File name:

Scorpion Virus 2.0.7z

Full analysis: https://app.any.run/tasks/b51c16d8-8ae4-49d7-9515-15503f213db2
Verdict: Malicious activity
Analysis date: January 30, 2025, 11:47:42
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
arch-exec
arch-doc
Indicators:
MIME: application/x-7z-compressed
File info: 7-zip archive data, version 0.4
MD5:

112D0206C47074A5705333F938F11A49

SHA1:

1B0F84906E41D075055136DCE15BB0E2FE59E15B

SHA256:

5A4DD413D1AE25918B7878922CD290B28B3640231A489F9F08E1DA6189587954

SSDEEP:

49152:85drGmap3PsX0Xadw03ONmHkpu8uZJG4NZk9ZoqHWTQqw306orolSfYDb0TegKJ9:8HrG33PsXUadPO89ZZw4zqZ7WT2eolue

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 1016)
    • Disables Windows Defender

      • Scorpion Virus 2.0.exe (PID: 2900)
    • Creates or modifies Windows services

      • Scorpion Virus 2.0.exe (PID: 2900)
    • UAC/LUA settings modification

      • Scorpion Virus 2.0.exe (PID: 2900)
    • Changes the login/logoff helper path in the registry

      • Scorpion Virus 2.0.exe (PID: 2900)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 1016)
      • Scorpion Virus 2.0.exe (PID: 2900)
    • Executable content was dropped or overwritten

      • Scorpion Virus 2.0.exe (PID: 2900)
    • The process executes via Task Scheduler

      • sipnotify.exe (PID: 1324)
      • ctfmon.exe (PID: 1284)
    • Reads the Internet Settings

      • sipnotify.exe (PID: 1324)
      • Scorpion Virus 2.0.exe (PID: 2900)
    • The system shut down or reboot

      • Scorpion Virus 2.0.exe (PID: 2900)
    • Reads settings of System Certificates

      • sipnotify.exe (PID: 1324)
  • INFO

    • Reads the computer name

      • wmpnscfg.exe (PID: 1452)
      • Scorpion Virus 2.0.exe (PID: 2900)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1016)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 1452)
    • Checks supported languages

      • wmpnscfg.exe (PID: 1452)
      • Scorpion Virus 2.0.exe (PID: 2900)
    • Reads the machine GUID from the registry

      • Scorpion Virus 2.0.exe (PID: 2900)
    • Process checks whether UAC notifications are on

      • Scorpion Virus 2.0.exe (PID: 2900)
    • Reads security settings of Internet Explorer

      • sipnotify.exe (PID: 1324)
    • Reads the software policy settings

      • sipnotify.exe (PID: 1324)
    • Creates files or folders in the user directory

      • Scorpion Virus 2.0.exe (PID: 2900)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.7z | 7-Zip compressed archive (v0.4) (57.1)
.7z | 7-Zip compressed archive (gen) (42.8)

EXIF

ZIP

FileVersion: 7z v0.04
ModifyDate: 2017:07:24 19:01:38+00:00
ArchivedFileName: READ ME!.txt
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
84
Monitored processes
7
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe wmpnscfg.exe no specs scorpion virus 2.0.exe no specs scorpion virus 2.0.exe shutdown.exe no specs ctfmon.exe no specs sipnotify.exe

Process information

PID
CMD
Path
Indicators
Parent process
920shutdown /r /f /t 0C:\Windows\System32\shutdown.exeScorpion Virus 2.0.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Shutdown and Annotation Tool
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\shutdown.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\secur32.dll
1016"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Scorpion Virus 2.0.7z"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
1073807364
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
1284C:\Windows\System32\ctfmon.exe C:\Windows\System32\ctfmon.exetaskeng.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
CTF Loader
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ctfmon.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msctfmonitor.dll
c:\windows\system32\msctf.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
1324C:\Windows\system32\sipnotify.exe -LogonOrUnlockC:\Windows\System32\sipnotify.exe
taskeng.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
sipnotify
Exit code:
0
Version:
6.1.7602.20480 (win7sp1_ldr_escrow.191010-1716)
Modules
Images
c:\windows\system32\sipnotify.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1452"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1792"C:\Users\admin\AppData\Local\Temp\Rar$EXb1016.48237\Scorpion Virus 2.0.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb1016.48237\Scorpion Virus 2.0.exeWinRAR.exe
User:
admin
Company:
Windows64
Integrity Level:
MEDIUM
Description:
Windows64
Exit code:
3221226540
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb1016.48237\scorpion virus 2.0.exe
c:\windows\system32\ntdll.dll
2900"C:\Users\admin\AppData\Local\Temp\Rar$EXb1016.48237\Scorpion Virus 2.0.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb1016.48237\Scorpion Virus 2.0.exe
WinRAR.exe
User:
admin
Company:
Windows64
Integrity Level:
HIGH
Description:
Windows64
Exit code:
1073807364
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb1016.48237\scorpion virus 2.0.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
4 676
Read events
4 628
Write events
47
Delete events
1

