File name:

ba0295710678a9ce9e4ac0845ff4bdd7438a3e6009940b657b8e7d5764d7d382.zip

Full analysis: https://app.any.run/tasks/67487838-e29f-4ceb-aba9-7b26872ea517
Verdict: Malicious activity
Analysis date: November 06, 2023, 16:34:14
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

60CCEA4EF79D057AFA341C9B95B982D2

SHA1:

17D313BB51DCD4B60556249005064BC0529836B5

SHA256:

3E0A10B7258A58358EE884FD2A0E5C4ADF8F17D6AF5A936488A79BB5C31C831D

SSDEEP:

98304:ngBiebajB+VmPI8zwBzESwy1ZHiWQ1sk7GpSo3m/c4q3yiF2w0qe4l/VBANqfMbO:9p+

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • EliteUnzipSetup.EliteUnzip_aa.ffjcmnpnoopgilmnfhloocdcbnimmmea.ch (1).exe (PID: 3756)
      • irsetup.exe (PID: 3856)
    • Connects to the CnC server

      • irsetup.exe (PID: 3856)
  • SUSPICIOUS

    • Reads the Internet Settings

      • EliteUnzipSetup.EliteUnzip_aa.ffjcmnpnoopgilmnfhloocdcbnimmmea.ch (1).exe (PID: 3756)
      • irsetup.exe (PID: 3856)
      • EliteUnzip.exe (PID: 3704)
    • Reads the Windows owner or organization settings

      • irsetup.exe (PID: 3856)
  • INFO

    • Checks supported languages

      • wmpnscfg.exe (PID: 3416)
      • EliteUnzipSetup.EliteUnzip_aa.ffjcmnpnoopgilmnfhloocdcbnimmmea.ch (1).exe (PID: 3756)
      • irsetup.exe (PID: 3856)
      • ngen.exe (PID: 3908)
      • Chrome-NativeMessagingDispatcher.exe (PID: 3748)
      • wmpnscfg.exe (PID: 3676)
      • EliteUnzip.exe (PID: 3704)
    • Reads the computer name

      • wmpnscfg.exe (PID: 3416)
      • EliteUnzipSetup.EliteUnzip_aa.ffjcmnpnoopgilmnfhloocdcbnimmmea.ch (1).exe (PID: 3756)
      • irsetup.exe (PID: 3856)
      • wmpnscfg.exe (PID: 3676)
      • EliteUnzip.exe (PID: 3704)
      • ngen.exe (PID: 3908)
    • Reads the machine GUID from the registry

      • wmpnscfg.exe (PID: 3416)
      • EliteUnzip.exe (PID: 3704)
      • irsetup.exe (PID: 3856)
      • wmpnscfg.exe (PID: 3676)
    • Manual execution by a user

      • EliteUnzipSetup.EliteUnzip_aa.ffjcmnpnoopgilmnfhloocdcbnimmmea.ch (1).exe (PID: 3756)
      • wmpnscfg.exe (PID: 3676)
      • EliteUnzip.exe (PID: 3704)
    • Create files in a temporary directory

      • EliteUnzipSetup.EliteUnzip_aa.ffjcmnpnoopgilmnfhloocdcbnimmmea.ch (1).exe (PID: 3756)
      • irsetup.exe (PID: 3856)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 3372)
    • Creates files in the program directory

      • irsetup.exe (PID: 3856)
    • Creates files or folders in the user directory

      • irsetup.exe (PID: 3856)
      • EliteUnzip.exe (PID: 3704)
    • Checks proxy server information

