File name:

Ausgleich nicht gedeckten Buchung Ihrer Bestellung Directpay AG vom 05.01.2015.zip

Full analysis: https://app.any.run/tasks/487859f5-0e72-48c2-9417-1c32f3bd2fe2
Verdict: Malicious activity
Analysis date: April 11, 2024, 10:56:49
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

0A46C38D8F3D3737B7B98AE3CB51865F

SHA1:

7A5ACE5D82D3AC9D8DB3B0899A3D8EE56F376349

SHA256:

3FE02DB61CC96D96CDAE2A2DFB1BF292C0462E0C33EA9E724EC29D7CBD4D916B

SSDEEP:

3072:EEIuLco7L/7Hh/nnrJ2F6losNneTTQUSfZrtZihR6ca:Eycs9PrO6hNnrU2diO

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 1836)
      • Rechnung 05.01.2015 - Inkasso Directpay AG.com (PID: 2292)
      • Rechnung 05.01.2015 - Inkasso Directpay AG.com (PID: 2672)
    • Changes the autorun value in the registry

      • dpnsvr.exe (PID: 1348)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 1836)
      • dpnsvr.exe (PID: 1348)
    • Starts a Microsoft application from unusual location

      • Rechnung 05.01.2015 - Inkasso Directpay AG.com (PID: 2292)
      • Rechnung 05.01.2015 - Inkasso Directpay AG.com (PID: 2908)
      • Rechnung 05.01.2015 - Inkasso Directpay AG.com (PID: 3164)
      • Rechnung 05.01.2015 - Inkasso Directpay AG.com (PID: 2672)
    • Executable content was dropped or overwritten

      • Rechnung 05.01.2015 - Inkasso Directpay AG.com (PID: 2292)
      • Rechnung 05.01.2015 - Inkasso Directpay AG.com (PID: 2672)
      • dpnsvr.exe (PID: 1348)
    • Application launched itself

      • Rechnung 05.01.2015 - Inkasso Directpay AG.com (PID: 2292)
      • Rechnung 05.01.2015 - Inkasso Directpay AG.com (PID: 2672)
      • Rechnung 05.01.2015 - Inkasso Directpay AG.com (PID: 2908)
    • Starts application with an unusual extension

      • Rechnung 05.01.2015 - Inkasso Directpay AG.com (PID: 2292)
      • Rechnung 05.01.2015 - Inkasso Directpay AG.com (PID: 2672)
      • Rechnung 05.01.2015 - Inkasso Directpay AG.com (PID: 2908)
    • Reads the Internet Settings

      • dpnsvr.exe (PID: 1348)
    • Executing commands from a ".bat" file

      • Rechnung 05.01.2015 - Inkasso Directpay AG.com (PID: 3164)
    • Starts CMD.EXE for commands execution

      • Rechnung 05.01.2015 - Inkasso Directpay AG.com (PID: 3164)
    • Uses ATTRIB.EXE to modify file attributes

      • cmd.exe (PID: 1928)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1836)
    • Create files in a temporary directory

      • Rechnung 05.01.2015 - Inkasso Directpay AG.com (PID: 2292)
      • Rechnung 05.01.2015 - Inkasso Directpay AG.com (PID: 3164)
      • Rechnung 05.01.2015 - Inkasso Directpay AG.com (PID: 2672)
      • dpnsvr.exe (PID: 1348)
    • Checks supported languages

      • Rechnung 05.01.2015 - Inkasso Directpay AG.com (PID: 2292)
      • Rechnung 05.01.2015 - Inkasso Directpay AG.com (PID: 2908)
      • Rechnung 05.01.2015 - Inkasso Directpay AG.com (PID: 2672)
      • Rechnung 05.01.2015 - Inkasso Directpay AG.com (PID: 3164)
    • Creates files or folders in the user directory

      • Rechnung 05.01.2015 - Inkasso Directpay AG.com (PID: 2292)
    • Manual execution by a user

      • Rechnung 05.01.2015 - Inkasso Directpay AG.com (PID: 2292)
    • Reads the computer name

      • Rechnung 05.01.2015 - Inkasso Directpay AG.com (PID: 2292)
      • Rechnung 05.01.2015 - Inkasso Directpay AG.com (PID: 2672)
    • Reads the machine GUID from the registry

      • Rechnung 05.01.2015 - Inkasso Directpay AG.com (PID: 3164)
      • Rechnung 05.01.2015 - Inkasso Directpay AG.com (PID: 2908)
    • Drops the executable file immediately after the start

      • dpnsvr.exe (PID: 1348)
    • Checks proxy server information

      • dpnsvr.exe (PID: 1348)
    • Reads security settings of Internet Explorer

      • dpnsvr.exe (PID: 1348)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2015:01:05 03:56:44
ZipCRC: 0xa5526971
ZipCompressedSize: 72683
ZipUncompressedSize: 90740
ZipFileName: Rechnung 05.01.2015 - Inkasso Directpay AG.com
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
49
Monitored processes
10
Malicious processes
4
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe rechnung 05.01.2015 - inkasso directpay ag.com rechnung 05.01.2015 - inkasso directpay ag.com no specs rechnung 05.01.2015 - inkasso directpay ag.com dpnsvr.exe rechnung 05.01.2015 - inkasso directpay ag.com no specs cmd.exe no specs attrib.exe no specs PhotoViewer.dll no specs PhotoViewer.dll no specs

