File name:

ebirforms_package-v7.9.4.2.zip

Full analysis: https://app.any.run/tasks/a675894a-17bf-4520-bf46-1ab0c7b221a2
Verdict: Malicious activity
Analysis date: January 29, 2024, 00:31:35
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

C91958806AEEDFDBCF37ED672EC76323

SHA1:

B4EEF52AE1F4BDC1CEBDC93F8772101D06E76EC4

SHA256:

42C4CB50CECF35BE19882AD7D71F7DD5B3ACFC2F1AEEEA8053A5F34D98249293

SSDEEP:

98304:DYtuzVTYpt6fg/asYIqsrWMyfDWFXFjjI1Zxzl9NtzzJgzjpNIDI0GBl1CIH19Av:HolbvhZSmY+sp0KzenvD+gO

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 2628)
      • Offline eBIRForms Package v7.9.4.2 setup.exe (PID: 2712)
      • Offline eBIRForms Package v7.9.4.2 setup.tmp (PID: 1824)
      • Offline eBIRForms Package v7.9.4.2 setup.exe (PID: 2244)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Offline eBIRForms Package v7.9.4.2 setup.exe (PID: 2244)
      • Offline eBIRForms Package v7.9.4.2 setup.exe (PID: 2712)
      • Offline eBIRForms Package v7.9.4.2 setup.tmp (PID: 1824)
    • Reads the Windows owner or organization settings

      • Offline eBIRForms Package v7.9.4.2 setup.tmp (PID: 1824)
    • Reads the Internet Settings

      • BIRForms.exe (PID: 1808)
      • mshta.exe (PID: 2900)
      • BIRForms.exe (PID: 452)
      • mshta.exe (PID: 2780)
    • Creates FileSystem object to access computer's file system (SCRIPT)

      • mshta.exe (PID: 2900)
    • Runs shell command (SCRIPT)

      • mshta.exe (PID: 2900)
  • INFO

    • Create files in a temporary directory

      • Offline eBIRForms Package v7.9.4.2 setup.exe (PID: 2712)
      • Offline eBIRForms Package v7.9.4.2 setup.exe (PID: 2244)
      • BIRForms.exe (PID: 1808)
    • Manual execution by a user

      • Offline eBIRForms Package v7.9.4.2 setup.exe (PID: 2712)
      • BIRForms.exe (PID: 1808)
      • explorer.exe (PID: 2528)
      • explorer.exe (PID: 3852)
      • BIRForms.exe (PID: 452)
    • Checks supported languages

      • Offline eBIRForms Package v7.9.4.2 setup.exe (PID: 2712)
      • Offline eBIRForms Package v7.9.4.2 setup.tmp (PID: 1824)
      • Offline eBIRForms Package v7.9.4.2 setup.tmp (PID: 876)
      • Offline eBIRForms Package v7.9.4.2 setup.exe (PID: 2244)
      • BIRForms.exe (PID: 452)
      • chkt.exe (PID: 3016)
      • chkt.exe (PID: 2836)
      • BIRForms.exe (PID: 1808)
    • Reads the computer name

      • Offline eBIRForms Package v7.9.4.2 setup.tmp (PID: 876)
      • Offline eBIRForms Package v7.9.4.2 setup.tmp (PID: 1824)
      • BIRForms.exe (PID: 1808)
      • BIRForms.exe (PID: 452)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2628)
    • Creates files in the program directory

      • Offline eBIRForms Package v7.9.4.2 setup.tmp (PID: 1824)
    • Checks proxy server information

      • mshta.exe (PID: 2900)
    • Reads Internet Explorer settings

      • mshta.exe (PID: 2900)
      • mshta.exe (PID: 2780)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2024:01:09 15:56:32
ZipCRC: 0x6a317002
ZipCompressedSize: 12003652
ZipUncompressedSize: 12026221
ZipFileName: Offline eBIRForms Package v7.9.4.2 setup.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
61
Monitored processes
13
Malicious processes
3
Suspicious processes
3

