File name:

CCSK.zip

Full analysis: https://app.any.run/tasks/87a32160-4b42-4ce1-8505-d1af7d70044e
Verdict: Malicious activity
Analysis date: May 20, 2022, 16:04:36
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

24C31D6215087D34B85FD7E96E5ABD11

SHA1:

83DA1CCC2E86A9F4E7B70FADA78A065802F1B2ED

SHA256:

3D54ABA572394717766FA716D5EFF3CEC8B899AE74BD709D54DCB16DC1D1D35B

SSDEEP:

49152:EQ0Ur1nOkf9k1kVpIlrlajOHHLUCq/ONsXwQOlXCcqq2bbhwUzcu3j:E5kOu9k+IrajOLUCLY0DqVwwz

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops executable file immediately after starts

      • WinRAR.exe (PID: 3504)
      • Setup.exe (PID: 3652)
      • study4exam.exe (PID: 768)
    • Application was dropped or rewritten from another process

      • Setup.exe (PID: 1776)
      • Setup.exe (PID: 3652)
      • study4exam.exe (PID: 768)
    • Loads dropped or rewritten executable

      • Setup.exe (PID: 3652)
      • study4exam.exe (PID: 768)
    • Changes settings of System certificates

      • Setup.exe (PID: 3652)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3504)
      • Setup.exe (PID: 3652)
      • study4exam.exe (PID: 768)
    • Checks supported languages

      • WinRAR.exe (PID: 3504)
      • Setup.exe (PID: 3652)
      • study4exam.exe (PID: 768)
    • Reads the computer name

      • WinRAR.exe (PID: 3504)
      • Setup.exe (PID: 3652)
      • study4exam.exe (PID: 768)
    • Drops a file with a compile date too recent

      • WinRAR.exe (PID: 3504)
      • Setup.exe (PID: 3652)
      • study4exam.exe (PID: 768)
    • Creates files in the program directory

      • Setup.exe (PID: 3652)
      • study4exam.exe (PID: 768)
    • Reads Environment values

      • Setup.exe (PID: 3652)
      • study4exam.exe (PID: 768)
    • Adds / modifies Windows certificates

      • Setup.exe (PID: 3652)
    • Creates a directory in Program Files

      • Setup.exe (PID: 3652)
    • Creates files in the user directory

      • Setup.exe (PID: 3652)
    • Creates a software uninstall entry

      • Setup.exe (PID: 3652)
  • INFO

    • Manual execution by user

      • Setup.exe (PID: 3652)
      • Setup.exe (PID: 1776)
      • study4exam.exe (PID: 768)
    • Reads the computer name

      • WISPTIS.EXE (PID: 4004)
      • WISPTIS.EXE (PID: 3216)
    • Checks supported languages

      • WISPTIS.EXE (PID: 4004)
      • WISPTIS.EXE (PID: 3216)
    • Reads settings of System Certificates

      • Setup.exe (PID: 3652)
      • study4exam.exe (PID: 768)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: Setup.exe
ZipUncompressedSize: 2112512
ZipCompressedSize: 1840089
ZipCRC: 0xb5d4aee2
ZipModifyDate: 2019:05:24 23:23:25
ZipCompression: Deflated
ZipBitFlag: -
ZipRequiredVersion: 20
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
49
Monitored processes
8
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe setup.exe no specs setup.exe wisptis.exe no specs wisptis.exe no specs study4exam.exe wisptis.exe no specs wisptis.exe

