| File name: | Win32.BigBang.zip |
| Full analysis: | https://app.any.run/tasks/6e15cb4b-7e0a-4e15-b857-d7e0ac60a1bf |
| Verdict: | Malicious activity |
| Analysis date: | February 26, 2020, 21:06:25 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | 574A0E7644AB1F6C16B98F56D34C09F9 |
| SHA1: | 2F0F5B72F3FA73DC94B93288BC6CBA338A1F8D30 |
| SHA256: | 40ECBA8DAE1929EA463CB366365690BDCEB6732ED173BC60E2EC2FF471B68A11 |
| SSDEEP: | 49152:hhKkl8U1GLyemlgdDHpKgyWf/S5llEbKVUVlz4/:h7DzXgeaf/S5XGFVlz4/ |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 788 |
|---|---|
| ZipBitFlag: | 0x0001 |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2019:07:19 22:14:08 |
| ZipCRC: | 0x072b2e73 |
| ZipCompressedSize: | 454564 |
| ZipUncompressedSize: | 1004544 |
| ZipFileName: | ImplantBigBang.bin |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1196 | "C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\Desktop\Win32.BigBang\TheBigBangImplant.bin | C:\Windows\system32\rundll32.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1712 | "C:\Users\admin\Desktop\Win32.BigBang\TheBigBangImplant.exe" | C:\Users\admin\Desktop\Win32.BigBang\TheBigBangImplant.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: Interenet Assistant Exit code: 4294967295 Version: 1.0.0.2 Modules
| |||||||||||||||
| 2804 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\Win32.BigBang.zip" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 3252 | "C:\Users\admin\Desktop\Win32.BigBang\TheBigBang.exe" | C:\Users\admin\Desktop\Win32.BigBang\TheBigBang.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 3868 | C:\Windows\system32\DllHost.exe /Processid:{76D0CB12-7604-4048-B83C-1005C7DDC503} | C:\Windows\system32\DllHost.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: COM Surrogate Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (2804) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (2804) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (2804) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2804) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\Win32.BigBang.zip | |||
| (PID) Process: | (2804) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2804) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2804) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2804) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (2804) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\Win32.BigBang | |||
| (PID) Process: | (2804) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface |
| Operation: | write | Name: | ShowPassword |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2804 | WinRAR.exe | C:\Users\admin\Desktop\Win32.BigBang\TheBigBangImplant.bin | executable | |
MD5:87D7D314F86F61A9099A51C269B4EC78 | SHA256:8EF13CCF86C1AC1C2FEF370A85B7C576AFEC11CF056C7D4EC288C126368F115C | |||
| 2804 | WinRAR.exe | C:\Users\admin\Desktop\Win32.BigBang\TheBigBang.bin | executable | |
MD5:A233D90B8E5C19C4B3373BB76EB11428 | SHA256:027B1042621F86394FD7DA27C5310E4906F41B96F6E5474875E63D39B32A9C11 | |||
| 2804 | WinRAR.exe | C:\Users\admin\Desktop\Win32.BigBang\ImplantBigBang.bin | executable | |
MD5:18864D22331FC6503641F128226AAEA8 | SHA256:E1F52EA30D25289F7A4A5C9D15BE97C8A4DFE10EB68AC9D031EDCC7275C23DBC | |||
| 2804 | WinRAR.exe | C:\Users\admin\Desktop\Win32.BigBang\TheBigBangAPT.doc | document | |
MD5:A3DC31C456508DF7DFAC8349EB0D2B65 | SHA256:63A73CF005EB328F3C7E99F0D28DA65980D9620B66D8C41939F6DB023418C864 | |||
| 1712 | TheBigBangImplant.exe | C:\ProgramData\Interenet Assistant\Interenet Assistant.exe | executable | |
MD5:87D7D314F86F61A9099A51C269B4EC78 | SHA256:8EF13CCF86C1AC1C2FEF370A85B7C576AFEC11CF056C7D4EC288C126368F115C | |||
| 3252 | TheBigBang.exe | C:\Users\admin\AppData\Local\Temp\SANA.jpg | image | |
MD5:C184533B999B4685AC08938C07280703 | SHA256:894C6563632250B7721CEE9788B5FEE5F212F4B6F31CB2A485BD68621512B796 | |||