URL:

https://yadi.sk/d/8tSVnsL5iClAww

Full analysis: https://app.any.run/tasks/e6ae51fc-d8b0-4760-a422-b78f4767084d
Verdict: Malicious activity
Analysis date: December 26, 2020, 10:29:11
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

9B3D936B349E2E7D6152BE2585A4F308

SHA1:

0BB4BA4DC25E9082A49C84C744E455BDE98851E9

SHA256:

5795B99F2FFE0D6E56AFC4E78B03884B7B26784A580C8A15E73CED5ED3C49C95

SSDEEP:

3:N8jVRbSn:2ZR2n

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Setup.exe (PID: 3744)
      • detdrv.exe (PID: 3692)
      • Cmitool.exe (PID: 1860)
      • Setup.exe (PID: 1504)
      • Setup.exe (PID: 3936)
      • Cmitool.exe (PID: 3352)
      • Cmitool.exe (PID: 2996)
      • Cmitool.exe (PID: 3948)
      • Cmitool.exe (PID: 2296)
    • Actions looks like stealing of personal data

      • Setup.exe (PID: 3744)
      • WinRAR.exe (PID: 2984)
    • Loads dropped or rewritten executable

      • Setup.exe (PID: 1504)
  • SUSPICIOUS

    • Drops a file with too old compile date

      • WinRAR.exe (PID: 2984)
      • Setup.exe (PID: 1504)
    • Drops a file that was compiled in debug mode

      • Setup.exe (PID: 1504)
      • WinRAR.exe (PID: 2984)
    • Executable content was dropped or overwritten

      • Setup.exe (PID: 1504)
      • WinRAR.exe (PID: 2984)
  • INFO

    • Application launched itself

      • chrome.exe (PID: 1868)
    • Reads the hosts file

      • chrome.exe (PID: 4060)
      • chrome.exe (PID: 1868)
    • Reads settings of System Certificates

      • chrome.exe (PID: 4060)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
66
Monitored processes
25
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs winrar.exe setup.exe no specs setup.exe setup.exe detdrv.exe no specs cmitool.exe cmitool.exe cmitool.exe cmitool.exe cmitool.exe

Process information

PID
CMD
Path
Indicators
Parent process
1464"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=996,18393124444309920493,17416951216751446911,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=12558867808050202576 --renderer-client-id=10 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3464 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
1504"C:\Users\admin\AppData\Local\Temp\Rar$EXa2984.1679\Sofware CrownMicro CNGH-210X,310X\WIN7\Setup.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2984.1679\Sofware CrownMicro CNGH-210X,310X\WIN7\Setup.exe
Setup.exe
User:
admin
Company:
Acresso Software Inc.
Integrity Level:
HIGH
Description:
InstallScript Setup Launcher
Exit code:
2147753984
Version:
16.0.435
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2984.1679\sofware crownmicro cngh-210x,310x\win7\setup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1736"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=996,18393124444309920493,17416951216751446911,131072 --enable-features=PasswordImport --lang=en-US --no-sandbox --service-request-channel-token=2863239092880629399 --mojo-platform-channel-handle=1936 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
1760"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=996,18393124444309920493,17416951216751446911,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=475788658440117100 --renderer-client-id=11 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3660 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
1812"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=996,18393124444309920493,17416951216751446911,131072 --enable-features=PasswordImport --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=15868543948800879808 --renderer-client-id=5 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2164 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
1860C:\Users\admin\AppData\Local\Temp\{D4BD9F1B-C331-4415-B67F-CBC52910D691}\{942F9AC6-31F5-464A-82D0-89C6390F7E24}\Cmitool.exe usb6620C:\Users\admin\AppData\Local\Temp\{D4BD9F1B-C331-4415-B67F-CBC52910D691}\{942F9AC6-31F5-464A-82D0-89C6390F7E24}\Cmitool.exe
Setup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Version:
1, 0, 0, 5
Modules
Images
c:\users\admin\appdata\local\temp\{d4bd9f1b-c331-4415-b67f-cbc52910d691}\{942f9ac6-31f5-464a-82d0-89c6390f7e24}\cmitool.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1868"C:\Program Files\Google\Chrome\Application\chrome.exe" --disk-cache-dir=null --disk-cache-size=1 --media-cache-size=1 --disable-gpu-shader-disk-cache --disable-background-networking "https://yadi.sk/d/8tSVnsL5iClAww"C:\Program Files\Google\Chrome\Application\chrome.exe
explorer.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
3221225547
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
1952"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=996,18393124444309920493,17416951216751446911,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=13165940954801898217 --renderer-client-id=7 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3292 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
1972"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=996,18393124444309920493,17416951216751446911,131072 --enable-features=PasswordImport --disable-gpu-sandbox --use-gl=disabled --gpu-preferences=KAAAAAAAAADgACAgAQAAAAAAAAAAAGAAAAAAAAAAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --service-request-channel-token=13904227666427685345 --mojo-platform-channel-handle=3236 /prefetch:2C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
2084"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=1672 --on-initialized-event-handle=316 --parent-handle=320 /prefetch:6C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
Total events
1 833
Read events
1 719
Write events
106
Delete events
8

