File name:

251005-p7dfjafk2s_pw_infected.zip

Full analysis: https://app.any.run/tasks/05e4cec0-a5fa-4279-9b37-3a2ce64ba42c
Verdict: Malicious activity
Threats:

Gh0st RAT is a malware with advanced trojan functionality that enables attackers to establish full control over the victim’s system. The spying capabilities of Gh0st RAT made it a go-to tool for numerous criminal groups in high-profile attacks against government and corporate organizations. The most common vector of attack involving this malware begins with spam and phishing emails.

Analysis date: October 05, 2025, 13:22:53
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
gh0st
rat
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=AES Encrypted
MD5:

E1AC0F77AD57735AAD6B4BF6EFC55682

SHA1:

DFDB5DCFD18120BAB0E605BFEF2997CC9DDCA8E9

SHA256:

5C53C526D85E5E260216E3872AA474A0E7696CFF0EAE5F09CAC4EF082F00C7E0

SSDEEP:

24576:/lg5uz7vYMFOatw/GDht3wdE/mYZ8XGVw+lD3N8wMLcckk3byy3OCwTh8rR1/0jf:/guz7vYMFOatw/GDht3wdE/mYZ8XGVwK

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • GH0ST mutex has been found

      • 94b4def0e023cc84e13852a6d360f4d5885c2d8bc502a8d380cb2ccdfdc739d7.exe (PID: 5180)
    • Create files in the Startup directory

      • 94b4def0e023cc84e13852a6d360f4d5885c2d8bc502a8d380cb2ccdfdc739d7.exe (PID: 5180)
    • Changes the autorun value in the registry

      • 94b4def0e023cc84e13852a6d360f4d5885c2d8bc502a8d380cb2ccdfdc739d7.exe (PID: 5180)
    • Uses sleep, probably for evasion detection (SCRIPT)

      • wscript.exe (PID: 4068)
      • wscript.exe (PID: 1048)
  • SUSPICIOUS

    • Executes WMI query (SCRIPT)

      • wscript.exe (PID: 1048)
      • wscript.exe (PID: 4068)
    • The process executes VB scripts

      • 94b4def0e023cc84e13852a6d360f4d5885c2d8bc502a8d380cb2ccdfdc739d7.exe (PID: 5180)
    • Reads security settings of Internet Explorer

      • 94b4def0e023cc84e13852a6d360f4d5885c2d8bc502a8d380cb2ccdfdc739d7.exe (PID: 5180)
    • Executable content was dropped or overwritten

      • 94b4def0e023cc84e13852a6d360f4d5885c2d8bc502a8d380cb2ccdfdc739d7.exe (PID: 5180)
    • Accesses WMI object, sets custom ImpersonationLevel (SCRIPT)

      • wscript.exe (PID: 4068)
      • wscript.exe (PID: 1048)
    • Connects to unusual port

      • 94b4def0e023cc84e13852a6d360f4d5885c2d8bc502a8d380cb2ccdfdc739d7.exe (PID: 5180)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 7788)
    • Creates files or folders in the user directory

      • 94b4def0e023cc84e13852a6d360f4d5885c2d8bc502a8d380cb2ccdfdc739d7.exe (PID: 5180)
    • Reads Microsoft Office registry keys

      • OpenWith.exe (PID: 4256)
    • The sample compiled with chinese language support

      • 94b4def0e023cc84e13852a6d360f4d5885c2d8bc502a8d380cb2ccdfdc739d7.exe (PID: 5180)
      • WinRAR.exe (PID: 7788)
    • Process checks computer location settings

      • 94b4def0e023cc84e13852a6d360f4d5885c2d8bc502a8d380cb2ccdfdc739d7.exe (PID: 5180)
    • Reads the computer name

      • 94b4def0e023cc84e13852a6d360f4d5885c2d8bc502a8d380cb2ccdfdc739d7.exe (PID: 5180)
    • Launching a file from the Startup directory

      • 94b4def0e023cc84e13852a6d360f4d5885c2d8bc502a8d380cb2ccdfdc739d7.exe (PID: 5180)
    • Checks supported languages

      • 94b4def0e023cc84e13852a6d360f4d5885c2d8bc502a8d380cb2ccdfdc739d7.exe (PID: 5180)
    • Manual execution by a user

      • 94b4def0e023cc84e13852a6d360f4d5885c2d8bc502a8d380cb2ccdfdc739d7.exe (PID: 5180)
    • Launching a file from a Registry key

