File name:

CCSK.zip

Full analysis: https://app.any.run/tasks/350b3540-daf8-43bd-b7a2-565d2d4274a5
Verdict: Malicious activity
Analysis date: May 20, 2022, 16:07:16
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

24C31D6215087D34B85FD7E96E5ABD11

SHA1:

83DA1CCC2E86A9F4E7B70FADA78A065802F1B2ED

SHA256:

3D54ABA572394717766FA716D5EFF3CEC8B899AE74BD709D54DCB16DC1D1D35B

SSDEEP:

49152:EQ0Ur1nOkf9k1kVpIlrlajOHHLUCq/ONsXwQOlXCcqq2bbhwUzcu3j:E5kOu9k+IrajOLUCLY0DqVwwz

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops executable file immediately after starts

      • WinRAR.exe (PID: 2952)
      • Setup.exe (PID: 2224)
      • Setup.exe (PID: 3812)
    • Actions looks like stealing of personal data

      • WinRAR.exe (PID: 2952)
    • Application was dropped or rewritten from another process

      • Setup.exe (PID: 752)
      • Setup.exe (PID: 2224)
      • Setup.exe (PID: 2616)
      • Setup.exe (PID: 3812)
    • Loads dropped or rewritten executable

      • Setup.exe (PID: 2224)
      • Setup.exe (PID: 3812)
    • Changes settings of System certificates

      • Setup.exe (PID: 3812)
  • SUSPICIOUS

    • Reads the computer name

      • Setup.exe (PID: 2224)
      • WinRAR.exe (PID: 2952)
      • Setup.exe (PID: 3812)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2952)
      • Setup.exe (PID: 2224)
      • Setup.exe (PID: 3812)
    • Drops a file with a compile date too recent

      • WinRAR.exe (PID: 2952)
      • Setup.exe (PID: 2224)
      • Setup.exe (PID: 3812)
    • Checks supported languages

      • Setup.exe (PID: 2224)
      • WinRAR.exe (PID: 2952)
      • Setup.exe (PID: 3812)
    • Creates files in the program directory

      • Setup.exe (PID: 2224)
      • Setup.exe (PID: 3812)
    • Reads Environment values

      • Setup.exe (PID: 3812)
      • Setup.exe (PID: 2224)
    • Adds / modifies Windows certificates

      • Setup.exe (PID: 3812)
    • Creates a directory in Program Files

      • Setup.exe (PID: 3812)
    • Creates files in the user directory

      • Setup.exe (PID: 3812)
    • Creates a software uninstall entry

      • Setup.exe (PID: 3812)
  • INFO

    • Checks supported languages

      • WISPTIS.EXE (PID: 2988)
      • taskmgr.exe (PID: 4068)
      • WISPTIS.EXE (PID: 1332)
    • Reads the computer name

      • WISPTIS.EXE (PID: 1332)
      • taskmgr.exe (PID: 4068)
    • Manual execution by user

