File name:

Moved Temporarily - Linkvertise Downloader.zip

Full analysis: https://app.any.run/tasks/82a58605-e776-4b3b-acf2-8356417f2895
Verdict: Malicious activity
Analysis date: June 17, 2023, 18:36:02
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

14783F6CCD84F78A382153FE88C458D5

SHA1:

32858999418078E93A627E6CDC319A577AC589DA

SHA256:

495A40230AC618C82B0FD08486D66C3F1E735F6D36032B74249D97E8715A5FBC

SSDEEP:

196608:fiRu3GRp0YvcFLVBHs7wklhuSKpbpiTwmCAj2qJNWUySvgMbkWRd:KvvEBMMkaNpbUT7CAaQmSvPI2

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Moved Temporarily - Linkvertise Downloader_rD-t9n1.exe (PID: 1592)
      • Moved Temporarily - Linkvertise Downloader_rD-t9n1.exe (PID: 2996)
    • Loads dropped or rewritten executable

      • Moved Temporarily - Linkvertise Downloader_rD-t9n1.tmp (PID: 2004)
  • SUSPICIOUS

    • Reads the Windows owner or organization settings

      • Moved Temporarily - Linkvertise Downloader_rD-t9n1.tmp (PID: 2004)
    • Executable content was dropped or overwritten

      • Moved Temporarily - Linkvertise Downloader_rD-t9n1.exe (PID: 2996)
      • Moved Temporarily - Linkvertise Downloader_rD-t9n1.tmp (PID: 2004)
      • Moved Temporarily - Linkvertise Downloader_rD-t9n1.exe (PID: 1592)
    • Reads settings of System Certificates

      • Moved Temporarily - Linkvertise Downloader_rD-t9n1.tmp (PID: 2004)
    • Reads the Internet Settings

      • Moved Temporarily - Linkvertise Downloader_rD-t9n1.tmp (PID: 2004)
  • INFO

    • Checks supported languages

      • Moved Temporarily - Linkvertise Downloader_rD-t9n1.exe (PID: 2996)
      • Moved Temporarily - Linkvertise Downloader_rD-t9n1.tmp (PID: 3120)
      • Moved Temporarily - Linkvertise Downloader_rD-t9n1.exe (PID: 1592)
      • Moved Temporarily - Linkvertise Downloader_rD-t9n1.tmp (PID: 2004)
    • Create files in a temporary directory

      • Moved Temporarily - Linkvertise Downloader_rD-t9n1.exe (PID: 2996)
      • Moved Temporarily - Linkvertise Downloader_rD-t9n1.exe (PID: 1592)
      • Moved Temporarily - Linkvertise Downloader_rD-t9n1.tmp (PID: 2004)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2524)
    • Application was dropped or rewritten from another process

      • Moved Temporarily - Linkvertise Downloader_rD-t9n1.tmp (PID: 3120)
      • Moved Temporarily - Linkvertise Downloader_rD-t9n1.tmp (PID: 2004)
    • Reads the computer name

      • Moved Temporarily - Linkvertise Downloader_rD-t9n1.tmp (PID: 3120)
      • Moved Temporarily - Linkvertise Downloader_rD-t9n1.tmp (PID: 2004)
    • The process checks LSA protection

      • Moved Temporarily - Linkvertise Downloader_rD-t9n1.tmp (PID: 3120)
      • Moved Temporarily - Linkvertise Downloader_rD-t9n1.tmp (PID: 2004)
    • Reads the machine GUID from the registry

      • Moved Temporarily - Linkvertise Downloader_rD-t9n1.tmp (PID: 2004)
    • Application launched itself

