| File name: | HEUR-Trojan-Ransom.MSIL.Encoder.gen-448de6e8dac16e82edffb183dfc61d43206c83b1bd7b65d93eed0f2450d11643.7z |
| Full analysis: | https://app.any.run/tasks/7338b283-9351-446d-b0ca-9ba95f8ba234 |
| Verdict: | Malicious activity |
| Threats: | Ransomware is a type of malicious software that locks users out of their system or data using different methods to force them to pay a ransom. Most often, such programs encrypt files on an infected machine and demand a fee to be paid in exchange for the decryption key. Additionally, such programs can be used to steal sensitive information from the compromised computer and even conduct DDoS attacks against affected organizations to pressure them into paying. |
| Analysis date: | April 24, 2025, 21:34:34 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-7z-compressed |
| File info: | 7-zip archive data, version 0.4 |
| MD5: | 9863869006FBE9D57CA8A6C6C4475132 |
| SHA1: | 0011016E83277E8EBC4C0066E1FD1EF4039C66F3 |
| SHA256: | 55FC8348A741FF6714B0E11C154A0ED24FF70CF6760527B9B746CA8F665C02BF |
| SSDEEP: | 1536:hGsczvGlrOmSyz/PFRlenRwyXakVkDilHhxNSygQcdddYw8weAljppp1Svp/FVqu:0sczvGlrvlsLX1qifxsy8bXoXBX5txb |
| .7z | | | 7-Zip compressed archive (v0.4) (57.1) |
|---|---|---|
| .7z | | | 7-Zip compressed archive (gen) (42.8) |
| FileVersion: | 7z v0.04 |
|---|---|
| ModifyDate: | 2021:09:29 12:22:48+00:00 |
| ArchivedFileName: | HEUR-Trojan-Ransom.MSIL.Encoder.gen-448de6e8dac16e82edffb183dfc61d43206c83b1bd7b65d93eed0f2450d11643.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 456 | "C:\Program Files\Mozilla Firefox\firefox.exe" | C:\Program Files\Mozilla Firefox\firefox.exe | firefox.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 668 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=6288 -childID 21 -isForBrowser -prefsHandle 6300 -prefMapHandle 6304 -prefsLen 31243 -prefMapSize 244583 -jsInitHandle 1532 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {586a863e-31a1-4764-a484-95a063ef09b9} 456 "\\.\pipe\gecko-crash-server-pipe.456" 261127b7a10 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 924 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=9952 -childID 59 -isForBrowser -prefsHandle 10184 -prefMapHandle 10180 -prefsLen 31243 -prefMapSize 244583 -jsInitHandle 1532 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {471b244e-88e7-436c-9959-90a10271106e} 456 "\\.\pipe\gecko-crash-server-pipe.456" 26114faad90 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 1012 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5196 -childID 7 -isForBrowser -prefsHandle 5212 -prefMapHandle 5204 -prefsLen 31243 -prefMapSize 244583 -jsInitHandle 1532 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {bb19def2-a20d-4269-893a-0910eeb4acbe} 456 "\\.\pipe\gecko-crash-server-pipe.456" 2610c0ba310 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 1040 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5552 -childID 9 -isForBrowser -prefsHandle 5188 -prefMapHandle 5232 -prefsLen 31243 -prefMapSize 244583 -jsInitHandle 1532 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {20fab683-2bb9-4ec0-a025-828df7b751a2} 456 "\\.\pipe\gecko-crash-server-pipe.456" 2610c0ba4d0 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 1096 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5116 -childID 6 -isForBrowser -prefsHandle 5104 -prefMapHandle 5100 -prefsLen 31243 -prefMapSize 244583 -jsInitHandle 1532 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {ff82f380-ed1d-4f5b-b28f-f60e28bb667f} 456 "\\.