File name:

NtfsPermissionsReporterInstallerFree.zip

Full analysis: https://app.any.run/tasks/153d61e6-44f0-4ad6-92bf-8fb89774d203
Verdict: Malicious activity
Analysis date: August 22, 2019, 10:14:34
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
opendir
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

4EBB505B57B17154ADEC11F7C0339BCE

SHA1:

38A80B60421FC772D22099BA6907D6E60DF5C7BE

SHA256:

3A35F3A2B36D358F3D936FBC0A31730719889B84E8FCCF9B9977EA023EF7206E

SSDEEP:

24576:Wq6VK79JH1LGFQi0qH36AeU4MJpL74iV3z4ETBWPYApCv8hsUyCCIEXEhMSyF:Wq6c9JHxGFdHMUx5jFTBWPz4v8hs/TD/

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • NtfsFreeSetup.exe (PID: 3408)
      • NtfsPermissionsReporter.exe (PID: 3868)
      • NtfsPermissionsReporter.exe (PID: 3920)
    • Loads the Task Scheduler DLL interface

      • NtfsFreeSetup.exe (PID: 3408)
    • Loads dropped or rewritten executable

      • NtfsPermissionsReporter.exe (PID: 3920)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3688)
      • msiexec.exe (PID: 2244)
      • NtfsFreeSetup.exe (PID: 3408)
      • msiexec.exe (PID: 3756)
    • Creates files in the user directory

      • NtfsFreeSetup.exe (PID: 3408)
    • Executed as Windows Service

      • vssvc.exe (PID: 3732)
    • Executed via COM

      • DrvInst.exe (PID: 3804)
    • Reads Environment values

      • NtfsPermissionsReporter.exe (PID: 3920)
  • INFO

    • Loads dropped or rewritten executable

      • MsiExec.exe (PID: 3468)
      • MsiExec.exe (PID: 2768)
    • Searches for installed software

      • msiexec.exe (PID: 3756)
    • Low-level read access rights to disk partition

      • vssvc.exe (PID: 3732)
    • Application launched itself

      • msiexec.exe (PID: 3756)
    • Dropped object may contain Bitcoin addresses

      • msiexec.exe (PID: 3756)
    • Creates files in the program directory

      • msiexec.exe (PID: 3756)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 3756)
    • Manual execution by user

      • NtfsPermissionsReporter.exe (PID: 3868)
      • NtfsPermissionsReporter.exe (PID: 3920)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2014:11:14 23:09:17
ZipCRC: 0xcefe06a5
ZipCompressedSize: 1280750
ZipUncompressedSize: 2083512
ZipFileName: NtfsFreeSetup.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
46
Monitored processes
10
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
drop and start start winrar.exe ntfsfreesetup.exe msiexec.exe msiexec.exe msiexec.exe no specs vssvc.exe no specs drvinst.exe no specs msiexec.exe no specs ntfspermissionsreporter.exe no specs ntfspermissionsreporter.exe

