analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
download:

file

Full analysis: https://app.any.run/tasks/a00e7d96-ca11-4476-ae41-caa24e053e95
Verdict: Malicious activity
Analysis date: September 11, 2019, 11:49:27
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

F4B7A2E7DC825CF65C1828A3D14070FD

SHA1:

67BD7E535F11B3624629612F58CF099C1BA37BB8

SHA256:

5876A7E32B8169FE811E35E89BCEB4EACB4E3E4F9F3F0E3D5D02A0E38840AB2A

SSDEEP:

3072:zWeYc1FCLJEY7gVx0EpDbu+a1wFuWzEvOTG1yNuvB:ijc1FgJExp7zE2TG1cuZ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • reg.exe (PID: 1108)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2748)
      • msiexec.exe (PID: 3712)
      • MsiExec.exe (PID: 2824)
    • Creates files in the user directory

      • MsiExec.exe (PID: 2824)
    • Starts CMD.EXE for commands execution

      • MsiExec.exe (PID: 2824)
    • Starts Microsoft Installer

      • WinRAR.exe (PID: 2748)
    • Uses REG.EXE to modify Windows registry

      • cmd.exe (PID: 3568)
    • Reads Internet Cache Settings

      • MsiExec.exe (PID: 2824)
  • INFO

    • Application launched itself

      • msiexec.exe (PID: 3712)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: Chave0938FJ39DKC299X9198V3927928.msi
ZipUncompressedSize: 287232
ZipCompressedSize: 126936
ZipCRC: 0x6f29998e
ZipModifyDate: 2019:09:09 00:50:28
ZipCompression: Deflated
ZipBitFlag: -
ZipRequiredVersion: 20
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
50
Monitored processes
12
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe msiexec.exe no specs msiexec.exe msiexec.exe cmd.exe no specs cmd.exe no specs reg.exe cmd.exe no specs cmd.exe no specs shutdown.exe no specs shutdown.exe no specs msiexec.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2748"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Downloads\file.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
1073807364
Version:
5.60.0
2404"C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\Rar$EXa2748.9359\Chave0938FJ39DKC299X9198V3927928.msi" C:\Windows\System32\msiexec.exeWinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
1073807364
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
3712C:\Windows\system32\msiexec.exe /VC:\Windows\system32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
2824C:\Windows\system32\MsiExec.exe -Embedding DF9FD0B2F55785FDAD0FDDC09100C281C:\Windows\system32\MsiExec.exe
msiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
1073807364
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
3864"C:\Windows\System32\cmd.exe" /C mkdir C:\Users\admin\AppData\Roaming\Sun\Javar\HRCSelgTbC:\Windows\System32\cmd.exeMsiExec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
3568"C:\Windows\System32\cmd.exe" /C start /MIN reg add HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v HRCSelgTb /t reg_sz /d "C:\Users\admin\AppData\Roaming\Sun\Javar\HRCSelgTb\HRCSelgTb.exe"C:\Windows\System32\cmd.exeMsiExec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
1108reg add HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v HRCSelgTb /t reg_sz /d "C:\Users\admin\AppData\Roaming\Sun\Javar\HRCSelgTb\HRCSelgTb.exe"C:\Windows\system32\reg.exe
cmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Registry Console Tool
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
3372"C:\Windows\System32\cmd.exe" /C shutdown -r -f -t 0C:\Windows\System32\cmd.exeMsiExec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1190
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
3492"C:\Windows\system32\cmd.exe" /c shutdown /r /t 1 /fC:\Windows\system32\cmd.exeMsiExec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
3028shutdown -r -f -t 0C:\Windows\system32\shutdown.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Shutdown and Annotation Tool
Exit code:
1190
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Total events
1 160
Read events
1 102
Write events
0
Delete events
0

Modification events

No data
Executable files
8
Suspicious files
1
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
3712msiexec.exeC:\Windows\Installer\MSI3911.tmp
MD5:
SHA256:
2824MsiExec.exeC:\Users\admin\AppData\Roaming\Sun\Javar\HRCSelgTb\HRCSelgTb.zipcompressed
MD5:E9D277CAAC81E1D15BE31B97475B3D79
SHA256:00E3E23A51A9B6003F4DF1AFAEF3F77A99012B511727270AD76A1AC0E1440899
2748WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2748.9359\Chave0938FJ39DKC299X9198V3927928.msiexecutable
MD5:30A9FCD516D5207E93A137222F0E42AE
SHA256:D7EB2DC1CD34B68BAD6F2D434960E7F408C05CD4D1E92D85CB32EC23173E3934
3712msiexec.exeC:\Windows\Installer\16c2f7.msiexecutable
MD5:30A9FCD516D5207E93A137222F0E42AE
SHA256:D7EB2DC1CD34B68BAD6F2D434960E7F408C05CD4D1E92D85CB32EC23173E3934
2824MsiExec.exeC:\Users\admin\AppData\Roaming\Desktop.logtext
MD5:A067F5EC97BA51B576825B69BC855E58
SHA256:CF3E339D25C3C023C9417FFC5D8E73F1DA828B18FEECAF14FDB9C24D04E49BA0
2824MsiExec.exeC:\Users\admin\AppData\Roaming\Sun\Javar\HRCSelgTb\HRCSelgTb.exeexecutable
MD5:7BEBF5B45EB82A3A63F5FDF2189626C7
SHA256:9F3503CEED44207C9D5A26D41E2C01838C15ED57A2706420F0B76BE4851E1533
2824MsiExec.exeC:\Users\admin\AppData\Roaming\Sun\Javar\HRCSelgTb\jesus.dmpexecutable
MD5:7BEBF5B45EB82A3A63F5FDF2189626C7
SHA256:9F3503CEED44207C9D5A26D41E2C01838C15ED57A2706420F0B76BE4851E1533
2824MsiExec.exeC:\Users\admin\AppData\Roaming\Sun\Javar\HRCSelgTb\borlndmm.dllexecutable
MD5:0CF6C24C611C58FE8B85DA545DD68364
SHA256:1C7FF99399A59491C7C016681EF3BE2890DCE818C3D6CCF2F18D27F2EEB3ACE9
3712msiexec.exeC:\Windows\Installer\MSI3931.tmpexecutable
MD5:9F1E5D66C2889018DAEF4AEF604EEBC4
SHA256:02A81AEA451CDFA2CD6668E3B814C4E50C6025E36B70AB972A8CC68ABA5B3222
2824MsiExec.exeC:\Users\admin\AppData\Roaming\Sun\Javar\HRCSelgTb\ssleay32.dllexecutable
MD5:A71BB55BE452A69F69A67DF2FE7C4097
SHA256:FF6C7F1C9DCFF3B3A90CF57A9B4341DDA0D76ADB9E8667B4A3F75E15A2B7A832
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
2
DNS requests
3
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2824
MsiExec.exe
216.58.207.36:80
www.google.com
Google Inc.
US
whitelisted
2824
MsiExec.exe
52.218.24.88:443
motk54lkasdfa.s3-eu-west-1.amazonaws.com
Amazon.com, Inc.
IE
unknown

DNS requests

Domain
IP
Reputation
motk54lkasdfa.s3-eu-west-1.amazonaws.com
  • 52.218.24.88
shared
www.google.com
  • 216.58.207.36
whitelisted

Threats

No threats detected
No debug info