File name:

christmastrees.zip

Full analysis: https://app.any.run/tasks/cc18f613-52e9-48b6-a309-ce360f23d601
Verdict: Malicious activity
Analysis date: October 05, 2023, 19:37:06
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract
MD5:

B75954D7A996A6D77DCC83EBDB3E96B9

SHA1:

AC05AAAB0D038E18E7FAE4068718006272CED5B7

SHA256:

401E212B56277C109FD04360B028270D46420FEAF476E66CC9543F7279990D36

SSDEEP:

98304:9PR631zulbcraRcc4ApXpYkVcKQI1x4HDz9hSnZ75DCWPgMQI2dqw99Mr2grBpXi:HOnmnJuJ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • HappyChristmas.exe (PID: 1120)
      • Christmas3.exe (PID: 3160)
      • LittleTree.exe (PID: 2588)
      • Christmas2.exe (PID: 3184)
      • LiveChristmasTree.exe (PID: 1892)
      • PlasticineTree.exe (PID: 2040)
      • LiveXmasTree.exe (PID: 1080)
      • PlasticineTree.exe (PID: 2948)
      • RedChristmasTree.exe (PID: 2668)
      • WinChristmasTree.exe (PID: 2420)
      • Xmas.exe (PID: 2464)
      • Xmas2.exe (PID: 2364)
      • XmasSpirit.exe (PID: 3364)
      • Tannenbaum.exe (PID: 592)
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Checks supported languages

      • Christmas3.exe (PID: 3160)
      • HappyChristmas.exe (PID: 1120)
      • Christmas2.exe (PID: 3184)
      • LiveChristmasTree.exe (PID: 1892)
      • LittleTree.exe (PID: 2588)
      • PlasticineTree.exe (PID: 2040)
      • LiveXmasTree.exe (PID: 1080)
      • PlasticineTree.exe (PID: 2948)
      • RedChristmasTree.exe (PID: 2668)
      • Tannenbaum.exe (PID: 592)
      • Xmas.exe (PID: 2464)
      • WinChristmasTree.exe (PID: 2420)
      • Xmas2.exe (PID: 2364)
      • XmasSpirit.exe (PID: 3364)
    • Create files in a temporary directory

      • LittleTree.exe (PID: 2588)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 3832)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2010:12:03 01:25:20
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: christmastrees/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
48
Monitored processes
15
Malicious processes
1
Suspicious processes
13

Behavior graph

Click at the process to see the details
drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start start winrar.exe no specs christmas3.exe no specs christmas2.exe no specs happychristmas.exe no specs littletree.exe no specs livechristmastree.exe no specs plasticinetree.exe no specs livexmastree.exe no specs plasticinetree.exe no specs redchristmastree.exe no specs tannenbaum.exe no specs winchristmastree.exe no specs xmas.exe no specs xmas2.exe no specs xmasspirit.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
592"C:\Users\admin\AppData\Local\Temp\Rar$EXa3832.17914\christmastrees\Tannenbaum.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3832.17914\christmastrees\Tannenbaum.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3832.17914\christmastrees\tannenbaum.exe
c:\windows\system32\kernelbase.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
1080"C:\Users\admin\AppData\Local\Temp\Rar$EXa3832.17155\christmastrees\LiveXmasTree.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3832.17155\christmastrees\LiveXmasTree.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3832.17155\christmastrees\livexmastree.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1120"C:\Users\admin\AppData\Local\Temp\Rar$EXa3832.15486\christmastrees\HappyChristmas.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3832.15486\christmastrees\HappyChristmas.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3832.15486\christmastrees\happychristmas.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1892"C:\Users\admin\AppData\Local\Temp\Rar$EXa3832.16789\christmastrees\LiveChristmasTree.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3832.16789\christmastrees\LiveChristmasTree.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3832.16789\christmastrees\livechristmastree.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
2040"C:\Users\admin\AppData\Local\Temp\Rar$EXa3832.17022\christmastrees\PlasticineTree.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3832.17022\christmastrees\PlasticineTree.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3832.17022\christmastrees\plasticinetree.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\lpk.dll
c:\windows\system32\advapi32.dll
2364"C:\Users\admin\AppData\Local\Temp\Rar$EXa3832.18464\christmastrees\Xmas2.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3832.18464\christmastrees\Xmas2.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3832.18464\christmastrees\xmas2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
2420"C:\Users\admin\AppData\Local\Temp\Rar$EXa3832.18073\christmastrees\WinChristmasTree.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3832.18073\christmastrees\WinChristmasTree.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3832.18073\christmastrees\winchristmastree.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2464"C:\Users\admin\AppData\Local\Temp\Rar$EXa3832.18212\christmastrees\Xmas.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3832.18212\christmastrees\Xmas.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3832.18212\christmastrees\xmas.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2588"C:\Users\admin\AppData\Local\Temp\Rar$EXa3832.16108\christmastrees\LittleTree.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3832.16108\christmastrees\LittleTree.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3832.16108\christmastrees\littletree.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
2668"C:\Users\admin\AppData\Local\Temp\Rar$EXa3832.17734\christmastrees\RedChristmasTree.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3832.17734\christmastrees\RedChristmasTree.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3832.17734\christmastrees\redchristmastree.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
Total events
1 354
Read events
1 338
Write events
16
Delete events
0

