File name:

SDI_R2201.zip

Full analysis: https://app.any.run/tasks/dfff2499-a39d-4215-80c2-79e4ff06d723
Verdict: Malicious activity
Analysis date: March 06, 2024, 02:02:40
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=store
MD5:

B985095D021BADC0B5D1D0B6CC1C4554

SHA1:

BDA8C7489D394B90395CCA9772A8A0D6A932CB62

SHA256:

44BFE7243DD089F4886545E05EBE7AEBC9ED2BA492E648FD73C53945B0703FCA

SSDEEP:

98304:aC2V3oiOYQlieLMV/WaAKpMgTRenDm2qDyc2nPNXosnWp+aaIBYfJKnhJmU9DEjU:hs1nE4UiGgAJE6k

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads the Internet Settings

      • SDI_R2201.exe (PID: 2636)
    • Reads security settings of Internet Explorer

      • SDI_R2201.exe (PID: 2636)
    • Starts CMD.EXE for commands execution

      • SDI_R2201.exe (PID: 2636)
    • Executes as Windows Service

      • VSSVC.exe (PID: 2780)
    • Searches for installed software

      • SDI_R2201.exe (PID: 2636)
  • INFO

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 3672)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3672)
    • Reads the computer name

      • SDI_R2201.exe (PID: 2636)
    • Checks supported languages

      • SDI_R2201.exe (PID: 2636)
    • Manual execution by a user

      • SDI_R2201.exe (PID: 2636)
      • SDI_R2201.exe (PID: 2036)
    • Reads the machine GUID from the registry

      • SDI_R2201.exe (PID: 2636)
    • Create files in a temporary directory

      • SDI_R2201.exe (PID: 2636)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0002
ZipCompression: None
ZipModifyDate: 2018:09:29 00:24:12
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: drivers/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
55
Monitored processes
9
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe sdi_r2201.exe no specs sdi_r2201.exe cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs vssvc.exe no specs cmd.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1348"C:\Windows\System32\cmd.exe" /c rd /s /q "C:\Users\admin\AppData\Local\Temp\SDI"C:\Windows\System32\cmd.exeSDI_R2201.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
2
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1780"C:\Windows\System32\cmd.exe" /c rd /s /q "C:\Users\admin\AppData\Local\Temp\SDI"C:\Windows\System32\cmd.exeSDI_R2201.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
2
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1860"C:\Windows\System32\cmd.exe" /c rd /s /q "C:\Users\admin\AppData\Local\Temp\SDI"C:\Windows\System32\cmd.exeSDI_R2201.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
2
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2036"C:\Users\admin\AppData\Local\Temp\SDI_R2201\SDI_R2201.exe" C:\Users\admin\AppData\Local\Temp\SDI_R2201\SDI_R2201.exeexplorer.exe
User:
admin
Company:
www.SamLab.ws
Integrity Level:
MEDIUM
Description:
Snappy Driver Installer
Exit code:
3221226540
Version:
1.22 1.22.1
Modules
Images
c:\users\admin\appdata\local\temp\sdi_r2201\sdi_r2201.exe
c:\windows\system32\ntdll.dll
2072"C:\Windows\System32\cmd.exe" /c rd /s /q "C:\Users\admin\AppData\Local\Temp\SDI"C:\Windows\System32\cmd.exeSDI_R2201.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
2
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2636"C:\Users\admin\AppData\Local\Temp\SDI_R2201\SDI_R2201.exe" C:\Users\admin\AppData\Local\Temp\SDI_R2201\SDI_R2201.exe
explorer.exe
User:
admin
Company:
www.SamLab.ws
Integrity Level:
HIGH
Description:
Snappy Driver Installer
Exit code:
0
Version:
1.22 1.22.1
Modules
Images
c:\users\admin\appdata\local\temp\sdi_r2201\sdi_r2201.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\comctl32.dll
c:\windows\system32\gdi32.dll
2728"C:\Windows\System32\cmd.exe" /c rd /s /q "C:\Users\admin\AppData\Local\Temp\SDI"C:\Windows\System32\cmd.exeSDI_R2201.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
2
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2780C:\Windows\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3672"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\SDI_R2201.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
16 099
Read events
15 934
Write events
165
Delete events
0