      • irsetup.exe (PID: 3856)
    • Reads Environment values

      • EliteUnzip.exe (PID: 3704)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0001
ZipCompression: Deflated
ZipModifyDate: 2023:11:06 16:33:58
ZipCRC: 0xfe3510e0
ZipCompressedSize: 3856418
ZipUncompressedSize: 4161288
ZipFileName: EliteUnzipSetup.EliteUnzip_aa.ffjcmnpnoopgilmnfhloocdcbnimmmea.ch (1).exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
54
Monitored processes
10
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs eliteunzipsetup.eliteunzip_aa.ffjcmnpnoopgilmnfhloocdcbnimmmea.ch (1).exe irsetup.exe ngen.exe no specs chrome-nativemessagingdispatcher.exe no specs wmpnscfg.exe no specs eliteunzip.exe wisptis.exe no specs wisptis.exe wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
300"C:\Windows\SYSTEM32\WISPTIS.EXE" /ManualLaunch;C:\Windows\System32\wisptis.exeEliteUnzip.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Pen and Touch Input Component
Exit code:
3221226540
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\wisptis.exe
c:\windows\system32\ntdll.dll
1352"C:\Windows\SYSTEM32\WISPTIS.EXE" /ManualLaunch;C:\Windows\System32\wisptis.exe
EliteUnzip.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Pen and Touch Input Component
Exit code:
24
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\wisptis.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
3372"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\ba0295710678a9ce9e4ac0845ff4bdd7438a3e6009940b657b8e7d5764d7d382.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3416"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ole32.dll
3676"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ole32.dll
3704"C:\Program Files\EliteUnzip\EliteUnzip.exe" /source=desktopC:\Program Files\EliteUnzip\EliteUnzip.exe
explorer.exe
User:
admin
Company:
Mindspark Interactive Network, Inc.
Integrity Level:
MEDIUM
Description:
Elite Unzip
Exit code:
0
Version:
1.1.8161.280
Modules
Images
c:\program files\eliteunzip\eliteunzip.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3748"C:\Program Files\EliteUnzip\Chrome-NativeMessagingDispatcher.exe" /register "HKLM" "com.mindspark.eliteunzip_aa" "ffjcmnpnoopgilmnfhloocdcbnimmmea" "C:\Program Files\EliteUnzip\manifest.json" "C:\Program Files\EliteUnzip\Chrome-NativeMessagingDispatcher.exe"C:\Program Files\EliteUnzip\Chrome-NativeMessagingDispatcher.exeirsetup.exe
User:
admin
Company:
Integrity Level:
HIGH
Description:
Exit code:
0
Version:
1.0.7.187
Modules
Images
c:\program files\eliteunzip\chrome-nativemessagingdispatcher.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\eliteunzip\nativemessagingdispatcher.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\ole32.dll
3756"C:\Users\admin\Desktop\EliteUnzipSetup.EliteUnzip_aa.ffjcmnpnoopgilmnfhloocdcbnimmmea.ch (1).exe" C:\Users\admin\Desktop\EliteUnzipSetup.EliteUnzip_aa.ffjcmnpnoopgilmnfhloocdcbnimmmea.ch (1).exe
explorer.exe
User:
admin
Company:
Mindspark Interactive Network
Integrity Level:
HIGH
Description:
Elite Unzip Setup
Exit code:
0
Version:
1.2.8161.280
Modules
Images
c:\users\admin\desktop\eliteunzipsetup.eliteunzip_aa.ffjcmnpnoopgilmnfhloocdcbnimmmea.ch (1).exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3856"C:\Users\admin\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe" __IRAOFF:1750226 "__IRAFN:C:\Users\admin\Desktop\EliteUnzipSetup.EliteUnzip_aa.ffjcmnpnoopgilmnfhloocdcbnimmmea.ch (1).exe" "__IRCT:1" "__IRTSS:4154786" "__IRSID:S-1-5-21-1302019708-1500728564-335382590-1000"C:\Users\admin\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe
EliteUnzipSetup.EliteUnzip_aa.ffjcmnpnoopgilmnfhloocdcbnimmmea.ch (1).exe
User:
admin
Company:
Indigo Rose Corporation
Integrity Level:
HIGH
Description:
Setup Application
Exit code:
0
Version:
9.2.0.0
Modules
Images
c:\users\admin\appdata\local\temp\_ir_sf_temp_0\irsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
3908"C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exe" install "C:\Program Files\EliteUnzip\EliteUnzip.exe" /queueC:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exeirsetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Common Language Runtime native compiler
Exit code:
0
Version:
4.0.30319.34209 built by: FX452RTMGDR
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\ngen.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcr120_clr0400.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
Total events
4 063
Read events
3 978
Write events
57
Delete events
28

