File name:

goodbyedpi-0.2.3rc3-2 (1).zip

Full analysis: https://app.any.run/tasks/35124691-7e8b-43ee-9219-ca7bd310c8d8
Verdict: Malicious activity
Analysis date: November 03, 2024, 22:06:54
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-exec
arch-doc
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=store
MD5:

55D4CE5319B22FD3E034D0EAAD96C770

SHA1:

F432FA8CBF4EB4C83021BE5BB8FC4881044E7F81

SHA256:

37F96B32D050DADCC930A639EBA68E1CCD57ED5C04A5F77DFCA908F01905A4C5

SSDEEP:

49152:O+hn6ufy7Xerr7yi7XevDMKwRMJIeMdbMwVtY4Y9aSrN+tGbj8JGOwjSVBHkpAzh:Rl6ufy7ufl7uLMKwRMilNFdwNk/GJ6HX

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 5604)
  • SUSPICIOUS

    • Drops a system driver (possible attempt to evade defenses)

      • WinRAR.exe (PID: 5604)
  • INFO

    • Manual execution by a user

      • cmd.exe (PID: 5600)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 5604)
    • The process uses the downloaded file

      • WinRAR.exe (PID: 5604)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2024:09:15 05:28:00
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: goodbyedpi-0.2.3rc3-2/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
138
Monitored processes
8
Malicious processes
0
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe rundll32.exe no specs cmd.exe no specs conhost.exe no specs goodbyedpi.exe no specs goodbyedpi.exe no specs goodbyedpi.exe conhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2224\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exegoodbyedpi.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5600C:\WINDOWS\system32\cmd.exe /c ""C:\Users\admin\Desktop\goodbyedpi-0.2.3rc3-2\1_russia_blacklist_YOUTUBE.cmd" "C:\Windows\System32\cmd.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cmdext.dll
c:\windows\system32\advapi32.dll
5604"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\goodbyedpi-0.2.3rc3-2 (1).zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
5736\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6180"C:\Users\admin\Desktop\goodbyedpi-0.2.3rc3-2\x86_64\goodbyedpi.exe" -9 --fake-gen 5 --fake-from-hex 160301FFFF01FFFFFF0303594F5552204144564552544953454D454E542048455245202D202431302F6D6F000000000009000000050003000000 --blacklist ..\russia-blacklist.txt --blacklist ..\russia-youtube.txtC:\Users\admin\Desktop\goodbyedpi-0.2.3rc3-2\x86_64\goodbyedpi.exe
cmd.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\users\admin\desktop\goodbyedpi-0.2.3rc3-2\x86_64\goodbyedpi.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
6752C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
7076"C:\Users\admin\Desktop\goodbyedpi-0.2.3rc3-2\x86_64\goodbyedpi.exe" -9 --fake-gen 5 --fake-from-hex 160301FFFF01FFFFFF0303594F5552204144564552544953454D454E542048455245202D202431302F6D6F000000000009000000050003000000 --blacklist ..\russia-blacklist.txt --blacklist ..\russia-youtube.txtC:\Users\admin\Desktop\goodbyedpi-0.2.3rc3-2\x86_64\goodbyedpi.execmd.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\goodbyedpi-0.2.3rc3-2\x86_64\goodbyedpi.exe
c:\windows\system32\ntdll.dll
7080goodbyedpi.exe -9 --fake-gen 5 --fake-from-hex 160301FFFF01FFFFFF0303594F5552204144564552544953454D454E542048455245202D202431302F6D6F000000000009000000050003000000 --blacklist ..\russia-blacklist.txt --blacklist ..\russia-youtube.txtC:\Users\admin\Desktop\goodbyedpi-0.2.3rc3-2\x86_64\goodbyedpi.execmd.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\goodbyedpi-0.2.3rc3-2\x86_64\goodbyedpi.exe
c:\windows\system32\ntdll.dll
Total events
1 987
Read events
1 969
Write events
18
Delete events
0

Modification events

(PID) Process:(5604) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\GoogleChromeEnterpriseBundle64.zip
(PID) Process:(5604) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\goodbyedpi-0.2.3rc3-2 (1).zip
(PID) Process:(5604) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(5604) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(5604) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(5604) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(5604) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF3D0000002D000000FD03000016020000
(PID) Process:(5604) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:name
Value:
256
(PID) Process:(5604) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(5604) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:psize
Value:
80
Executable files
7
Suspicious files
0
Text files
18
Unknown types
0

