analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

Antivirus Platinum.zip

Full analysis: https://app.any.run/tasks/d93ba477-8d03-4756-938b-8d4d8969562b
Verdict: Malicious activity
Analysis date: July 12, 2020, 11:42:26
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

FF84853A0F564152BD0B98D3FA63E695

SHA1:

47D628D279DE8A0D47534F93FA5B046BB7F4C991

SHA256:

3AAA9E8EA7C213575FD3AC4EC004629B4EDE0DE06E243F6AAD3CF2403E65D3F2

SSDEEP:

12288:pKAT6gPoHT7CzZy7fmzVyaF3zA0mKz8doC3m/LuXCC32H+REYWzTdjhoMlX1Q4QM:2gPoHT7CtEfwyaFDAjKz8Bm/LYC+3uYi

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

    • Registers / Runs the DLL via REGSVR32.EXE

      • cmd.exe (PID: 680)
    • Loads dropped or rewritten executable

      • regsvr32.exe (PID: 3788)
      • regsvr32.exe (PID: 2176)
    • Changes Security Center notification settings

      • antivirus-platinum.exe (PID: 956)
    • Task Manager has been disabled (taskmgr)

      • antivirus-platinum.exe (PID: 956)
    • Disables the Shutdown in Start menu

      • antivirus-platinum.exe (PID: 956)
    • Disables registry editing tools (regedit)

      • antivirus-platinum.exe (PID: 956)
    • Disables Windows System Restore

      • antivirus-platinum.exe (PID: 956)
    • Disables the LogOff in Start menu

      • antivirus-platinum.exe (PID: 956)
  • SUSPICIOUS

    • Application launched itself

    • Executable content was dropped or overwritten

    • Creates files in the Windows directory

    • Starts CMD.EXE for commands execution

      • 302746537.exe (PID: 1748)
    • Changes the started page of IE

      • antivirus-platinum.exe (PID: 956)
    • Uses ATTRIB.EXE to modify file attributes

      • cmd.exe (PID: 680)
    • Modifies files in Chrome extension folder

      • chrome.exe (PID: 1004)
    • Starts Internet Explorer

      • antivirus-platinum.exe (PID: 956)
  • INFO

    • Manual execution by user

    • Reads the hosts file

      • chrome.exe (PID: 1004)
      • chrome.exe (PID: 2248)
    • Application launched itself

      • chrome.exe (PID: 1004)
    • Reads Internet Cache Settings

      • iexplore.exe (PID: 3836)
      • iexplore.exe (PID: 2876)
    • Changes internet zones settings

      • iexplore.exe (PID: 3836)
    • Creates files in the user directory

      • iexplore.exe (PID: 2876)
    • Reads internet explorer settings

      • iexplore.exe (PID: 2876)
    • Reads settings of System Certificates

      • iexplore.exe (PID: 2876)
      • chrome.exe (PID: 2248)
    • Adds / modifies Windows certificates

      • iexplore.exe (PID: 2876)
    • Changes settings of System certificates

      • iexplore.exe (PID: 2876)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0001
ZipCompression: Deflated
ZipModifyDate: 2010:01:30 10:06:03
ZipCRC: 0x2888ddb9
ZipCompressedSize: 716234
ZipUncompressedSize: 757637
ZipFileName: [email protected]
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
81
Monitored processes
41
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start drop and start winrar.exe no specs [email protected] no specs [email protected] 302746537.exe no specs cmd.exe no specs regsvr32.exe no specs regsvr32.exe no specs antivirus-platinum.exe no specs attrib.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs iexplore.exe iexplore.exe

Process information

PID
CMD
Path
Indicators
Parent process
1852"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Antivirus Platinum.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3360"C:\Users\admin\Desktop\[email protected]" C:\Users\admin\Desktop\[email protected]explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\[email protected]
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2876"C:\Users\admin\Desktop\[email protected]" -el -s2 "-dC:\WINDOWS" "-p" "-sp"C:\Users\admin\Desktop\[email protected]
[email protected]
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\[email protected]
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1748"C:\WINDOWS\302746537.exe" C:\WINDOWS\302746537.exe[email protected]
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\windows\302746537.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
680cmd /c ""C:\Users\admin\AppData\Local\Temp\7EC.tmp\302746537.bat" "C:\Windows\system32\cmd.exe302746537.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2176regsvr32 /s c:\windows\comctl32.ocxC:\Windows\system32\regsvr32.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3788regsvr32 /s c:\windows\mscomctl.ocxC:\Windows\system32\regsvr32.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
956c:\windows\antivirus-platinum.exe c:\windows\antivirus-platinum.execmd.exe
User:
admin
Company:
BKHN
Integrity Level:
HIGH
Exit code:
0
Version:
1.00
Modules
Images
c:\windows\antivirus-platinum.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2584attrib +h c:\windows\antivirus-platinum.exeC:\Windows\system32\attrib.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Attribute Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\attrib.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ulib.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1004"C:\Program Files\Google\Chrome\Application\chrome.exe" C:\Program Files\Google\Chrome\Application\chrome.exe
explorer.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
3221225547
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
Total events
4 343
Read events
2 269
Write events
0
Delete events
0