Modification events

(PID) Process:(1016) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1016) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1016) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1016) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1016) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1016) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1016) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1016) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(1016) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(1016) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
Executable files
3
Suspicious files
1
Text files
8
Unknown types
0

Dropped files

PID
Process
Filename
Type
1016WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb1016.48237\READ ME!.txttext
MD5:5D9B832D73B3B57910F642C87695E8C9
SHA256:1EBF3B134846783147B711977E30A135AE9A72912B0013A4DFBFD46F0378B497
2900Scorpion Virus 2.0.exeC:\Users\admin\AppData\Local\Windows64\Scorpion_Virus_2.0.exe_Url_wcic03pn5rmrdmvwjpratj5jtgle0tpt\1.0.0.0\user.configxml
MD5:383145FF4DF55EEA0A92F264881062FF
SHA256:4F0BD7AB3D3B33CE882F565D7590898DC3B9C2F5439906B4AFD447E79BFEFC56
1324sipnotify.exeC:\Users\admin\AppData\Local\Microsoft\Windows\SipNotify\eoscontent\metadata.jsonbinary
MD5:E8A970BA6CE386EED9A5E724F26212A6
SHA256:7E06107D585D8FC7870998F3856DCC3E35800AA97E4406AAB83BC8444B6CBDE3
2900Scorpion Virus 2.0.exeC:\Windows\System32\Windows64.exeexecutable
MD5:8696422ED156C32782A6AB3AEC6849F1
SHA256:FB5710B40D6CFFABB38D73745B0D4BB7A2398D24C2322EFA3097A09476ABC8A0
1324sipnotify.exeC:\Users\admin\AppData\Local\Microsoft\Windows\SipNotify\eoscontent\en-us.htmlhtml
MD5:9752942B57692148B9F614CF4C119A36
SHA256:E31B834DD53FA6815F396FC09C726636ABF98F3367F0CF1590EF5EB3801C75D1
1016WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb1016.48237\Scorpion Virus 2.0.exeexecutable
MD5:2600121D5FB3448EB4B445AF9B546580
SHA256:8EBAADEBB489D03B33D734330C45D9E11FAAA35778E43DBE3E176BD1D06A860C
1324sipnotify.exeC:\Users\admin\AppData\Local\Microsoft\Windows\SipNotify\eoscontent\main.jpgimage
MD5:B342ACE63F77961249A084C61EABC884
SHA256:E5067BBA2095B5DA7C3171EC116E9A92337E24E471339B0860A160076EFE49B9
1324sipnotify.exeC:\Users\admin\AppData\Local\Microsoft\Windows\SipNotify\eoscontent\styles.csstext
MD5:3383EEF350240253D7C2C2564381B3CB
SHA256:85443493D86D6D7FB0E07BC9705DFC9C858086FBA1B0E508092AB328D5F145E8
1324sipnotify.exeC:\Users\admin\AppData\Local\Microsoft\Windows\SipNotify\eoscontent\script.jstext
MD5:A2682382967C351F7ED21762F9E5DE9E
SHA256:36B1D26F1EC69685648C0528C2FCE95A3C2DBECF828CDFA4A8B4239A15B644A2
1324sipnotify.exeC:\Users\admin\AppData\Local\Microsoft\Windows\SipNotify\eoscontent\microsoft-logo.pngimage
MD5:B7C73A0CFBA68CC70C35EF9C63703CE4
SHA256:1D8B27A0266FF526CF95447F3701592A908848467D37C09A00A2516C1F29A013
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
13
DNS requests
2
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1324
sipnotify.exe
HEAD
200
104.102.45.145:80
http://query.prod.cms.rt.microsoft.com/cms/api/am/binary/RE2JgkA?v=133827113067030000
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1108
svchost.exe
224.0.0.252:5355
whitelisted
1092
svchost.exe
224.0.0.252:5355
whitelisted
1324
sipnotify.exe
104.102.45.145:80
query.prod.cms.rt.microsoft.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.184.206
whitelisted
query.prod.cms.rt.microsoft.com
  • 104.102.45.145
whitelisted

Threats

No threats detected
No debug info