File name:

Macromedia Flash 4.7z

Full analysis: https://app.any.run/tasks/9f072851-65c2-4c1d-849c-fa54225b85fd
Verdict: Malicious activity
Analysis date: March 26, 2025, 22:33:07
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
arch-exec
arch-doc
Indicators:
MIME: application/x-7z-compressed
File info: 7-zip archive data, version 0.2
MD5:

5B3BEC7CEFE30B8AC511E80EE761EBC5

SHA1:

C29CAFF4EEF1B0DF6B8500A0546D927B921B6615

SHA256:

523E5BF7E11010B9B8A699343329F5FA84D7597762A95D0496B7ECF198E27210

SSDEEP:

98304:LtqpSw5JjBJipV+Z/u4bYd6VCocH3sm7ORctEDEefVD7ipFq1xhcQDQ0Zuj06y7x:4M9mQ9YnYOvzrv7X7qGQ/Acxe

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 2848)
  • SUSPICIOUS

    • Starts application with an unusual extension

      • Setup.exe (PID: 268)
    • Executable content was dropped or overwritten

      • _INS5576._MP (PID: 1784)
      • Setup.exe (PID: 1460)
      • Setup.exe (PID: 268)
    • Process drops legitimate windows executable

      • _INS5576._MP (PID: 1784)
    • There is functionality for taking screenshot (YARA)

      • Setup.exe (PID: 1460)
      • Setup.exe (PID: 268)
      • _INS5576._MP (PID: 1784)
    • Creates file in the systems drive root

      • _ISDel.exe (PID: 1888)
    • Creates a software uninstall entry

      • _INS5576._MP (PID: 1784)
    • Creates/Modifies COM task schedule object

      • _INS5576._MP (PID: 1784)
    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 2848)
  • INFO

    • Create files in a temporary directory

      • Setup.exe (PID: 268)
      • _INS5576._MP (PID: 1784)
      • Setup.exe (PID: 1460)
      • Flash.exe (PID: 3160)
      • Flash.exe (PID: 2732)
    • Reads the computer name

      • _ISDel.exe (PID: 1888)
      • _INS5576._MP (PID: 1784)
      • Setup.exe (PID: 268)
      • Flash.exe (PID: 3160)
      • Flash.exe (PID: 2732)
    • Checks supported languages

      • _ISDel.exe (PID: 1888)
      • _INS5576._MP (PID: 1784)
      • Setup.exe (PID: 1460)
      • Flash.exe (PID: 3160)
      • Flash.exe (PID: 2732)
      • Setup.exe (PID: 268)
    • The sample compiled with english language support

      • WinRAR.exe (PID: 2848)
      • _INS5576._MP (PID: 1784)
      • Setup.exe (PID: 1460)
      • Setup.exe (PID: 268)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2848)
    • Creates files in the program directory

      • _INS5576._MP (PID: 1784)
    • Reads the Internet Settings

      • explorer.exe (PID: 1440)
    • Reads security settings of Internet Explorer

      • explorer.exe (PID: 1440)
    • Reads the machine GUID from the registry

      • Flash.exe (PID: 3160)
      • Flash.exe (PID: 2732)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.7z | 7-Zip compressed archive (gen) (100)

EXIF

ZIP

FileVersion: 7z v0.02
ModifyDate: 2017:08:02 01:24:12+00:00
ArchivedFileName: Macromedia Flash 4
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
45
Monitored processes
10
Malicious processes
2
Suspicious processes
2

