analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
download:

file

Full analysis: https://app.any.run/tasks/b771c0f3-7689-4d06-9e52-c6b3ae891a73
Verdict: Malicious activity
Analysis date: September 11, 2019, 11:51:58
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

F4B7A2E7DC825CF65C1828A3D14070FD

SHA1:

67BD7E535F11B3624629612F58CF099C1BA37BB8

SHA256:

5876A7E32B8169FE811E35E89BCEB4EACB4E3E4F9F3F0E3D5D02A0E38840AB2A

SSDEEP:

3072:zWeYc1FCLJEY7gVx0EpDbu+a1wFuWzEvOTG1yNuvB:ijc1FgJExp7zE2TG1cuZ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • reg.exe (PID: 3216)
  • SUSPICIOUS

    • Uses REG.EXE to modify Windows registry

      • cmd.exe (PID: 2688)
    • Starts Microsoft Installer

      • WinRAR.exe (PID: 3684)
    • Creates files in the user directory

      • MsiExec.exe (PID: 2140)
    • Executable content was dropped or overwritten

      • MsiExec.exe (PID: 2140)
      • WinRAR.exe (PID: 3684)
      • msiexec.exe (PID: 3504)
    • Starts CMD.EXE for commands execution

      • MsiExec.exe (PID: 2140)
    • Reads Internet Cache Settings

      • MsiExec.exe (PID: 2140)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: Chave0938FJ39DKC299X9198V3927928.msi
ZipUncompressedSize: 287232
ZipCompressedSize: 126936
ZipCRC: 0x6f29998e
ZipModifyDate: 2019:09:09 00:50:28
ZipCompression: Deflated
ZipBitFlag: -
ZipRequiredVersion: 20
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
48
Monitored processes
11
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe msiexec.exe no specs msiexec.exe msiexec.exe cmd.exe no specs cmd.exe no specs reg.exe cmd.exe no specs cmd.exe no specs shutdown.exe no specs shutdown.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3684"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Downloads\file.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.60.0
2284"C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\Rar$EXa3684.24606\Chave0938FJ39DKC299X9198V3927928.msi" C:\Windows\System32\msiexec.exeWinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
3504C:\Windows\system32\msiexec.exe /VC:\Windows\system32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
2140C:\Windows\system32\MsiExec.exe -Embedding B6C9E912DC52A32257BAFC0F3446F549C:\Windows\system32\MsiExec.exe
msiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
1073807364
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
3724"C:\Windows\System32\cmd.exe" /C mkdir C:\Users\admin\AppData\Roaming\Sun\Javar\YdkqkTpQeC:\Windows\System32\cmd.exeMsiExec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
2688"C:\Windows\System32\cmd.exe" /C start /MIN reg add HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v YdkqkTpQe /t reg_sz /d "C:\Users\admin\AppData\Roaming\Sun\Javar\YdkqkTpQe\YdkqkTpQe.exe"C:\Windows\System32\cmd.exeMsiExec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
3216reg add HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v YdkqkTpQe /t reg_sz /d "C:\Users\admin\AppData\Roaming\Sun\Javar\YdkqkTpQe\YdkqkTpQe.exe"C:\Windows\system32\reg.exe
cmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Registry Console Tool
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
2460"C:\Windows\System32\cmd.exe" /C shutdown -r -f -t 0C:\Windows\System32\cmd.exeMsiExec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
2592"C:\Windows\system32\cmd.exe" /c shutdown /r /t 1 /fC:\Windows\system32\cmd.exeMsiExec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1115
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
4092shutdown -r -f -t 0C:\Windows\system32\shutdown.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Shutdown and Annotation Tool
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Total events
1 138
Read events
1 091
Write events
0
Delete events
0

Modification events

No data
Executable files
8
Suspicious files
1
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
3504msiexec.exeC:\Windows\Installer\MSI32B8.tmp
MD5:
SHA256:
3504msiexec.exeC:\Windows\Installer\16bf6c.msiexecutable
MD5:30A9FCD516D5207E93A137222F0E42AE
SHA256:D7EB2DC1CD34B68BAD6F2D434960E7F408C05CD4D1E92D85CB32EC23173E3934
3684WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3684.24606\Chave0938FJ39DKC299X9198V3927928.msiexecutable
MD5:30A9FCD516D5207E93A137222F0E42AE
SHA256:D7EB2DC1CD34B68BAD6F2D434960E7F408C05CD4D1E92D85CB32EC23173E3934
2140MsiExec.exeC:\Users\admin\AppData\Roaming\Sun\Javar\YdkqkTpQe\YdkqkTpQe.zipcompressed
MD5:92768AECD376602E57FE0AC9FB3713F3
SHA256:E59178F5043710A325BA4E0B95746952FAC6C480FF830F8A4BFD0EF75E8E4844
2140MsiExec.exeC:\Users\admin\AppData\Roaming\Sun\Javar\YdkqkTpQe\YdkqkTpQe.exeexecutable
MD5:5659155B5BA46C971A326740789A4324
SHA256:4C691C7F1FD7206DC2E49349FEC65563A6CD996DD10EE42324C666282B5926B3
2140MsiExec.exeC:\Users\admin\AppData\Roaming\Sun\Javar\YdkqkTpQe\jesus.dmpexecutable
MD5:5659155B5BA46C971A326740789A4324
SHA256:4C691C7F1FD7206DC2E49349FEC65563A6CD996DD10EE42324C666282B5926B3
2140MsiExec.exeC:\Users\admin\AppData\Roaming\Desktop.logtext
MD5:A067F5EC97BA51B576825B69BC855E58
SHA256:CF3E339D25C3C023C9417FFC5D8E73F1DA828B18FEECAF14FDB9C24D04E49BA0
2140MsiExec.exeC:\Users\admin\AppData\Roaming\Sun\Javar\YdkqkTpQe\borlndmm.dllexecutable
MD5:0CF6C24C611C58FE8B85DA545DD68364
SHA256:1C7FF99399A59491C7C016681EF3BE2890DCE818C3D6CCF2F18D27F2EEB3ACE9
2140MsiExec.exeC:\Users\admin\AppData\Roaming\Sun\Javar\YdkqkTpQe\ssleay32.dllexecutable
MD5:A71BB55BE452A69F69A67DF2FE7C4097
SHA256:FF6C7F1C9DCFF3B3A90CF57A9B4341DDA0D76ADB9E8667B4A3F75E15A2B7A832
3504msiexec.exeC:\Windows\Installer\MSI32D8.tmpexecutable
MD5:9F1E5D66C2889018DAEF4AEF604EEBC4
SHA256:02A81AEA451CDFA2CD6668E3B814C4E50C6025E36B70AB972A8CC68ABA5B3222
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
2
DNS requests
2
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2140
MsiExec.exe
172.217.16.132:80
www.google.com
Google Inc.
US
whitelisted
2140
MsiExec.exe
52.218.101.16:443
motk54lkasdfa.s3-eu-west-1.amazonaws.com
Amazon.com, Inc.
IE
unknown

DNS requests

Domain
IP
Reputation
motk54lkasdfa.s3-eu-west-1.amazonaws.com
  • 52.218.101.16
shared
www.google.com
  • 172.217.16.132
whitelisted

Threats

No threats detected
No debug info