File name: | BustaGuess.zip |
Full analysis: | https://app.any.run/tasks/cdadae42-381e-46bb-88a6-a0dcd2866c4e |
Verdict: | Malicious activity |
Analysis date: | February 19, 2024, 11:25:17 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/zip |
File info: | Zip archive data, at least v2.0 to extract, compression method=store |
MD5: | E6E2ECC3AFC2154E190483793E161556 |
SHA1: | 20FFF3BE33BE155A5E36F5339E8F5523630674C9 |
SHA256: | 54090DC19A8647EA05E020D722AC2D40A6481E7C4ACF07ED7B3EAD70A91A776D |
SSDEEP: | 98304:WGSN2NknwfciGDNcHmY9IkvxqNHleBj5F20PaDKrlCDEWWAE2+6Z:WRIGwEiGDyGY9pxxjZZWWAEc |
.zip | | | ZIP compressed archive (100) |
---|
ZipRequiredVersion: | 20 |
---|---|
ZipBitFlag: | - |
ZipCompression: | None |
ZipModifyDate: | 2022:03:17 17:20:36 |
ZipCRC: | 0x00000000 |
ZipCompressedSize: | - |
ZipUncompressedSize: | - |
ZipFileName: | BustaGuess/ |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
268 | schtasks.exe /create /tn "yGpBconhost" /sc ONSTART /tr "'C:\Windows\Installer\{90140000-006E-0410-0000-0000000FF1CE}\conhost.exe'" /rl HIGHEST /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
296 | schtasks.exe /create /tn "Gc2yexplorer" /sc ONLOGON /tr "'C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\explorer.exe'" /rl HIGHEST /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
316 | schtasks.exe /create /tn "YwLkexplorer" /sc ONSTART /tr "'C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\explorer.exe'" /rl HIGHEST /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
572 | schtasks.exe /create /tn "conhost" /sc MINUTE /mo 5 /tr "'C:\Windows\Installer\{90140000-006E-0410-0000-0000000FF1CE}\conhost.exe'" /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
764 | schtasks.exe /create /tn "7CU2dwm" /sc MINUTE /mo 10 /tr "'C:\Documents and Settings\dwm.exe'" /rl HIGHEST /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
896 | schtasks.exe /create /tn "QdIOSearchProtocolHost" /sc ONLOGON /tr "'C:\Windows\ehome\en-US\SearchProtocolHost.exe'" /rl HIGHEST /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
952 | schtasks.exe /create /tn "KTPMlsass" /sc MINUTE /mo 5 /tr "'C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\lsass.exe'" /rl HIGHEST /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
1020 | schtasks.exe /create /tn "lsass" /sc MINUTE /mo 14 /tr "'C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\lsass.exe'" /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
1072 | schtasks.exe /create /tn "YtnQfontPerfsvcwinsession" /sc MINUTE /mo 14 /tr "'C:\Recovery\345b46fe-a9f9-11e7-a83c-e8a4f72b1d33\fontPerfsvcwinsession.exe'" /rl HIGHEST /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
1124 | schtasks.exe /create /tn "ctfmon" /sc MINUTE /mo 12 /tr "'C:\MSOCache\All Users\{90140000-00A1-041F-0000-0000000FF1CE}-C\ctfmon.exe'" /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
|
(PID) Process: | (1432) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtBMP |
Value: | |||
(PID) Process: | (1432) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtIcon |
Value: | |||
(PID) Process: | (1432) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (1432) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
(PID) Process: | (1432) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
(PID) Process: | (1432) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
(PID) Process: | (1432) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\BustaGuess.zip | |||
(PID) Process: | (1432) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | name |
Value: 120 | |||
(PID) Process: | (1432) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | size |
Value: 80 | |||
