File name:

Spacesniffer_1_3_0_2.zip

Full analysis: https://app.any.run/tasks/ab5334d3-1224-4bcd-a46a-1d36820d62e4
Verdict: Malicious activity
Analysis date: July 07, 2024, 02:40:42
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

31020E03CB02C0A1CB5923EA06B041E1

SHA1:

E60F353FB86D9BD515F597866334A6C36E85273D

SHA256:

51AE6351A0173C278979EC312D3407A1CDA481880BC383A91129E2CBCA7DDD18

SSDEEP:

98304:DyW1Ea30gP44Sfefn1ln3c6Ox1qLCVTdfHuA6/KELE2ItEORe0cCv0/pGnYYZcKp:8JoEsc

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 3908)
      • setup.exe (PID: 1760)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 3908)
    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 3908)
      • setup.exe (PID: 1760)
      • setup.exe (PID: 1496)
    • Starts a Microsoft application from unusual location

      • setup.exe (PID: 1760)
      • setup.exe (PID: 1496)
    • Executable content was dropped or overwritten

      • setup.exe (PID: 1760)
    • Checks Windows Trust Settings

      • setup.exe (PID: 1760)
      • setup.exe (PID: 1496)
    • Connects to unusual port

      • setup.exe (PID: 1760)
      • setup.exe (PID: 1496)
  • INFO

    • Checks supported languages

      • setup.exe (PID: 1760)
      • SpaceSniffer.exe (PID: 1048)
      • SpaceSniffer.exe (PID: 5236)
      • setup.exe (PID: 1496)
    • Reads the computer name

      • SpaceSniffer.exe (PID: 5236)
      • setup.exe (PID: 1760)
      • setup.exe (PID: 1496)
      • SpaceSniffer.exe (PID: 1048)
    • Checks proxy server information

      • setup.exe (PID: 1760)
      • setup.exe (PID: 1496)
    • Reads the machine GUID from the registry

      • setup.exe (PID: 1760)
      • setup.exe (PID: 1496)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3908)
    • Manual execution by a user

      • setup.exe (PID: 1496)
    • Reads the software policy settings

      • setup.exe (PID: 1760)
      • setup.exe (PID: 1496)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2024:06:26 10:24:28
ZipCRC: 0x750a3590
ZipCompressedSize: 921
ZipUncompressedSize: 1944
ZipFileName: Disclaimer.txt
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
128
Monitored processes
5
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe setup.exe spacesniffer.exe no specs setup.exe spacesniffer.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1048C:\Users\Public\Downloads\SpaceSniffer.exesetup.exe
User:
admin
Company:
Uderzo Software e Consulenza Informatica
Integrity Level:
MEDIUM
Description:
Disk space analysis tool
Version:
1.3.0.2
Modules
Images
c:\users\public\downloads\spacesniffer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
1496"C:\Users\admin\Desktop\setup.exe" C:\Users\admin\Desktop\setup.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\users\admin\desktop\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
1760"C:\Users\admin\AppData\Local\Temp\Rar$EXa3908.39263\setup.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3908.39263\setup.exe
WinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3908.39263\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
3908"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\Spacesniffer_1_3_0_2.zipC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
5236C:\Users\Public\Downloads\SpaceSniffer.exesetup.exe
User:
admin
Company:
Uderzo Software e Consulenza Informatica
Integrity Level:
MEDIUM
Description:
Disk space analysis tool
Exit code:
0
Version:
1.3.0.2
Modules
Images
c:\users\public\downloads\spacesniffer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
Total events
13 115
Read events
13 075
Write events
40
Delete events
0

Modification events

(PID) Process:(3908) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3908) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3908) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\GoogleChromeEnterpriseBundle64.zip
(PID) Process:(3908) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Spacesniffer_1_3_0_2.zip
(PID) Process:(3908) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3908) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3908) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3908) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3908) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3908) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
Executable files
9
Suspicious files
4
Text files
4
Unknown types
0

Dropped files

PID
Process
Filename
Type
3908WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3908.39263\Disclaimer.txttext
MD5:9BE250E513AEB89502B35F21C0FBF0C4
SHA256:AC88CF90B4E7643F27EA762D1643CC58D631DC021135BF9B4F02C43A2242894B
3908WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3908.39263\wer.dllexecutable
MD5:DE0C40C4D3AAF9507F4FAF89D20B229A
SHA256:D6AA982536115DAA01E30F8515415F1C436D73ABA3F42D8CE3160E1F5870214E
1760setup.exeC:\Users\Public\Downloads\SpaceSniffer.exeexecutable
MD5:B310E7335EAE66A533E985B377E81612
SHA256:FC0629D450F8A57BC93E1BA1CDEF0BFF49C1A4CF0725C2A1F52116FD67D9FE8E
3908WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3908.39263\werx.dllexecutable
MD5:0A0CD54859A60630714A076934111E7C
SHA256:C91552FCD8829E182B620D29B333ED5187296F9612F79815F87267A2817823F9
3908WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3908.5956\vcruntime140.dllexecutable
MD5:699DD61122D91E80ABDFCC396CE0EC10
SHA256:F843CD00D9AFF9A902DD7C98D6137639A10BD84904D81A085C28A3B29F8223C1
3908WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3908.5956\Release Notes.txttext
MD5:46FEB3FF3CAED4B53B508DB39664B52E
SHA256:1E3E232CAC8757FBFA45DF3D6288860C0CE7F3425BD3CBAF051510B8928B28AA
3908WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3908.5956\SpaceSniffer User Manual.pdfpdf
MD5:3D1F422D948C87957A56A23593818A8D
SHA256:9EF8CF15B269454E4443FC7F99AA7A582DBD98CE108A45485B3BCF3BD437286C
3908WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3908.5956\Disclaimer.txttext
MD5:9BE250E513AEB89502B35F21C0FBF0C4
SHA256:AC88CF90B4E7643F27EA762D1643CC58D631DC021135BF9B4F02C43A2242894B
3908WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3908.5956\setup.exeexecutable
MD5:0A9EE8F50EF336B422521E133F6CC751
SHA256:4A135F60A5193F543D452C9D01E98546C44680E7BDF6C043E8837B1DFEAE3875
3908WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3908.39263\vcruntime140.dllexecutable
MD5:699DD61122D91E80ABDFCC396CE0EC10
SHA256:F843CD00D9AFF9A902DD7C98D6137639A10BD84904D81A085C28A3B29F8223C1
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
35
DNS requests
6
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3832
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
unknown
2196
MoUsoCoreWorker.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
unknown
3040
OfficeClickToRun.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D
unknown
unknown
3832
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4032
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:137
whitelisted
4448
svchost.exe
40.127.240.158:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
4392
RUXIMICS.exe
40.127.240.158:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
2196
MoUsoCoreWorker.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
2196
MoUsoCoreWorker.exe
40.127.240.158:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
4
System
192.168.100.255:138
whitelisted
6004
svchost.exe
40.127.240.158:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
4448
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1760
setup.exe
91.92.252.21:9443
BG
unknown

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
whitelisted
self.events.data.microsoft.com
  • 20.42.65.91
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
slscr.update.microsoft.com
  • 20.114.59.183
whitelisted
www.microsoft.com
  • 23.35.229.160
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.3.187.198
whitelisted

Threats

PID
Process
Class
Message
1760
setup.exe
Misc Attack
ET DROP Spamhaus DROP Listed Traffic Inbound group 13
No debug info