File name:

cowaxess_1.0.0_x64_installer.zip

Full analysis: https://app.any.run/tasks/5eb514c0-8657-4aa1-957f-a7453d50e137
Verdict: Suspicious activity
Analysis date: March 23, 2020, 22:20:26
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract
MD5:

D7B63D4EB444C65AE7C7960C9604BC1A

SHA1:

A7DD6DA9C700FC04B93409199138B1256883CB14

SHA256:

48CE42841A0283E63A976C501467EA92DF5B3515181BE5BAB1CF18C197B4C286

SSDEEP:

98304:EKH99AzYL1wBpgS3ArWV0o+srVpooxPQFgjEFbwWYu6epcOMG:T9EYlWV0oBrQbNOu6Uck

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • cowaxess_1.0.0_x64_installer.exe (PID: 2556)
      • cowaxess_1.0.0_x64_installer.exe (PID: 2072)
      • icw_base_4.3.0_x64_installer.exe (PID: 2916)
      • nsA870.tmp (PID: 3212)
      • nsB34E.tmp (PID: 3460)
    • Loads dropped or rewritten executable

      • cowaxess_1.0.0_x64_installer.exe (PID: 2072)
      • icw_base_4.3.0_x64_installer.exe (PID: 2916)
    • Detects Cygwin installation

      • icw_base_4.3.0_x64_installer.exe (PID: 2916)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • cowaxess_1.0.0_x64_installer.exe (PID: 2072)
      • WinRAR.exe (PID: 3020)
      • icw_base_4.3.0_x64_installer.exe (PID: 2916)
    • Starts application with an unusual extension

      • cowaxess_1.0.0_x64_installer.exe (PID: 2072)
      • icw_base_4.3.0_x64_installer.exe (PID: 2916)
    • Creates a software uninstall entry

      • cowaxess_1.0.0_x64_installer.exe (PID: 2072)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2019:07:19 00:09:23
ZipCRC: 0xf71dd0e1
ZipCompressedSize: 4382856
ZipUncompressedSize: 4382856
ZipFileName: cowaxess_1.0.0_x64_installer.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
44
Monitored processes
6
Malicious processes
2
Suspicious processes
2

Behavior graph

Click at the process to see the details
drop and start drop and start start drop and start winrar.exe cowaxess_1.0.0_x64_installer.exe no specs cowaxess_1.0.0_x64_installer.exe nsa870.tmp no specs icw_base_4.3.0_x64_installer.exe nsb34e.tmp no specs

Process information

PID
CMD
Path
Indicators
Parent process
2072"C:\Users\admin\AppData\Local\Temp\Rar$EXa3020.37900\cowaxess_1.0.0_x64_installer.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3020.37900\cowaxess_1.0.0_x64_installer.exe
WinRAR.exe
User:
admin
Company:
itefix.net
Integrity Level:
HIGH
Description:
cowaxess
Exit code:
0
Version:
1.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3020.37900\cowaxess_1.0.0_x64_installer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
2556"C:\Users\admin\AppData\Local\Temp\Rar$EXa3020.37900\cowaxess_1.0.0_x64_installer.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3020.37900\cowaxess_1.0.0_x64_installer.exeWinRAR.exe
User:
admin
Company:
itefix.net
Integrity Level:
MEDIUM
Description:
cowaxess
Exit code:
3221226540
Version:
1.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3020.37900\cowaxess_1.0.0_x64_installer.exe
c:\systemroot\system32\ntdll.dll
2916"C:\Users\admin\AppData\Local\Temp\nsd8ECD.tmp\icw_base_4.3.0_x64_installer.exe" /SC:\Users\admin\AppData\Local\Temp\nsd8ECD.tmp\icw_base_4.3.0_x64_installer.exe
nsA870.tmp
User:
admin
Company:
Itefix Consulting and Software
Integrity Level:
HIGH
Description:
icw base
Exit code:
0
Version:
4.3.0
Modules
Images
c:\users\admin\appdata\local\temp\nsd8ecd.tmp\icw_base_4.3.0_x64_installer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
3020"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\cowaxess_1.0.0_x64_installer.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3212"C:\Users\admin\AppData\Local\Temp\nsd8ECD.tmp\nsA870.tmp" "C:\Users\admin\AppData\Local\Temp\nsd8ECD.tmp\icw_base_4.3.0_x64_installer.exe" /SC:\Users\admin\AppData\Local\Temp\nsd8ECD.tmp\nsA870.tmpcowaxess_1.0.0_x64_installer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\nsd8ecd.tmp\nsa870.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3460"C:\Users\admin\AppData\Local\Temp\nsyAA34.tmp\nsB34E.tmp" "c:\cowaxess_x64\bin\bash" -c "/bin/ln /bin/bash /bin/sh"C:\Users\admin\AppData\Local\Temp\nsyAA34.tmp\nsB34E.tmpicw_base_4.3.0_x64_installer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
3221225501
Modules
Images
c:\users\admin\appdata\local\temp\nsyaa34.tmp\nsb34e.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
Total events
1 137
Read events
1 120
Write events
17
Delete events
0

