File name:

sans-for-pdf_136165018.zip

Full analysis: https://app.any.run/tasks/8812884c-8085-4d21-bb59-1d248b5e5c4f
Verdict: Malicious activity
Analysis date: May 03, 2021, 20:53:26
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

C04FF5AE330E233CE9D2CB8443837B63

SHA1:

C28A6895E5DD50DB4704E8E77C83820A2440D05C

SHA256:

3AA0EEF2882AEA9CB75BB354130093FE0D6C3AF3AFA47CBC021892C1F95D11E9

SSDEEP:

196608:i9IYlqq+uKFBIOAqpR2ML4l9mdEG+0FG7faOi:4jh+HFee2Mmmi0FG7C

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • sans-for-pdf_136165018.exe (PID: 2156)
      • sans-for-pdf_136165018.exe (PID: 2652)
      • Sit.exe (PID: 4016)
      • sya2w3os.ocg.exe (PID: 2780)
      • sya2w3os.ocg.exe (PID: 2664)
    • Drops executable file immediately after starts

      • sans-for-pdf_136165018.exe (PID: 2652)
      • sans-for-pdf_136165018.exe (PID: 2156)
      • sans-for-pdf_136165018.tmp (PID: 3080)
      • sya2w3os.ocg.exe (PID: 2664)
      • sya2w3os.ocg.exe (PID: 2780)
    • Loads dropped or rewritten executable

      • Sit.exe (PID: 4016)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1248)
      • sans-for-pdf_136165018.exe (PID: 2652)
      • sans-for-pdf_136165018.exe (PID: 2156)
      • sans-for-pdf_136165018.tmp (PID: 3080)
      • sya2w3os.ocg.exe (PID: 2664)
      • sya2w3os.ocg.exe (PID: 2780)
    • Reads Windows owner or organization settings

      • sans-for-pdf_136165018.tmp (PID: 3080)
    • Reads the Windows organization settings

      • sans-for-pdf_136165018.tmp (PID: 3080)
    • Drops a file with too old compile date

      • sans-for-pdf_136165018.tmp (PID: 3080)
    • Creates a directory in Program Files

      • sans-for-pdf_136165018.tmp (PID: 3080)
    • Drops a file with a compile date too recent

      • sans-for-pdf_136165018.tmp (PID: 3080)
    • Drops a file that was compiled in debug mode

      • sans-for-pdf_136165018.tmp (PID: 3080)
  • INFO

    • Application was dropped or rewritten from another process

      • sans-for-pdf_136165018.tmp (PID: 2644)
      • sans-for-pdf_136165018.tmp (PID: 3080)
      • sya2w3os.ocg.tmp (PID: 1392)
      • sya2w3os.ocg.tmp (PID: 1592)
    • Creates files in the program directory

      • sans-for-pdf_136165018.tmp (PID: 3080)
    • Loads dropped or rewritten executable

      • sans-for-pdf_136165018.tmp (PID: 3080)
    • Creates a software uninstall entry

      • sans-for-pdf_136165018.tmp (PID: 3080)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: sya2w3os.ocg.exe
ZipUncompressedSize: 4136792
ZipCompressedSize: 3661082
ZipCRC: 0xc2f14acd
ZipModifyDate: 2019:12:24 23:16:18
ZipCompression: Deflated
ZipBitFlag: -
ZipRequiredVersion: 20
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
54
Monitored processes
10
Malicious processes
2
Suspicious processes
3

Behavior graph

Click at the process to see the details
drop and start drop and start start drop and start drop and start drop and start drop and start drop and start winrar.exe sans-for-pdf_136165018.exe sans-for-pdf_136165018.tmp no specs sans-for-pdf_136165018.exe sans-for-pdf_136165018.tmp sit.exe sya2w3os.ocg.exe sya2w3os.ocg.tmp no specs sya2w3os.ocg.exe sya2w3os.ocg.tmp no specs

