File name:

S7Z_03.exe

Full analysis: https://app.any.run/tasks/ec007f3c-0f7f-4018-82b5-53cbff754c5b
Verdict: Malicious activity
Analysis date: December 21, 2023, 01:48:43
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

EF76819DC5FA734A1B4C6E49FBC2A237

SHA1:

594F4BEE632CB428F0B499159A80263AEE235CF8

SHA256:

443DE93152B1B51BE5C721861400C157CBCE875AB07FE7D35628F003FF11A3DC

SSDEEP:

98304:2+cD4dn2fnoZOwb7fQSJiozvgS3TKfvSg46/bstvXKSVRXXkbbn7lU//czE1oxXn:47vKML

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • S7Z_03.exe (PID: 2044)
      • S7Z_03.exe (PID: 492)
      • S7Z_03.tmp (PID: 268)
    • Registers / Runs the DLL via REGSVR32.EXE

      • s7z.exe (PID: 696)
  • SUSPICIOUS

    • Reads the Windows owner or organization settings

      • S7Z_03.tmp (PID: 268)
    • Reads settings of System Certificates

      • s7z.exe (PID: 784)
      • s7z.exe (PID: 2128)
      • s7z.exe (PID: 1576)
      • s7z.exe (PID: 2384)
      • s7z.exe (PID: 2192)
    • Drops 7-zip archiver for unpacking

      • S7Z_03.tmp (PID: 268)
    • Reads the Internet Settings

      • s7z.exe (PID: 696)
      • s7z.exe (PID: 2192)
    • Checks Windows Trust Settings

      • s7z.exe (PID: 2192)
    • Reads Internet Explorer settings

      • s7z.exe (PID: 2192)
    • Reads Microsoft Outlook installation path

      • s7z.exe (PID: 2192)
    • Detected use of alternative data streams (AltDS)

      • s7z.exe (PID: 2192)
    • Reads security settings of Internet Explorer

      • s7z.exe (PID: 2192)
  • INFO

    • Checks supported languages

      • S7Z_03.tmp (PID: 2036)
      • S7Z_03.exe (PID: 2044)
      • S7Z_03.exe (PID: 492)
      • S7Z_03.tmp (PID: 268)
      • s7z.exe (PID: 784)
      • s7z.exe (PID: 2128)
      • s7z.exe (PID: 696)
      • s7z.exe (PID: 2192)
      • s7z.exe (PID: 2384)
      • s7z.exe (PID: 1576)
    • Reads the computer name

      • S7Z_03.tmp (PID: 2036)
      • S7Z_03.tmp (PID: 268)
      • s7z.exe (PID: 784)
      • s7z.exe (PID: 1576)
      • s7z.exe (PID: 2128)
      • s7z.exe (PID: 696)
      • s7z.exe (PID: 2384)
      • s7z.exe (PID: 2192)
    • Create files in a temporary directory

      • S7Z_03.exe (PID: 492)
      • S7Z_03.exe (PID: 2044)
      • S7Z_03.tmp (PID: 268)
    • Reads the machine GUID from the registry

      • s7z.exe (PID: 784)
      • s7z.exe (PID: 2128)
      • s7z.exe (PID: 1576)
      • s7z.exe (PID: 2192)
      • s7z.exe (PID: 2384)
    • Creates files or folders in the user directory

      • S7Z_03.tmp (PID: 268)
      • s7z.exe (PID: 696)
      • s7z.exe (PID: 1576)
      • s7z.exe (PID: 2192)
    • Creates files in the program directory

      • S7Z_03.tmp (PID: 268)
      • s7z.exe (PID: 2192)
    • Checks proxy server information

      • s7z.exe (PID: 2192)
    • Reads product name

      • s7z.exe (PID: 2192)
    • Reads Environment values

      • s7z.exe (PID: 2192)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (67.7)
.exe | Win32 EXE PECompact compressed (generic) (25.6)
.exe | Win32 Executable (generic) (2.7)
.exe | Win16/32 Executable Delphi generic (1.2)
.exe | Generic Win/DOS Executable (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:02:15 15:54:16+01:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741888
InitializedDataSize: 171520
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 1.5.0.0
ProductVersionNumber: 1.5.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: 武汉锐森卓鑫网络科技有限公司
FileDescription: 7Z解压缩 Setup
FileVersion: 1.5
LegalCopyright:
OriginalFileName:
ProductName: 7Z解压缩
ProductVersion: 1.5
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
49
Monitored processes
11
Malicious processes
9
Suspicious processes
0

Behavior graph

Click at the process to see the details
start s7z_03.exe no specs s7z_03.tmp no specs s7z_03.exe s7z_03.tmp no specs s7z.exe s7z.exe s7z.exe no specs s7z.exe regsvr32.exe no specs s7z.exe s7z.exe

