| File name: | Artemis.zip |
| Full analysis: | https://app.any.run/tasks/19008014-24fb-41cd-8c7e-cfcc66011f47 |
| Verdict: | Malicious activity |
| Analysis date: | November 02, 2023, 00:23:47 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | 2599847A7535908F7C0DB0A6B16DBF0E |
| SHA1: | 702EFBA00D45134BF229D352280F7BA6274D7282 |
| SHA256: | 4FCE8D0D64CCEA6E75440354FB309D72E9C91C4D9F344B543952FB18FDD18C4F |
| SSDEEP: | 393216:6rGzQvxdnEOSvGon7f527yj/yuvCGR3O3v:WGMvx9EpvGAdZjxv53O3v |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | 0x0009 |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2014:01:04 22:33:38 |
| ZipCRC: | 0x6ac677af |
| ZipCompressedSize: | 13362568 |
| ZipUncompressedSize: | 13370880 |
| ZipFileName: | InstallBC201401.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 312 | "C:\Program Files\BenFit14\BC14.exe" | C:\Program Files\BenFit14\BC14.exe | — | explorer.exe | |||||||||||
User: admin Company: Decision Support Software LLC Integrity Level: MEDIUM Description: CSRS-FERS Benefits Calculator and Retirement Affordability Analyzer Exit code: 0 Version: 14.00 Modules
| |||||||||||||||
| 460 | "C:\Program Files\BenFit14\UpChek14.exe" | C:\Program Files\BenFit14\UpChek14.exe | — | BC14.exe | |||||||||||
User: admin Company: Decision Support Software LLC Integrity Level: MEDIUM Description: CSRS and FERS Benefits Calculator and Retirement Analyzer update check program Exit code: 3221226540 Version: 14.00 Modules
| |||||||||||||||
| 760 | "C:\ProgramData\InstallMate\{1E453EA8-BB42-419D-8067-D2477A36B761}\x86\regsvr32.exe" "C:\Windows\system32\vbSendMail.dll" /r | C:\ProgramData\InstallMate\{1E453EA8-BB42-419D-8067-D2477A36B761}\x86\regsvr32.exe | — | InstallBC201401.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Out-of-process DLL registration helper Exit code: 0 Version: 2013.12.25.1059U Modules
| |||||||||||||||
| 820 | "C:\ProgramData\InstallMate\{1E453EA8-BB42-419D-8067-D2477A36B761}\x86\regsvr32.exe" "C:\Windows\system32\CSCapt32.ocx" /r | C:\ProgramData\InstallMate\{1E453EA8-BB42-419D-8067-D2477A36B761}\x86\regsvr32.exe | — | InstallBC201401.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Out-of-process DLL registration helper Exit code: 0 Version: 2013.12.25.1059U Modules
| |||||||||||||||
| 860 | "C:\Users\admin\Desktop\InstallBC201401.exe" | C:\Users\admin\Desktop\InstallBC201401.exe | — | explorer.exe | |||||||||||
User: admin Company: Decision Support Software LLC Integrity Level: MEDIUM Description: Installer for CSRS-FERS Benefits Calculator and Retirement Analy Exit code: 3221226540 Version: 2014.1.4.1230 Modules
| |||||||||||||||
| 1016 | "C:\ProgramData\InstallMate\{1E453EA8-BB42-419D-8067-D2477A36B761}\x86\regsvr32.exe" "C:\Windows\system32\TabCtl32.Ocx" /r | C:\ProgramData\InstallMate\{1E453EA8-BB42-419D-8067-D2477A36B761}\x86\regsvr32.exe | — | InstallBC201401.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Out-of-process DLL registration helper Exit code: 0 Version: 2013.12.25.1059U Modules
| |||||||||||||||
| 1128 | "C:\ProgramData\InstallMate\{1E453EA8-BB42-419D-8067-D2477A36B761}\x86\regsvr32.exe" "C:\Windows\system32\msstkprp.dll" /r | C:\ProgramData\InstallMate\{1E453EA8-BB42-419D-8067-D2477A36B761}\x86\regsvr32.exe | — | InstallBC201401.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Out-of-process DLL registration helper Exit code: 0 Version: 2013.12.25.1059U Modules
| |||||||||||||||
| 1192 | "C:\ProgramData\InstallMate\{1E453EA8-BB42-419D-8067-D2477A36B761}\x86\regsvr32.exe" "C:\Windows\system32\RMChart.ocx" /r | C:\ProgramData\InstallMate\{1E453EA8-BB42-419D-8067-D2477A36B761}\x86\regsvr32.exe | — | InstallBC201401.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Out-of-process DLL registration helper Exit code: 0 Version: 2013.12.25.1059U Modules
| |||||||||||||||
| 1648 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --use-gl=angle --use-angle=swiftshader-webgl --mojo-platform-channel-handle=1500 --field-trial-handle=1260,i,17531025528775315216,6249779330791231545,131072 /prefetch:2 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1688 | "C:\Users\admin\Desktop\InstallBC201401.exe" | C:\Users\admin\Desktop\InstallBC201401.exe | explorer.exe | ||||||||||||
User: admin Company: Decision Support Software LLC Integrity Level: HIGH Description: Installer for CSRS-FERS Benefits Calculator and Retirement Analy Exit code: 0 Version: 2014.1.4.1230 Modules
