File name:

Test2.zip

Full analysis: https://app.any.run/tasks/10e18e42-89ee-4c15-b628-a7f66edf33ee
Verdict: Malicious activity
Analysis date: October 08, 2023, 07:46:15
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

02A1B70F44E310FE665647F27B053924

SHA1:

E4D8122C5AF7AEDC1807EADB902A3DE16543AF66

SHA256:

4CEC9F992238676E1A881FF9966EAC5642A2EE37CAB8AB41A7D90F9455A0D951

SSDEEP:

98304:56Um36OSPUZuWDr+tlsH+bdOXlcpD80dXvdq8OZdTDQMJthjNKKXc3LcN1F2AS7z:g6YGZKeQwif/mh7f5GEkjQX

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Windows Driver Foundation (WDF).exe (PID: 2844)
    • Loads dropped or rewritten executable

      • Windows Driver Foundation (WDF).exe (PID: 2844)
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Manual execution by a user

      • Windows Driver Foundation (WDF).exe (PID: 2844)
    • Checks supported languages

      • Windows Driver Foundation (WDF).exe (PID: 2844)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 1648)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2023:10:08 10:40:20
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: Test2/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
36
Monitored processes
3
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs searchprotocolhost.exe no specs windows driver foundation (wdf).exe

Process information

PID
CMD
Path
Indicators
Parent process
1648"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Test2.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\winrar\winrar.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2844"C:\Users\admin\Desktop\Test2\Windows Driver Foundation (WDF).exe" C:\Users\admin\Desktop\Test2\Windows Driver Foundation (WDF).exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Version:
10.0.0.0
Modules
Images
c:\users\admin\desktop\test2\windows driver foundation (wdf).exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-crt-convert-l1-1-0.dll
c:\windows\system32\ucrtbase.dll
3920"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe4_ Global\UsGthrCtrlFltPipeMssGthrPipe4 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7601.24542 (win7sp1_ldr_escrow.191209-2211)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
1 675
Read events
1 655
Write events
20
Delete events
0

Modification events

(PID) Process:(1648) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1648) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(1648) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(1648) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(1648) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1648) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1648) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1648) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1648) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
(PID) Process:(1648) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\General
Operation:writeName:LastFolder
Value:
C:\Users\admin\Desktop
Executable files
14
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
1648WinRAR.exeC:\Users\admin\Desktop\Test2\Qt5QuickShapes.dllexecutable
MD5:82C24F6B916C5700714C9D6ECD40A6F8
SHA256:C01578938A32E51CF27BCF476A8F175D6F4E0F718BF4F2C2694D4B1717E0AD27
1648WinRAR.exeC:\Users\admin\Desktop\Test2\Qt5QmlWorkerScript.dllexecutable
MD5:52AA72CC6DBD67F5F203AFD72BA0DF92
SHA256:42FAEA919D50C5112C6A24E2E40FEEE6EAABB08DFD1330BB8B91FA249FB8B2BE
1648WinRAR.exeC:\Users\admin\Desktop\Test2\Windows Driver Foundation (WDF).exeexecutable
MD5:F592F783785A6AB0F2FB5F5C6511B9CB
SHA256:B2DF1B307BF0CEE1CC53766CD84C25A393CFEABCDFF2E58D44EA370A5A36BC6C
1648WinRAR.exeC:\Users\admin\Desktop\Test2\Qt5QuickControls2.dllexecutable
MD5:E48AA30CD0C78B122CA323A0278B5406
SHA256:E4D227E4782AC1231BB57C3974B2018634F61670EF78375CA67AAE5244C05FEB
1648WinRAR.exeC:\Users\admin\Desktop\Test2\Qt5Core.dllexecutable
MD5:7D180286E9C071C7BC3A6BC2ACE792AC
SHA256:4F8DC460162407CFCCB1BE6EF9CCE45C4449DE838AEFFA3FD33378F01A3F9CC4
1648WinRAR.exeC:\Users\admin\Desktop\Test2\Qt5QmlModels.dllexecutable
MD5:78E8091FEB2E6CE5646459DB0EA9E465
SHA256:065C8D687DC74964123F4BB06319565B163B164AB09DADC1EB6929EE19755735
1648WinRAR.exeC:\Users\admin\Desktop\Test2\Qt5Svg.dllexecutable
MD5:EF0D5A2DC1D7A921F2BB0EB3EEF2E481
SHA256:ADE28D4CBAC1E033468CB48F380352F0DF7FBBCE03261C48827B8A5ED7A1548E
1648WinRAR.exeC:\Users\admin\Desktop\Test2\Qt5RemoteObjects.dllexecutable
MD5:90440E9BB21020744D7EE012C85FC9C7
SHA256:618B020A57C4E3992119C839D66E64992201378B128B3778F43D864FA9C2ADC4
1648WinRAR.exeC:\Users\admin\Desktop\Test2\Qt5Quick.dllexecutable
MD5:07266E7D049AC4499F34CE281F3A50D7
SHA256:5F246016691FF883243EE9B3C9215EB16B859B12AEFC5F4BBD2FBDA3911883DE
1648WinRAR.exeC:\Users\admin\Desktop\Test2\Qt5Network.dllexecutable
MD5:2E3DB1CD1EC59D08706438258E86EA30
SHA256:37275F3EA79D15A2792BF21F71F1DF825F201CF8B33AA1F94CA93D62D76B216C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
unknown
2656
svchost.exe
239.255.255.250:1900
unknown
1088
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:137
unknown

DNS requests

No data

Threats

No threats detected
Process
Message
Windows Driver Foundation (WDF).exe
qt.qpa.plugin: Could not find the Qt platform plugin "windows" in ""