analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

setup_nx1OhGbZ_MALICIOUS.zip

Full analysis: https://app.any.run/tasks/6a1b7f3c-0de7-44e2-ac97-1fbfd99b5cce
Verdict: Malicious activity
Analysis date: April 01, 2023, 00:38:15
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

7EAE0F42B76EA57FB7EA8F0DF7F0051A

SHA1:

051C0F3B0FDDD2AE8519A9C1E45055509F074CBB

SHA256:

4F85978A0B19F386CE2B1A4555C811A05BFC41101E06A76EC7F407E952AA9D68

SSDEEP:

196608:pKM5aUpAI6rSLKSu9gqUd09yHwP9ITXFiFA50ycJFhWwGZJhHEx:gWP8eBuCHI9CYyOcwybkx

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • setup_nx1OhGbZ.exe (PID: 3496)
      • setup_nx1OhGbZ.exe (PID: 660)
    • Starts NET.EXE for service management

      • is-M8M6N.tmp (PID: 1592)
      • net.exe (PID: 3552)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • setup_nx1OhGbZ.exe (PID: 660)
      • is-M8M6N.tmp (PID: 1592)
    • Reads the Windows owner or organization settings

      • is-M8M6N.tmp (PID: 1592)
    • Reads the Internet Settings

      • IC331.exe (PID: 2452)
  • INFO

    • Manual execution by a user

      • setup_nx1OhGbZ.exe (PID: 3496)
      • setup_nx1OhGbZ.exe (PID: 660)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2064)
    • Create files in a temporary directory

      • setup_nx1OhGbZ.exe (PID: 660)
      • is-M8M6N.tmp (PID: 1592)
      • IC331.exe (PID: 2452)
    • Checks supported languages

      • is-M8M6N.tmp (PID: 1592)
      • setup_nx1OhGbZ.exe (PID: 660)
      • IC331.exe (PID: 2452)
      • IC331.exe (PID: 3592)
    • Reads the computer name

      • is-M8M6N.tmp (PID: 1592)
      • IC331.exe (PID: 2452)
      • IC331.exe (PID: 3592)
    • The process checks LSA protection

      • is-M8M6N.tmp (PID: 1592)
      • IC331.exe (PID: 2452)
      • IC331.exe (PID: 3592)
    • Application was dropped or rewritten from another process

      • is-M8M6N.tmp (PID: 1592)
    • Creates files in the program directory

      • is-M8M6N.tmp (PID: 1592)
    • Reads the machine GUID from the registry

      • IC331.exe (PID: 3592)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: .............exe
ZipUncompressedSize: 6120168
ZipCompressedSize: 5638711
ZipCRC: 0x2246b6f2
ZipModifyDate: 2019:11:07 00:30:48
ZipCompression: Deflated
ZipBitFlag: -
ZipRequiredVersion: 20
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
51
Monitored processes
10
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start drop and start winrar.exe setup_nx1ohgbz.exe no specs setup_nx1ohgbz.exe is-m8m6n.tmp net.exe no specs ic331.exe net1.exe no specs net.exe no specs ic331.exe net1.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2064"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\setup_nx1OhGbZ_MALICIOUS.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\lpk.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\sechost.dll
3496"C:\Users\admin\Desktop\setup_nx1OhGbZ.exe" C:\Users\admin\Desktop\setup_nx1OhGbZ.exeexplorer.exe
User:
admin
Company:
Ride Software
Integrity Level:
MEDIUM
Description:
Image Comparer
Exit code:
3221226540
Version:
0.0.3.29
Modules
Images
c:\users\admin\desktop\setup_nx1ohgbz.exe
c:\windows\system32\ntdll.dll
660"C:\Users\admin\Desktop\setup_nx1OhGbZ.exe" C:\Users\admin\Desktop\setup_nx1OhGbZ.exe
explorer.exe
User:
admin
Company:
Ride Software
Integrity Level:
HIGH
Description:
Image Comparer
Version:
0.0.3.29
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\desktop\setup_nx1ohgbz.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
1592"C:\Users\admin\AppData\Local\Temp\is-EU987.tmp\is-M8M6N.tmp" /SL4 $60128 "C:\Users\admin\Desktop\setup_nx1OhGbZ.exe" 4598089 53248 C:\Users\admin\AppData\Local\Temp\is-EU987.tmp\is-M8M6N.tmp
setup_nx1OhGbZ.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Version:
51.47.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-eu987.tmp\is-m8m6n.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
1236"C:\Windows\system32\net.exe" helpmsg 25C:\Windows\System32\net.exeis-M8M6N.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Net Command
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\net.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\netutils.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\browcli.dll
2452"C:\Program Files\ImageComparer\IC331.exe"C:\Program Files\ImageComparer\IC331.exe
is-M8M6N.tmp
User:
admin
Integrity Level:
HIGH
Exit code:
0
Version:
1.0.3.30
Modules
Images
c:\program files\imagecomparer\ic331.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2936C:\Windows\system32\net1 helpmsg 25C:\Windows\System32\net1.exenet.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Net Command
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\net1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dsrole.dll
c:\windows\system32\netutils.dll
3552"C:\Windows\system32\net.exe" pause ImageComparer331C:\Windows\System32\net.exeis-M8M6N.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Net Command
Exit code:
2
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\net.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\netutils.dll
c:\windows\system32\samcli.dll
3592"C:\Program Files\ImageComparer\IC331.exe" b63ae5a0ee4717297ebfa1fdb7f3c490C:\Program Files\ImageComparer\IC331.exe
is-M8M6N.tmp
User:
admin
Integrity Level:
HIGH
Version:
1.0.3.30
Modules
Images
c:\program files\imagecomparer\ic331.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\version.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\sechost.dll
3864C:\Windows\system32\net1 pause ImageComparer331C:\Windows\System32\net1.exenet.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Net Command
Exit code:
2
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\net1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dsrole.dll
c:\windows\system32\samcli.dll
Total events
4 388
Read events
4 350
Write events
38
Delete events
0