      • iexplore.exe (PID: 1252)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: _piece01.exe
ZipUncompressedSize: 15269232
ZipCompressedSize: 117760
ZipCRC: 0x1574d1fb
ZipModifyDate: 2023:06:01 12:28:32
ZipCompression: Deflated
ZipBitFlag: -
ZipRequiredVersion: 20
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
47
Monitored processes
7
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start drop and start drop and start winrar.exe moved temporarily - linkvertise downloader_rd-t9n1.exe moved temporarily - linkvertise downloader_rd-t9n1.tmp no specs moved temporarily - linkvertise downloader_rd-t9n1.exe moved temporarily - linkvertise downloader_rd-t9n1.tmp iexplore.exe iexplore.exe

Process information

PID
CMD
Path
Indicators
Parent process
1252"C:\Program Files\Internet Explorer\iexplore.exe" https://drive.google.com/file/d/1elW2EoPlIgazSLKWteSnuZ1jnt2VU-tM/view?usp=sharingC:\Program Files\Internet Explorer\iexplore.exe
Moved Temporarily - Linkvertise Downloader_rD-t9n1.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
1592"C:\Users\admin\AppData\Local\Temp\Rar$EXa2524.46213\Moved Temporarily - Linkvertise Downloader_rD-t9n1.exe" /SPAWNWND=$60180 /NOTIFYWND=$B01B4 C:\Users\admin\AppData\Local\Temp\Rar$EXa2524.46213\Moved Temporarily - Linkvertise Downloader_rD-t9n1.exe
Moved Temporarily - Linkvertise Downloader_rD-t9n1.tmp
User:
admin
Company:
Integrity Level:
HIGH
Description:
Línkvertise
Exit code:
0
Version:
4.2.442.12
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2524.46213\moved temporarily - linkvertise downloader_rd-t9n1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2004"C:\Users\admin\AppData\Local\Temp\is-3O94R.tmp\Moved Temporarily - Linkvertise Downloader_rD-t9n1.tmp" /SL5="$7017E,10373288,1230848,C:\Users\admin\AppData\Local\Temp\Rar$EXa2524.46213\Moved Temporarily - Linkvertise Downloader_rD-t9n1.exe" /SPAWNWND=$60180 /NOTIFYWND=$B01B4 C:\Users\admin\AppData\Local\Temp\is-3O94R.tmp\Moved Temporarily - Linkvertise Downloader_rD-t9n1.tmp
Moved Temporarily - Linkvertise Downloader_rD-t9n1.exe
User:
admin
Company:
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-3o94r.tmp\moved temporarily - linkvertise downloader_rd-t9n1.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\mpr.dll
c:\windows\system32\user32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\shlwapi.dll
2524"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Moved Temporarily - Linkvertise Downloader.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
2972"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:1252 CREDAT:275457 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2996"C:\Users\admin\AppData\Local\Temp\Rar$EXa2524.46213\Moved Temporarily - Linkvertise Downloader_rD-t9n1.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2524.46213\Moved Temporarily - Linkvertise Downloader_rD-t9n1.exe
WinRAR.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Línkvertise
Exit code:
0
Version:
4.2.442.12
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2524.46213\moved temporarily - linkvertise downloader_rd-t9n1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\shlwapi.dll
3120"C:\Users\admin\AppData\Local\Temp\is-C7A36.tmp\Moved Temporarily - Linkvertise Downloader_rD-t9n1.tmp" /SL5="$B01B4,10373288,1230848,C:\Users\admin\AppData\Local\Temp\Rar$EXa2524.46213\Moved Temporarily - Linkvertise Downloader_rD-t9n1.exe" C:\Users\admin\AppData\Local\Temp\is-C7A36.tmp\Moved Temporarily - Linkvertise Downloader_rD-t9n1.tmpMoved Temporarily - Linkvertise Downloader_rD-t9n1.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-c7a36.tmp\moved temporarily - linkvertise downloader_rd-t9n1.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
21 377
Read events
21 220
Write events
153
Delete events
4

Modification events

(PID) Process:(2524) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16D\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2524) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(2524) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2524) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(2524) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2524) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2524) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2524) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2524) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2524) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
Executable files
7
Suspicious files
27
Text files
23
Unknown types
0