Modification events

(PID) Process:(3416) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{D8025145-09C3-4F44-AF6F-2C7102B6D22B}\{E484809C-25EB-4679-B0A6-DAEDBE311F21}
Operation:delete keyName:(default)
Value:
(PID) Process:(3416) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{D8025145-09C3-4F44-AF6F-2C7102B6D22B}
Operation:delete keyName:(default)
Value:
(PID) Process:(3416) wmpnscfg.exeKey:HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Health\{ADA2D2C1-5D74-47C7-8C9D-49273AAF4C05}
Operation:delete keyName:(default)
Value:
(PID) Process:(3372) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\17A\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3372) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(3372) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3372) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3372) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3372) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3372) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
19
Suspicious files
9
Text files
9
Unknown types
0

Dropped files

PID
Process
Filename
Type
3856irsetup.exeC:\Users\admin\AppData\Local\Temp\_ir_sf_temp_0\irsetup.datbinary
MD5:986E542DC5D8C2201B253962566BDE98
SHA256:304BBF4410893EFE8C479517994B7EAEA8D72F657F7EC60DF0F03750B27EF6F7
3756EliteUnzipSetup.EliteUnzip_aa.ffjcmnpnoopgilmnfhloocdcbnimmmea.ch (1).exeC:\Users\admin\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exeexecutable
MD5:B6440CF92D3DE542ED6D4CFFE56758D1
SHA256:541A9B71B37E5D9522889835CFE5C1B753164CA6742344D5E4125A3678878DB6
3856irsetup.exeC:\Program Files\EliteUnzip\lua5.1.dllexecutable
MD5:8C0B6838878F3DD76135F999DDB1C900
SHA256:F537713BBE56322189B5CA120537B25D380DA267BAC4B6A3FCAFA62C1C8A0777
3856irsetup.exeC:\Program Files\EliteUnzip\uninstall.exeexecutable
MD5:B6440CF92D3DE542ED6D4CFFE56758D1
SHA256:541A9B71B37E5D9522889835CFE5C1B753164CA6742344D5E4125A3678878DB6
3856irsetup.exeC:\Program Files\EliteUnzip\IAC.Helpers.dllexecutable
MD5:4E98BFB885DF52CF3B2C131ED49464BE
SHA256:3991E8ADC3391E34F3429222FF175103C6E1ABFD04219F72FDF132293CB93128
3856irsetup.exeC:\Users\admin\AppData\Local\Temp\Elite Unzip Setup Log.txttext
MD5:EFC676125DA09EC1EF7CAFCB6F8775D4
SHA256:834A17BD1D531E251EEBAEB7E2643C1DB44647027DEFC0A0CEDEAD357703A299
3856irsetup.exeC:\Users\admin\AppData\Local\Temp\_ir_sf_temp_0\IRIMG1.PNGimage
MD5:372DB7A863DF53D0AF9EA16E423FEB7F
SHA256:3EA0483261D3EE82A0F2F29DF59FC19F7F690CAF261A785C40EEC883C83B453E
3756EliteUnzipSetup.EliteUnzip_aa.ffjcmnpnoopgilmnfhloocdcbnimmmea.ch (1).exeC:\Users\admin\AppData\Local\Temp\_ir_sf_temp_0\lua5.1.dllexecutable
MD5:8C0B6838878F3DD76135F999DDB1C900
SHA256:F537713BBE56322189B5CA120537B25D380DA267BAC4B6A3FCAFA62C1C8A0777
3856irsetup.exeC:\Program Files\EliteUnzip\Uninstall\uniADB9.tmpbinary
MD5:FF1D74BF7EDB65B596DDF835BCFBF841