Process information

PID
CMD
Path
Indicators
Parent process
1112C:\Windows\system32\DllHost.exe /Processid:{76D0CB12-7604-4048-B83C-1005C7DDC503}C:\Windows\System32\dllhost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
COM Surrogate
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\dllhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1348dpnsvr.exeC:\Windows\System32\dpnsvr.exe
Rechnung 05.01.2015 - Inkasso Directpay AG.com
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft DirectPlay8 Server
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\dpnsvr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1740attrib -r -s -h "C:\Users\admin\Desktop\Rechnung 05.01.2015 - Inkasso Directpay AG.com"C:\Windows\System32\attrib.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Attribute Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\attrib.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ulib.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1836"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\Ausgleich nicht gedeckten Buchung Ihrer Bestellung Directpay AG vom 05.01.2015.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
1928C:\Windows\system32\cmd.exe /c C:\Users\admin\AppData\Local\Temp\696582F3.bat "C:\Users\admin\Desktop\Rechnung 05.01.2015 - Inkasso Directpay AG.com"C:\Windows\System32\cmd.exeRechnung 05.01.2015 - Inkasso Directpay AG.com
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2292"C:\Users\admin\Desktop\Rechnung 05.01.2015 - Inkasso Directpay AG.com" C:\Users\admin\Desktop\Rechnung 05.01.2015 - Inkasso Directpay AG.com
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft® Help Workshop
Exit code:
0
Version:
4.03.0002.9
Modules
Images
c:\users\admin\desktop\rechnung 05.01.2015 - inkasso directpay ag.com
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
2672"C:\Users\admin\Desktop\Rechnung 05.01.2015 - Inkasso Directpay AG.com"C:\Users\admin\Desktop\Rechnung 05.01.2015 - Inkasso Directpay AG.com
Rechnung 05.01.2015 - Inkasso Directpay AG.com
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft® Help Workshop
Exit code:
0
Version:
4.03.0002.9
Modules
Images
c:\users\admin\desktop\rechnung 05.01.2015 - inkasso directpay ag.com
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
2908"C:\Users\admin\Desktop\Rechnung 05.01.2015 - Inkasso Directpay AG.com"C:\Users\admin\Desktop\Rechnung 05.01.2015 - Inkasso Directpay AG.comRechnung 05.01.2015 - Inkasso Directpay AG.com
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft® Help Workshop
Exit code:
0
Version:
4.03.0002.9
Modules
Images
c:\users\admin\desktop\rechnung 05.01.2015 - inkasso directpay ag.com
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imm32.dll
2968C:\Windows\system32\DllHost.exe /Processid:{76D0CB12-7604-4048-B83C-1005C7DDC503}C:\Windows\System32\dllhost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
COM Surrogate
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\dllhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3164"C:\Users\admin\Desktop\Rechnung 05.01.2015 - Inkasso Directpay AG.com"C:\Users\admin\Desktop\Rechnung 05.01.2015 - Inkasso Directpay AG.comRechnung 05.01.2015 - Inkasso Directpay AG.com
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft® Help Workshop
Exit code:
0
Version:
4.03.0002.9
Modules
Images
c:\users\admin\desktop\rechnung 05.01.2015 - inkasso directpay ag.com
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imm32.dll
Total events
8 401
Read events
8 358
Write events
37
Delete events
6

Modification events

(PID) Process:(1836) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1836) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1836) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1836) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(1836) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(1836) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(1836) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\Ausgleich nicht gedeckten Buchung Ihrer Bestellung Directpay AG vom 05.01.2015.zip
(PID) Process:(1836) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1836) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1836) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
5
Suspicious files
1
Text files
1
Unknown types
1

Dropped files

PID
Process
Filename
Type
1836WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1836.332\Rechnung 05.01.2015 - Inkasso Directpay AG.comexecutable
MD5:
SHA256:
2292Rechnung 05.01.2015 - Inkasso Directpay AG.comC:\Users\admin\AppData\Roaming\farmstead.cbinary
MD5:
SHA256:
2292Rechnung 05.01.2015 - Inkasso Directpay AG.comC:\Users\admin\AppData\Local\Temp\nsn39F8.tmp\farmstead.dllexecutable
MD5:
SHA256:
2672Rechnung 05.01.2015 - Inkasso Directpay AG.comC:\Users\admin\AppData\Local\Temp\nsw43DB.tmp\farmstead.dllexecutable
MD5:
SHA256:
3164Rechnung 05.01.2015 - Inkasso Directpay AG.comC:\Users\admin\AppData\Local\Temp\696582F3.battext
MD5:
SHA256:
1348dpnsvr.exeC:\Users\admin\AppData\Local\Temp\Definitionpiece\definition-increase.exeexecutable
MD5:
SHA256:
1348dpnsvr.exeC:\Users\admin\AppData\Local\Temp\~3cce221d.tmpbinary
MD5:
SHA256:
1836WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1836.3935\Rechnung 05.01.2015 - Inkasso Directpay AG.comexecutable
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
5
DNS requests
1
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1348
dpnsvr.exe
POST
216.218.185.162:80
http://clockpunchposition.com/guestbook.php?pd=HxchalUJSQCT&tw=0
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
1348
dpnsvr.exe
216.218.185.162:80
clockpunchposition.com
HURRICANE
US
unknown

DNS requests

Domain
IP
Reputation
clockpunchposition.com
  • 216.218.185.162
unknown

Threats

PID
Process
Class
Message
Potential Corporate Privacy Violation
ET POLICY Unsupported/Fake Windows NT Version 5.0
No debug info