      • taskmgr.exe (PID: 4068)
    • Reads settings of System Certificates

      • Setup.exe (PID: 3812)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: Setup.exe
ZipUncompressedSize: 2112512
ZipCompressedSize: 1840089
ZipCRC: 0xb5d4aee2
ZipModifyDate: 2019:05:24 23:23:25
ZipCompression: Deflated
ZipBitFlag: -
ZipRequiredVersion: 20
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
50
Monitored processes
10
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
drop and start drop and start drop and start drop and start start winrar.exe setup.exe no specs setup.exe setup.exe no specs setup.exe wisptis.exe no specs wisptis.exe no specs wisptis.exe no specs wisptis.exe no specs taskmgr.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
752"C:\Users\admin\AppData\Local\Temp\Rar$EXa2952.074\Setup.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2952.074\Setup.exeWinRAR.exe
User:
admin
Company:
Byte01 Solutions
Integrity Level:
MEDIUM
Description:
Setup
Exit code:
3221226540
Version:
1.2.1905.2423
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\appdata\local\temp\rar$exa2952.074\setup.exe
1332"C:\Windows\SYSTEM32\WISPTIS.EXE" /ManualLaunch;C:\Windows\SYSTEM32\WISPTIS.EXESetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Pen and Touch Input Component
Exit code:
24
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wisptis.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\lpk.dll
2188"C:\Windows\SYSTEM32\WISPTIS.EXE" /ManualLaunch;C:\Windows\SYSTEM32\WISPTIS.EXESetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Pen and Touch Input Component
Exit code:
3221226540
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\wisptis.exe
c:\windows\system32\ntdll.dll
2212"C:\Windows\SYSTEM32\WISPTIS.EXE" /ManualLaunch;C:\Windows\SYSTEM32\WISPTIS.EXESetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Pen and Touch Input Component
Exit code:
3221226540
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\wisptis.exe
c:\windows\system32\ntdll.dll
2224"C:\Users\admin\AppData\Local\Temp\Rar$EXa2952.074\Setup.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2952.074\Setup.exe
WinRAR.exe
User:
admin
Company:
Byte01 Solutions
Integrity Level:
HIGH
Description:
Setup
Exit code:
0
Version:
1.2.1905.2423
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2952.074\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
2616"C:\Users\admin\AppData\Local\Temp\Rar$EXa2952.169\Setup.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2952.169\Setup.exeWinRAR.exe
User:
admin
Company:
Byte01 Solutions
Integrity Level:
MEDIUM
Description:
Setup
Exit code:
3221226540
Version:
1.2.1905.2423
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2952.169\setup.exe
c:\windows\system32\ntdll.dll
2952"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\CCSK.zip"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2988"C:\Windows\SYSTEM32\WISPTIS.EXE" /ManualLaunch;C:\Windows\SYSTEM32\WISPTIS.EXESetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Pen and Touch Input Component
Exit code:
23
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\wisptis.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
3812"C:\Users\admin\AppData\Local\Temp\Rar$EXa2952.169\Setup.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2952.169\Setup.exe
WinRAR.exe
User:
admin
Company:
Byte01 Solutions
Integrity Level:
HIGH
Description:
Setup
Exit code:
0
Version:
1.2.1905.2423
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2952.169\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
4068"C:\Windows\system32\taskmgr.exe" /4C:\Windows\system32\taskmgr.exeExplorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Task Manager
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskmgr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
6 165
Read events
6 058
Write events
107
Delete events
0

Modification events

(PID) Process:(2952) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2952) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2952) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2952) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(2952) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2952) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\CCSK.zip
(PID) Process:(2952) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2952) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2952) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2952) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
6
Suspicious files
3
Text files
3
Unknown types
5

Dropped files

PID
Process
Filename
Type
2952WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2952.169\manifest.mnxfli
MD5:
SHA256:
2952WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2952.074\manifest.mnxfli
MD5:
SHA256:
3812Setup.exeC:\Program Files\study4exam\manifest.mnxfli
MD5:
SHA256:
2224Setup.exeC:\ProgramData\study4exam\Logs\Setup20220520_001.logtext
MD5:
SHA256:
3812Setup.exeC:\Program Files\study4exam\study4exam.icoimage
MD5:
SHA256:
3812Setup.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\study4exam.lnklnk
MD5:
SHA256:
3812Setup.exeC:\Users\admin\AppData\Local\Temp\tmpBE90.tmpcompressed
MD5:
SHA256:
3812Setup.exeC:\ProgramData\study4exam\Exams\CCSK.exmcompressed
MD5:
SHA256:
2224Setup.exeC:\ProgramData\study4exam\Logs\Setup20220520.logtext
MD5:
SHA256:
3812Setup.exeC:\Users\admin\Desktop\study4exam.lnklnk
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
2
DNS requests
3
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3812
Setup.exe
78.157.192.94:443
www.practice4exam.com
UK Dedicated Servers Limited
GB
unknown
2224
Setup.exe
78.157.192.94:443
www.practice4exam.com
UK Dedicated Servers Limited
GB
unknown

DNS requests

Domain
IP
Reputation
www.practice4exam.com
  • 78.157.192.94
whitelisted
dns.msftncsi.com
  • 131.107.255.255
shared

Threats

No threats detected
No debug info