download:

file

Full analysis: https://app.any.run/tasks/a00e7d96-ca11-4476-ae41-caa24e053e95
Verdict: Malicious activity
Analysis date: September 11, 2019, 11:49:27
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

F4B7A2E7DC825CF65C1828A3D14070FD

SHA1:

67BD7E535F11B3624629612F58CF099C1BA37BB8

SHA256:

5876A7E32B8169FE811E35E89BCEB4EACB4E3E4F9F3F0E3D5D02A0E38840AB2A

SSDEEP:

3072:zWeYc1FCLJEY7gVx0EpDbu+a1wFuWzEvOTG1yNuvB:ijc1FgJExp7zE2TG1cuZ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • reg.exe (PID: 1108)
  • SUSPICIOUS

    • Starts Microsoft Installer

      • WinRAR.exe (PID: 2748)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2748)
      • MsiExec.exe (PID: 2824)
      • msiexec.exe (PID: 3712)
    • Creates files in the user directory

      • MsiExec.exe (PID: 2824)
    • Starts CMD.EXE for commands execution

      • MsiExec.exe (PID: 2824)
    • Reads Internet Cache Settings

      • MsiExec.exe (PID: 2824)
    • Uses REG.EXE to modify Windows registry

      • cmd.exe (PID: 3568)
  • INFO

    • Application launched itself

      • msiexec.exe (PID: 3712)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2019:09:09 00:50:28
ZipCRC: 0x6f29998e
ZipCompressedSize: 126936
ZipUncompressedSize: 287232
ZipFileName: Chave0938FJ39DKC299X9198V3927928.msi
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
50
Monitored processes
12
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe msiexec.exe no specs msiexec.exe msiexec.exe cmd.exe no specs cmd.exe no specs reg.exe cmd.exe no specs cmd.exe no specs shutdown.exe no specs shutdown.exe no specs msiexec.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1108reg add HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v HRCSelgTb /t reg_sz /d "C:\Users\admin\AppData\Roaming\Sun\Javar\HRCSelgTb\HRCSelgTb.exe"C:\Windows\system32\reg.exe
cmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Registry Console Tool
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\reg.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2180shutdown /r /t 1 /fC:\Windows\system32\shutdown.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Shutdown and Annotation Tool
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\shutdown.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\secur32.dll
2404"C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\Rar$EXa2748.9359\Chave0938FJ39DKC299X9198V3927928.msi" C:\Windows\System32\msiexec.exeWinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
1073807364
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2748"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Downloads\file.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
1073807364
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2824C:\Windows\system32\MsiExec.exe -Embedding DF9FD0B2F55785FDAD0FDDC09100C281C:\Windows\system32\MsiExec.exe
msiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
1073807364
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3028shutdown -r -f -t 0C:\Windows\system32\shutdown.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Shutdown and Annotation Tool
Exit code:
1190
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\shutdown.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\secur32.dll
3372"C:\Windows\System32\cmd.exe" /C shutdown -r -f -t 0C:\Windows\System32\cmd.exeMsiExec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1190
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3492"C:\Windows\system32\cmd.exe" /c shutdown /r /t 1 /fC:\Windows\system32\cmd.exeMsiExec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3568"C:\Windows\System32\cmd.exe" /C start /MIN reg add HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v HRCSelgTb /t reg_sz /d "C:\Users\admin\AppData\Roaming\Sun\Javar\HRCSelgTb\HRCSelgTb.exe"C:\Windows\System32\cmd.exeMsiExec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3644C:\Windows\system32\MsiExec.exe -Embedding 743C2EA720C1E1A75CC1A55E8134C47DC:\Windows\system32\MsiExec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Total events
1 160
Read events
1 102
Write events
58
Delete events
0

Modification events

(PID) Process:(2748) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2748) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2748) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2748) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Downloads\file.zip
(PID) Process:(2748) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2748) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2748) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2748) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2748) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(2748) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
Executable files
8
Suspicious files
1
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
3712msiexec.exeC:\Windows\Installer\MSI3911.tmp
MD5:
SHA256:
2748WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2748.9359\Chave0938FJ39DKC299X9198V3927928.msiexecutable
MD5:
SHA256:
3712msiexec.exeC:\Windows\Installer\16c2f7.msiexecutable
MD5:
SHA256:
2824MsiExec.exeC:\Users\admin\AppData\Roaming\Sun\Javar\HRCSelgTb\borlndmm.dllexecutable
MD5:0CF6C24C611C58FE8B85DA545DD68364
SHA256:1C7FF99399A59491C7C016681EF3BE2890DCE818C3D6CCF2F18D27F2EEB3ACE9
2824MsiExec.exeC:\Users\admin\AppData\Roaming\Sun\Javar\HRCSelgTb\HRCSelgTb.zipcompressed
MD5:
SHA256:
2824MsiExec.exeC:\Users\admin\AppData\Roaming\Desktop.logtext
MD5:A067F5EC97BA51B576825B69BC855E58
SHA256:CF3E339D25C3C023C9417FFC5D8E73F1DA828B18FEECAF14FDB9C24D04E49BA0
2824MsiExec.exeC:\Users\admin\AppData\Roaming\Sun\Javar\HRCSelgTb\ssleay32.dllexecutable
MD5:A71BB55BE452A69F69A67DF2FE7C4097
SHA256:FF6C7F1C9DCFF3B3A90CF57A9B4341DDA0D76ADB9E8667B4A3F75E15A2B7A832
2824MsiExec.exeC:\Users\admin\AppData\Roaming\Sun\Javar\HRCSelgTb\jesus.dmpexecutable
MD5:
SHA256:
2824MsiExec.exeC:\Users\admin\AppData\Roaming\Sun\Javar\HRCSelgTb\HRCSelgTb.exeexecutable
MD5:
SHA256:
2824MsiExec.exeC:\Users\admin\AppData\Roaming\Sun\Javar\HRCSelgTb\libeay32.dllexecutable
MD5:1F3D6EA5E7DAB4126B5315261785408B
SHA256:FC66F65545E6F8D875E82509BCB4ED4BD3DF1869734D8F4FD206C9B7E8726499
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
2
DNS requests
3
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2824
MsiExec.exe
52.218.24.88:443
motk54lkasdfa.s3-eu-west-1.amazonaws.com
Amazon.com, Inc.
IE
unknown
2824
MsiExec.exe
216.58.207.36:80
www.google.com
Google Inc.
US
whitelisted

DNS requests

Domain
IP
Reputation
motk54lkasdfa.s3-eu-west-1.amazonaws.com
  • 52.218.24.88
shared
www.google.com
  • 216.58.207.36
malicious

Threats

No threats detected
No debug info