File name:

Macromedia Flash 4.7z

Full analysis: https://app.any.run/tasks/9f072851-65c2-4c1d-849c-fa54225b85fd
Verdict: Malicious activity
Analysis date: March 26, 2025, 22:33:07
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
arch-exec
arch-doc
Indicators:
MIME: application/x-7z-compressed
File info: 7-zip archive data, version 0.2
MD5:

5B3BEC7CEFE30B8AC511E80EE761EBC5

SHA1:

C29CAFF4EEF1B0DF6B8500A0546D927B921B6615

SHA256:

523E5BF7E11010B9B8A699343329F5FA84D7597762A95D0496B7ECF198E27210

SSDEEP:

98304:LtqpSw5JjBJipV+Z/u4bYd6VCocH3sm7ORctEDEefVD7ipFq1xhcQDQ0Zuj06y7x:4M9mQ9YnYOvzrv7X7qGQ/Acxe

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 2848)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 2848)
    • Process drops legitimate windows executable

      • _INS5576._MP (PID: 1784)
    • Creates file in the systems drive root

      • _ISDel.exe (PID: 1888)
    • There is functionality for taking screenshot (YARA)

      • Setup.exe (PID: 1460)
      • Setup.exe (PID: 268)
      • _INS5576._MP (PID: 1784)
    • Executable content was dropped or overwritten

      • Setup.exe (PID: 1460)
      • Setup.exe (PID: 268)
      • _INS5576._MP (PID: 1784)
    • Starts application with an unusual extension

      • Setup.exe (PID: 268)
    • Creates a software uninstall entry

      • _INS5576._MP (PID: 1784)
    • Creates/Modifies COM task schedule object

      • _INS5576._MP (PID: 1784)
  • INFO

    • The sample compiled with english language support

      • Setup.exe (PID: 1460)
      • WinRAR.exe (PID: 2848)
      • Setup.exe (PID: 268)
      • _INS5576._MP (PID: 1784)
    • Checks supported languages

      • Setup.exe (PID: 1460)
      • Setup.exe (PID: 268)
      • _ISDel.exe (PID: 1888)
      • _INS5576._MP (PID: 1784)
      • Flash.exe (PID: 3160)
      • Flash.exe (PID: 2732)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2848)
    • Reads the computer name

      • Setup.exe (PID: 268)
      • _INS5576._MP (PID: 1784)
      • _ISDel.exe (PID: 1888)
      • Flash.exe (PID: 2732)
      • Flash.exe (PID: 3160)
    • Create files in a temporary directory

      • Setup.exe (PID: 1460)
      • Setup.exe (PID: 268)
      • _INS5576._MP (PID: 1784)
      • Flash.exe (PID: 3160)
      • Flash.exe (PID: 2732)
    • Reads the Internet Settings

      • explorer.exe (PID: 1440)
    • Reads the machine GUID from the registry

      • Flash.exe (PID: 3160)
      • Flash.exe (PID: 2732)
    • Creates files in the program directory

      • _INS5576._MP (PID: 1784)
    • Reads security settings of Internet Explorer

      • explorer.exe (PID: 1440)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.7z | 7-Zip compressed archive (gen) (100)

EXIF

ZIP

FileVersion: 7z v0.02
ModifyDate: 2017:08:02 01:24:12+00:00
ArchivedFileName: Macromedia Flash 4
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
45
Monitored processes
10
Malicious processes
2
Suspicious processes
2

