| download: | /SecHex/SecHex-Spoofy/releases/download/V1.5.8-23.02.24/V1.5.6.+.V1.5.8.zip |
| Full analysis: | https://app.any.run/tasks/3370ae6d-33a2-4328-9b92-4fea4b406891 |
| Verdict: | Malicious activity |
| Analysis date: | July 09, 2024, 17:33:11 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract, compression method=store |
| MD5: | 376D8646FCCD79826D049751BC72EC81 |
| SHA1: | 63B00BC8E21D97D3BE49495A0511B7D38645B6B2 |
| SHA256: | 54B51BF19FFCE063577597534E1658D25E5756072366CCEAFEC91AF5D7382F4A |
| SSDEEP: | 98304:Snf8jQPQtBCnJlQn73N4yUdMBR+XnQXqOGlQDlIT1e4GQjzrDk/xCW2RjXkxrFHG:nVmcgX |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | None |
| ZipModifyDate: | 2024:02:23 20:04:36 |
| ZipCRC: | 0x00000000 |
| ZipCompressedSize: | - |
| ZipUncompressedSize: | - |
| ZipFileName: | V1.5.6 + V1.5.8/SecHex-Spoofy V1.5.6/ |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 428 | C:\Windows\syswow64\MsiExec.exe -Embedding DFE751B3750BE554F0FDAF7EC0A153CA | C:\Windows\SysWOW64\msiexec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows® installer Exit code: 0 Version: 5.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 444 | C:\WINDOWS\system32\msiexec.exe /V | C:\Windows\System32\msiexec.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Version: 5.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 564 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6028 --field-trial-handle=2424,i,13919617078119884899,15375546389026967226,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 1052 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=2532 --field-trial-handle=2268,i,5974715815408052465,17023086751462104141,262144 --variations-seed-version /prefetch:3 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | msedge.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Version: 122.0.2365.59 Modules
| |||||||||||||||
| 1068 | C:\Windows\syswow64\MsiExec.exe -Embedding FCD29162A87815B05E2563D4947A581F | C:\Windows\SysWOW64\msiexec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows® installer Exit code: 0 Version: 5.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1124 | C:\Windows\syswow64\MsiExec.exe -Embedding 6B4B1E4207894945629AF031BC30F27B | C:\Windows\SysWOW64\msiexec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows® installer Exit code: 0 Version: 5.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1292 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5992 --field-trial-handle=2424,i,13919617078119884899,15375546389026967226,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 1292 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=4580 --field-trial-handle=2268,i,5974715815408052465,17023086751462104141,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 1384 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5224 -childID 3 -isForBrowser -prefsHandle 5220 -prefMapHandle 5216 -prefsLen 31207 -prefMapSize 244343 -jsInitHandle 1444 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {055f99d5-cd1f-4cb8-97b2-c11bc33b3ca6} 2392 "\\.\pipe\gecko-crash-server-pipe.2392" 1bd53ca4310 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 1700 | "C:\Users\admin\Downloads\dotnet-sdk-6.0.132-win-x64.exe" | C:\Users\admin\Downloads\dotnet-sdk-6.0.132-win-x64.exe | msedge.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft .NET SDK 6.0.132 (x64) Version: 6.1.3224.31507 Modules
| |||||||||||||||
| (PID) Process: | (6428) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (6428) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (6428) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\GoogleChromeEnterpriseBundle64.zip | |||
| (PID) Process: | (6428) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\V1.5.6.+.V1.5.8.zip | |||
| (PID) Process: | (6428) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (6428) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (6428) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (6428) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (2968) firefox.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Launcher |
Value: 52EF359601000000 | |||
| (PID) Process: | (2392) firefox.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Browser |
Value: 7A91369601000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6428 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa6428.21524\V1.5.6 + V1.5.8\SecHex-Spoofy V1.5.6\SecHex-GUI.exe | executable | |
MD5:A3A73BB0B21C4C4C0771D4FDA37AD34A | SHA256:9C04CA4639650F2707E817C8852BF8E128AB328FA4EF790ABA96F8EC17AD5316 | |||
