF205749CF4AB13E7CE20CB3735214B7BA9DD709086F41617
2472nstC6BA.tmpC:\Program Files\RedFox\CloneCD\ExecuteWithUAC.exeexecutable
MD5:57CFD2E9CC23E1C6B0584B7AFCAB2EBA
SHA256:DA4BF249FE578186E0CC1DE7947C7FDB85D471134546B120F7B98674CBDD9BE9
2472nstC6BA.tmpC:\Program Files\RedFox\CloneCD\setacl.exeexecutable
MD5:ACDE12FA9A971A254C76C34C0BBE8608
SHA256:243DEE6B04AA006BAEE70922DBE9AA80FD0682CBEF5E12AD1540CFD8D1188705
2472nstC6BA.tmpC:\Program Files\RedFox\CloneCD\HelpLauncher.exeexecutable
MD5:0B174759776FBD484DEF9B4E57D94F3D
SHA256:9FAA8A31051E3EE8FF1ED1EE8BBC1977964750B84DB9A377585CF1ACA909821C
2472nstC6BA.tmpC:\Program Files\RedFox\CloneCD\ElbyECC.dllexecutable
MD5:1450924F290543B85A0C41F549F38D37
SHA256:F1B11E7B683DDE1E1D501F5161F8DB5878627CD96A12E65382C523C44633BA6E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info