File name: | U R AN IDIOT.zip |
Full analysis: | https://app.any.run/tasks/b54a2adb-f81a-47c9-b2b8-b6f714268594 |
Verdict: | Malicious activity |
Analysis date: | December 06, 2022, 02:43:01 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/zip |
File info: | Zip archive data, at least v2.0 to extract |
MD5: | 28F787777A8C8B34334994E106805895 |
SHA1: | D92EC9863B9EDD571ADE75B53F17C4152367E61C |
SHA256: | 375426642D9AB22111E3E054C45A43C2A6DC9591DBE65F345CAF765D6F811E00 |
SSDEEP: | 6144:bZVR5r1qDuF5h9lpd42dx6V9QUVRZnwBy60NEA7DlgoOFn:bLUDu/jd42mQUVomyA7DljSn |
.zip | | | ZIP compressed archive (100) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
1540 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\U R AN IDIOT.zip" | C:\Program Files\WinRAR\WinRAR.exe | Explorer.EXE | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
1972 | "C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" | C:\Windows\system32\SearchProtocolHost.exe | — | SearchIndexer.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft Windows Search Protocol Host Version: 7.00.7601.24542 (win7sp1_ldr_escrow.191209-2211) Modules
| |||||||||||||||
1400 | "C:\Users\admin\Desktop\YouAreAnIdiot.exe" | C:\Users\admin\Desktop\YouAreAnIdiot.exe | Explorer.EXE | ||||||||||||
User: admin Company: Microsoft Integrity Level: MEDIUM Description: Microsoft Word 2010 Exit code: 1 Version: 1.0.0.0 Modules
| |||||||||||||||
3168 | "C:\Windows\system32\taskmgr.exe" /4 | C:\Windows\system32\taskmgr.exe | — | Explorer.EXE | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Task Manager Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
|
(PID) Process: | (1540) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtBMP |
Value: | |||
(PID) Process: | (1540) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtIcon |
Value: | |||
(PID) Process: | (1540) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\16D\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (1540) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
(PID) Process: | (1540) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
(PID) Process: | (1540) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\U R AN IDIOT.zip | |||
(PID) Process: | (1540) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | name |
Value: 120 | |||
(PID) Process: | (1540) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | size |
Value: 80 | |||
(PID) Process: | (1540) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | type |
Value: 120 | |||
(PID) Process: | (1540) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | mtime |
Value: 100 |
PID | Process | Filename | Type | |
---|---|---|---|---|
1400 | YouAreAnIdiot.exe | C:\Users\admin\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\settings.sxx | sol | |
MD5:4E442C66F85325FE25C83EE8855432CA | SHA256:C1F7F9394B37899EC9EFE36DD2C26C80837F357D86F20F67DC13F6491F0CFEA9 | |||
1540 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1540.7442\AxInterop.ShockwaveFlashObjects.dll | executable | |
MD5:451112D955AF4FE3C0D00F303D811D20 | SHA256:0D57A706D4E10CCA3AED49B341A651F29046F5EF1328878D616BE93C3B4CBCE9 | |||
1540 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1540.7442\Interop.ShockwaveFlashObjects.dll | executable | |
MD5:E869D1D4545C212D9068A090A370DED3 | SHA256:63AF704211A03F6FF6530EBFCA095B6C97636AB66E5A6DE80D167B19C3C30C66 | |||
1540 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1540.7442\YouAreAnIdiot.exe | executable | |
MD5:E263C5B306480143855655233F76DC5A | SHA256:1F69810B8FE71E30A8738278ADF09DD982F7DE0AB9891D296CE7EA61B3FA4F69 | |||
1400 | YouAreAnIdiot.exe | C:\Users\admin\AppData\Roaming\Macromedia\Flash Player\openssl\cache\RevocationCacheFile.dat | gmc | |
MD5:0F343B0931126A20F133D67C2B018A3B | SHA256:5F70BF18A086007016E948B04AED3B82103A36BEA41755B6CDDFAF10ACE3C6EF | |||
1400 | YouAreAnIdiot.exe | C:\Users\admin\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\settings.sol | sol | |
MD5:4E442C66F85325FE25C83EE8855432CA | SHA256:C1F7F9394B37899EC9EFE36DD2C26C80837F357D86F20F67DC13F6491F0CFEA9 |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
1400 | YouAreAnIdiot.exe | POST | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/ | US | der | 471 b | whitelisted |
1400 | YouAreAnIdiot.exe | POST | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/ | US | der | 471 b | whitelisted |
1400 | YouAreAnIdiot.exe | POST | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/ | US | der | 471 b | whitelisted |
1400 | YouAreAnIdiot.exe | POST | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/ | US | der | 471 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
1400 | YouAreAnIdiot.exe | 23.35.236.137:443 | geo2.adobe.com | AKAMAI-AS | DE | suspicious |
1400 | YouAreAnIdiot.exe | 23.32.59.230:443 | fpdownload.macromedia.com | AKAMAI-AS | DE | suspicious |
1400 | YouAreAnIdiot.exe | 93.184.220.29:80 | ocsp.digicert.com | EDGECAST | GB | whitelisted |
Domain | IP | Reputation |
---|---|---|
geo2.adobe.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
fpdownload.macromedia.com |
| whitelisted |