\pipe\gecko-crash-server-pipe.456" 2610c0ba150 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 1128 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=10380 -childID 62 -isForBrowser -prefsHandle 10372 -prefMapHandle 10368 -prefsLen 31243 -prefMapSize 244583 -jsInitHandle 1532 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {b8c1b837-1241-4349-80f2-5a456697fcc7} 456 "\\.\pipe\gecko-crash-server-pipe.456" 26114faa4d0 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 1132 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=6768 -childID 23 -isForBrowser -prefsHandle 6568 -prefMapHandle 6312 -prefsLen 31243 -prefMapSize 244583 -jsInitHandle 1532 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {d7fb878e-f49e-4744-acf5-10ab9a5cb51c} 456 "\\.\pipe\gecko-crash-server-pipe.456" 26112ef8150 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 2240 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5056 -childID 3 -isForBrowser -prefsHandle 5060 -prefMapHandle 5084 -prefsLen 31243 -prefMapSize 244583 -jsInitHandle 1532 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {a83b3d16-b057-45a7-9a9a-1cb2692e1616} 456 "\\.\pipe\gecko-crash-server-pipe.456" 2610dc3d4d0 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 2552 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5560 -childID 10 -isForBrowser -prefsHandle 5380 -prefMapHandle 5236 -prefsLen 31243 -prefMapSize 244583 -jsInitHandle 1532 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {a65a07d5-0da7-48b7-98ea-fe5c9dc9ffa7} 456 "\\.\pipe\gecko-crash-server-pipe.456" 2610c0ba690 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| (PID) Process: | (5072) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\preferences.zip | |||
| (PID) Process: | (5072) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\chromium_ext.zip | |||
| (PID) Process: | (5072) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\omni_23_10_2024_.zip | |||
| (PID) Process: | (5072) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\7338b283-9351-446d-b0ca-9ba95f8ba234.7z | |||
| (PID) Process: | (5072) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (5072) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (5072) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (5072) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (5072) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface |
| Operation: | write | Name: | ShowPassword |
Value: 0 | |||
| (PID) Process: | (5072) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\MainWin |
| Operation: | write | Name: | Placement |
Value: 2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF3D0000002D000000FD03000016020000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 7768 | HEUR-Trojan-Ransom.MSIL.Encoder.gen-448de6e8dac16e82edffb183dfc61d43206c83b1bd7b65d93eed0f2450d11643.exe | C:\Users\admin\Desktop\thoughfall.rtf | binary | |
MD5:963CC5B1E8466F80BDA78FABE7711FA9 | SHA256:1502F6703DC89E244792BEC26E88A98D98A1DF90D77783FE245C8BAE04EEEC83 | |||
| 7768 | HEUR-Trojan-Ransom.MSIL.Encoder.gen-448de6e8dac16e82edffb183dfc61d43206c83b1bd7b65d93eed0f2450d11643.exe | C:\Users\admin\Desktop\photorecently.jpg | binary | |
MD5:21C22BA3F349CC701193C9B15E1D3A8A | SHA256:67D34C4234809755DDF25F52CC8EDF9644A0796E66FC283E863D02947072FC56 | |||
| 7768 | HEUR-Trojan-Ransom.MSIL.Encoder.gen-448de6e8dac16e82edffb183dfc61d43206c83b1bd7b65d93eed0f2450d11643.exe | C:\Users\admin\Desktop\bboy.rtf.chickedmik | binary | |
MD5:9BCA5FBBDA4755ED786C45A2A4EAEB46 | SHA256:18D4475574819DE799277F172D97B157E8B7FDFA597DF926D9FAC9ABA38CE792 | |||