Behavior graph

Click at the process to see the details
start winrar.exe setup.exe no specs setup.exe setup.exe _ins5576._mp _isdel.exe no specs explorer.exe no specs explorer.exe no specs flash.exe no specs flash.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
268"C:\Users\admin\AppData\Local\Temp\pft4021~tmp\Setup.exe" /SMSC:\Users\admin\AppData\Local\Temp\pft4021~tmp\Setup.exe
Setup.exe
User:
admin
Company:
InstallShield Software Corporation
Integrity Level:
HIGH
Description:
32-bit Setup Launcher
Version:
5, 52, 164, 0
Modules
Images
c:\users\admin\appdata\local\temp\pft4021~tmp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1440C:\Windows\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -EmbeddingC:\Windows\explorer.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1460"C:\Users\admin\AppData\Local\Temp\Rar$EXa2848.21210\Macromedia Flash 4\Setup.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2848.21210\Macromedia Flash 4\Setup.exe
WinRAR.exe
User:
admin
Company:
InstallShield Software Corporation
Integrity Level:
HIGH
Description:
PackageForTheWeb Stub
Version:
2.04.001
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2848.21210\macromedia flash 4\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\comctl32.dll
1484"C:\Users\admin\AppData\Local\Temp\Rar$EXa2848.21210\Macromedia Flash 4\Setup.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2848.21210\Macromedia Flash 4\Setup.exeWinRAR.exe
User:
admin
Company:
InstallShield Software Corporation
Integrity Level:
MEDIUM
Description:
PackageForTheWeb Stub
Exit code:
3221226540
Version:
2.04.001
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2848.21210\macromedia flash 4\setup.exe
c:\windows\system32\ntdll.dll
1784C:\Users\admin\AppData\Local\Temp\_ISTMP1.DIR\_INS5576._MPC:\Users\admin\AppData\Local\Temp\_ISTMP1.DIR\_INS5576._MP
Setup.exe
User:
admin
Company:
InstallShield Software Corporation
Integrity Level:
HIGH
Description:
InstallShield Engine
Version:
5, 53, 168, 0
Modules
Images
c:\users\admin\appdata\local\temp\_istmp1.dir\_ins5576._mp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winspool.drv
1888C:\Users\admin\AppData\Local\Temp\pft4021~tmp\_ISDEL.EXEC:\Users\admin\AppData\Local\Temp\pft4021~tmp\_ISDel.exeSetup.exe
User:
admin
Company:
InstallShield Software Corporation
Integrity Level:
HIGH
Description:
32-bit InstallShield Deleter.
Version:
5, 51, 138, 0
Modules
Images
c:\users\admin\appdata\local\temp\pft4021~tmp\_isdel.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\apphelp.dll
2732"C:\Program Files\Macromedia\Flash 4\Flash.exe" C:\Program Files\Macromedia\Flash 4\Flash.exeexplorer.exe
User:
admin
Company:
Macromedia, Inc.
Integrity Level:
MEDIUM
Description:
Flash 4.0 r4
Version:
4,0,4,0
Modules
Images
c:\program files\macromedia\flash 4\flash.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\avifil32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2848"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Macromedia Flash 4.7z"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3160"C:\Program Files\Macromedia\Flash 4\Flash.exe" C:\Program Files\Macromedia\Flash 4\Flash.exeexplorer.exe
User:
admin
Company:
Macromedia, Inc.
Integrity Level:
MEDIUM
Description:
Flash 4.0 r4
Exit code:
2
Version:
4,0,4,0
Modules
Images
c:\program files\macromedia\flash 4\flash.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\avifil32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3856explorer.exe "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Macromedia Flash 4"C:\Windows\explorer.exe_INS5576._MP
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
11 195
Read events
10 991
Write events
202
Delete events
2

Modification events

(PID) Process:(2848) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2848) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2848) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2848) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2848) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(2848) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(2848) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Macromedia Flash 4.7z
(PID) Process:(2848) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2848) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2848) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
26
Suspicious files
72
Text files
552
Unknown types
1

Dropped files

PID
Process
Filename
Type
1460Setup.exeC:\Users\admin\AppData\Local\Temp\pft4021~tmp\pftw1.pkg
MD5:
SHA256:
1460Setup.exeC:\Users\admin\AppData\Local\Temp\pft4021~tmp\data1.cab
MD5:
SHA256:
1460Setup.exeC:\Users\admin\AppData\Local\Temp\pft4021~tmp\lang.dattext
MD5:70627BD56FE92A5C97027CBBD88BACD0
SHA256:B67A09F3FE25B08025810BBB20B8FAE05672D0A723F2DBED84F04224A89E6344
1460Setup.exeC:\Users\admin\AppData\Local\Temp\pft4021~tmp\layout.binbinary
MD5:0BA51445DABE940024B128D331A76C43
SHA256:078BD59F2221773391A8C435B4C2B1E12EE8996845FCE2CC7D017FDA687D5D59
1460Setup.exeC:\Users\admin\AppData\Local\Temp\pft4021~tmp\data1.hdrcompressed
MD5:EBA4A36F6A760DEEE3DEE8DC3D8A8F8E
SHA256:8873ABF5A3E61A96D9686F0FE83EDBDCC510E03C9CAB2B4451C496E0B2D7E8DC
2848WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2848.21210\Macromedia Flash 4\Setup.exeexecutable
MD5:FA302BD51465095DB2808AB1CA1B9FC2
SHA256:74B4F2EFD76A09EE5023095B2CC487D3AD40895AC780C39F96391540595B3EEA
1460Setup.exeC:\Users\admin\AppData\Local\Temp\pft4021~tmp\Setup.bmpimage
MD5:96084BD9E01E5F4184DD55306E2DAEE9
SHA256:34C7EDCAB8374D8E774EA9191883521C20FE1C908E6ADA48C0BB0D6CE8528AFE
1460Setup.exeC:\Users\admin\AppData\Local\Temp\pft4021~tmp\DATA.TAGtext
MD5:B12927B0A055949C01988004D85E4399
SHA256:64DE6A46FA4008FB42FA6E7749F241EFE7D74C3EB327E50570DBE7CD7E23B645
1460Setup.exeC:\Users\admin\AppData\Local\Temp\pft4021~tmp\setup.lidtext
MD5:1B79748E93A541CC1590505B6C72828A
SHA256:708D29C649525882937031B3D73CC851B7B1BC30772EB4E0E2A71523908F2EB5
1460Setup.exeC:\Users\admin\AppData\Local\Temp\pft4021~tmp\_ISDel.exeexecutable
MD5:51161BF79F25FF278912005078AD93D5
SHA256:B5DC0FEB738A91CE3CFA982647FE2779787335C6C2C598D5B49818565D7C3E84
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
5
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.174
whitelisted

Threats

No threats detected
No debug info