File name: | Test2.zip |
Full analysis: | https://app.any.run/tasks/10e18e42-89ee-4c15-b628-a7f66edf33ee |
Verdict: | Malicious activity |
Analysis date: | October 08, 2023, 07:46:15 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/zip |
File info: | Zip archive data, at least v2.0 to extract |
MD5: | 02A1B70F44E310FE665647F27B053924 |
SHA1: | E4D8122C5AF7AEDC1807EADB902A3DE16543AF66 |
SHA256: | 4CEC9F992238676E1A881FF9966EAC5642A2EE37CAB8AB41A7D90F9455A0D951 |
SSDEEP: | 98304:56Um36OSPUZuWDr+tlsH+bdOXlcpD80dXvdq8OZdTDQMJthjNKKXc3LcN1F2AS7z:g6YGZKeQwif/mh7f5GEkjQX |
.zip | | | ZIP compressed archive (100) |
---|
ZipRequiredVersion: | 20 |
---|---|
ZipBitFlag: | - |
ZipCompression: | None |
ZipModifyDate: | 2023:10:08 10:40:20 |
ZipCRC: | 0x00000000 |
ZipCompressedSize: | - |
ZipUncompressedSize: | - |
ZipFileName: | Test2/ |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
1648 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Test2.zip" | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
2844 | "C:\Users\admin\Desktop\Test2\Windows Driver Foundation (WDF).exe" | C:\Users\admin\Desktop\Test2\Windows Driver Foundation (WDF).exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Version: 10.0.0.0 Modules
| |||||||||||||||
3920 | "C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe4_ Global\UsGthrCtrlFltPipeMssGthrPipe4 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" | C:\Windows\System32\SearchProtocolHost.exe | — | SearchIndexer.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft Windows Search Protocol Host Exit code: 0 Version: 7.00.7601.24542 (win7sp1_ldr_escrow.191209-2211) Modules
|
(PID) Process: | (1648) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (1648) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
(PID) Process: | (1648) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
(PID) Process: | (1648) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
(PID) Process: | (1648) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | name |
Value: 120 | |||
(PID) Process: | (1648) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | size |
Value: 80 | |||
(PID) Process: | (1648) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | type |
Value: 120 | |||
(PID) Process: | (1648) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | mtime |
Value: 100 | |||
(PID) Process: | (1648) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin |
Operation: | write | Name: | Placement |
Value: 2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000 | |||
(PID) Process: | (1648) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\General |
Operation: | write | Name: | LastFolder |
Value: C:\Users\admin\Desktop |
PID | Process | Filename | Type | |
---|---|---|---|---|
1648 | WinRAR.exe | C:\Users\admin\Desktop\Test2\Qt5QuickShapes.dll | executable | |
MD5:82C24F6B916C5700714C9D6ECD40A6F8 | SHA256:C01578938A32E51CF27BCF476A8F175D6F4E0F718BF4F2C2694D4B1717E0AD27 | |||
1648 | WinRAR.exe | C:\Users\admin\Desktop\Test2\Qt5QmlWorkerScript.dll | executable | |
MD5:52AA72CC6DBD67F5F203AFD72BA0DF92 | SHA256:42FAEA919D50C5112C6A24E2E40FEEE6EAABB08DFD1330BB8B91FA249FB8B2BE | |||
1648 | WinRAR.exe | C:\Users\admin\Desktop\Test2\Windows Driver Foundation (WDF).exe | executable | |
MD5:F592F783785A6AB0F2FB5F5C6511B9CB | SHA256:B2DF1B307BF0CEE1CC53766CD84C25A393CFEABCDFF2E58D44EA370A5A36BC6C | |||
1648 | WinRAR.exe | C:\Users\admin\Desktop\Test2\Qt5QuickControls2.dll | executable | |
MD5:E48AA30CD0C78B122CA323A0278B5406 | SHA256:E4D227E4782AC1231BB57C3974B2018634F61670EF78375CA67AAE5244C05FEB | |||
1648 | WinRAR.exe | C:\Users\admin\Desktop\Test2\Qt5Core.dll | executable | |
MD5:7D180286E9C071C7BC3A6BC2ACE792AC | SHA256:4F8DC460162407CFCCB1BE6EF9CCE45C4449DE838AEFFA3FD33378F01A3F9CC4 | |||
1648 | WinRAR.exe | C:\Users\admin\Desktop\Test2\Qt5QmlModels.dll | executable | |
MD5:78E8091FEB2E6CE5646459DB0EA9E465 | SHA256:065C8D687DC74964123F4BB06319565B163B164AB09DADC1EB6929EE19755735 | |||
1648 | WinRAR.exe | C:\Users\admin\Desktop\Test2\Qt5Svg.dll | executable | |
MD5:EF0D5A2DC1D7A921F2BB0EB3EEF2E481 | SHA256:ADE28D4CBAC1E033468CB48F380352F0DF7FBBCE03261C48827B8A5ED7A1548E | |||
1648 | WinRAR.exe | C:\Users\admin\Desktop\Test2\Qt5RemoteObjects.dll | executable | |
MD5:90440E9BB21020744D7EE012C85FC9C7 | SHA256:618B020A57C4E3992119C839D66E64992201378B128B3778F43D864FA9C2ADC4 | |||
1648 | WinRAR.exe | C:\Users\admin\Desktop\Test2\Qt5Quick.dll | executable | |
MD5:07266E7D049AC4499F34CE281F3A50D7 | SHA256:5F246016691FF883243EE9B3C9215EB16B859B12AEFC5F4BBD2FBDA3911883DE | |||
1648 | WinRAR.exe | C:\Users\admin\Desktop\Test2\Qt5Network.dll | executable | |
MD5:2E3DB1CD1EC59D08706438258E86EA30 | SHA256:37275F3EA79D15A2792BF21F71F1DF825F201CF8B33AA1F94CA93D62D76B216C |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | unknown |
2656 | svchost.exe | 239.255.255.250:1900 | — | — | — | unknown |
1088 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | unknown |
Process | Message |
---|---|
Windows Driver Foundation (WDF).exe | qt.qpa.plugin: Could not find the Qt platform plugin "windows" in ""
|