Behavior graph

Click at the process to see the details
start winrar.exe setup.exe no specs setup.exe setup.exe _ins5576._mp _isdel.exe no specs explorer.exe no specs explorer.exe no specs flash.exe no specs flash.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
268"C:\Users\admin\AppData\Local\Temp\pft4021~tmp\Setup.exe" /SMSC:\Users\admin\AppData\Local\Temp\pft4021~tmp\Setup.exe
Setup.exe
User:
admin
Company:
InstallShield Software Corporation
Integrity Level:
HIGH
Description:
32-bit Setup Launcher
Version:
5, 52, 164, 0
Modules
Images
c:\users\admin\appdata\local\temp\pft4021~tmp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1440C:\Windows\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -EmbeddingC:\Windows\explorer.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1460"C:\Users\admin\AppData\Local\Temp\Rar$EXa2848.21210\Macromedia Flash 4\Setup.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2848.21210\Macromedia Flash 4\Setup.exe
WinRAR.exe
User:
admin
Company:
InstallShield Software Corporation
Integrity Level:
HIGH
Description:
PackageForTheWeb Stub
Version:
2.04.001
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2848.21210\macromedia flash 4\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\comctl32.dll
1484"C:\Users\admin\AppData\Local\Temp\Rar$EXa2848.21210\Macromedia Flash 4\Setup.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2848.21210\Macromedia Flash 4\Setup.exeWinRAR.exe
User:
admin
Company:
InstallShield Software Corporation
Integrity Level:
MEDIUM
Description:
PackageForTheWeb Stub
Exit code:
3221226540
Version:
2.04.001
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2848.21210\macromedia flash 4\setup.exe
c:\windows\system32\ntdll.dll
1784C:\Users\admin\AppData\Local\Temp\_ISTMP1.DIR\_INS5576._MPC:\Users\admin\AppData\Local\Temp\_ISTMP1.DIR\_INS5576._MP
Setup.exe
User:
admin
Company:
InstallShield Software Corporation
Integrity Level:
HIGH
Description:
InstallShield Engine
Version:
5, 53, 168, 0
Modules
Images
c:\users\admin\appdata\local\temp\_istmp1.dir\_ins5576._mp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winspool.drv
1888C:\Users\admin\AppData\Local\Temp\pft4021~tmp\_ISDEL.EXEC:\Users\admin\AppData\Local\Temp\pft4021~tmp\_ISDel.exeSetup.exe
User:
admin
Company:
InstallShield Software Corporation
Integrity Level:
HIGH
Description:
32-bit InstallShield Deleter.
Version:
5, 51, 138, 0
Modules
Images
c:\users\admin\appdata\local\temp\pft4021~tmp\_isdel.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\apphelp.dll
2732"C:\Program Files\Macromedia\Flash 4\Flash.exe" C:\Program Files\Macromedia\Flash 4\Flash.exeexplorer.exe
User:
admin
Company:
Macromedia, Inc.
Integrity Level:
MEDIUM
Description:
Flash 4.0 r4
Version:
4,0,4,0
Modules
Images
c:\program files\macromedia\flash 4\flash.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\avifil32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2848"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Macromedia Flash 4.7z"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3160"C:\Program Files\Macromedia\Flash 4\Flash.exe" C:\Program Files\Macromedia\Flash 4\Flash.exeexplorer.exe
User:
admin
Company:
Macromedia, Inc.
Integrity Level:
MEDIUM
Description:
Flash 4.0 r4
Exit code:
2
Version:
4,0,4,0
Modules
Images
c:\program files\macromedia\flash 4\flash.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\avifil32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3856explorer.exe "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Macromedia Flash 4"C:\Windows\explorer.exe_INS5576._MP
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
11 195
Read events
10 991
Write events
202
Delete events
2

Modification events

(PID) Process:(2848) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2848) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2848) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2848) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2848) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(2848) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(2848) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Macromedia Flash 4.7z
(PID) Process:(2848) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2848) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2848) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
26
Suspicious files
72
Text files
552
Unknown types
1

Dropped files

PID
Process
Filename
Type
1460Setup.exeC:\Users\admin\AppData\Local\Temp\pft4021~tmp\pftw1.pkg
MD5:
SHA256:
1460Setup.exeC:\Users\admin\AppData\Local\Temp\pft4021~tmp\data1.cab
MD5:
SHA256:
1460Setup.exeC:\Users\admin\AppData\Local\Temp\pft4021~tmp\Setup.bmpimage
MD5:96084BD9E01E5F4184DD55306E2DAEE9
SHA256:34C7EDCAB8374D8E774EA9191883521C20FE1C908E6ADA48C0BB0D6CE8528AFE
1460Setup.exeC:\Users\admin\AppData\Local\Temp\pft4021~tmp\Setup.exeexecutable
MD5:71E6DD8A9DE4A9BAF89FCA951768059A
SHA256:5656E87DA0641C9DCFCD0EE8949CE72B3FA6A7D0E8B1FD985A16F6BD6C34CE52
1460Setup.exeC:\Users\admin\AppData\Local\Temp\pft4021~tmp\lang.dattext
MD5:70627BD56FE92A5C97027CBBD88BACD0
SHA256:B67A09F3FE25B08025810BBB20B8FAE05672D0A723F2DBED84F04224A89E6344
1460Setup.exeC:\Users\admin\AppData\Local\Temp\pft4021~tmp\_ISDel.exeexecutable
MD5:51161BF79F25FF278912005078AD93D5
SHA256:B5DC0FEB738A91CE3CFA982647FE2779787335C6C2C598D5B49818565D7C3E84
2848WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2848.21210\Macromedia Flash 4\Macromedia Flash 4.txttext
MD5:A18067C260F86F3D7A0B3C0214BF2978
SHA256:CAF380AD8D25B2E7AE6C652541E77FB3C0D3E02EC1A83B96A5FA0E59242241B5
1460Setup.exeC:\Users\admin\AppData\Local\Temp\pft4021~tmp\SETUP.INItext
MD5:92D9D705846B2F819F89BB156C9DB615
SHA256:2FE4609F3052E6383BA2F51A215994E1B254944957BC35C6DC5BFF49AC270380
1460Setup.exeC:\Users\admin\AppData\Local\Temp\pft4021~tmp\_INST32I.EX_??_
MD5:6229A86A1D291C311DA49A7D69A49A1F
SHA256:B2FF4E8402A5160C491B1AC7EBA0073FBBE2220DCE107441461B250544EFF35A
1460Setup.exeC:\Users\admin\AppData\Local\Temp\pft4021~tmp\_sys1.hdrcompressed
MD5:B32283A102F455A44D6526C7A4AE67C5
SHA256:EB0A6CFD46B7FAD31A6640C797A077C4E78A4DF98C5B1CCF434E591DB895B35A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
5
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.174
whitelisted

Threats

No threats detected
No debug info