File name:

3f5b0b46c66b5b9ca002e9c0da75375c31f7deab8e143e6311f36fc292d51391

Full analysis: https://app.any.run/tasks/665a82e1-4f98-44b7-902a-d44b2b425942
Verdict: Malicious activity
Analysis date: April 17, 2024, 23:19:35
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract, compression method=store
MD5:

5D0D875E40D51A575D9A22FFC5E9B356

SHA1:

FECA7A04C0A51926BF8CC48A1ACA821174DB6E17

SHA256:

3F5B0B46C66B5B9CA002E9C0DA75375C31F7DEAB8E143E6311F36FC292D51391

SSDEEP:

12288:+kEFlqQ83rE0WNVASYUJpjgClHLB2KJlO:9EFlQ3rE9LASYmZgCl9rJE

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 1536)
      • Proposed List of China Philippines Maritime Cooperation Projects.exe (PID: 1316)
    • Changes the autorun value in the registry

      • Proposed List of China Philippines Maritime Cooperation Projects.exe (PID: 1316)
      • Proposed List of China Philippines Maritime Cooperation Projects.exe (PID: 3584)
      • Proposed List of China Philippines Maritime Cooperation Projects.exe (PID: 3948)
      • vfaview.exe (PID: 848)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 1536)
    • Executable content was dropped or overwritten

      • Proposed List of China Philippines Maritime Cooperation Projects.exe (PID: 1316)
    • Reads the date of Windows installation

      • pwsh.exe (PID: 884)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1536)
    • Checks supported languages

      • Proposed List of China Philippines Maritime Cooperation Projects.exe (PID: 1316)
      • Proposed List of China Philippines Maritime Cooperation Projects.exe (PID: 3584)
      • pwsh.exe (PID: 884)
      • Proposed List of China Philippines Maritime Cooperation Projects.exe (PID: 3948)
      • vfaview.exe (PID: 848)
    • Creates files in the program directory

      • Proposed List of China Philippines Maritime Cooperation Projects.exe (PID: 1316)
    • Manual execution by a user

      • explorer.exe (PID: 3968)
      • pwsh.exe (PID: 884)
      • Proposed List of China Philippines Maritime Cooperation Projects.exe (PID: 3948)
      • cmd.exe (PID: 1728)
    • Reads the computer name

      • pwsh.exe (PID: 884)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2024:04:01 14:27:10
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: Proposed List of China Philippines Maritime Cooperation Projects/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
55
Monitored processes
12
Malicious processes
2
Suspicious processes
3

Behavior graph

Click at the process to see the details
start winrar.exe proposed list of china philippines maritime cooperation projects.exe schtasks.exe no specs proposed list of china philippines maritime cooperation projects.exe schtasks.exe no specs explorer.exe no specs pwsh.exe cmd.exe no specs proposed list of china philippines maritime cooperation projects.exe schtasks.exe no specs vfaview.exe schtasks.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
848vfaview.exe C:\ProgramData\FaxVentaPrint024\vfaview.exe
cmd.exe
User:
admin
Company:
Venta Association
Integrity Level:
MEDIUM
Description:
VentaFax Engine Controller
Exit code:
0
Version:
7, 7, 0, 8
Modules
Images
c:\programdata\faxventaprint024\vfaview.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\programdata\faxventaprint024\vntfxf32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
884"C:\Program Files\PowerShell\7\pwsh.exe" -WorkingDirectory ~C:\Program Files\PowerShell\7\pwsh.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
pwsh
Version:
7.2.11.500
Modules
Images
c:\program files\powershell\7\pwsh.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
1316"C:\Users\admin\AppData\Local\Temp\Rar$EXa1536.31243\Proposed List of China Philippines Maritime Cooperation Projects\Proposed List of China Philippines Maritime Cooperation Projects.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa1536.31243\Proposed List of China Philippines Maritime Cooperation Projects\Proposed List of China Philippines Maritime Cooperation Projects.exe
WinRAR.exe
User:
admin
Company:
Venta Association
Integrity Level:
MEDIUM
Description:
VentaFax Engine Controller
Exit code:
0
Version:
7, 7, 0, 8
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa1536.31243\proposed list of china philippines maritime cooperation projects\proposed list of china philippines maritime cooperation projects.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\temp\rar$exa1536.31243\proposed list of china philippines maritime cooperation projects\vntfxf32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
1536"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\3f5b0b46c66b5b9ca002e9c0da75375c31f7deab8e143e6311f36fc292d51391.zipC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
1728"C:\Windows\System32\cmd.exe" C:\Windows\System32\cmd.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
3221225786
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2524/F /Create /TN VentaPrint /SC minute /MO 5 /TR "C:\ProgramData\FaxVentaPrint024\vfaview.exe FaxVentaPrint024"C:\Windows\System32\schtasks.exeProposed List of China Philippines Maritime Cooperation Projects.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Manages scheduled tasks
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
2652/F /Create /TN VentaPrint /SC minute /MO 5 /TR "C:\ProgramData\FaxVentaPrint024\vfaview.exe FaxVentaPrint024"C:\Windows\System32\schtasks.exeProposed List of China Philippines Maritime Cooperation Projects.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Manages scheduled tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
3584"C:\Users\admin\AppData\Local\Temp\Rar$EXa1536.32074\Proposed List of China Philippines Maritime Cooperation Projects\Proposed List of China Philippines Maritime Cooperation Projects.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa1536.32074\Proposed List of China Philippines Maritime Cooperation Projects\Proposed List of China Philippines Maritime Cooperation Projects.exe
WinRAR.exe
User:
admin
Company:
Venta Association
Integrity Level:
MEDIUM
Description:
VentaFax Engine Controller
Exit code:
0
Version:
7, 7, 0, 8
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa1536.32074\proposed list of china philippines maritime cooperation projects\proposed list of china philippines maritime cooperation projects.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\temp\rar$exa1536.32074\proposed list of china philippines maritime cooperation projects\vntfxf32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
3948"C:\Users\admin\Documents\Proposed List of China Philippines Maritime Cooperation Projects.exe" C:\Users\admin\Documents\Proposed List of China Philippines Maritime Cooperation Projects.exe
explorer.exe
User:
admin
Company:
Venta Association
Integrity Level:
MEDIUM
Description:
VentaFax Engine Controller
Exit code:
0
Version:
7, 7, 0, 8
Modules
Images
c:\users\admin\documents\proposed list of china philippines maritime cooperation projects.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\documents\vntfxf32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
3956/F /Create /TN VentaPrint /SC minute /MO 5 /TR "C:\ProgramData\FaxVentaPrint024\vfaview.exe FaxVentaPrint024"C:\Windows\System32\schtasks.exeProposed List of China Philippines Maritime Cooperation Projects.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Manages scheduled tasks
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
Total events
9 791
Read events
9 700
Write events
91
Delete events
0

