| download: | Update.zip |
| Full analysis: | https://app.any.run/tasks/4355d2bb-4b3e-4ac3-9ed0-23f651ef459f |
| Verdict: | Malicious activity |
| Analysis date: | April 27, 2018, 15:52:27 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v1.0 to extract |
| MD5: | 335D983B6FD3FA3CF1C1030B8420577F |
| SHA1: | 2457B91EA741E38D749A12E014A25DDF7C98949E |
| SHA256: | 3D1D4C88F5C2E708263002B4D82E80CC51C6539EF906EFA87E795B84F251BF6D |
| SSDEEP: | 24576:dCF1GcbDa3kPpIULj++AzwoQS+6XK3eZCJ59TFray/W21Ggv:sF15IkPaUn++W+669J59TFW2yA |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 10 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2018:04:22 17:47:10 |
| ZipCRC: | 0xb580dab2 |
| ZipCompressedSize: | 101789 |
| ZipUncompressedSize: | 295848 |
| ZipFileName: | SAInfrastructure.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 768 | "C:\Program Files\7-Zip\7zFM.exe" "C:\Users\admin\AppData\Local\Temp\Update.zip" | C:\Program Files\7-Zip\7zFM.exe | explorer.exe | ||||||||||||
User: admin Company: Igor Pavlov Integrity Level: MEDIUM Description: 7-Zip File Manager Exit code: 0 Version: 16.04 Modules
| |||||||||||||||
| 2708 | "C:\Users\admin\AppData\Local\Temp\7zO003C8A00\SysAidAgentUpdate.exe" | C:\Users\admin\AppData\Local\Temp\7zO003C8A00\SysAidAgentUpdate.exe | — | 7zFM.exe | |||||||||||
User: admin Company: SysAid Technology Ltd. Integrity Level: MEDIUM Description: SysAid Agent Exit code: 0 Version: 18.1.43.1 Modules
| |||||||||||||||
| (PID) Process: | (768) 7zFM.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (768) 7zFM.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
| (PID) Process: | (2708) SysAidAgentUpdate.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\91\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2708 | SysAidAgentUpdate.exe | C:\Users\admin\AppData\Local\Temp\Cab2CBF.tmp | — | |
MD5:— | SHA256:— | |||
| 2708 | SysAidAgentUpdate.exe | C:\Users\admin\AppData\Local\Temp\Tar2CC0.tmp | — | |
MD5:— | SHA256:— | |||
| 2708 | SysAidAgentUpdate.exe | C:\Users\admin\AppData\Local\Temp\Cab2CD0.tmp | — | |
MD5:— | SHA256:— | |||
| 2708 | SysAidAgentUpdate.exe | C:\Users\admin\AppData\Local\Temp\Tar2CD1.tmp | — | |
MD5:— | SHA256:— | |||
| 2708 | SysAidAgentUpdate.exe | C:\Users\admin\AppData\Local\Temp\Cab41C2.tmp | — | |
MD5:— | SHA256:— | |||
| 2708 | SysAidAgentUpdate.exe | C:\Users\admin\AppData\Local\Temp\Tar41C3.tmp | — | |
MD5:— | SHA256:— | |||
| 2708 | SysAidAgentUpdate.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\223DE96EE265046957A660ED7C9DD9E7_EFF9B9BA98DEAA773F261FA85A0B1771 | binary | |
MD5:— | SHA256:— | |||
| 2708 | SysAidAgentUpdate.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\520FE53DDCAF9AEA9A13B095769E6749_D38FE93F60D60D0094702F3EB8BDDC5F | der | |
MD5:— | SHA256:— | |||
| 2708 | SysAidAgentUpdate.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\520FE53DDCAF9AEA9A13B095769E6749_D38FE93F60D60D0094702F3EB8BDDC5F | binary | |
MD5:— | SHA256:— | |||
| 2708 | SysAidAgentUpdate.exe | C:\Users\admin\AppData\Local\Temp\7zO003C8A00\logs\SysAidAgentUpdate.txt | text | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 188.121.36.239:80 | http://ocsp.godaddy.com//MEIwQDA%2BMDwwOjAJBgUrDgMCGgUABBQdI2%2BOBkuXH93foRUj4a7lAr4rGwQUOpqFBxBnKLbv9r0FQW4gwZTaD94CAQc%3D | NL | der | 1.69 Kb | whitelisted |
— | — | GET | 200 | 188.121.36.239:80 | http://ocsp.godaddy.com//MEowSDBGMEQwQjAJBgUrDgMCGgUABBS2CA1fbGt26xPkOKX4ZguoUjM0TgQUQMK9J47MNIMwojPX%2B2yz8LQsgM4CCQCOyNtGUJdESw%3D%3D | NL | der | 1.74 Kb | whitelisted |
— | — | GET | 200 | 8.248.1.254:80 | http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab | US | compressed | 52.4 Kb | whitelisted |
— | — | GET | 200 | 8.248.1.254:80 | http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/47BEABC922EAE80E78783462A79F45C254FDE68B.crt | US | der | 969 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 188.121.36.239:80 | ocsp.godaddy.com | GoDaddy.com, LLC | NL | unknown |
— | — | 8.248.1.254:80 | www.download.windowsupdate.com | Level 3 Communications, Inc. | US | suspicious |
Domain | IP | Reputation |
|---|---|---|
www.download.windowsupdate.com |
| whitelisted |
ocsp.godaddy.com |
| whitelisted |