File name:

Stardock Fences v3.0.9.11 Final Eng_Rus.7z

Full analysis: https://app.any.run/tasks/a9419678-a525-410b-b78a-708a5c7b0a21
Verdict: Malicious activity
Analysis date: October 23, 2023, 19:08:29
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-7z-compressed
File info: 7-zip archive data, version 0.4
MD5:

A52336A26571CAF37463DFFF7CDB444A

SHA1:

9E498033464E15BAC95218682292CB4857A3D6B7

SHA256:

51E0AC976928850001034CA2C0E47B938D5D31D42CBA285268DC8333708DEB0A

SSDEEP:

98304:Y91d4610ItV4nYfawe0Hx5bX9DCMV/5oKxN7ZB/xk+JynG83Avpw3nIlJxDlA1Je:sc59TGw1NYnT+O8gCm

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Fences3-sd-setup.exe (PID: 844)
      • irsetup.exe (PID: 2312)
    • Application was dropped or rewritten from another process

      • Fences3-sd-setup.exe (PID: 3532)
      • Fences3-sd-setup.exe (PID: 844)
      • irsetup.exe (PID: 2312)
      • GetMachineSID.exe (PID: 3404)
    • Loads dropped or rewritten executable

      • irsetup.exe (PID: 2312)
  • SUSPICIOUS

    • Start notepad (likely ransomware note)

      • WinRAR.exe (PID: 3628)
    • Reads the Internet Settings

      • Fences3-sd-setup.exe (PID: 844)
      • irsetup.exe (PID: 2312)
    • Reads the Windows owner or organization settings

      • irsetup.exe (PID: 2312)
    • The process exported the data from the registry

      • irsetup.exe (PID: 2312)
  • INFO

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 3628)
    • Checks supported languages

      • Fences3-sd-setup.exe (PID: 844)
      • irsetup.exe (PID: 2312)
      • GetMachineSID.exe (PID: 3404)
    • Create files in a temporary directory

      • Fences3-sd-setup.exe (PID: 844)
      • irsetup.exe (PID: 2312)
      • GetMachineSID.exe (PID: 3404)
      • reg.exe (PID: 2280)
    • Reads the computer name

      • Fences3-sd-setup.exe (PID: 844)
      • irsetup.exe (PID: 2312)
      • GetMachineSID.exe (PID: 3404)
    • Checks proxy server information

      • irsetup.exe (PID: 2312)
    • Reads the machine GUID from the registry

      • irsetup.exe (PID: 2312)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.7z | 7-Zip compressed archive (v0.4) (57.1)
.7z | 7-Zip compressed archive (gen) (42.8)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
48
Monitored processes
7
Malicious processes
4
Suspicious processes
1

Behavior graph

Click at the process to see the details
drop and start drop and start start drop and start drop and start winrar.exe no specs notepad.exe no specs fences3-sd-setup.exe no specs fences3-sd-setup.exe irsetup.exe getmachinesid.exe no specs reg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
124"C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\AppData\Local\Temp\Rar$DIa3628.10809\About the program.txtC:\Windows\System32\notepad.exeWinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\notepad.exe
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
844"C:\Users\admin\AppData\Local\Temp\Rar$EXa3628.11428\Stardock Fences v3.0.9.11 Final Eng_Rus\Fences3-sd-setup.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3628.11428\Stardock Fences v3.0.9.11 Final Eng_Rus\Fences3-sd-setup.exe
WinRAR.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup Application
Exit code:
5
Version:
9.5.1.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3628.11428\stardock fences v3.0.9.11 final eng_rus\fences3-sd-setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
2280"C:\Windows\system32\reg.exe" export HKLM\Software\Stardock C:\Users\admin\AppData\Local\Temp\registry_export.txt /yC:\Windows\System32\reg.exeirsetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Registry Console Tool
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\reg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
2312"C:\Users\admin\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe" __IRAOFF:1954746 "__IRAFN:C:\Users\admin\AppData\Local\Temp\Rar$EXa3628.11428\Stardock Fences v3.0.9.11 Final Eng_Rus\Fences3-sd-setup.exe" "__IRCT:3" "__IRTSS:12702823" "__IRSID:S-1-5-21-1302019708-1500728564-335382590-1000"C:\Users\admin\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe
Fences3-sd-setup.exe
User:
admin
Company:
Indigo Rose Corporation
Integrity Level:
HIGH
Description:
Setup Application
Exit code:
5
Version:
9.5.1.0
Modules
Images
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
3404"C:\Users\admin\AppData\Local\Temp\_ir_sf_temp_0\GetMachineSID.exe" C:\Users\admin\AppData\Local\Temp\_ir_sf_temp_0\GetMachineSID.tmpC:\Users\admin\AppData\Local\Temp\_ir_sf_temp_0\GetMachineSID.exeirsetup.exe
User:
admin
Company:
Stardock Software, Inc
Integrity Level:
HIGH
Description:
Installer Helper
Exit code:
0
Version:
1.0.0.1
Modules
Images
c:\users\admin\appdata\local\temp\_ir_sf_temp_0\getmachinesid.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
3532"C:\Users\admin\AppData\Local\Temp\Rar$EXa3628.11428\Stardock Fences v3.0.9.11 Final Eng_Rus\Fences3-sd-setup.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3628.11428\Stardock Fences v3.0.9.11 Final Eng_Rus\Fences3-sd-setup.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup Application
Exit code:
3221226540
Version:
9.5.1.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3628.11428\stardock fences v3.0.9.11 final eng_rus\fences3-sd-setup.exe
c:\windows\system32\ntdll.dll
3628"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Stardock Fences v3.0.9.11 Final Eng_Rus.7z"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\comdlg32.dll
Total events
2 984
Read events
2 937
Write events
47
Delete events
0