Modification events

No data
Executable files
4
Suspicious files
112
Text files
281
Unknown types
35

Dropped files

PID
Process
Filename
Type
1852WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb1852.49919\[email protected]
MD5:
SHA256:
1004chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-5F0AF771-3EC.pma
MD5:
SHA256:
1004chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\95143aa7-1fd5-44b0-b020-188e03cd1be7.tmp
MD5:
SHA256:
2876[email protected]C:\Users\admin\Desktop\AntiVirus Platinum.lnklnk
MD5:136081BAEC1BC929FA50E8B982CC7D0C
SHA256:5388A70D47DA0126082761CD3ACDE35528E29994321399CA00415D28169AEE47
1004chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000028.dbtmp
MD5:
SHA256:
1004chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.oldtext
MD5:DA692BE42E4EF2668AE7499A7D5DA720
SHA256:EB865CAF59002C092F5FDBE22D01935866BC1277108B29E897052CB2439630ED
1004chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.oldtext
MD5:F69C20D5B552B8D973FB1CBA5FDD7D87
SHA256:48799968D50E2D74E625A0AB18E93C6792AF20010334C6BB4E935C8D26F7026A
1004chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\LOG.oldtext
MD5:AC43135B8C9FED46A92448C4E711F45C
SHA256:D840BA7CEBACF86DDBAD75BFB61A53449AA7AE3DE6B8ADC97FE45624626A6F09
1004chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\LOG.old
MD5:
SHA256:
1004chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Last Versiontext
MD5:1A89A1BEBE6C843C4FF582E7ED33CA1F
SHA256:65099CA087B66AA8CA420AB121DAAD713E1DB5A61C5A574D9B1C0DF24F012520
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
25
TCP/UDP connections
60
DNS requests
41
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2876
iexplore.exe
GET
301
104.17.119.40:80
http://secureservices2010.webs.com/update/update.txt
US
malicious
2876
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEAo3h2ReX7SMIk79G%2B0UDDw%3D
US
der
471 b
whitelisted
2876
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA%2Fz5hY5qj0aEmX0H4s05bY%3D
US
der
1.47 Kb
whitelisted
2876
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQrBBNpPfHTPX6Jy6BVzyBPnBWMnQQUPnQtH89FdQR%2BP8Cihz5MQ4NRE8YCEA4Gpe7b9YPekM6FHtCr%2BMk%3D
US
der
278 b
whitelisted
2876
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQrBBNpPfHTPX6Jy6BVzyBPnBWMnQQUPnQtH89FdQR%2BP8Cihz5MQ4NRE8YCEAXoVMFsORfvvHup8VBgwtU%3D
US
der
278 b
whitelisted
2248
chrome.exe
GET
302
172.217.18.14:80
http://redirector.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvY2Y1QUFXUjZlVjI5UldyLVpDTFJFcEx6QQ/7719.805.0.2_pkedcjkdefgpdelpbcmbmeomcjbeemfm.crx
US
html
523 b
whitelisted
2248
chrome.exe
GET
200
172.217.132.8:80
http://r3---sn-5hne6nsd.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvY2Y1QUFXUjZlVjI5UldyLVpDTFJFcEx6QQ/7719.805.0.2_pkedcjkdefgpdelpbcmbmeomcjbeemfm.crx?cms_redirect=yes&mh=Nf&mip=45.86.201.12&mm=28&mn=sn-5hne6nsd&ms=nvh&mt=1594553536&mv=u&mvi=3&pl=27&shardbypass=yes
US
crx
823 Kb
whitelisted
2876
iexplore.exe
GET
200
151.139.128.14:80
http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEDlyRDr5IrdR19NsEN0xNZU%3D
US
der
471 b
whitelisted
2876
iexplore.exe
GET
200
151.139.128.14:80
http://ocsp.sectigo.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBRDC9IOTxN6GmyRjyTl2n4yTUczyAQUjYxexFStiuF36Zv5mwXhuAGNYeECEQC5UUQDFilM79r2jgo50n2A
US
der
472 b
whitelisted
2248
chrome.exe
GET
200
209.85.226.73:80
http://r4---sn-5hnekn7k.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvOTRmQUFXVHlhaGJaUTdMLWtCSkNJUl9ZQQ/1.0.0.5_nmmhkkegccagdldgiimedpiccmgmieda.crx?cms_redirect=yes&mh=QJ&mip=45.86.201.12&mm=28&mn=sn-5hnekn7k&ms=nvh&mt=1594553536&mv=u&mvi=4&pl=27&shardbypass=yes
US
crx
293 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2248
chrome.exe
172.217.18.99:443
www.google.com.ua
Google Inc.
US
whitelisted
2248
chrome.exe
172.217.22.99:443
www.gstatic.com
Google Inc.
US
whitelisted
2248
chrome.exe
172.217.23.142:443
ogs.google.com.ua
Google Inc.
US
whitelisted
2248
chrome.exe
216.58.205.227:443
clientservices.googleapis.com
Google Inc.
US
whitelisted
2248
chrome.exe
216.58.212.138:443
fonts.googleapis.com
Google Inc.
US
whitelisted
2248
chrome.exe
172.217.23.110:443
apis.google.com
Google Inc.
US
whitelisted
2248
chrome.exe
172.217.18.13:443
accounts.google.com
Google Inc.
US
whitelisted
2248
chrome.exe
216.58.207.67:443
fonts.gstatic.com
Google Inc.
US
whitelisted
2248
chrome.exe
172.217.22.3:443
www.google.nl
Google Inc.
US
whitelisted
2248
chrome.exe
172.217.21.227:443
ssl.gstatic.com
Google Inc.
US
whitelisted

DNS requests

Domain
IP
Reputation
clientservices.googleapis.com
  • 216.58.205.227
whitelisted
accounts.google.com
  • 172.217.18.13
shared
www.google.com.ua
  • 172.217.18.99
whitelisted
fonts.googleapis.com
  • 216.58.212.138
whitelisted
www.gstatic.com
  • 172.217.22.99
whitelisted
fonts.gstatic.com
  • 216.58.207.67
whitelisted
apis.google.com
  • 172.217.23.110
whitelisted
ogs.google.com.ua
  • 172.217.23.142
whitelisted
www.google.com
  • 172.217.22.36
whitelisted
www.google.nl
  • 172.217.22.3
whitelisted

Threats

No threats detected
No debug info