| 6428 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa6428.21524\V1.5.6 + V1.5.8\SecHex-Spoofy V1.5.6\SecHex-GUI.dll | executable | |
MD5:AD714EE48D2E829C5012C65DE6166C05 | SHA256:7D32D13D123871650794A1E172ADC70BC8DAFBDB762F49D889F813844D532B20 | |||
| 6428 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa6428.21524\V1.5.6 + V1.5.8\SecHex-Spoofy V1.5.8 (testing)\runtimes\win\lib\net6.0\System.ServiceProcess.ServiceController.dll | executable | |
MD5:1C710EF8481E54352A4E1F66A8F7AD8C | SHA256:D11B97C114101961BCC7ACB0BB17E536708593C0321B6107942FBA20CB430C65 | |||
| 6428 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa6428.21524\V1.5.6 + V1.5.8\SecHex-Spoofy V1.5.6\SecHex-GUI.pdb | binary | |
MD5:D2F1182DA0077F1E60E33F1EFA03584A | SHA256:593169A5292387FF27C5C5DE33DB0FA1EAF65290FD52C6FF93D49233E7EBDEBC | |||
| 6428 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa6428.21524\V1.5.6 + V1.5.8\SecHex-Spoofy V1.5.8 (testing)\runtimes\win\lib\netcoreapp3.0\System.Runtime.WindowsRuntime.UI.Xaml.dll | executable | |
MD5:7141C72E54FE9A7ED39EF89814DE67D9 | SHA256:884442E44BCEF27D917E5DE5B69CBD4A297830E0B98B84495C7AB7486FA47332 | |||
| 6428 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa6428.21524\V1.5.6 + V1.5.8\SecHex-Spoofy V1.5.8 (testing)\SecHex-GUI.dll | executable | |
MD5:5B65AC01D6BABF936451FB1540A680B4 | SHA256:39882D08403185D68A6363EB5066BD212003FBD479E6AA78FFBE97C4191949FE | |||
| 6428 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa6428.21524\V1.5.6 + V1.5.8\SecHex-Spoofy V1.5.8 (testing)\SecHex-GUI.pdb | binary | |
MD5:7D0E9A9AE399A11B9B6645CB1577C326 | SHA256:64D236DE60EA2D3257DBA85C5C1DFA3E8C2123821F8E4ADE7C0CDD1C3A1D4A37 | |||
| 6428 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa6428.21524\V1.5.6 + V1.5.8\SecHex-Spoofy V1.5.8 (testing)\SecHex-GUI.deps.json | binary | |
MD5:64AE126CF65A9096D5730E060B448293 | SHA256:A4CADD5C4F3922A4ADA9E4BBC13E2BD779280A9B8CF537B66475FB3559BC7122 | |||
| 2392 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\urlCache-current.bin | binary | |
MD5:297E88D7CEB26E549254EC875649F4EB | SHA256:8B75D4FB1845BAA06122888D11F6B65E6A36B140C54A72CC13DF390FD7C95702 | |||
| 2392 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3680 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | unknown |
2392 | firefox.exe | POST | 200 | 95.101.54.145:80 | http://r10.o.lencr.org/ | unknown | — | — | unknown |
2392 | firefox.exe | POST | 200 | 2.16.202.114:80 | http://r11.o.lencr.org/ | unknown | — | — | unknown |
2392 | firefox.exe | POST | 200 | 2.16.202.114:80 | http://r11.o.lencr.org/ | unknown | — | — | unknown |
2392 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/canonical.html | unknown | — | — | unknown |
2392 | firefox.exe | POST | 200 | 95.101.54.145:80 | http://r10.o.lencr.org/ | unknown | — | — | unknown |
2392 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/success.txt?ipv4 | unknown | — | — | unknown |
2392 | firefox.exe | POST | 200 | 95.101.54.145:80 | http://r10.o.lencr.org/ | unknown | — | — | unknown |
2392 | firefox.exe | POST | 200 | 2.16.241.8:80 | http://r3.o.lencr.org/ | unknown | — | — | unknown |
2392 | firefox.exe | POST | 200 | 95.101.54.145:80 | http://r10.o.lencr.org/ | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1792 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
3868 | RUXIMICS.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4032 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
3680 | svchost.exe | 20.190.159.75:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
3680 | svchost.exe | 192.229.221.95:80 | fp2e7a.wpc.phicdn.net | EDGECAST | US | whitelisted |
4656 | SearchApp.exe | 2.23.209.177:443 | www.bing.com | Akamai International B.V. | GB | unknown |
1060 | svchost.exe | 184.28.89.167:443 | go.microsoft.com | AKAMAI-AS | US | unknown |
3040 | OfficeClickToRun.exe | 52.111.243.31:443 | nexusrules.officeapps.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | unknown |
Domain | IP | Reputation |
|---|---|---|
login.live.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
nexusrules.officeapps.live.com |
| whitelisted |
detectportal.firefox.com |
| whitelisted |
prod.detectportal.prod.cloudops.mozgcp.net |
| whitelisted |
contile.services.mozilla.com |
| whitelisted |
example.org |
| whitelisted |
ipv4only.arpa |
| whitelisted |
spocs.getpocket.com |
| whitelisted |
prod.ads.prod.webservices.mozgcp.net |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
7836 | msedge.exe | Potentially Bad Traffic | ET DNS Query for .cc TLD |
7836 | msedge.exe | Potentially Bad Traffic | ET DNS Query for .cc TLD |