Modification events

(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3672) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\SDI_R2201.zip
(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
2
Suspicious files
1
Text files
236
Unknown types
9

Dropped files

PID
Process
Filename
Type
3672WinRAR.exeC:\Users\admin\AppData\Local\Temp\SDI_R2201\tools\SDI\langs\arabic.txttext
MD5:1F6CE2008F0841D4965F4A7D3AA76DD1
SHA256:12EECF9155829256FE3E8C7A4BA37F1F5C222E961FBAD6945383FAD96A83F0B5
3672WinRAR.exeC:\Users\admin\AppData\Local\Temp\SDI_R2201\tools\SDI\langs\chinese_zh.txttext
MD5:EAE8E356B8D4372902F6ACA9959985F2
SHA256:4206E23A077026C61B0F57B350803327F1B0A33D2BD7B06EA47375A6E82810CD
3672WinRAR.exeC:\Users\admin\AppData\Local\Temp\SDI_R2201\tools\SDI\langs\czech.txttext
MD5:898076B87800DEA4582E047AD919F128
SHA256:92E556B79C7A9AA1B8255FDAC3759375D0CF2BA9AA53FA64F53B323730A307EB
3672WinRAR.exeC:\Users\admin\AppData\Local\Temp\SDI_R2201\tools\SDI\langs\croatian.txttext
MD5:275228CEFEF0757D3C42B060F02519DA
SHA256:88486FD85208FC049604AD08B6786161346AFC4A1B6386C0110E601AF2337830
3672WinRAR.exeC:\Users\admin\AppData\Local\Temp\SDI_R2201\tools\SDI\langs\estonian.txttext
MD5:724C5950CEB61C69CD8616600E5E8C18
SHA256:6F3B89F6EB5D303C5EA644026516E91EC427B9A896599BED4EB015C6A4301689
3672WinRAR.exeC:\Users\admin\AppData\Local\Temp\SDI_R2201\tools\SDI\langs\french.txttext
MD5:31DD0A654FF0E3EC327EA116517C87B4
SHA256:55F1C8AB29E06F7C16D82EB2DB5DC9338C2848306BE3F6BAEF4D39ED63FA6445
3672WinRAR.exeC:\Users\admin\AppData\Local\Temp\SDI_R2201\tools\SDI\langs\farsi.txttext
MD5:12FD932E37EC6420EB1E0986662F83CD
SHA256:219E5FBEFEC1D9DAC59EA449802C99842302E3278A770D3068724217222487A4
3672WinRAR.exeC:\Users\admin\AppData\Local\Temp\SDI_R2201\tools\SDI\langs\danish.txttext
MD5:BF38AE3F54CFEFE7C25B6E4D819E279F
SHA256:1E9C98C1342B71D50D0A4B4A4FBE90384876B9CABE03E30DBFD46792C89F70EC
3672WinRAR.exeC:\Users\admin\AppData\Local\Temp\SDI_R2201\tools\SDI\langs\german.txttext
MD5:459A4AA3871C0901A8BB1BCF18A95E9F
SHA256:60F37DEB0A2358C125D661E578EFBAB84B4D00F0ECED4E17694000CA5A8B8F72
3672WinRAR.exeC:\Users\admin\AppData\Local\Temp\SDI_R2201\tools\SDI\langs\english.txttext
MD5:3847CA6996306078F53B1BD3D1CDC4A0
SHA256:CE2E90B7488184CE71B463CBB5EF594BD96FFAEA1F81473ABCC4F28851352249
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
5
DNS requests
4
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2636
SDI_R2201.exe
GET
200
185.26.122.80:80
http://driveroff.net/SDI_Update.torrent
unknown
binary
431 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2636
SDI_R2201.exe
185.26.122.80:80
driveroff.net
Hostland LTD
RU
unknown

DNS requests

Domain
IP
Reputation
router.bittorrent.com
  • 67.215.246.10
shared
router.utorrent.com
  • 82.221.103.244
whitelisted
router.bitcomet.com
unknown
driveroff.net
  • 185.26.122.80
unknown

Threats

PID
Process
Class
Message
2636
SDI_R2201.exe
Potential Corporate Privacy Violation
ET P2P Possible Torrent Download via HTTP Request
No debug info