File name:

Sulfoxide.zip

Full analysis: https://app.any.run/tasks/e4565280-bdc4-4a30-9bf5-1f80b0082c28
Verdict: Malicious activity
Analysis date: July 29, 2022, 12:17:10
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

42FA3C89D33352CAFFA30A25B747039F

SHA1:

3D49AE9E43C96F3F756A9EA0ACA2FCF90D2B477B

SHA256:

46E4E720E22B811A37A31EF0ABAEA3E20667E28A70F41CA038585536C6D37EEF

SSDEEP:

49152:znkUG3ugg2LDrIkO99dHv3hywmCmzpkkiqnaaWhmz+BxFPxaAw0:zkFfzOX9xmCopkk9abMMZxaf0

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • vcredist_x86.EXE (PID: 1364)
      • Sulfoxide.exe (PID: 3176)
      • J4y9CFyq6urM74Uj.exe (PID: 964)
    • Drops executable file immediately after starts

      • WinRAR.exe (PID: 2916)
      • msiexec.exe (PID: 3168)
      • Sulfoxide.exe (PID: 3176)
    • Changes the autorun value in the registry

      • vcredist_x86.EXE (PID: 1364)
    • Loads dropped or rewritten executable

      • J4y9CFyq6urM74Uj.exe (PID: 964)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2916)
      • vcredist_x86.EXE (PID: 1364)
      • msiexec.exe (PID: 3168)
      • Sulfoxide.exe (PID: 3176)
    • Reads the computer name

      • WinRAR.exe (PID: 2916)
      • MsiExec.exe (PID: 3432)
      • J4y9CFyq6urM74Uj.exe (PID: 964)
      • msiexec.exe (PID: 3168)
    • Checks supported languages

      • WinRAR.exe (PID: 2916)
      • vcredist_x86.EXE (PID: 1364)
      • MsiExec.exe (PID: 3432)
      • J4y9CFyq6urM74Uj.exe (PID: 964)
      • Sulfoxide.exe (PID: 3176)
      • msiexec.exe (PID: 3168)
    • Drops a file with a compile date too recent

      • WinRAR.exe (PID: 2916)
      • msiexec.exe (PID: 3168)
      • Sulfoxide.exe (PID: 3176)
    • Reads Environment values

      • vssvc.exe (PID: 124)
    • Reads the Windows organization settings

      • msiexec.exe (PID: 3168)
      • msiexec.exe (PID: 3200)
    • Reads Windows owner or organization settings

      • msiexec.exe (PID: 3168)
      • msiexec.exe (PID: 3200)
    • Executed as Windows Service

      • vssvc.exe (PID: 124)
    • Starts itself from another location

      • Sulfoxide.exe (PID: 3176)
  • INFO

    • Manual execution by user

      • vcredist_x86.EXE (PID: 1364)
      • Sulfoxide.exe (PID: 3176)
    • Checks supported languages

      • msiexec.exe (PID: 3200)
      • vssvc.exe (PID: 124)
    • Reads the computer name

      • msiexec.exe (PID: 3200)
      • vssvc.exe (PID: 124)
    • Reads settings of System Certificates

      • msiexec.exe (PID: 3200)
      • msiexec.exe (PID: 3168)
    • Checks Windows Trust Settings

      • msiexec.exe (PID: 3168)
      • msiexec.exe (PID: 3200)
    • Creates files in the program directory

      • msiexec.exe (PID: 3168)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 3168)
    • Application launched itself

      • msiexec.exe (PID: 3168)
    • Searches for installed software

      • msiexec.exe (PID: 3168)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: Sulfoxide.exe
ZipUncompressedSize: 307200
ZipCompressedSize: 80985
ZipCRC: 0xa22d7f1e
ZipModifyDate: 2022:07:22 22:57:00
ZipCompression: Deflated
ZipBitFlag: -
ZipRequiredVersion: 20
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
53
Monitored processes
8
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start drop and start winrar.exe vcredist_x86.exe msiexec.exe no specs msiexec.exe vssvc.exe no specs msiexec.exe no specs sulfoxide.exe j4y9cfyq6urm74uj.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
124C:\Windows\system32\vssvc.exeC:\Windows\system32\vssvc.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
964"C:\Users\admin\AppData\Local\Temp\J4y9CFyq6urM74Uj.exe"C:\Users\admin\AppData\Local\Temp\J4y9CFyq6urM74Uj.exeSulfoxide.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\j4y9cfyq6urm74uj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
1364"C:\Users\admin\Desktop\vcredist_x86.EXE" C:\Users\admin\Desktop\vcredist_x86.EXE
Explorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Win32 Cabinet Self-Extractor
Exit code:
0
Version:
6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
Modules
Images
c:\users\admin\desktop\vcredist_x86.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2916"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\Sulfoxide.zip"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
3168C:\Windows\system32\msiexec.exe /VC:\Windows\system32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3176"C:\Users\admin\Desktop\Sulfoxide.exe" C:\Users\admin\Desktop\Sulfoxide.exe
Explorer.EXE
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\sulfoxide.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
3200msiexec /i vcredist.msiC:\Windows\system32\msiexec.exevcredist_x86.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3432C:\Windows\system32\MsiExec.exe -Embedding A47D17C00E4652DC49DF8C4EB2A117ADC:\Windows\system32\MsiExec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\kernel32.dll
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
10 510
Read events
9 715
Write events
781
Delete events
14

Modification events

(PID) Process:(2916) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2916) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2916) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2916) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(2916) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2916) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\Sulfoxide.zip
(PID) Process:(2916) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2916) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2916) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2916) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
30
Suspicious files
8
Text files
10
Unknown types
13

Dropped files

PID
Process
Filename
Type
3168msiexec.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
3168msiexec.exeC:\System Volume Information\SPP\snapshot-2binary
MD5:
SHA256:
3168msiexec.exeC:\Users\admin\AppData\Local\Temp\~DF51FFE62C85DE678C.TMPgmc
MD5:
SHA256:
3168msiexec.exeC:\System Volume Information\SPP\OnlineMetadataCache\{17bdae3d-79b6-4de2-8cb6-d85e5a225aa8}_OnDiskSnapshotPropbinary
MD5:
SHA256:
3168msiexec.exeC:\Windows\Installer\101fc1.ipibinary
MD5:
SHA256:
3168msiexec.exeC:\Windows\Installer\MSI3319.tmpbinary
MD5:
SHA256:
2916WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2916.19835\Sulfoxide.exeexecutable
MD5:0DD677A9C9BDD504DD0B06676A9C5D7A
SHA256:82CD406837C00A3A251490B3442322DE9F101C43EEC36D1208014F363C2A5ED4
3168msiexec.exeC:\Windows\Installer\MSI2424.tmpexecutable
MD5:85221B3BCBA8DBE4B4A46581AA49F760
SHA256:F6E34A4550E499346F5AB1D245508F16BF765FF24C4988984B89E049CA55737F
1364vcredist_x86.EXEC:\Users\admin\AppData\Local\Temp\IXP000.TMP\vcredist.msiexecutable
MD5:B20BBEB818222B657DF49A9CFE4FED79
SHA256:91BDD063F6C53126737791C9ECCF0B2F4CF44927831527245BC89A0BE06C0CB4
1364vcredist_x86.EXEC:\Users\admin\AppData\Local\Temp\IXP000.TMP\vcredis1.cabcompressed
MD5:CC064D4B81619991DE8131A86AD77681
SHA256:913EE5A1CAE3E5A1872B3A5EFAAA00C58E4BEB692492B138F76967DA671B0477
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info