Process information

PID
CMD
Path
Indicators
Parent process
768"C:\Program Files\study4exam\study4exam.exe" C:\Program Files\study4exam\study4exam.exe
Explorer.EXE
User:
admin
Company:
Byte01 Solutions
Integrity Level:
MEDIUM
Description:
Examulator
Exit code:
0
Version:
1.2.2005.0607
Modules
Images
c:\program files\study4exam\study4exam.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1776"C:\Users\admin\Desktop\Setup.exe" C:\Users\admin\Desktop\Setup.exeExplorer.EXE
User:
admin
Company:
Byte01 Solutions
Integrity Level:
MEDIUM
Description:
Setup
Exit code:
3221226540
Version:
1.2.1905.2423
Modules
Images
c:\users\admin\desktop\setup.exe
c:\windows\system32\ntdll.dll
2112"C:\Windows\SYSTEM32\WISPTIS.EXE" /ManualLaunch;C:\Windows\SYSTEM32\WISPTIS.EXEstudy4exam.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Pen and Touch Input Component
Exit code:
3221226540
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\wisptis.exe
c:\windows\system32\ntdll.dll
2804"C:\Windows\SYSTEM32\WISPTIS.EXE" /ManualLaunch;C:\Windows\SYSTEM32\WISPTIS.EXESetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Pen and Touch Input Component
Exit code:
3221226540
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\wisptis.exe
c:\windows\system32\ntdll.dll
3216"C:\Windows\SYSTEM32\WISPTIS.EXE" /ManualLaunch;C:\Windows\SYSTEM32\WISPTIS.EXE
study4exam.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Pen and Touch Input Component
Exit code:
24
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\wisptis.exe
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\oleaut32.dll
3504"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\CCSK.zip"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3652"C:\Users\admin\Desktop\Setup.exe" C:\Users\admin\Desktop\Setup.exe
Explorer.EXE
User:
admin
Company:
Byte01 Solutions
Integrity Level:
HIGH
Description:
Setup
Exit code:
0
Version:
1.2.1905.2423
Modules
Images
c:\users\admin\desktop\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
4004"C:\Windows\SYSTEM32\WISPTIS.EXE" /ManualLaunch;C:\Windows\SYSTEM32\WISPTIS.EXESetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Pen and Touch Input Component
Exit code:
24
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\wisptis.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
Total events
8 862
Read events
8 732
Write events
130
Delete events
0

Modification events

(PID) Process:(3504) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3504) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3504) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3504) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(3504) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3504) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\CCSK.zip
(PID) Process:(3504) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3504) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3504) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3504) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
6
Suspicious files
11
Text files
3
Unknown types
4

Dropped files

PID
Process
Filename
Type
3652Setup.exeC:\Users\admin\Desktop\study4exam.lnklnk
MD5:
SHA256:
3652Setup.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\study4exam.lnklnk
MD5:
SHA256:
3504WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3504.34508\manifest.mnxfli
MD5:
SHA256:
3652Setup.exeC:\Users\admin\AppData\Local\Temp\tmpEFF5.tmpcompressed
MD5:
SHA256:
768study4exam.exeC:\ProgramData\study4exam\Logs\study4exam20220520.logtext
MD5:
SHA256:
768study4exam.exeC:\ProgramData\study4exam\exmdta.db-journalbinary
MD5:
SHA256:
3652Setup.exeC:\ProgramData\study4exam\Logs\Setup20220520.logtext
MD5:
SHA256:
3652Setup.exeC:\Program Files\study4exam\study4exam.icoimage
MD5:
SHA256:
3652Setup.exeC:\Program Files\study4exam\manifest.mnxfli
MD5:
SHA256:
3504WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3504.34508\Setup.exeexecutable
MD5:95994837BBDACA8970D421B66385E104
SHA256:AD0D58CF17629FD5456EFCC94556AB88D280B103E5B129EDBF410C5E785E380E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
6
DNS requests
3
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3652
Setup.exe
78.157.192.94:443
www.practice4exam.com
UK Dedicated Servers Limited
GB
unknown
768
study4exam.exe
51.104.28.68:443
fn-byte01.azurewebsites.net
Microsoft Corporation
GB
unknown
768
study4exam.exe
78.157.192.94:443
www.practice4exam.com
UK Dedicated Servers Limited
GB
unknown

DNS requests

Domain
IP
Reputation
www.practice4exam.com
  • 78.157.192.94
whitelisted
fn-byte01.azurewebsites.net
  • 51.104.28.68
unknown

Threats

No threats detected
No debug info