Modification events

(PID) Process:(3020) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3020) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3020) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3020) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\cowaxess_1.0.0_x64_installer.zip
(PID) Process:(3020) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3020) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3020) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3020) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3020) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(3020) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
Executable files
66
Suspicious files
2
Text files
22
Unknown types
1

Dropped files

PID
Process
Filename
Type
2072cowaxess_1.0.0_x64_installer.exeC:\Users\admin\AppData\Local\Temp\nsd8ECD.tmp\ioSpecial.initext
MD5:
SHA256:
3020WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3020.37900\cowaxess_1.0.0_x64_installer.exeexecutable
MD5:
SHA256:
2072cowaxess_1.0.0_x64_installer.exeC:\Users\admin\AppData\Local\Temp\nsd8ECD.tmp\icw_base_4.3.0_x64_installer.exeexecutable
MD5:
SHA256:
2072cowaxess_1.0.0_x64_installer.exeC:\Users\admin\AppData\Local\Temp\nsd8ECD.tmp\nsA870.tmpexecutable
MD5:
SHA256:
2916icw_base_4.3.0_x64_installer.exeC:\Users\admin\AppData\Local\Temp\nsyAA34.tmp\System.dllexecutable
MD5:56A321BD011112EC5D8A32B2F6FD3231
SHA256:BB6DF93369B498EAA638B0BCDC4BB89F45E9B02CA12D28BCEDF4629EA7F5E0F1
2072cowaxess_1.0.0_x64_installer.exeC:\Users\admin\AppData\Local\Temp\nsd8ECD.tmp\System.dllexecutable
MD5:56A321BD011112EC5D8A32B2F6FD3231
SHA256:BB6DF93369B498EAA638B0BCDC4BB89F45E9B02CA12D28BCEDF4629EA7F5E0F1
2916icw_base_4.3.0_x64_installer.exeC:\cowaxess_x64\etc\terminfo\63\cygwinbinary
MD5:329C09B031FB83FCBD3D87A27422D312
SHA256:5585A682CEC0AAD2E16FD10293BBA036A5CEF112857593C57287F8D2EFB7F0E3
2072cowaxess_1.0.0_x64_installer.exeC:\Users\admin\AppData\Local\Temp\nsd8ECD.tmp\modern-wizard.bmpimage
MD5:E50EBEDF624346AD85A3DDBB17105248
SHA256:04155C6AEE385339149548BD55B97DC400D9E4A99102AE0CA9A41250CB02D536
2072cowaxess_1.0.0_x64_installer.exeC:\Users\admin\AppData\Local\Temp\nsd8ECD.tmp\InstallOptions.dllexecutable
MD5:D753362649AECD60FF434ADF171A4E7F
SHA256:8F24C6CF0B06D18F3C07E7BFCA4E92AFCE71834663746CFAA9DDF52A25D5C586
2916icw_base_4.3.0_x64_installer.exeC:\cowaxess_x64\fstab.txttext
MD5:0357CE686419410E659534E68419E876
SHA256:9FA2112C0E0EC3FDF02A1FE4434C8E7041D4C479670B85E59F6078E6DAD37D9D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info