| File name: | 3dcb5e3575cdd7d544e2e4b95f87ad11d30ac7df9e8322134ca3533d7a6b9acf.zip |
| Full analysis: | https://app.any.run/tasks/1f6514aa-41d1-42ae-8d90-5161686f799f |
| Verdict: | Malicious activity |
| Analysis date: | June 15, 2024, 17:40:15 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract, compression method=deflate |
| MD5: | AF69B92083813D541E38E2B750168A8F |
| SHA1: | 16397C26380BFA8DD7FA27D271398A0090188EA1 |
| SHA256: | 3DCB5E3575CDD7D544E2E4B95F87AD11D30AC7DF9E8322134CA3533D7A6B9ACF |
| SSDEEP: | 98304:9e1GSRkz61AC5/FM0gl8ICun3xUdQnvWqMHvIU0YG8knEVpwktWCtuuJxldgi7aE:QO3qxIw |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2023:05:26 10:10:00 |
| ZipCRC: | 0xac38ab53 |
| ZipCompressedSize: | 758008 |
| ZipUncompressedSize: | 1778184 |
| ZipFileName: | Everything.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 472 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa5620.7933\Everything.exe" -isrunas | C:\Users\admin\AppData\Local\Temp\Rar$EXa5620.7933\Everything.exe | Everything.exe | ||||||||||||
User: admin Company: voidtools Integrity Level: HIGH Description: Everything Exit code: 0 Version: 1.4.1.1024 Modules
| |||||||||||||||
| 624 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa5620.7281\Последняя активность .exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa5620.7281\Последняя активность .exe | — | WinRAR.exe | |||||||||||
User: admin Company: NirSoft Integrity Level: MEDIUM Description: LastActivityView Exit code: 3221226540 Version: 1.32 Modules
| |||||||||||||||
| 708 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa5620.4255\История устройств.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa5620.4255\История устройств.exe | — | WinRAR.exe | |||||||||||
User: admin Company: NirSoft Integrity Level: MEDIUM Description: Lists USB Devices Version: 3.06 Modules
| |||||||||||||||
| 1120 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa5620.7539\Удаленные папки.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa5620.7539\Удаленные папки.exe | WinRAR.exe | ||||||||||||
User: admin Company: Goversoft LLC Integrity Level: HIGH Description: ShellBag AnalyZer & Cleaner Version: 1.28.0.0 Modules
| |||||||||||||||
| 1864 | C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding | C:\Windows\System32\rundll32.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2084 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa5620.4155\Everything.exe" -isrunas | C:\Users\admin\AppData\Local\Temp\Rar$EXa5620.4155\Everything.exe | Everything.exe | ||||||||||||
User: admin Company: voidtools Integrity Level: HIGH Description: Everything Version: 1.4.1.1024 Modules
| |||||||||||||||
| 2312 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa5620.4939\Последняя активность .exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa5620.4939\Последняя активность .exe | WinRAR.exe | ||||||||||||
User: admin Company: NirSoft Integrity Level: HIGH Description: LastActivityView Version: 1.32 Modules
| |||||||||||||||
| 3196 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa5620.7281\Последняя активность .exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa5620.7281\Последняя активность .exe | WinRAR.exe | ||||||||||||
User: admin Company: NirSoft Integrity Level: HIGH Description: LastActivityView Version: 1.32 Modules
| |||||||||||||||
| 3644 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa5620.4155\Everything.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa5620.4155\Everything.exe | — | WinRAR.exe | |||||||||||
User: admin Company: voidtools Integrity Level: MEDIUM Description: Everything Version: 1.4.1.1024 Modules
| |||||||||||||||
| 4424 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa5620.7933\Everything.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa5620.7933\Everything.exe | — | WinRAR.exe | |||||||||||
User: admin Company: voidtools Integrity Level: MEDIUM Description: Everything Exit code: 0 Version: 1.4.1.1024 Modules
| |||||||||||||||
| (PID) Process: | (5620) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (5620) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (5620) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\GoogleChromeEnterpriseBundle64.zip | |||
| (PID) Process: | (5620) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\3dcb5e3575cdd7d544e2e4b95f87ad11d30ac7df9e8322134ca3533d7a6b9acf.zip | |||