Modification events

(PID) Process:(3628) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3628) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(3628) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3628) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3628) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3628) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3628) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3628) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3628) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3628) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
Executable files
6
Suspicious files
2
Text files
14
Unknown types
0

Dropped files

PID
Process
Filename
Type
2312irsetup.exeC:\Users\admin\AppData\Local\Temp\_ir_sf_temp_0\IRIMG2.JPGimage
MD5:AC40DED6736E08664F2D86A65C47EF60
SHA256:F35985FE1E46A767BE7DCEA35F8614E1EDD60C523442E6C2C2397D1E23DBD3EA
3628WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3628.11428\Stardock Fences v3.0.9.11 Final Eng_Rus\Fences3-sd-setup.exe.md5text
MD5:9E28EAF239EAAE9055A2DB2206039CFD
SHA256:014ED731FB39E2F33F6DAD5693EB9800F77387EC19660B8A771C29EB53E2434B
844Fences3-sd-setup.exeC:\Users\admin\AppData\Local\Temp\_ir_sf_temp_0\lua5.1.dllexecutable
MD5:05CEB6D2E88A896D6ADA0AB3F0DC40AA
SHA256:B574D89422AFCAAE5446D8FD88D3B7CB48D608CF5411DB761916B35C9999B41A
3628WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3628.11428\Stardock Fences v3.0.9.11 Final Eng_Rus\Читать.txttext
MD5:F15D0656E5C671A36E4459930EE46B67
SHA256:C4B83BA1BF61B1F7BEDB542C8A6493E39185C6F33589F4A5EEF24C17C3E4EBAA
3628WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3628.11428\Stardock Fences v3.0.9.11 Final Eng_Rus\Fences3-sd-setup.exeexecutable
MD5:178BA67902FC6A05A040ED3D2F537A95
SHA256:92235DA746A26B69A05ED67D9CCF2113996F9EA38DB6B39D41665FB52847394B
2312irsetup.exeC:\Users\admin\AppData\Local\Temp\_ir_sf_temp_0\Unicode.lmdexecutable
MD5:513C279740C287DEC3508AE26D7916C0
SHA256:A285299F207A0093158C05D46996B880032A9B11FB456CE78BBA18988BE9B14A
2312irsetup.exeC:\Users\admin\AppData\Local\Temp\_ir_sf_temp_0\irsetup.datbinary
MD5:BDE6F93A56946AF3C4F0A08C2CCC2C1A
SHA256:656CFE99F9A0AD977458534D338276E7CB656F1D29E771E03BB80666B528FE26
3628WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DIa3628.10809\About the program.txttext
MD5:E45B9A8AB8D926D3D0962DA43D8F2364
SHA256:980BCA7FC719EA3CB280963A4AA769F8D6C14BA813BFD090A95FA767F560C5FE
2312irsetup.exeC:\Users\admin\AppData\Local\Temp\_ir_sf_temp_0\GetMachineSID.exeexecutable
MD5:55BBF335F75F2A2FE0A5DAF603964D41
SHA256:723ADAE0E69127A6BFBC65C5EF552A351264205EA5E2BC3B80E505FEAA5D0E43
2312irsetup.exeC:\Users\admin\AppData\Local\Temp\_ir_sf_temp_0\eula.txttext
MD5:B255E01ECEDAD3F7A600109B01943074
SHA256:5B756A48762AD896DE58B973E4B87D4E76FF25023A727F0A08AAD9EA66E7B843
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
6
DNS requests
1
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2312
irsetup.exe
POST
200
66.79.209.82:80
http://install.api.stardock.net/installer/Initialize/?format=xml
unknown
text
453 b
unknown
2312
irsetup.exe
POST
200
66.79.209.82:80
http://install.api.stardock.net/installer/SaveInstallStats/?format=xml
unknown
text
219 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2656
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:137
whitelisted
2312
irsetup.exe
66.79.209.82:80
install.api.stardock.net
TELNET
US
unknown
4
System
192.168.100.255:138
whitelisted
1088
svchost.exe
224.0.0.252:5355
unknown

DNS requests

Domain
IP
Reputation
install.api.stardock.net
  • 66.79.209.82
whitelisted

Threats

Found threats are available for the paid subscriptions
2 ETPRO signatures available at the full report
No debug info