File name:

McQuay-Duct-Sizer-1.zip.zip

Full analysis: https://app.any.run/tasks/162213f9-f3f1-442f-8f14-d74d9f0cb0e4
Verdict: Malicious activity
Analysis date: November 02, 2023, 18:53:16
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

0C986A525CB1FCDF1E84EBAFD3111A90

SHA1:

6953C947889A5C91D4968C5881C27E1FCB8E8EE3

SHA256:

3890E02EE09C6D3C5EDF0C8E99B8C9C0C61A4E9E42F3E8DA35E43A8C8BB1A9F7

SSDEEP:

12288:ZtZI/Hqh8U9iIfift/Z4tmWKCm4TM03jvZ9sxq:ZtZI/Hqz9iIfWt/eQWKCrTM03jZGxq

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Creates a writable file the system directory

      • printfilterpipelinesvc.exe (PID: 3524)
      • DuctSizer.exe (PID: 2932)
  • SUSPICIOUS

    • Application launched itself

      • WinRAR.exe (PID: 3416)
    • Uses RUNDLL32.EXE to load library

      • WinRAR.exe (PID: 3196)
  • INFO

    • Checks supported languages

      • ONENOTE.EXE (PID: 3612)
      • DuctSizer.exe (PID: 2932)
      • DuctSizer.exe (PID: 3920)
      • ONENOTEM.EXE (PID: 3756)
    • Reads the computer name

      • DuctSizer.exe (PID: 2932)
      • ONENOTE.EXE (PID: 3612)
    • Reads Microsoft Office registry keys

      • ONENOTE.EXE (PID: 3612)
    • Create files in a temporary directory

      • DuctSizer.exe (PID: 2932)
      • ONENOTE.EXE (PID: 3612)
      • DuctSizer.exe (PID: 3920)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 3196)
    • Reads Environment values

      • ONENOTE.EXE (PID: 3612)
    • Reads the machine GUID from the registry

      • ONENOTE.EXE (PID: 3612)
      • DuctSizer.exe (PID: 2932)
      • DuctSizer.exe (PID: 3920)
    • Creates files or folders in the user directory

      • ONENOTE.EXE (PID: 3612)
      • printfilterpipelinesvc.exe (PID: 3524)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 788
ZipBitFlag: 0x0001
ZipCompression: Deflated
ZipModifyDate: 2023:11:02 17:23:14
ZipCRC: 0x7108fac1
ZipCompressedSize: 360372
ZipUncompressedSize: 360717
ZipFileName: McQuay-Duct-Sizer-1.zip
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
45
Monitored processes
8
Malicious processes
0
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe no specs winrar.exe no specs ductsizer.exe no specs printfilterpipelinesvc.exe no specs onenote.exe no specs onenotem.exe no specs rundll32.exe no specs ductsizer.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2932"C:\Users\admin\AppData\Local\Temp\Rar$EXa3196.21002\McQuay Duct Sizer\McQuay Duct Sizer\DuctSizer.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3196.21002\McQuay Duct Sizer\McQuay Duct Sizer\DuctSizer.exeWinRAR.exe
User:
admin
Company:
NaSoft, contact Nafziger@nonline.net
Integrity Level:
MEDIUM
Exit code:
0
Version:
6.00
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3196.21002\mcquay duct sizer\mcquay duct sizer\ductsizer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
3196"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\Rar$DIb3416.19485\McQuay-Duct-Sizer-1.zipC:\Program Files\WinRAR\WinRAR.exeWinRAR.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3416"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\McQuay-Duct-Sizer-1.zip.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3524C:\Windows\system32\printfilterpipelinesvc.exe -EmbeddingC:\Windows\System32\printfilterpipelinesvc.exesvchost.exe
User:
LOCAL SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Print Filter Pipeline Host
Exit code:
0
Version:
6.1.7601.24537 (win7sp1_ldr_escrow.191114-1547)
Modules
Images
c:\windows\system32\printfilterpipelinesvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3612/insertdoc "C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\{15267671-0471-46CA-88B7-E5BD27F4079F}.xps" 133434248404540000C:\Program Files\Microsoft Office\Office14\ONENOTE.EXEprintfilterpipelinesvc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft OneNote
Exit code:
0
Version:
14.0.6022.1000
Modules
Images
c:\program files\microsoft office\office14\onenote.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3756/tsrC:\Program Files\Microsoft Office\Office14\ONENOTEM.EXEONENOTE.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft OneNote Quick Launcher
Exit code:
0
Version:
14.0.6015.1000
Modules
Images
c:\program files\microsoft office\office14\onenotem.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
3828"C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\AppData\Local\Temp\Rar$DIa3196.24772\DT_DUCT.DLLC:\Windows\System32\rundll32.exeWinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
3920"C:\Users\admin\AppData\Local\Temp\Rar$EXa3196.25063\McQuay Duct Sizer\McQuay Duct Sizer\DuctSizer.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3196.25063\McQuay Duct Sizer\McQuay Duct Sizer\DuctSizer.exeWinRAR.exe
User:
admin
Company:
NaSoft, contact Nafziger@nonline.net
Integrity Level:
MEDIUM
Exit code:
0
Version:
6.00
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3196.25063\mcquay duct sizer\mcquay duct sizer\ductsizer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
Total events
4 027
Read events
3 965
Write events
58
Delete events
4