      • 94b4def0e023cc84e13852a6d360f4d5885c2d8bc502a8d380cb2ccdfdc739d7.exe (PID: 5180)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0009
ZipCompression: Unknown (99)
ZipModifyDate: 1980:00:00 00:00:00
ZipCRC: 0x00000000
ZipCompressedSize: 542755
ZipUncompressedSize: 1172036
ZipFileName: 94b4def0e023cc84e13852a6d360f4d5885c2d8bc502a8d380cb2ccdfdc739d7
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
174
Monitored processes
6
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe openwith.exe no specs slui.exe no specs #GH0ST 94b4def0e023cc84e13852a6d360f4d5885c2d8bc502a8d380cb2ccdfdc739d7.exe wscript.exe no specs wscript.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1048"C:\WINDOWS\System32\WScript.exe" "C:\Users\admin\AppData\Roaming\Microsoft\VBS3.vbs" C:\Windows\SysWOW64\wscript.exe94b4def0e023cc84e13852a6d360f4d5885c2d8bc502a8d380cb2ccdfdc739d7.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Windows Based Script Host
Version:
5.812.10240.16384
Modules
Images
c:\windows\syswow64\wscript.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
2128C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
4068"C:\WINDOWS\System32\WScript.exe" "C:\Users\admin\AppData\Roaming\Microsoft\VBS3.vbs" C:\Windows\SysWOW64\wscript.exe94b4def0e023cc84e13852a6d360f4d5885c2d8bc502a8d380cb2ccdfdc739d7.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Windows Based Script Host
Version:
5.812.10240.16384
Modules
Images
c:\windows\syswow64\wscript.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
4256C:\WINDOWS\system32\OpenWith.exe -EmbeddingC:\Windows\System32\OpenWith.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Pick an app
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\openwith.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
5180"C:\Users\admin\Desktop\94b4def0e023cc84e13852a6d360f4d5885c2d8bc502a8d380cb2ccdfdc739d7.exe" C:\Users\admin\Desktop\94b4def0e023cc84e13852a6d360f4d5885c2d8bc502a8d380cb2ccdfdc739d7.exe
explorer.exe
User:
admin
Company:
邓学彬(泪闯天涯)
Integrity Level:
MEDIUM
Description:
本程序使用“黑月 - 应用程序向导”生成
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\94b4def0e023cc84e13852a6d360f4d5885c2d8bc502a8d380cb2ccdfdc739d7.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ws2_32.dll
7788"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\251005-p7dfjafk2s_pw_infected.zipC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
Total events
8 662
Read events
8 632
Write events
17
Delete events
13

Modification events

(PID) Process:(7788) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(7788) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(7788) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(7788) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(7788) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(7788) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\251005-p7dfjafk2s_pw_infected.zip
(PID) Process:(7788) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(7788) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(7788) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(7788) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
3
Suspicious files
1
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
518094b4def0e023cc84e13852a6d360f4d5885c2d8bc502a8d380cb2ccdfdc739d7.exeC:\Users\admin\AppData\Roaming\Microsoft\svchcst.exeexecutable
MD5:98D20776C314ACA169680DCD48BB18E1
SHA256:2BDC597A2768BCBF3E19649B9B3B622A71E1261C2A0330FCD45AD9F9F03F904F
518094b4def0e023cc84e13852a6d360f4d5885c2d8bc502a8d380cb2ccdfdc739d7.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\win.lnkbinary
MD5:C4CC76ADCB6D4C5DE09E3FA94F26F3A9
SHA256:02AAEF92E167C0DF1A020AD974C671828DB2E726CDF04ED20B34F13AEF9B279B
7788WinRAR.exeC:\Users\admin\Desktop\94b4def0e023cc84e13852a6d360f4d5885c2d8bc502a8d380cb2ccdfdc739d7executable
MD5:EC6BA19B25EA656C79DB91991786F279
SHA256:94B4DEF0E023CC84E13852A6D360F4D5885C2D8BC502A8D380CB2CCDFDC739D7
518094b4def0e023cc84e13852a6d360f4d5885c2d8bc502a8d380cb2ccdfdc739d7.exeC:\Users\admin\AppData\Roaming\Microsoft\VBS3.vbstext
MD5:46F7D8CF8B19861E6076D14EE0DA5FBE
SHA256:62AD53CB3487F8E503379C28CD61C3BE31B13EA45A3818DF19BB72620832FE56
518094b4def0e023cc84e13852a6d360f4d5885c2d8bc502a8d380cb2ccdfdc739d7.exeC:\Users\admin\AppData\Roaming\Microsoft\Config.initext
MD5:5611518085F0E601B7AF262B73CA1E21
SHA256:8E59E3DC5427519534AF0CFB2713D94388D03240F4F6D2C9EC6A13DB1D9812AB
518094b4def0e023cc84e13852a6d360f4d5885c2d8bc502a8d380cb2ccdfdc739d7.exeC:\Users\admin\AppData\Roaming\svchcst.exeexecutable
MD5:EC6BA19B25EA656C79DB91991786F279
SHA256:94B4DEF0E023CC84E13852A6D360F4D5885C2D8BC502A8D380CB2CCDFDC739D7
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
33
DNS requests
17
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4288
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
binary
471 b
whitelisted
7992
backgroundTaskHost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
US
binary
314 b
whitelisted
332
backgroundTaskHost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
US
binary
471 b
whitelisted
5296
backgroundTaskHost.exe
GET
200
162.159.142.9:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
binary
471 b
whitelisted
4288
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
binary
471 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
6332
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6016
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
6016
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5948
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5224
SearchApp.exe
104.126.37.145:443
www.bing.com
Akamai International B.V.
DE
whitelisted
4288
svchost.exe
20.190.159.4:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4288
svchost.exe
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
7992
backgroundTaskHost.exe
104.126.37.145:443
www.bing.com
Akamai International B.V.
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 20.73.194.208
whitelisted
google.com
  • 142.250.185.78
whitelisted
www.bing.com
  • 104.126.37.145
  • 104.126.37.128
whitelisted
login.live.com
  • 20.190.159.4
  • 20.190.159.2
  • 20.190.159.131
  • 40.126.31.71
  • 20.190.159.130
  • 20.190.159.75
  • 40.126.31.130
  • 40.126.31.69
whitelisted
ocsp.digicert.com
  • 184.30.131.245
  • 162.159.142.9
  • 172.66.2.5
whitelisted
client.wns.windows.com
  • 172.211.123.248
  • 172.211.123.249
whitelisted
arc.msn.com
  • 20.199.58.43
whitelisted
slscr.update.microsoft.com
  • 135.233.95.144
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.242.39.171
whitelisted
fd.api.iris.microsoft.com
  • 20.223.36.55
whitelisted

Threats

PID
Process
Class
Message
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
No debug info