File name:

11f44531fb088d31307d87b01e8eabff.zip.zip

Full analysis: https://app.any.run/tasks/215e32ac-d748-4636-877c-64dd230a99a2
Verdict: Malicious activity
Analysis date: February 17, 2024, 21:37:39
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v5.1 to extract, compression method=AES Encrypted
MD5:

0CBEDE8A169ECBBABD533AA9202D9015

SHA1:

6C75C16101B222CDFAD0044B30B4C490D3D37097

SHA256:

38B01A12B8DCD39EBDCF9E97772E848237330EB227E1CCEE80125564B27377E5

SSDEEP:

3072:h8xXZyytZ551PJxnd+HEOA2ewGGetw/Ycw8lEbbvBjFUQlqnV:Cl9B2HQRwG9a/JEbDJFgV

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 4052)
    • Calls Win API functions (MACROS)

      • EXCEL.EXE (PID: 3772)
    • Unusual execution from MS Office

      • EXCEL.EXE (PID: 3772)
    • Registers / Runs the DLL via REGSVR32.EXE

      • EXCEL.EXE (PID: 3772)
    • Connection from MS Office application

      • EXCEL.EXE (PID: 3772)
  • SUSPICIOUS

    • Application launched itself

      • WinRAR.exe (PID: 4052)
    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 4052)
  • INFO

    • Reads Microsoft Office registry keys

      • WinRAR.exe (PID: 3952)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3952)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 3952)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 51
ZipBitFlag: 0x0009
ZipCompression: Unknown (99)
ZipModifyDate: 2024:01:31 15:39:40
ZipCRC: 0x421a932f
ZipCompressedSize: 109157
ZipUncompressedSize: 109381
ZipFileName: 11f44531fb088d31307d87b01e8eabff.zip
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
42
Monitored processes
5
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs winrar.exe excel.exe regsvr32.exe no specs regsvr32.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2340regsvr32 -s ..\iroto.dllC:\Windows\System32\regsvr32.exeEXCEL.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft(C) Register Server
Exit code:
3
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3772"C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /ddeC:\Program Files\Microsoft Office\Office14\EXCEL.EXE
WinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Excel
Exit code:
0
Version:
14.0.6024.1000
Modules
Images
c:\program files\microsoft office\office14\excel.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3952"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\Rar$DIb4052.35282\11f44531fb088d31307d87b01e8eabff.zipC:\Program Files\WinRAR\WinRAR.exe
WinRAR.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3992regsvr32 -s ..\iroto1.dllC:\Windows\System32\regsvr32.exeEXCEL.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft(C) Register Server
Exit code:
3
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
4052"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\11f44531fb088d31307d87b01e8eabff.zip.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
12 535
Read events
12 296
Write events
99
Delete events
140

Modification events

(PID) Process:(4052) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(4052) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(4052) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(4052) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(4052) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(4052) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(4052) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\11f44531fb088d31307d87b01e8eabff.zip.zip
(PID) Process:(4052) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(4052) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(4052) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
2
Suspicious files
2
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
3772EXCEL.EXEC:\Users\admin\AppData\Local\Temp\CVR37E3.tmp.cvr
MD5:
SHA256:
4052WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DIb4052.35282\11f44531fb088d31307d87b01e8eabff.zipcompressed
MD5:9458859ABFD384F38362AF01FB306F14
SHA256:6CEC2BF8E5BDE0A9D885CA6276D5A3D77AFFE4225824836A762984E7ECDC8A40
3952WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DIb3952.36424\research-1646684671.xlsdocument
MD5:B775CD8BE83696CA37B2FE00BCB40574
SHA256:1DF68D55968BB9D2DB4D0D18155188A03A442850FF543C8595166AC6987DF820
3952WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DIb3952.38319\iroto.dllexecutable
MD5:E03BDE4862D4D93AC2CEED85ABF50B18
SHA256:055B9E9AF987AEC9BA7ADB0EEF947F39B516A213D663CC52A71C7F0AF146A946
3952WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DIb3952.40060\iroto1.dllexecutable
MD5:8E6FBEFCBAC2A1967941FA692C82C3CA
SHA256:E05C717B43F7E204F315EB8C298F9715791385516335ACD8F20EC9E26C3E9B0B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
8
DNS requests
2
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
224.0.0.252:5355
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
3772
EXCEL.EXE
188.209.214.83:443
nws.visionconsulting.ro
ROMARG SRL
RO
unknown

DNS requests

Domain
IP
Reputation
nws.visionconsulting.ro
  • 188.209.214.83
unknown
royalpalm.sparkblue.lk
unknown

Threats

No threats detected
No debug info