Modification events

(PID) Process:(3416) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\17A\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3416) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(3416) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3416) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3416) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3416) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3416) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3416) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3416) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3416) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
Executable files
4
Suspicious files
14
Text files
4
Unknown types
0

Dropped files

PID
Process
Filename
Type
3524printfilterpipelinesvc.exeC:\Windows\system32\spool\PRINTERS\PP90dk8oth97l0fwx5emt8wocp.TMP
MD5:
SHA256:
3524printfilterpipelinesvc.exeC:\Windows\system32\spool\PRINTERS\PP7dfat_ykb4ipnlkrqhkhi6afd.TMP
MD5:
SHA256:
3524printfilterpipelinesvc.exeC:\Windows\system32\spool\PRINTERS\PPe9ck11pr4ilkzv4fr2ua9ccgb.TMP
MD5:
SHA256:
3612ONENOTE.EXEC:\Users\admin\AppData\Local\Temp\CVR2CE.tmp.cvr
MD5:
SHA256:
3196WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3196.21002\McQuay Duct Sizer\McQuay Duct Sizer\DT_DUCT.DLLbinary
MD5:CB33E875A22231DF940F8004EDD92D24
SHA256:279A7572825673311AF37D7B225DF3037EF6F34AB6F17B335E2D94FEF92BE701
3196WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3196.21002\McQuay Duct Sizer\McQuay Duct Sizer\MCQUAY.DLLimage
MD5:12181C9D00D05E0F663128ED584EFB8A
SHA256:B1156A248E3747829903941F77E000D521D11D4B38AC1899069B3F0247E2FEE1
2932DuctSizer.exeC:\Users\admin\AppData\Local\Temp\fntFFC3.tmpbinary
MD5:1171028651A0217165684F983CDF3A3B
SHA256:1D071EA275A34D2B0308A7BCB8284A5EA3F916E676BA148A4DAD75C918D94860
2932DuctSizer.exeC:\Users\admin\AppData\Local\Temp\fntFFB3.tmpbinary
MD5:000388B9A607030C5942C2B13BDB5634
SHA256:421CDF9718843CBB6CB45B4854F6E0B291674424508EFD9616611AE48CFE27A2
2932DuctSizer.exeC:\Windows\system32\spool\PRINTERS\00002.SPLbinary
MD5:81B750323B5D0E84D7A2408479AAC69D
SHA256:75B43C113F1D67BA1D73D005CB4339C2464F9318832F034200174862D0AFD0AB
3524printfilterpipelinesvc.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\{15267671-0471-46CA-88B7-E5BD27F4079F}.xpsbinary
MD5:81B750323B5D0E84D7A2408479AAC69D
SHA256:75B43C113F1D67BA1D73D005CB4339C2464F9318832F034200174862D0AFD0AB
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
2588
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info