| 7768 | HEUR-Trojan-Ransom.MSIL.Encoder.gen-448de6e8dac16e82edffb183dfc61d43206c83b1bd7b65d93eed0f2450d11643.exe | C:\Users\admin\AppData\ChickiMiki Design.exe | executable | |
MD5:63C98DB59F68E9B7FA09D35CCFB271E7 | SHA256:9427D13846402473783E6FDE78E285E5CAC863DEB3E4CD05F5DEADD9969F49BB | |||
| 7768 | HEUR-Trojan-Ransom.MSIL.Encoder.gen-448de6e8dac16e82edffb183dfc61d43206c83b1bd7b65d93eed0f2450d11643.exe | C:\Users\admin\DCPqx44432432.exe | executable | |
MD5:E75A484E15EB8974B5836F57EC753B65 | SHA256:448DE6E8DAC16E82EDFFB183DFC61D43206C83B1BD7B65D93EED0F2450D11643 | |||
| 7768 | HEUR-Trojan-Ransom.MSIL.Encoder.gen-448de6e8dac16e82edffb183dfc61d43206c83b1bd7b65d93eed0f2450d11643.exe | C:\Users\admin\Desktop\listinggeneral.jpg.chickedmik | binary | |
MD5:BFBBB5B030EF40DD1407558CA4195153 | SHA256:AB3125F991D0B76F9025EC360160092477B78A91B5882C533AFADAF01181A2DC | |||
| 7768 | HEUR-Trojan-Ransom.MSIL.Encoder.gen-448de6e8dac16e82edffb183dfc61d43206c83b1bd7b65d93eed0f2450d11643.exe | C:\Users\admin\Desktop\bboy.rtf | binary | |
MD5:9BCA5FBBDA4755ED786C45A2A4EAEB46 | SHA256:18D4475574819DE799277F172D97B157E8B7FDFA597DF926D9FAC9ABA38CE792 | |||
| 7768 | HEUR-Trojan-Ransom.MSIL.Encoder.gen-448de6e8dac16e82edffb183dfc61d43206c83b1bd7b65d93eed0f2450d11643.exe | C:\Users\admin\Desktop\memberssets.rtf | binary | |
MD5:009EBF42A1642E9018B9B1C0E7CA74B0 | SHA256:1886D45528A46823A3ADE06DD3701B1A4A86F846AE96E5A98AC8D7FF993FEE72 | |||
| 7768 | HEUR-Trojan-Ransom.MSIL.Encoder.gen-448de6e8dac16e82edffb183dfc61d43206c83b1bd7b65d93eed0f2450d11643.exe | C:\Users\admin\Desktop\secsent.jpg | binary | |
MD5:44B0B01EE46BA779E022EC17F162A553 | SHA256:2099228566950C91E1622FC53C06262E5E356369E3D2A10B81604754BC5D0AC1 | |||
| 7768 | HEUR-Trojan-Ransom.MSIL.Encoder.gen-448de6e8dac16e82edffb183dfc61d43206c83b1bd7b65d93eed0f2450d11643.exe | C:\Users\admin\Desktop\listinggeneral.jpg | binary | |
MD5:BFBBB5B030EF40DD1407558CA4195153 | SHA256:AB3125F991D0B76F9025EC360160092477B78A91B5882C533AFADAF01181A2DC | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 2.16.241.12:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
8024 | SIHClient.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
8024 | SIHClient.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
6544 | svchost.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
456 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/canonical.html | unknown | — | — | whitelisted |
456 | firefox.exe | POST | 200 | 2.16.168.117:80 | http://r11.o.lencr.org/ | unknown | — | — | whitelisted |
456 | firefox.exe | POST | 200 | 2.16.168.117:80 | http://r11.o.lencr.org/ | unknown | — | — | whitelisted |
456 | firefox.exe | POST | 200 | 172.217.16.195:80 | http://o.pki.goog/s/wr3/FIY | unknown | — | — | whitelisted |
456 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/success.txt?ipv4 | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 2.16.241.12:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
— | — | 95.101.149.131:80 | www.microsoft.com | Akamai International B.V. | NL | whitelisted |
2104 | svchost.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2112 | svchost.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
3216 | svchost.exe | 172.211.123.249:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | FR | whitelisted |
6544 | svchost.exe | 20.190.160.64:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6544 | svchost.exe | 184.30.131.245:80 | ocsp.digicert.com | AKAMAI-AS | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |
detectportal.firefox.com |
| whitelisted |