Dropped files

PID
Process
Filename
Type
5604WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5604.43509\goodbyedpi-0.2.3rc3-2\licenses\LICENSE-goodbyedpi.txttext
MD5:C4082B6C254C9FB71136710391D9728B
SHA256:E03BA41D7FAB20700769FE4118BAB50D800CB74F990353A05D2F5FFF1C228363
5604WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5604.43509\goodbyedpi-0.2.3rc3-2\x86\goodbyedpi.exeexecutable
MD5:9C3F16D5A0AFF180F9D04AE6C0FE1F28
SHA256:66E202C9FCE9E769E2BC791B7FD6F56F21EAB59F607F4ED0724E0C68C430DD1F
5604WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5604.43509\goodbyedpi-0.2.3rc3-2\service_remove.cmdtext
MD5:204B35D000D6B29C1102B1D8B6A63DC7
SHA256:63915B4B09658CDFEC4C74923650398D9FC497AE3CE9E68C5592337051D2FB64
5604WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5604.43509\goodbyedpi-0.2.3rc3-2\x86_64\WinDivert.dllexecutable
MD5:88E1C19B978436258F7C938013408A8A
SHA256:6110BFA44667405179C3E15E12AF1B62037E447ED59B054B19042032995E6C7E
5604WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5604.43509\goodbyedpi-0.2.3rc3-2\x86_64\WinDivert64.sysexecutable
MD5:6A33620DE63BCCAF5E5314EE49CD58FB
SHA256:E69B5BA3F0CD6CFB2983E442636E7F0B342B61B15264B0328317D4559C82CF50
5604WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5604.43509\goodbyedpi-0.2.3rc3-2\1_russia_blacklist_dnsredir.cmdtext
MD5:06018C5958CDDD1D0CF3135762AEB2EB
SHA256:472D9BD4F0366BB9478B6CD61302F12BF6CFFBED038508A67087250BF610E355
5604WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5604.43509\goodbyedpi-0.2.3rc3-2\0_russia_update_blacklist_file.cmdtext
MD5:A6AF4B081A4CBCD448759306B2366EAC
SHA256:D9D7C57C7DEDB3A4E6566DDD7623758F53986A2C34E0CD3784B84F7F881A01C4
5604WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5604.43509\goodbyedpi-0.2.3rc3-2\x86_64\goodbyedpi.exeexecutable
MD5:AFA7F66231B9CEC7237E738B622C0181
SHA256:8D412B094BB9C137FF25BA9A794D1122ECC84BB776DEBFF6C249723A13CC31CD
5604WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5604.43509\goodbyedpi-0.2.3rc3-2\x86\WinDivert64.sysexecutable
MD5:6A33620DE63BCCAF5E5314EE49CD58FB
SHA256:E69B5BA3F0CD6CFB2983E442636E7F0B342B61B15264B0328317D4559C82CF50
5604WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5604.43509\goodbyedpi-0.2.3rc3-2\1_russia_blacklist.cmdtext
MD5:76763259E528CD27E998FB4C665C2B78
SHA256:69C8B67FAFBCA446CE5302E97F9947191ECB84D2A51EAE61D4955DC3E2147DA0
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
30
DNS requests
17
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6944
svchost.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6944
svchost.exe
GET
200
23.53.40.176:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
4
System
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
4
System
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
624
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
6944
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5700
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5488
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4360
SearchApp.exe
104.126.37.154:443
www.bing.com
Akamai International B.V.
DE
whitelisted
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
4
System
192.168.100.255:138
whitelisted
6944
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6944
svchost.exe
23.53.40.176:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
6944
svchost.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 51.124.78.146
  • 40.127.240.158
whitelisted
www.bing.com
  • 104.126.37.154
  • 104.126.37.139
  • 104.126.37.145
  • 104.126.37.144
  • 104.126.37.163
  • 104.126.37.161
  • 104.126.37.170
  • 104.126.37.153
  • 104.126.37.171
  • 104.126.37.130
  • 104.126.37.146
  • 104.126.37.128
  • 104.126.37.152
  • 104.126.37.136
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
google.com
  • 142.250.74.206
whitelisted
crl.microsoft.com
  • 23.53.40.176
  • 23.53.40.178
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
login.live.com
  • 20.190.159.71
  • 20.190.159.73
  • 20.190.159.2
  • 20.190.159.0
  • 40.126.31.69
  • 40.126.31.67
  • 20.190.159.75
  • 20.190.159.64
whitelisted
th.bing.com
  • 104.126.37.144
  • 104.126.37.136
  • 104.126.37.154
  • 104.126.37.153
  • 104.126.37.152
  • 104.126.37.139
  • 104.126.37.128
  • 104.126.37.146
  • 104.126.37.130
whitelisted
go.microsoft.com
  • 23.218.210.69
whitelisted
slscr.update.microsoft.com
  • 4.175.87.197
whitelisted

Threats

No threats detected
No debug info