Process information

PID
CMD
Path
Indicators
Parent process
268"C:\Users\admin\AppData\Local\Temp\is-9DVQF.tmp\S7Z_03.tmp" /SL5="$501AC,4377363,914432,C:\Users\admin\AppData\Local\Temp\S7Z_03.exe" /SPAWNWND=$301B2 /NOTIFYWND=$301AA C:\Users\admin\AppData\Local\Temp\is-9DVQF.tmp\S7Z_03.tmpS7Z_03.exe
User:
admin
Company:
武汉锐森卓鑫网络科技有限公司
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-9dvqf.tmp\s7z_03.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
492"C:\Users\admin\AppData\Local\Temp\S7Z_03.exe" /SPAWNWND=$301B2 /NOTIFYWND=$301AA C:\Users\admin\AppData\Local\Temp\S7Z_03.exe
S7Z_03.tmp
User:
admin
Company:
武汉锐森卓鑫网络科技有限公司
Integrity Level:
HIGH
Description:
7Z解压缩 Setup
Exit code:
0
Version:
1.5
Modules
Images
c:\users\admin\appdata\local\temp\s7z_03.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\comctl32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
696"C:\Users\admin\AppData\Roaming\7z\s7z.exe" -c assocC:\Users\admin\AppData\Roaming\7z\s7z.exeS7Z_03.tmp
User:
admin
Integrity Level:
HIGH
Description:
s7z
Exit code:
0
Version:
1.21.1.202
Modules
Images
c:\users\admin\appdata\roaming\7z\s7z.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
784"C:\Users\admin\AppData\Local\Temp\is-84IG1.tmp\s7z.exe" -c report -s "expose_install_page,expose,user,install_page"C:\Users\admin\AppData\Local\Temp\is-84IG1.tmp\s7z.exe
S7Z_03.tmp
User:
admin
Integrity Level:
HIGH
Description:
s7z
Exit code:
0
Version:
1.21.1.202
Modules
Images
c:\users\admin\appdata\local\temp\is-84ig1.tmp\s7z.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
1540"C:\Windows\System32\regsvr32.exe" /s "C:\Users\admin\AppData\Roaming\7z/ShellExt.dll"C:\Windows\System32\regsvr32.exes7z.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1576"C:\Users\admin\AppData\Local\Temp\is-84IG1.tmp\s7z.exe" -c report -s "set_file_assoc,set,user,install_page"C:\Users\admin\AppData\Local\Temp\is-84IG1.tmp\s7z.exe
S7Z_03.tmp
User:
admin
Integrity Level:
HIGH
Description:
s7z
Exit code:
0
Version:
1.21.1.202
Modules
Images
c:\users\admin\appdata\local\temp\is-84ig1.tmp\s7z.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2036"C:\Users\admin\AppData\Local\Temp\is-N378R.tmp\S7Z_03.tmp" /SL5="$301AA,4377363,914432,C:\Users\admin\AppData\Local\Temp\S7Z_03.exe" C:\Users\admin\AppData\Local\Temp\is-N378R.tmp\S7Z_03.tmpS7Z_03.exe
User:
admin
Company:
武汉锐森卓鑫网络科技有限公司
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-n378r.tmp\s7z_03.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2044"C:\Users\admin\AppData\Local\Temp\S7Z_03.exe" C:\Users\admin\AppData\Local\Temp\S7Z_03.exeexplorer.exe
User:
admin
Company:
武汉锐森卓鑫网络科技有限公司
Integrity Level:
MEDIUM
Description:
7Z解压缩 Setup
Exit code:
0
Version:
1.5
Modules
Images
c:\users\admin\appdata\local\temp\s7z_03.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\comctl32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
2128"C:\Users\admin\AppData\Local\Temp\is-84IG1.tmp\s7z.exe" -c report -s "click_install,click,user,install_page"C:\Users\admin\AppData\Local\Temp\is-84IG1.tmp\s7z.exe
S7Z_03.tmp
User:
admin
Integrity Level:
HIGH
Description:
s7z
Exit code:
0
Version:
1.21.1.202
Modules
Images
c:\users\admin\appdata\local\temp\is-84ig1.tmp\s7z.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2192"C:\Users\admin\AppData\Roaming\7z\s7z.exe"C:\Users\admin\AppData\Roaming\7z\s7z.exe
S7Z_03.tmp
User:
admin
Integrity Level:
MEDIUM
Description:
s7z
Exit code:
0
Version:
1.21.1.202
Modules
Images
c:\users\admin\appdata\roaming\7z\s7z.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
16 874
Read events
16 776
Write events
91
Delete events
7

Modification events

(PID) Process:(784) s7z.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(696) s7z.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.zip\OpenWithList
Operation:delete keyName:(default)
Value:
(PID) Process:(696) s7z.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:GlobalAssocChangedCounter
Value:
115
(PID) Process:(696) s7z.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(696) s7z.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(696) s7z.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(696) s7z.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2128) s7z.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1576) s7z.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(268) S7Z_03.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:RegFilesHash
Value:
2C6610BF9745C3FABB25F9863EAC931B20E7D2A9B75A8E08A2BCE4B8A9994E61
Executable files
15
Suspicious files
9
Text files
72
Unknown types
0