Behavior graph

Click at the process to see the details
start winrar.exe offline ebirforms package v7.9.4.2 setup.exe offline ebirforms package v7.9.4.2 setup.tmp no specs offline ebirforms package v7.9.4.2 setup.exe offline ebirforms package v7.9.4.2 setup.tmp birforms.exe no specs mshta.exe chkt.exe no specs chkt.exe no specs explorer.exe no specs explorer.exe no specs birforms.exe no specs mshta.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
452"C:\eBIRForms\BIRForms.exe" C:\eBIRForms\BIRForms.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\ebirforms\birforms.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winspool.drv
876"C:\Users\admin\AppData\Local\Temp\is-H7EOV.tmp\Offline eBIRForms Package v7.9.4.2 setup.tmp" /SL5="$F0156,11779280,57856,C:\Users\admin\Desktop\Offline eBIRForms Package v7.9.4.2 setup.exe" C:\Users\admin\AppData\Local\Temp\is-H7EOV.tmp\Offline eBIRForms Package v7.9.4.2 setup.tmpOffline eBIRForms Package v7.9.4.2 setup.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-h7eov.tmp\offline ebirforms package v7.9.4.2 setup.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
1808"C:\eBIRForms\BIRForms.exe" C:\eBIRForms\BIRForms.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\ebirforms\birforms.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winspool.drv
1824"C:\Users\admin\AppData\Local\Temp\is-REVBJ.tmp\Offline eBIRForms Package v7.9.4.2 setup.tmp" /SL5="$A0214,11779280,57856,C:\Users\admin\Desktop\Offline eBIRForms Package v7.9.4.2 setup.exe" /SPAWNWND=$D0180 /NOTIFYWND=$F0156 C:\Users\admin\AppData\Local\Temp\is-REVBJ.tmp\Offline eBIRForms Package v7.9.4.2 setup.tmp
Offline eBIRForms Package v7.9.4.2 setup.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-revbj.tmp\offline ebirforms package v7.9.4.2 setup.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
2244"C:\Users\admin\Desktop\Offline eBIRForms Package v7.9.4.2 setup.exe" /SPAWNWND=$D0180 /NOTIFYWND=$F0156 C:\Users\admin\Desktop\Offline eBIRForms Package v7.9.4.2 setup.exe
Offline eBIRForms Package v7.9.4.2 setup.tmp
User:
admin
Company:
Integrity Level:
HIGH
Description:
eBIRForms Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\desktop\offline ebirforms package v7.9.4.2 setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
2528"C:\Windows\explorer.exe" C:\Windows\explorer.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2628"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\ebirforms_package-v7.9.4.2.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2712"C:\Users\admin\Desktop\Offline eBIRForms Package v7.9.4.2 setup.exe" C:\Users\admin\Desktop\Offline eBIRForms Package v7.9.4.2 setup.exe
explorer.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
eBIRForms Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\desktop\offline ebirforms package v7.9.4.2 setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
2780"C:\Windows\System32\mshta.exe" "C:\Users\admin\AppData\Local\Temp\{3B1D7364-9D06-4894-812C-CEAD409FE3FE}\BIRForms.hta" C:\Windows\System32\mshta.exeBIRForms.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft (R) HTML Application host
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\windows\system32\mshta.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2836"C:\eBIRForms\chkt.exe" "123323343"C:\eBIRForms\chkt.exemshta.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1
Modules
Images
c:\ebirforms\chkt.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
Total events
3 782
Read events
3 598
Write events
178
Delete events
6

Modification events

(PID) Process:(2628) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2628) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(2628) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(2628) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2628) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(2628) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2628) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2628) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2628) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2628) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
Executable files
11
Suspicious files
3
Text files
458
Unknown types
0

Dropped files

PID
Process
Filename
Type
1824Offline eBIRForms Package v7.9.4.2 setup.tmpC:\eBIRForms\is-BF4DJ.tmp
MD5:
SHA256:
1824Offline eBIRForms Package v7.9.4.2 setup.tmpC:\eBIRForms\BIRForms.exe
MD5:
SHA256:
1824Offline eBIRForms Package v7.9.4.2 setup.tmpC:\eBIRForms\is-QOJ4J.tmpexecutable
MD5:00457E27FE7D048E51D9746845AF2E7A
SHA256:429337F44F84B93CD1095DF48C8F3265E5EDE7C646D1B48D9B80F4F92DE74D2C
2712Offline eBIRForms Package v7.9.4.2 setup.exeC:\Users\admin\AppData\Local\Temp\is-H7EOV.tmp\Offline eBIRForms Package v7.9.4.2 setup.tmpexecutable
MD5:832DAB307E54AA08F4B6CDD9B9720361
SHA256:CC783A04CCBCA4EDD06564F8EC88FE5A15F1E3BB26CEC7DE5E090313520D98F3
1824Offline eBIRForms Package v7.9.4.2 setup.tmpC:\eBIRForms\Encrypt.exeexecutable
MD5:00457E27FE7D048E51D9746845AF2E7A
SHA256:429337F44F84B93CD1095DF48C8F3265E5EDE7C646D1B48D9B80F4F92DE74D2C
1824Offline eBIRForms Package v7.9.4.2 setup.tmpC:\eBIRForms\unins000.exeexecutable
MD5:BDB0D33964B81735AA98C860C3F8B666
SHA256:19C46F63075E1D759CF92575EABEE9D40E170098EC9F928FF1E9A3093E620E5A
1824Offline eBIRForms Package v7.9.4.2 setup.tmpC:\eBIRForms\cFTPSend.exeexecutable
MD5:451E0561438B36DEB68D360655808D11
SHA256:5D3DBDA56E3FFFFEFB23F2FD46A5AF0C0DECC389D70921C453C3F813BB806262
1824Offline eBIRForms Package v7.9.4.2 setup.tmpC:\eBIRForms\is-EGQUC.tmpexecutable
MD5:451E0561438B36DEB68D360655808D11
SHA256:5D3DBDA56E3FFFFEFB23F2FD46A5AF0C0DECC389D70921C453C3F813BB806262
1824Offline eBIRForms Package v7.9.4.2 setup.tmpC:\eBIRForms\is-6LPUS.tmpexecutable
MD5:83633F731C54A30F5747F78D3EEEE7A3
SHA256:C00BD4131A725AF53F48C6385D3332C4B789E15441BF52BBAC73117C96C1B0AC
1824Offline eBIRForms Package v7.9.4.2 setup.tmpC:\eBIRForms\is-2BVSS.tmpexecutable
MD5:BDB0D33964B81735AA98C860C3F8B666
SHA256:19C46F63075E1D759CF92575EABEE9D40E170098EC9F928FF1E9A3093E620E5A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
5
DNS requests
1
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2900
mshta.exe
GET
200
162.250.122.202:80
http://birgovph.com/ebirformsVersion.php?data=0.26751060850877445
unknown
text
54 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2900
mshta.exe
162.250.122.202:80
birgovph.com
IS-AS-1
US
unknown

DNS requests

Domain
IP
Reputation
birgovph.com
  • 162.250.122.202
unknown

Threats

No threats detected
No debug info