Modification events

(PID) Process:(1868) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(1868) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(1868) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
Operation:writeName:StatusCodes
Value:
(PID) Process:(1868) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
Operation:writeName:StatusCodes
Value:
01000000
(PID) Process:(1868) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(1868) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
Operation:writeName:dr
Value:
1
(PID) Process:(1868) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome
Operation:writeName:UsageStatsInSample
Value:
0
(PID) Process:(1868) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes
Operation:delete valueName:3252-13245750958665039
Value:
0
(PID) Process:(1868) chrome.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}
Operation:writeName:usagestats
Value:
0
(PID) Process:(1868) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes
Operation:delete valueName:1868-13253452168014000
Value:
259
Executable files
198
Suspicious files
78
Text files
20 258
Unknown types
88

Dropped files

PID
Process
Filename
Type
1868chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-5FE71089-74C.pma
MD5:
SHA256:
1868chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG.old
MD5:
SHA256:
1868chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\LOG.old
MD5:
SHA256:
1868chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG.old~RF142f9a.TMP
MD5:
SHA256:
1868chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\e091fecd-e9aa-40e4-b95a-e1c573ac894a.tmp
MD5:
SHA256:
1868chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000048.dbtmp
MD5:
SHA256:
1868chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Platform Notifications\LOG.old
MD5:
SHA256:
1868chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\metadata\LOG.old
MD5:
SHA256:
1868chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\LOG.old
MD5:
SHA256:
1868chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\LOG.old~RF14321a.TMP
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
66
DNS requests
45
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4060
chrome.exe
178.154.131.215:443
yastatic.net
YANDEX LLC
RU
whitelisted
4060
chrome.exe
77.88.21.119:443
mc.yandex.ru
YANDEX LLC
RU
whitelisted
4060
chrome.exe
77.88.21.127:443
downloader.disk.yandex.ru
YANDEX LLC
RU
whitelisted
4060
chrome.exe
213.180.206.105:443
s387sas.storage.yandex.net
YANDEX LLC
RU
whitelisted
4060
chrome.exe
77.88.33.202:443
s265vla.storage.yandex.net
YANDEX LLC
RU
whitelisted
4060
chrome.exe
216.58.212.174:443
play.google.com
Google Inc.
US
whitelisted
4060
chrome.exe
93.158.134.207:443
redirect.appmetrica.yandex.com
YANDEX LLC
RU
whitelisted
4060
chrome.exe
87.250.250.50:443
yadi.sk
YANDEX LLC
RU
whitelisted
4060
chrome.exe
172.217.18.99:443
www.gstatic.com
Google Inc.
US
whitelisted
4060
chrome.exe
172.217.18.3:443
fonts.gstatic.com
Google Inc.
US
whitelisted

DNS requests

Domain
IP
Reputation
yadi.sk
  • 87.250.250.50
shared
accounts.google.com
  • 172.217.5.237
shared
yastatic.net
  • 178.154.131.215
  • 178.154.131.217
  • 178.154.131.216
whitelisted
mc.yandex.ru
  • 77.88.21.119
  • 87.250.250.119
  • 93.158.134.119
  • 87.250.251.119
whitelisted
disk.yandex.com
  • 87.250.250.50
shared
disk.yandex.ru
  • 87.250.250.50
shared
yandex.ru
  • 77.88.55.70
  • 5.255.255.70
  • 5.255.255.60
  • 77.88.55.66
whitelisted
disk.yandex.com.am
  • 87.250.250.50
shared
disk.yandex.az
  • 87.250.250.50
shared
disk.yandex.by
  • 87.250.250.50
shared

Threats

No threats detected
Process
Message
Cmitool.exe
Try USB Detector
Cmitool.exe
Try USB Detector
Cmitool.exe
Try USB Detector
Cmitool.exe
Try USB Detector
Cmitool.exe
Try USB Detector