Process information

PID
CMD
Path
Indicators
Parent process
2244 /i "C:\Users\admin\AppData\Roaming\Cjwdev\NTFS Permissions Reporter Free Edition 1.5.0\install\NtfsFreeSetup.msi" AI_SETUPEXEPATH="C:\Users\admin\AppData\Local\Temp\Rar$EXa3688.40201\NtfsFreeSetup.exe" SETUPEXEDIR="C:\Users\admin\AppData\Local\Temp\Rar$EXa3688.40201\" EXE_CMD_LINE="/exenoupdates /exelang 0 /noprereqs "C:\Windows\system32\msiexec.exe
NtfsFreeSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2768C:\Windows\system32\MsiExec.exe -Embedding 0EDF12C043A359C94A745CFA5E22310EC:\Windows\system32\MsiExec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3408"C:\Users\admin\AppData\Local\Temp\Rar$EXa3688.40201\NtfsFreeSetup.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3688.40201\NtfsFreeSetup.exe
WinRAR.exe
User:
admin
Company:
Cjwdev
Integrity Level:
MEDIUM
Description:
This installer database contains the logic and data required to install NTFS Permissions Reporter Free Edition.
Exit code:
0
Version:
1.5.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3688.40201\ntfsfreesetup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
3468C:\Windows\system32\MsiExec.exe -Embedding 00E1FCF4C432ADA427F524648699B2C7 CC:\Windows\system32\MsiExec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3688"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\NtfsPermissionsReporterInstallerFree.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3732C:\Windows\system32\vssvc.exeC:\Windows\system32\vssvc.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\vssvc.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3756C:\Windows\system32\msiexec.exe /VC:\Windows\system32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3804DrvInst.exe "1" "200" "STORAGE\VolumeSnapshot\HarddiskVolumeSnapshot22" "" "" "695c3f483" "00000000" "000003C8" "000004B8"C:\Windows\system32\DrvInst.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
3868"C:\Program Files\Cjwdev\NTFS Permissions Reporter Free Edition\NtfsPermissionsReporter.exe" C:\Program Files\Cjwdev\NTFS Permissions Reporter Free Edition\NtfsPermissionsReporter.exeexplorer.exe
User:
admin
Company:
Cjwdev Ltd
Integrity Level:
MEDIUM
Description:
NTFS Permissions Reporting Tool
Exit code:
3221226540
Version:
1.5.0.1
Modules
Images
c:\program files\cjwdev\ntfs permissions reporter free edition\ntfspermissionsreporter.exe
c:\systemroot\system32\ntdll.dll
3920"C:\Program Files\Cjwdev\NTFS Permissions Reporter Free Edition\NtfsPermissionsReporter.exe" C:\Program Files\Cjwdev\NTFS Permissions Reporter Free Edition\NtfsPermissionsReporter.exe
explorer.exe
User:
admin
Company:
Cjwdev Ltd
Integrity Level:
HIGH
Description:
NTFS Permissions Reporting Tool
Exit code:
0
Version:
1.5.0.1
Modules
Images
c:\program files\cjwdev\ntfs permissions reporter free edition\ntfspermissionsreporter.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
1 295
Read events
978
Write events
305
Delete events
12

Modification events

(PID) Process:(3688) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3688) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3688) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3688) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\NtfsPermissionsReporterInstallerFree.zip
(PID) Process:(3688) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3688) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3688) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3688) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3688) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(3688) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
Executable files
12
Suspicious files
7
Text files
44
Unknown types
1

Dropped files

PID
Process
Filename
Type
2244msiexec.exeC:\Users\admin\AppData\Local\Temp\MSIC29A.tmp
MD5:
SHA256:
2244msiexec.exeC:\Users\admin\AppData\Local\Temp\MSIC2BA.tmp
MD5:
SHA256:
2244msiexec.exeC:\Users\admin\AppData\Local\Temp\MSIC2CB.tmp
MD5:
SHA256:
3756msiexec.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
3756msiexec.exeC:\Windows\Installer\MSI1C72.tmp
MD5:
SHA256:
3756msiexec.exeC:\Windows\Installer\MSI1C92.tmp
MD5:
SHA256:
3756msiexec.exeC:\Users\admin\AppData\Local\Temp\~DFE443217E865E1D61.TMP
MD5:
SHA256:
3732vssvc.exeC:
MD5:
SHA256:
3756msiexec.exeC:\Windows\Installer\MSI1F63.tmp
MD5:
SHA256:
3756msiexec.exeC:\Windows\Installer\MSI2001.tmp
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
2
DNS requests
1
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3920
NtfsPermissionsReporter.exe
GET
94.136.40.103:80
http://www.cjwdev.co.uk/Software/NtfsReports/LatestVersionFreeV2.xml
GB
malicious
3920
NtfsPermissionsReporter.exe
GET
200
94.136.40.103:80
http://www.cjwdev.co.uk/Software/NtfsReports/LatestVersionFreeV2.xml
GB
xml
2.12 Kb
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3920
NtfsPermissionsReporter.exe
94.136.40.103:80
www.cjwdev.co.uk
Host Europe GmbH
GB
malicious

DNS requests

Domain
IP
Reputation
www.cjwdev.co.uk
  • 94.136.40.103
malicious

Threats

No threats detected
No debug info