Modification events

(PID) Process:(3832) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3832) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(3832) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3832) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3832) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3832) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3832) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3832) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3832) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3832) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
Executable files
196
Suspicious files
0
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
3832WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3832.14831\christmastrees\LittleTree.exeexecutable
MD5:4CA0822A9A9A9EB0AA9DD6810F86D9A9
SHA256:FB585F758E24C7BAE12F685CD55E0006AB9E24EFC75A0D7D1284D724364AE330
3832WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3832.14291\christmastrees\XmasSpirit.exeexecutable
MD5:D788705B98E4DEDBE2710A39BE1CAA2E
SHA256:D6FCE72AB4703B403C1ECD66A775954EA666DA2B79DFB6264AAEF6B88C53D591
3832WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3832.14831\christmastrees\LiveXmasTree.exeexecutable
MD5:488CDC49C218ECF5F403733EDCAA1FE7
SHA256:D7299CFD51EE7284F87E41A1303740EF4D71B58A9FBDBF4B272248209ED3F023
3832WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3832.14291\christmastrees\Xmas.exeexecutable
MD5:D37D6A591B5DE19F1193D9DB241B8C31
SHA256:96C28CC748EFE33BCCF4D5A6593605634B2E055981F1587C5E7EFAB5020CCEBB
3832WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3832.14291\christmastrees\WinChristmasTree.exeexecutable
MD5:74E584D91DA72F3307D5F0E9267347F1
SHA256:D4EC25B5F3BD5A8183B2D15F7D5FA9ED5EEB132193F8A9BB24EE79DE14EFBA55
3832WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3832.14291\christmastrees\LiveXmasTree.exeexecutable
MD5:488CDC49C218ECF5F403733EDCAA1FE7
SHA256:D7299CFD51EE7284F87E41A1303740EF4D71B58A9FBDBF4B272248209ED3F023
3832WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3832.14831\christmastrees\Christmas3.exeexecutable
MD5:DA3494560E63EE111F64524819B4D6C6
SHA256:D72FFA0780739CCF5D08954DC549568A618A36A58D626DBDED3EC80C42C4B64D
3832WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3832.14831\christmastrees\Tannenbaum.exeexecutable
MD5:67D6B920B8A5D9257AF6E61EE588B51D
SHA256:86079A7C085CE8139364B12B69E48EB7E3141B2D2903DE3CC95E05BB8D661015
3832WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3832.14291\christmastrees\Christmas2.exeexecutable
MD5:FCF6D9715EE06D1E9BECFD64F889F275
SHA256:B7E3F5E7E4B0EB34BE428E84A4E86BC13969278A426F503ACAA12CB880BB2E3F
3832WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3832.14831\christmastrees\RainbowTree.exeexecutable
MD5:AABAF31660FF58C2E9896F48EE80CAC1
SHA256:2A764C988813656D8910B2D80923C75C7455861398198FBA8C675C9C8EC8B35D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
3
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2656
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted

DNS requests

No data

Threats

No threats detected
No debug info