Modification events

(PID) Process:(1536) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1536) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1536) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1536) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(1536) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(1536) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(1536) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\3f5b0b46c66b5b9ca002e9c0da75375c31f7deab8e143e6311f36fc292d51391.zip
(PID) Process:(1536) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1536) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1536) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
8
Suspicious files
2
Text files
1
Unknown types
2

Dropped files

PID
Process
Filename
Type
884pwsh.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_vfy5hcmk.qwn.psm1
MD5:
SHA256:
884pwsh.exeC:\Users\admin\AppData\Local\Microsoft\PowerShell\7.2.11\update1_v7.4.2_2024-04-12
MD5:
SHA256:
1536WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1536.31243\Proposed List of China Philippines Maritime Cooperation Projects\vntfxf32.dllexecutable
MD5:443411004E8C439C24A66DC3DEFA40DF
SHA256:3AA933ED37229A77AC190D853656BAC9065B770A9C38750AE3361BA371E28CED
1536WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1536.31243\Proposed List of China Philippines Maritime Cooperation Projects\Proposed List of China Philippines Maritime Cooperation Projects.exeexecutable
MD5:AF3DC30851F4294697D01C8852529A58
SHA256:B1AFF58645CD3D91D1EDF8D70F5D4645E3EF79B95DA130E2266C12FCFD13FA29
884pwsh.exeC:\Users\admin\AppData\Local\Microsoft\PowerShell\StartupProfileData-Interactivebinary
MD5:7D4DA99967DE374A46EA96A915296434
SHA256:60CBF785A84172E11D6FD5C6615FDABF1CB103AF41B17F70376A7F90F78265CA
1316Proposed List of China Philippines Maritime Cooperation Projects.exeC:\ProgramData\FaxVentaPrint024\vntfxf32.dllexecutable
MD5:443411004E8C439C24A66DC3DEFA40DF
SHA256:3AA933ED37229A77AC190D853656BAC9065B770A9C38750AE3361BA371E28CED
884pwsh.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_hveztm4h.bvh.ps1text
MD5:07933EB007C7F0B505BA84B8C248227E
SHA256:C6035476F29AA7F93B19DDF7522906BC039EDFC6F6602D872E2EEAEC9D11FF3F
1536WinRAR.exeC:\Users\admin\Documents\Proposed List of China Philippines Maritime Cooperation Projects.exeexecutable
MD5:AF3DC30851F4294697D01C8852529A58
SHA256:B1AFF58645CD3D91D1EDF8D70F5D4645E3EF79B95DA130E2266C12FCFD13FA29
1316Proposed List of China Philippines Maritime Cooperation Projects.exeC:\ProgramData\FaxVentaPrint024\vfaview.exeexecutable
MD5:AF3DC30851F4294697D01C8852529A58
SHA256:B1AFF58645CD3D91D1EDF8D70F5D4645E3EF79B95DA130E2266C12FCFD13FA29
884pwsh.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\e1a648060a327b80.customDestinations-msbinary
MD5:A20A86C096ADCB3F2B94729E95AC8359
SHA256:9B6C50119EFA806C4BD1CD2C2B0A8524F261AA19EC2B882AD52677A2A0ADC273
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
7
DNS requests
3
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
884
pwsh.exe
104.119.110.121:443
aka.ms
AKAMAI-AS
DE
unknown
884
pwsh.exe
52.239.160.36:443
pscoretestdata.blob.core.windows.net
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
884
pwsh.exe
20.50.88.245:443
dc.services.visualstudio.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
unknown

DNS requests

Domain
IP
Reputation
aka.ms
  • 104.119.110.121
whitelisted
pscoretestdata.blob.core.windows.net
  • 52.239.160.36
unknown
dc.services.visualstudio.com
  • 20.50.88.245
whitelisted

Threats

No threats detected
Process
Message
pwsh.exe
Profiler was prevented from loading notification profiler due to app settings. Process ID (decimal): 884. Message ID: [0x2509].