| |||||||||||||||
| (PID) Process: | (3552) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3552) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (3552) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (3552) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (3552) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3552) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3552) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3552) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (1688) InstallBC201401.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs |
| Operation: | write | Name: | C:\Windows\system32\mscomctl.ocx |
Value: 1 | |||
| (PID) Process: | (1128) regsvr32.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7EBDAAE1-8120-11CF-899F-00AA00688B10} |
| Operation: | delete key | Name: | (default) |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1688 | InstallBC201401.exe | C:\Users\Public\Documents\bc13SupportFiles\BCHELP.pdf._tm | — | |
MD5:— | SHA256:— | |||
| 1688 | InstallBC201401.exe | C:\Users\Public\Documents\bc13SupportFiles\BCHELP.pdf | — | |
MD5:— | SHA256:— | |||
| 1688 | InstallBC201401.exe | C:\ProgramData\InstallMate\{1E453EA8-BB42-419D-8067-D2477A36B761}\Readme.txt | text | |
MD5:741E8AAD1477503D201A622321D3A49A | SHA256:7936796E1A2A732AF971E7F137960EEF4891981379D2ED103B377002E8C6C59D | |||
| 1688 | InstallBC201401.exe | C:\ProgramData\InstallMate\{1E453EA8-BB42-419D-8067-D2477A36B761}\_Setup.dll | executable | |
MD5:76DDA4C8CE17DF4591C5B9A7363854CE | SHA256:735A433ADE90EAF829FD9C11C4BF6A33DCF712F5451BBAB0B6B9435EDE7B6259 | |||
| 1688 | InstallBC201401.exe | C:\Users\admin\AppData\Local\Temp\135E2990\Setup.exe | executable | |
MD5:39C78ACD07821DF6F706F695B5E566AB | SHA256:6C70D20E43651F4F40A39F0F5B9346157C17A9BBB0E2C738C713F545550FE58F | |||
| 1688 | InstallBC201401.exe | C:\Users\admin\AppData\Local\Temp\135E2990\Setup.ico | image | |
MD5:C3926CEF276C0940DADBC8142153CEC9 | SHA256:0EC48E3C1886BC0169A4BC262F012E9B7914E3B440BB0ECC4D8123924ABC9B93 | |||
| 1688 | InstallBC201401.exe | C:\ProgramData\InstallMate\{1E453EA8-BB42-419D-8067-D2477A36B761}\Setup.ico | image | |
MD5:C3926CEF276C0940DADBC8142153CEC9 | SHA256:0EC48E3C1886BC0169A4BC262F012E9B7914E3B440BB0ECC4D8123924ABC9B93 | |||
| 1688 | InstallBC201401.exe | C:\ProgramData\InstallMate\{1E453EA8-BB42-419D-8067-D2477A36B761}\x86\regsvr32.exe | executable | |
MD5:1EBDE0A475B84CD863C5888C435DE16D | SHA256:BC184B1F003F4CA5D6AF2A38FDC201C15B028FA706BA4294777CACD8985C5DCF | |||
| 1688 | InstallBC201401.exe | C:\Users\Public\Documents\bc13SupportFiles\Table13.SPT._tm | binary | |
MD5:B8140207AC6185B6B24C75763C1BC33C | SHA256:AFC04FD5D5FDCAD43BDDF36009C4B6AA76E4E3699EFE24D9A14B3D065343B4E1 | |||
| 1688 | InstallBC201401.exe | C:\Users\Public\Documents\bc13SupportFiles\Table13.SPT | binary | |
MD5:B8140207AC6185B6B24C75763C1BC33C | SHA256:AFC04FD5D5FDCAD43BDDF36009C4B6AA76E4E3699EFE24D9A14B3D065343B4E1 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3884 | msedge.exe | GET | 301 | 209.182.199.110:80 | http://www.fedretiresoftware.com/ | unknown | html | 242 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2656 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1088 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
3884 | msedge.exe | 13.107.42.16:443 | config.edge.skype.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
1908 | msedge.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
3884 | msedge.exe | 204.79.197.239:443 | edge.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
3884 | msedge.exe | 20.31.251.109:443 | nav-edge.smartscreen.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | unknown |
3884 | msedge.exe | 209.182.199.110:80 | www.fedretiresoftware.com | IMH-IAD | US | unknown |
3884 | msedge.exe | 209.182.199.110:443 | www.fedretiresoftware.com | IMH-IAD | US | unknown |
Domain | IP | Reputation |
|---|---|---|
config.edge.skype.com |
| whitelisted |
www.fedretiresoftware.com |
| whitelisted |
edge.microsoft.com |
| whitelisted |
nav-edge.smartscreen.microsoft.com |
| whitelisted |
data-edge.smartscreen.microsoft.com |
| whitelisted |
fedretiresoftware.com |
| unknown |
fonts.gstatic.com |
| whitelisted |
fonts.googleapis.com |
| whitelisted |
www.googletagmanager.com |
| whitelisted |
hcaptcha.com |
| whitelisted |