SHA256:109EE1C14BE93A3D0346CA7B8AF06214F14113F142C2C42A4597438CDF48FC5C
3856irsetup.exeC:\Program Files\EliteUnzip\DesktopSdk.dllexecutable
MD5:7F489BDC699271132892E8EB9B6646BF
SHA256:CD458C1BD8DFF970BBDE43DE1856E839F7BB27CB99282779172A430AED126000
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
7
DNS requests
1
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3704
EliteUnzip.exe
GET
204
34.120.232.229:80
http://anx.mindspark.com/tr.gif?anxa=EliteUnzip&anxv=1.1.8161.280&anxt=&anxp=&anxsi=&userAgent=&result=Success&time=1234&totalTime=-1&dotnet=v2.0.50727.5420%2Fsp2%3Bv3.0.30729.5420%2Fsp2%3Bv3.5.30729.5420%2Fsp1%3Bv4.5.51209%2Fsp-%2FClient%3Bv4.5.51209%2Fsp-%2FFull%3Bv4.0.0.0%2Fsp-%2FClient%3B&gpu=0&os=6.1.7601.65536%3AService%20Pack%201&is64bitos=False&source=desktop&mode=smart&totalMemory=3220692992&availableMemory=2616356864&cpuCount=4&monitorCount=0&anxe=AppStartup&
unknown
unknown
3856
irsetup.exe
GET
204
34.120.232.229:80
http://anx.mindspark.com/xt8a.gif?installationResult=Success&dotNetVersionInstalled=&dotNetExistingVersion=4%2e5%2e50709&product=Elite%20Unzip&anxe=Install&osDetail=6%2e1&defaultBrowser=IEXPLORE%2eEXE&anxd=2014%2d11%2d20&anxv=1%2e2%2e8161%2e280&anxa=ProductInstaller&osArchitecture=32
unknown
unknown
3704
EliteUnzip.exe
GET
204
34.120.232.229:80
http://anx.mindspark.com/tr.gif?anxa=EliteUnzip&anxv=1.1.8161.280&anxt=&anxp=&anxsi=&userAgent=&section=DropZone&label=Settings&anxe=UIControl&
unknown
unknown
3704
EliteUnzip.exe
GET
204
34.120.232.229:80
http://anx.mindspark.com/tr.gif?anxa=EliteUnzip&anxv=1.1.8161.280&anxt=&anxp=&anxsi=&userAgent=&section=About&label=Close&anxe=UIControl&
unknown
unknown
3704
EliteUnzip.exe
GET
204
34.120.232.229:80
http://anx.mindspark.com/tr.gif?anxa=EliteUnzip&anxv=1.1.8161.280&anxt=&anxp=&anxsi=&userAgent=&section=DropZone&label=Add&anxe=UIControl&
unknown
unknown
3704
EliteUnzip.exe
GET
204
34.120.232.229:80
http://anx.mindspark.com/tr.gif?anxa=EliteUnzip&anxv=1.1.8161.280&anxt=&anxp=&anxsi=&userAgent=&section=Settings&label=Close&anxe=UIControl&
unknown
unknown
3704
EliteUnzip.exe
GET
204
34.120.232.229:80
http://anx.mindspark.com/tr.gif?anxa=EliteUnzip&anxv=1.1.8161.280&anxt=&anxp=&anxsi=&userAgent=&section=DropZone&label=About&anxe=UIControl&
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2588
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
3856
irsetup.exe
34.120.232.229:80
anx.mindspark.com
GOOGLE-CLOUD-PLATFORM
US
unknown
3704
EliteUnzip.exe
34.120.232.229:80
anx.mindspark.com
GOOGLE-CLOUD-PLATFORM
US
unknown

DNS requests

Domain
IP
Reputation
anx.mindspark.com
  • 34.120.232.229
whitelisted

Threats

Found threats are available for the paid subscriptions
2 ETPRO signatures available at the full report
Process
Message
EliteUnzip.exe
FolderView Licensed = True
EliteUnzip.exe
FileView Licensed = True