| (PID) Process: | (5620) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (5620) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (5620) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (5620) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (5620) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\3c\52C64B7E |
| Operation: | write | Name: | @C:\WINDOWS\System32\acppage.dll,-6002 |
Value: Windows Batch File | |||
| (PID) Process: | (5620) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 5620 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa5620.4155\Everything.lng | binary | |
MD5:BA118BDF7118802BEEA188727B155D5F | SHA256:270C2DBD55642543479C7E7E62F99EC11BBC65496010B1354A2BE9482269D471 | |||
| 5620 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa5620.4155\История устройств.exe | executable | |
MD5:D0D19F2CCCACF70BC84846076ACC11C8 | SHA256:63012EA9CE8ED335DB7BDD33FA7BB449AA1BA31755C6845C1E79C11CB60DC908 | |||
| 5620 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa5620.4155\История устройств.cfg | text | |
MD5:DEEF3031DC8749D779BC83E2E603AD1B | SHA256:DC91446502EDFE569227E5EB87EE544FC4E9B295C1BB728AE4EFC208C2AA0211 | |||
| 5620 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa5620.4255\Everything.lng | binary | |
MD5:BA118BDF7118802BEEA188727B155D5F | SHA256:270C2DBD55642543479C7E7E62F99EC11BBC65496010B1354A2BE9482269D471 | |||
| 5620 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa5620.4155\Последние запущенные.cfg | text | |
MD5:1E9E77443C463D23A8BCB4CEF89EF955 | SHA256:F7A266A952AE664AFEBAABDFFAA4F89B4A5FF2682BF17D882FBB33AB52062298 | |||
| 5620 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa5620.4155\Everything.exe | executable | |
MD5:A7067594451CAB167A4F463BE9D0209C | SHA256:D3A6ED07BD3B52C62411132D060560F9C0C88CE183851F16B632A99B4D4E7581 | |||
| 5620 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa5620.4155\Последняя активность .cfg | text | |
MD5:942D131E26674308ED06E419F0831EC4 | SHA256:4CC9590D6E1ACEA97381E290459DC5818EB53B16D8791574D04A813F5FE52543 | |||
| 5620 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa5620.4255\Удаленные папки.exe | executable | |
MD5:FAAFF4148DB8CDA4068234F5D5110C60 | SHA256:58304B1ED9A66D44938F1E04767D1219194693BC918750388F259B1D0D251DC1 | |||
| 5620 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa5620.4255\Открыть appdata.bat | text | |
MD5:200AADBF80CEABC021F7AE98213CF3DE | SHA256:04FAC8CB5297EEA5CB8FB5F645D53682F429D5E4D86DB62D9FF4106E88AAEEE5 | |||
| 5620 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa5620.4255\История устройств.exe | executable | |
MD5:D0D19F2CCCACF70BC84846076ACC11C8 | SHA256:63012EA9CE8ED335DB7BDD33FA7BB449AA1BA31755C6845C1E79C11CB60DC908 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
5960 | RUXIMICS.exe | GET | 200 | 92.123.236.192:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | unknown |
5380 | svchost.exe | GET | 200 | 92.123.236.192:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | unknown |
5960 | RUXIMICS.exe | GET | 200 | 23.200.213.221:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | unknown |
5140 | MoUsoCoreWorker.exe | GET | 200 | 23.200.213.221:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | unknown |
5380 | svchost.exe | GET | 200 | 23.200.213.221:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | unknown |
— | — | POST | — | 20.42.65.84:443 | https://self.events.data.microsoft.com/OneCollector/1.0/ | unknown | — | — | — |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
5380 | svchost.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | unknown |
5960 | RUXIMICS.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
5140 | MoUsoCoreWorker.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
5960 | RUXIMICS.exe | 92.123.236.192:80 | crl.microsoft.com | Akamai International B.V. | FR | unknown |
5380 | svchost.exe | 92.123.236.192:80 | crl.microsoft.com | Akamai International B.V. | FR | unknown |
— | — | 239.255.255.250:1900 | — | — | — | unknown |
5380 | svchost.exe | 23.200.213.221:80 | www.microsoft.com | AKAMAI-AS | FR | unknown |
5960 | RUXIMICS.exe | 23.200.213.221:80 | www.microsoft.com | AKAMAI-AS | FR | unknown |
5140 | MoUsoCoreWorker.exe | 23.200.213.221:80 | www.microsoft.com | AKAMAI-AS | FR | unknown |
Domain | IP | Reputation |
|---|---|---|
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
self.events.data.microsoft.com |
| whitelisted |