Dropped files

PID
Process
Filename
Type
2524WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2524.46213\_piece01.exe
MD5:
SHA256:
2524WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2524.46213\_piece02.exe
MD5:
SHA256:
2524WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2524.46213\_piece03.exe
MD5:
SHA256:
2524WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2524.46213\_piece04.exe
MD5:
SHA256:
2524WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2524.46213\_piece05.exe
MD5:
SHA256:
2524WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2524.46213\_piece06.exe
MD5:
SHA256:
2524WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2524.46213\_piece07.exe
MD5:
SHA256:
2524WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2524.46213\_piece08.exe
MD5:
SHA256:
2524WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2524.46213\_piece09.exe
MD5:
SHA256:
2524WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2524.46213\_piece10.exe
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
31
DNS requests
14
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2972
iexplore.exe
GET
200
23.53.40.56:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?8017dcf81888efa5
NL
compressed
4.70 Kb
whitelisted
2972
iexplore.exe
GET
200
23.53.40.56:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?9980f43a7e6d89bf
NL
compressed
4.70 Kb
whitelisted
2972
iexplore.exe
GET
200
142.250.185.131:80
http://ocsp.pki.goog/gts1c3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEDDLEy%2BYobS%2BEGhw2qYKJ4o%3D
US
der
471 b
whitelisted
2972
iexplore.exe
GET
200
142.250.185.131:80
http://ocsp.pki.goog/gts1c3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEDQPF4dGoxt4Ci8O%2BnFtCGA%3D
US
der
471 b
whitelisted
2972
iexplore.exe
GET
200
142.250.185.131:80
http://ocsp.pki.goog/gts1c3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEHhNV%2BonQeuRCpZqY45WCS0%3D
US
der
471 b
whitelisted
2972
iexplore.exe
GET
200
142.250.185.131:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
US
der
1.41 Kb
whitelisted
2972
iexplore.exe
GET
200
142.250.185.131:80
http://ocsp.pki.goog/gts1c3/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEQCeWX0Pxye%2FaApODVdtRukJ
US
der
472 b
whitelisted
2972
iexplore.exe
GET
200
142.250.185.131:80
http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFNZazTHGPUBUGY%3D
US
der
724 b
whitelisted
1252
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA8Ull8gIGmZT9XHrHiJQeI%3D
US
der
1.47 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1076
svchost.exe
224.0.0.252:5355
unknown
2972
iexplore.exe
142.250.186.46:443
drive.google.com
GOOGLE
US
whitelisted
2972
iexplore.exe
142.250.185.131:80
ocsp.pki.goog
GOOGLE
US
whitelisted
2004
Moved Temporarily - Linkvertise Downloader_rD-t9n1.tmp
13.225.84.120:443
d2vlpggfgyaxd1.cloudfront.net
AMAZON-02
US
whitelisted
2972
iexplore.exe
23.53.40.56:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
suspicious
2972
iexplore.exe
172.217.18.3:443
fonts.gstatic.com
GOOGLE
US
whitelisted
2972
iexplore.exe
142.250.185.141:443
accounts.google.com
GOOGLE
US
whitelisted
2972
iexplore.exe
142.250.186.67:443
www.gstatic.com
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
d2vlpggfgyaxd1.cloudfront.net
  • 13.225.84.120
  • 13.225.84.84
  • 13.225.84.8
  • 13.225.84.184
unknown
drive.google.com
  • 142.250.186.46
shared
ctldl.windowsupdate.com
  • 23.53.40.56
  • 23.53.40.40
  • 23.53.40.35
  • 23.53.40.83
whitelisted
ocsp.pki.goog
  • 142.250.185.131
whitelisted
accounts.google.com
  • 142.250.185.141
shared
www.gstatic.com
  • 142.250.186.67
whitelisted
fonts.gstatic.com
  • 172.217.18.3
whitelisted
www.google.com
  • 142.250.185.196
malicious
accounts.youtube.com
  • 142.250.186.78
whitelisted
play.google.com
  • 142.250.181.238
whitelisted

Threats

No threats detected
No debug info