File name:

NetworkDistribution.zip

Full analysis: https://app.any.run/tasks/d40edf4e-c95e-441f-bb06-cc4394a84e06
Verdict: Malicious activity
Analysis date: April 22, 2020, 09:55:36
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

03B442697B6FD7713531A5EFCC8E085B

SHA1:

9FDFA12EB8C52F52A7094E72278E18C01F64BA66

SHA256:

5CF76E8E443497438B344DB9F9A6B1DBA488C086A7B38FEE437A1853AFDF67BA

SSDEEP:

98304:Sqip1qvGyUXcgCVrnhGaesYfd69AZ92LK5Qig:bOyUXcgG4aK36ww

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 3676)
      • svchost.exe (PID: 3452)
      • svchost.exe (PID: 2816)
      • spoolsv.exe (PID: 2740)
      • svchost.exe (PID: 4004)
    • Application was dropped or rewritten from another process

      • svchost.exe (PID: 3452)
      • svchost.exe (PID: 2816)
      • svchost.exe (PID: 4004)
      • spoolsv.exe (PID: 2740)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3392)
    • Creates executable files which already exist in Windows

      • WinRAR.exe (PID: 3392)
  • INFO

    • Manual execution by user

      • svchost.exe (PID: 3452)
      • svchost.exe (PID: 2816)
      • spoolsv.exe (PID: 2740)
      • svchost.exe (PID: 4004)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2017:04:14 20:01:08
ZipCRC: 0xc8102596
ZipCompressedSize: 41203
ZipUncompressedSize: 153600
ZipFileName: NetworkDistribution/_pytrch.pyd
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
49
Monitored processes
6
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe searchprotocolhost.exe no specs svchost.exe no specs svchost.exe no specs svchost.exe spoolsv.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2740"C:\Users\admin\Desktop\NetworkDistribution\spoolsv.exe" C:\Users\admin\Desktop\NetworkDistribution\spoolsv.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
41
Modules
Images
c:\users\admin\desktop\networkdistribution\spoolsv.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\desktop\networkdistribution\trfo-2.dll
c:\users\admin\desktop\networkdistribution\posh-0.dll
c:\windows\system32\msvcrt.dll
c:\users\admin\desktop\networkdistribution\ucl.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
2816"C:\Users\admin\Desktop\NetworkDistribution\svchost.exe" C:\Users\admin\Desktop\NetworkDistribution\svchost.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
41
Modules
Images
c:\users\admin\desktop\networkdistribution\svchost.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\desktop\networkdistribution\trch-1.dll
c:\users\admin\desktop\networkdistribution\libxml2.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
3392"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\NetworkDistribution.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3452"C:\Users\admin\Desktop\NetworkDistribution\svchost.exe" C:\Users\admin\Desktop\NetworkDistribution\svchost.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
41
Modules
Images
c:\users\admin\desktop\networkdistribution\svchost.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\desktop\networkdistribution\trch-1.dll
c:\users\admin\desktop\networkdistribution\libxml2.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
3676"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe5_ Global\UsGthrCtrlFltPipeMssGthrPipe5 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
4004"C:\Users\admin\Desktop\NetworkDistribution\svchost.exe" C:\Users\admin\Desktop\NetworkDistribution\svchost.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
41
Modules
Images
c:\users\admin\desktop\networkdistribution\svchost.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\desktop\networkdistribution\trch-1.dll
c:\users\admin\desktop\networkdistribution\libxml2.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
Total events
784
Read events
759
Write events
25
Delete events
0

Modification events

(PID) Process:(3392) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3392) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3392) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3392) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\NetworkDistribution.zip
(PID) Process:(3392) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3392) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3392) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3392) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3392) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath
Operation:writeName:0
Value:
C:\Users\admin\Desktop
(PID) Process:(3676) SearchProtocolHost.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
Executable files
52
Suspicious files
0
Text files
7
Unknown types
1

Dropped files

PID
Process
Filename
Type
3392WinRAR.exeC:\Users\admin\Desktop\NetworkDistribution\etchCore-0.x86.dllexecutable
MD5:1F0669F13DC0545917E8397063F806DB
SHA256:3596E8FA5E19E860A2029FA4AB7A4F95FADF073FEB88E4F82B19A093E1E2737C
3392WinRAR.exeC:\Users\admin\Desktop\NetworkDistribution\adfw-2.dllexecutable
MD5:31D696F93EC84E635C4560034340E171
SHA256:F06D02359666B763E189402B7FBF9DFA83BA6F4DA2E7D037B3F9AEBEFD2D5A45
3392WinRAR.exeC:\Users\admin\Desktop\NetworkDistribution\cnli-1.dllexecutable
MD5:A539D27F33EF16E52430D3D2E92E9D5C
SHA256:DB0831E19A4E3A736EA7498DADC2D6702342F75FD8F7FBAE1894EE2E9738C2B4
3392WinRAR.exeC:\Users\admin\Desktop\NetworkDistribution\coli-0.dllexecutable
MD5:3C2FE2DBDF09CFA869344FDB53307CB2
SHA256:0439628816CABE113315751E7113A9E9F720D7E499FFDD78ACBAC1ED8BA35887
3392WinRAR.exeC:\Users\admin\Desktop\NetworkDistribution\dmgd-1.dllexecutable
MD5:1CA9E6EB86036DAEA4DFA3297F70D542
SHA256:9B8EC5D0C10CCDD3933B7712BA40065D1B0DD3FFA7968FB28AD426CD5EEE5001
3392WinRAR.exeC:\Users\admin\Desktop\NetworkDistribution\cnli-0.dllexecutable
MD5:EE2D6E1D976A3A92FB1C2524278922AE
SHA256:D3DB1E56360B25E7F36ABB822E03C18D23A19A9B5F198E16C16E06785FC8C5FA
3392WinRAR.exeC:\Users\admin\Desktop\NetworkDistribution\exma.dllexecutable
MD5:649B368C52DE83E52474A20CE4F83425
SHA256:C977AC10AA3D2250A1AF39630F532184A5185F505BCD5F03EA7083A3A701A969
3392WinRAR.exeC:\Users\admin\Desktop\NetworkDistribution\exma-1.dllexecutable
MD5:BA629216DB6CF7C0C720054B0C9A13F3
SHA256:15292172A83F2E7F07114693AB92753ED32311DFBA7D54FE36CC7229136874D9
3392WinRAR.exeC:\Users\admin\Desktop\NetworkDistribution\etchCore-0.x64.dllexecutable
MD5:4FF94C163565A38A27CF997AD07B3D69
SHA256:FE4640FEFA4BEF02041A771A206F9184ADB38DE051F0D8726C4579736FE13BB6
3392WinRAR.exeC:\Users\admin\Desktop\NetworkDistribution\dmgd-4.dllexecutable
MD5:A05C7011AB464E6C353A057973F5A06E
SHA256:50F329E034DB96BA254328CD1E0F588AF6126C341ED92DDF4AEB96BC76835937
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info