Process information

PID
CMD
Path
Indicators
Parent process
1248"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\sans-for-pdf_136165018.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\comdlg32.dll
1392"C:\Users\admin\AppData\Local\Temp\is-84URU.tmp\sya2w3os.ocg.tmp" /SL5="$30224,3403402,721408,C:\Users\admin\AppData\Local\Temp\Rar$EXa1248.9076\sya2w3os.ocg.exe" /SPAWNWND=$20226 /NOTIFYWND=$40178 C:\Users\admin\AppData\Local\Temp\is-84URU.tmp\sya2w3os.ocg.tmpsya2w3os.ocg.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
1
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-84uru.tmp\sya2w3os.ocg.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1592"C:\Users\admin\AppData\Local\Temp\is-KUU9L.tmp\sya2w3os.ocg.tmp" /SL5="$40178,3403402,721408,C:\Users\admin\AppData\Local\Temp\Rar$EXa1248.9076\sya2w3os.ocg.exe" C:\Users\admin\AppData\Local\Temp\is-KUU9L.tmp\sya2w3os.ocg.tmpsya2w3os.ocg.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
1
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-kuu9l.tmp\sya2w3os.ocg.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2156"C:\Users\admin\AppData\Local\Temp\Rar$EXa1248.6607\sans-for-pdf_136165018.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa1248.6607\sans-for-pdf_136165018.exe
WinRAR.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Sed Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa1248.6607\sans-for-pdf_136165018.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2644"C:\Users\admin\AppData\Local\Temp\is-3158O.tmp\sans-for-pdf_136165018.tmp" /SL5="$401A0,3629961,721408,C:\Users\admin\AppData\Local\Temp\Rar$EXa1248.6607\sans-for-pdf_136165018.exe" C:\Users\admin\AppData\Local\Temp\is-3158O.tmp\sans-for-pdf_136165018.tmpsans-for-pdf_136165018.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-3158o.tmp\sans-for-pdf_136165018.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2652"C:\Users\admin\AppData\Local\Temp\Rar$EXa1248.6607\sans-for-pdf_136165018.exe" /SPAWNWND=$30164 /NOTIFYWND=$401A0 C:\Users\admin\AppData\Local\Temp\Rar$EXa1248.6607\sans-for-pdf_136165018.exe
sans-for-pdf_136165018.tmp
User:
admin
Company:
Integrity Level:
HIGH
Description:
Sed Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa1248.6607\sans-for-pdf_136165018.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2664"C:\Users\admin\AppData\Local\Temp\Rar$EXa1248.9076\sya2w3os.ocg.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa1248.9076\sya2w3os.ocg.exe
WinRAR.exe
User:
admin
Company:
KirySoft
Integrity Level:
MEDIUM
Description:
WSCC4 (x64)
Exit code:
1
Version:
4.0.1.7
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa1248.9076\sya2w3os.ocg.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2780"C:\Users\admin\AppData\Local\Temp\Rar$EXa1248.9076\sya2w3os.ocg.exe" /SPAWNWND=$20226 /NOTIFYWND=$40178 C:\Users\admin\AppData\Local\Temp\Rar$EXa1248.9076\sya2w3os.ocg.exe
sya2w3os.ocg.tmp
User:
admin
Company:
KirySoft
Integrity Level:
HIGH
Description:
WSCC4 (x64)
Exit code:
1
Version:
4.0.1.7
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa1248.9076\sya2w3os.ocg.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3080"C:\Users\admin\AppData\Local\Temp\is-3PFMN.tmp\sans-for-pdf_136165018.tmp" /SL5="$5014A,3629961,721408,C:\Users\admin\AppData\Local\Temp\Rar$EXa1248.6607\sans-for-pdf_136165018.exe" /SPAWNWND=$30164 /NOTIFYWND=$401A0 C:\Users\admin\AppData\Local\Temp\is-3PFMN.tmp\sans-for-pdf_136165018.tmp
sans-for-pdf_136165018.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-3pfmn.tmp\sans-for-pdf_136165018.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
4016"C:\Program Files\Sed/\autem\Sit.exe" c897633c8a0744fd1e4b65f79e0052ddC:\Program Files\Sed\autem\Sit.exe
sans-for-pdf_136165018.tmp
User:
admin
Company:
Terra Informatica Software, Inc., British Columbia, Canada.
Integrity Level:
HIGH
Description:
HTMLayout - embeddable HTML rendering and layout component
Exit code:
0
Version:
3, 3, 3, 12
Modules
Images
c:\program files\sed\autem\sit.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\program files\sed\autem\sqlite3.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
Total events
1 379
Read events
1 276
Write events
103
Delete events
0

Modification events

(PID) Process:(1248) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1248) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1248) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1248) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\sans-for-pdf_136165018.zip
(PID) Process:(1248) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1248) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1248) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1248) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1248) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(1248) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
Executable files
12
Suspicious files
0
Text files
20
Unknown types
1

Dropped files

PID
Process
Filename
Type
3080sans-for-pdf_136165018.tmpC:\Program Files\Sed\is-F397F.tmp
MD5:
SHA256:
3080sans-for-pdf_136165018.tmpC:\Program Files\Sed\is-CHN3I.tmp
MD5:
SHA256:
3080sans-for-pdf_136165018.tmpC:\Program Files\Sed\is-G5CH8.tmp
MD5:
SHA256:
3080sans-for-pdf_136165018.tmpC:\Program Files\Sed\is-PAFRU.tmp
MD5:
SHA256:
3080sans-for-pdf_136165018.tmpC:\Program Files\Sed\autem\is-T01GI.tmp
MD5:
SHA256:
3080sans-for-pdf_136165018.tmpC:\Program Files\Sed\autem\is-GV6K1.tmp
MD5:
SHA256:
3080sans-for-pdf_136165018.tmpC:\Program Files\Sed\autem\is-A08IL.tmp
MD5:
SHA256:
3080sans-for-pdf_136165018.tmpC:\Program Files\Sed\autem\is-QL4E0.tmp
MD5:
SHA256:
3080sans-for-pdf_136165018.tmpC:\Program Files\Sed\autem\is-7LI20.tmp
MD5:
SHA256:
3080sans-for-pdf_136165018.tmpC:\Program Files\Sed\autem\is-B39U5.tmp
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
2
DNS requests
1
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4016
Sit.exe
POST
104.21.84.93:80
http://grigblog.club/v2/events
US
malicious
4016
Sit.exe
POST
104.21.84.93:80
http://grigblog.club/v2/events
US
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4016
Sit.exe
104.21.84.93:80
grigblog.club
Cloudflare Inc
US
malicious

DNS requests

Domain
IP
Reputation
grigblog.club
  • 104.21.84.93
  • 172.67.190.230
malicious

Threats

PID
Process
Class
Message
4016
Sit.exe
A Network Trojan was detected
ET MALWARE DownloadAssistant Activity
4016
Sit.exe
A Network Trojan was detected
ET MALWARE DownloadAssistant Activity
No debug info