File name:

Win32.BigBang.zip

Full analysis: https://app.any.run/tasks/6e15cb4b-7e0a-4e15-b857-d7e0ac60a1bf
Verdict: Malicious activity
Analysis date: February 26, 2020, 21:06:25
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

574A0E7644AB1F6C16B98F56D34C09F9

SHA1:

2F0F5B72F3FA73DC94B93288BC6CBA338A1F8D30

SHA256:

40ECBA8DAE1929EA463CB366365690BDCEB6732ED173BC60E2EC2FF471B68A11

SSDEEP:

49152:hhKkl8U1GLyemlgdDHpKgyWf/S5llEbKVUVlz4/:h7DzXgeaf/S5XGFVlz4/

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • TheBigBangImplant.exe (PID: 1712)
      • TheBigBang.exe (PID: 3252)
    • Loads the Task Scheduler COM API

      • TheBigBangImplant.exe (PID: 1712)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2804)
      • TheBigBangImplant.exe (PID: 1712)
    • Creates files in the program directory

      • TheBigBangImplant.exe (PID: 1712)
    • Executed via COM

      • DllHost.exe (PID: 3868)
  • INFO

    • Manual execution by user

      • rundll32.exe (PID: 1196)
      • TheBigBang.exe (PID: 3252)
      • TheBigBangImplant.exe (PID: 1712)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 788
ZipBitFlag: 0x0001
ZipCompression: Deflated
ZipModifyDate: 2019:07:19 22:14:08
ZipCRC: 0x072b2e73
ZipCompressedSize: 454564
ZipUncompressedSize: 1004544
ZipFileName: ImplantBigBang.bin
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
44
Monitored processes
5
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe rundll32.exe no specs thebigbangimplant.exe thebigbang.exe no specs PhotoViewer.dll no specs

Process information

PID
CMD
Path
Indicators
Parent process
1196"C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\Desktop\Win32.BigBang\TheBigBangImplant.binC:\Windows\system32\rundll32.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
1712"C:\Users\admin\Desktop\Win32.BigBang\TheBigBangImplant.exe" C:\Users\admin\Desktop\Win32.BigBang\TheBigBangImplant.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Interenet Assistant
Exit code:
4294967295
Version:
1.0.0.2
Modules
Images
c:\users\admin\desktop\win32.bigbang\thebigbangimplant.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2804"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\Win32.BigBang.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3252"C:\Users\admin\Desktop\Win32.BigBang\TheBigBang.exe" C:\Users\admin\Desktop\Win32.BigBang\TheBigBang.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\win32.bigbang\thebigbang.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3868C:\Windows\system32\DllHost.exe /Processid:{76D0CB12-7604-4048-B83C-1005C7DDC503}C:\Windows\system32\DllHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
COM Surrogate
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\dllhost.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
Total events
760
Read events
734
Write events
26
Delete events
0

Modification events

(PID) Process:(2804) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2804) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2804) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2804) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\Win32.BigBang.zip
(PID) Process:(2804) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2804) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2804) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2804) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2804) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath
Operation:writeName:0
Value:
C:\Users\admin\Desktop\Win32.BigBang
(PID) Process:(2804) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
Executable files
4
Suspicious files
1
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
2804WinRAR.exeC:\Users\admin\Desktop\Win32.BigBang\TheBigBangImplant.binexecutable
MD5:87D7D314F86F61A9099A51C269B4EC78
SHA256:8EF13CCF86C1AC1C2FEF370A85B7C576AFEC11CF056C7D4EC288C126368F115C
2804WinRAR.exeC:\Users\admin\Desktop\Win32.BigBang\TheBigBang.binexecutable
MD5:A233D90B8E5C19C4B3373BB76EB11428
SHA256:027B1042621F86394FD7DA27C5310E4906F41B96F6E5474875E63D39B32A9C11
2804WinRAR.exeC:\Users\admin\Desktop\Win32.BigBang\ImplantBigBang.binexecutable
MD5:18864D22331FC6503641F128226AAEA8
SHA256:E1F52EA30D25289F7A4A5C9D15BE97C8A4DFE10EB68AC9D031EDCC7275C23DBC
2804WinRAR.exeC:\Users\admin\Desktop\Win32.BigBang\TheBigBangAPT.docdocument
MD5:A3DC31C456508DF7DFAC8349EB0D2B65
SHA256:63A73CF005EB328F3C7E99F0D28DA65980D9620B66D8C41939F6DB023418C864
1712TheBigBangImplant.exeC:\ProgramData\Interenet Assistant\Interenet Assistant.exeexecutable
MD5:87D7D314F86F61A9099A51C269B4EC78
SHA256:8EF13CCF86C1AC1C2FEF370A85B7C576AFEC11CF056C7D4EC288C126368F115C
3252TheBigBang.exeC:\Users\admin\AppData\Local\Temp\SANA.jpgimage
MD5:C184533B999B4685AC08938C07280703
SHA256:894C6563632250B7721CEE9788B5FEE5F212F4B6F31CB2A485BD68621512B796
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info