Dropped files

PID
Process
Filename
Type
268S7Z_03.tmpC:\Users\admin\AppData\Local\Temp\is-84IG1.tmp\button_setup_or_next.pngimage
MD5:B830992AD4492109077B45993344F326
SHA256:3948C9F1561B3C60AFFD86BB812F40E435F862E3274B85402F3DE879CBC94492
268S7Z_03.tmpC:\Users\admin\AppData\Local\Temp\is-84IG1.tmp\button_uncustomize_setup.pngimage
MD5:AF7A3A479A421F4BC4310528295A208E
SHA256:89991B86617AB9B27B7589A365494FEC4FC5FD6485A191ACEC1CE71565941C20
268S7Z_03.tmpC:\Users\admin\AppData\Local\Temp\is-84IG1.tmp\button_finish.pngimage
MD5:DEC3351DC30F778CC5C3627119C27F37
SHA256:0D9CFEB25E77BB67CDE01009CBB0DC2F2E1EE22672912754077972CDE0E4F088
492S7Z_03.exeC:\Users\admin\AppData\Local\Temp\is-9DVQF.tmp\S7Z_03.tmpexecutable
MD5:04A19167682EB8D63C1C6487C2F8A4FB
SHA256:A14B3FF641FD5D3DE6DCCFE9D2EEBF961A1E8A9C3E13EA57C22B3D35AC21E734
268S7Z_03.tmpC:\Users\admin\AppData\Local\Temp\is-84IG1.tmp\button_minimize.pngimage
MD5:6005B11B5367048E887D25013CE80D57
SHA256:F096172AAD5F09C7631CB5B7097B590F64EFF3D5B80E78DEDADDC5BCFA0E1268
268S7Z_03.tmpC:\Users\admin\AppData\Local\Temp\is-84IG1.tmp\progressbar_background.pngimage
MD5:038330FCE2530647FE8B4943CBB9EC34
SHA256:67D54AEDFCE969F983EFB1A4E8D615D483FDDCC38CB9B2BDD594D23A420509B4
268S7Z_03.tmpC:\Users\admin\AppData\Local\Temp\is-84IG1.tmp\checkbox_setdefault.pngimage
MD5:52C3C9189F43AE7AF7FCAD4CAF78A762
SHA256:38E6033772767C73F42488464E2660DB03A42034998503DF91C4C9BDB7D75418
268S7Z_03.tmpC:\Users\admin\AppData\Local\Temp\is-84IG1.tmp\checkbox_license.pngimage
MD5:FB0E8D4963B5AE20B4973BA9668C1289
SHA256:B592B6A41E49A01C59A87EC99A26138ECEC3E5F4736714ABE06209A9687CCE91
268S7Z_03.tmpC:\Users\admin\AppData\Local\Temp\is-84IG1.tmp\background_installing.pngimage
MD5:9252234D86E9970CD81F9928EB3E93E9
SHA256:B226D798C7D608BC6908B2E37AE52F3F886409A31083702ABF2163668598738A
268S7Z_03.tmpC:\Users\admin\AppData\Local\Temp\is-84IG1.tmp\background_finish.pngimage
MD5:6761F16A9001115031BFB40B5485285D
SHA256:ABBDD8681DEC6143F45DED81FF3C1BC9AD2F2A61D70BDAF42EAA5C7B67400B8F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
17
DNS requests
4
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2192
s7z.exe
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?75a04d33cfed2632
unknown
compressed
4.66 Kb
unknown
2192
s7z.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ5rEWLwbJFq%2FmAU80sm7E%3D
unknown
binary
471 b
unknown
2192
s7z.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSXi0cW5bD2WLrmnasWibg2OuPDpgQUVXRPsnJP9WC6UNHX5lFcmgGHGtcCEAtw24M536J09gmb3DJjvus%3D
unknown
binary
471 b
unknown
1080
svchost.exe
GET
304
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?eca8823d6d0692d6
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
784
s7z.exe
163.181.92.237:443
dot.coldlake1.com
Zhejiang Taobao Network Co.,Ltd
DE
unknown
1576
s7z.exe
163.181.92.237:443
dot.coldlake1.com
Zhejiang Taobao Network Co.,Ltd
DE
unknown
2128
s7z.exe
163.181.92.237:443
dot.coldlake1.com
Zhejiang Taobao Network Co.,Ltd
DE
unknown
2384
s7z.exe
163.181.92.237:443
dot.coldlake1.com
Zhejiang Taobao Network Co.,Ltd
DE
unknown
2192
s7z.exe
58.218.215.158:443
s7zapp.whrszx.com
Chinanet
CN
unknown
2192
s7z.exe
163.181.92.237:443
dot.coldlake1.com
Zhejiang Taobao Network Co.,Ltd
DE
unknown
2192
s7z.exe
93.184.221.240:80
ctldl.windowsupdate.com
EDGECAST
GB
whitelisted

DNS requests

Domain
IP
Reputation
dot.coldlake1.com
  • 163.181.92.237
  • 163.181.92.234
  • 163.181.92.231
  • 163.181.92.232
  • 163.181.92.236
  • 163.181.92.233
  • 163.181.92.238
  • 163.181.92.235
unknown
s7zapp.whrszx.com
  • 58.218.215.158
unknown
ctldl.windowsupdate.com
  • 93.184.221.240
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted

Threats

No threats detected
No debug info