Modification events

(PID) Process:(2064) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16D\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2064) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(2064) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2064) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(2064) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2064) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2064) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2064) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2064) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
(PID) Process:(2064) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\General
Operation:writeName:LastFolder
Value:
C:\Users\admin\Desktop
Executable files
24
Suspicious files
2
Text files
110
Unknown types
14

Dropped files

PID
Process
Filename
Type
1592is-M8M6N.tmpC:\Program Files\ImageComparer\is-F24JV.tmp
MD5:
SHA256:
1592is-M8M6N.tmpC:\Program Files\ImageComparer\IC331.exe
MD5:
SHA256:
1592is-M8M6N.tmpC:\Program Files\ImageComparer\unins000.exeexecutable
MD5:96849FA92EF62435996A9D9C408A89EC
SHA256:645FBB9E61D046DE381D93184CCEC4217FB73798A8E49FDF0C7541158DFF0436
660setup_nx1OhGbZ.exeC:\Users\admin\AppData\Local\Temp\is-EU987.tmp\is-M8M6N.tmpexecutable
MD5:F27688E08D7E37A05550CB5F54638CEB
SHA256:D1E139D7B26CFE14880626639A10CAB84B75F88DBD276D0D60CBD7BF6B97D068
1592is-M8M6N.tmpC:\Program Files\ImageComparer\is-LT8IA.tmpexecutable
MD5:96849FA92EF62435996A9D9C408A89EC
SHA256:645FBB9E61D046DE381D93184CCEC4217FB73798A8E49FDF0C7541158DFF0436
2064WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2064.49842\setup_nx1OhGbZ.exeexecutable
MD5:DA7AC3A3E4E984577909C5E851E09B1E
SHA256:7D675185BA56CD703153D3DAB94D6CA44BD364BD72322771C3963ED592ED0E92
1592is-M8M6N.tmpC:\Program Files\ImageComparer\bolide.urltext
MD5:B21E0D429B97AB92EDE6E27D983703B8
SHA256:96EF4DBBA4E8149D6A8B1B29C8627ABDDD218AC1526A7825353303CB3EEBF9FF
1592is-M8M6N.tmpC:\Program Files\ImageComparer\license.rtftext
MD5:1B3506E8F4793058B3317508F9D6BC4E
SHA256:65F715CA5830E3D7604749A4E037F475D9A25E6CE88729D6083ADEB8E67C99EE
1592is-M8M6N.tmpC:\Program Files\ImageComparer\is-LTE6H.tmptext
MD5:B21E0D429B97AB92EDE6E27D983703B8
SHA256:96EF4DBBA4E8149D6A8B1B29C8627ABDDD218AC1526A7825353303CB3EEBF9FF
1592is-M8M6N.tmpC:\Users\admin\AppData\Local\Temp\is-DAPFQ.tmp\_isetup\_iscrypt.dllexecutable
MD5:A69559718AB506675E907FE49DEB71E9
SHA256:2F6294F9AA09F59A574B5DCD33BE54E16B39377984F3D5658CDA44950FA0F8FC
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
2
DNS requests
2
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3592
IC331.exe
POST
104.21.86.39:80
http://jorjfordmust.sbs/new/net_api
US
suspicious
2452
IC331.exe
GET
200
209.197.3.8:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?6456533434
US
compressed
61.1 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2452
IC331.exe
209.197.3.8:80
ctldl.windowsupdate.com
STACKPATH-CDN
US
whitelisted
104.21.86.39:80
jorjfordmust.sbs
CLOUDFLARENET
suspicious

DNS requests

Domain
IP
Reputation
ctldl.windowsupdate.com
  • 209.197.3.8
whitelisted
jorjfordmust.sbs
  • 104.21.86.39
  • 172.67.214.126
unknown

Threats

No threats detected
No debug info