(PID) Process: | (1432) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | type |
Value: 120 |
PID | Process | Filename | Type | |
---|---|---|---|---|
1432 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1432.44691\BustaGuess\dll\DLL_PenSuit.dll | executable | |
MD5:1F7FFEA4DD13500622F1C2F8FCD6D173 | SHA256:20925E5FC22342EEFD2EC58B81953117BA26E7FC0E076B87BCBF7C80DFB4A52A | |||
1432 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1432.44691\BustaGuess\cc32100mt.dll | executable | |
MD5:1EC6FE4798163C9EAB3BC7835FBF4F47 | SHA256:D221DA673572C2D0C8EDC23DE7DFEEA3E6CD6E994427AE48565A16751A3871BC | |||
1432 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1432.44691\BustaGuess\borlndmm.dll | executable | |
MD5:E3FCF256B4683AB92703842985B5E725 | SHA256:CA1F509D6779BC005F332027D50E9BAFA952BCF970953593A9566973B4122759 | |||
1432 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1432.44691\BustaGuess\BustaGuess.exe | executable | |
MD5:B4FD51350A4AF9FB273ADC47106A579D | SHA256:1465B7FFE8761EE7DB2F6482061F44852145C5D3C05894F40EF1565FB8B40C84 | |||
1432 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1432.44691\BustaGuess\dbghelp.dll | executable | |
MD5:74EDBB03DE3291FCF2094AF1FB363F1D | SHA256:DCA9F45EFED8EAB442B491AEBDA3E3CCE7F5F9FC5DE527D2DBDFD85A5BE85DFA | |||
1432 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1432.44691\BustaGuess\dll\DLL_MouseDeviceManager.dll | executable | |
MD5:D9E11A2AB50B4FF6AD95EEE5FED3EB48 | SHA256:A48D804C0732591B4C891AC2A7B32D0D627602B950FEC30143A5DAFD5AEE103B | |||
1432 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1432.44691\BustaGuess\dll\DLL_AnalyzeGesturesInRight.dll | executable | |
MD5:03890A9FAA8613F47EF0A1932F1A875D | SHA256:52D5E0A454325462C724038311462BB499096B037560B657B8C02870B929473C | |||
1432 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1432.44691\BustaGuess\dll\DLL_ZoomControl.dll | executable | |
MD5:ADA979540911494C857A89AB110152EC | SHA256:02E887718CC03263E594C09D12777926A45CA7E82A9D8D9C7B4E4177A107F042 | |||
1432 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1432.44691\BustaGuess\dll\DLL_ScrollbarControl.dll | executable | |
MD5:16AB9BDACDD35134895B8681D25089C0 | SHA256:B751E0A0C31F31847948003C094D2F0C6024501048CE87F2C2E9274E1A5CC0FC | |||
1432 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1432.44691\BustaGuess\dll\DLL_Wheel4D.dll | executable | |
MD5:9D1E44B28200D8C3F34D00250F97ED9B | SHA256:6C2A2B0C2D005C4D1F434871B494C72D126EC8AF17ED43D34F80E2249078AFFD |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
3652 | dwm.exe | GET | 400 | 141.8.197.42:80 | http://a0646788.xsph.ru/providerjavascriptCpuUpdatewindows.php?aRAcs8leQABmW=um4UDqOTebYRa&1f193d62ec9c62635c7a577ab8036ca6=ab400134a35ae28afb0d0ba5228d6dfd&dc8ff4a64801661ad57705042575a3b4=wNwcTM4EDN1kTM4Q2MjNWNlJDOwUDNlJ2YhBDMyQWY1IGO0MzNlljZ&aRAcs8leQABmW=um4UDqOTebYRa | unknown | html | 154 b | — |
3652 | dwm.exe | GET | 400 | 141.8.197.42:80 | http://a0646788.xsph.ru/providerjavascriptCpuUpdatewindows.php?aRAcs8leQABmW=um4UDqOTebYRa&1f193d62ec9c62635c7a577ab8036ca6=ab400134a35ae28afb0d0ba5228d6dfd&dc8ff4a64801661ad57705042575a3b4=wNwcTM4EDN1kTM4Q2MjNWNlJDOwUDNlJ2YhBDMyQWY1IGO0MzNlljZ&aRAcs8leQABmW=um4UDqOTebYRa | unknown | html | 154 b | — |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | unknown |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
3652 | dwm.exe | 141.8.197.42:80 | a0646788.xsph.ru | Sprinthost.ru LLC | RU | unknown |
Domain | IP | Reputation |
---|---|---|
a0646788.xsph.ru |
| unknown |
PID | Process | Class | Message |
---|---|---|---|
— | — | Misc activity | ET INFO Observed DNS Query to xsph .ru Domain |