analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

病毒样本.7z

Full analysis: https://app.any.run/tasks/e19cd016-7aed-4730-af03-b26abfc8ff2c
Verdict: Malicious activity
Threats:

Trojans are a group of malicious programs distinguished by their ability to masquerade as benign software. Depending on their type, trojans possess a variety of capabilities, ranging from maintaining full remote control over the victim’s machine to stealing data and files, as well as dropping other malware. At the same time, the main functionality of each trojan family can differ significantly depending on its type. The most common trojan infection chain starts with a phishing email.

Analysis date: July 18, 2019, 08:12:48
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
trojan
dupzom
Indicators:
MIME: application/x-7z-compressed
File info: 7-zip archive data, version 0.3
MD5:

91A052BAFF9F59BE636E40DB668DF850

SHA1:

ABC5876C6DB8A72FB6F277B953373DE5922D8249

SHA256:

5DDA3485C0BFA5E0A0FA1C9913FCB3CD8153FCE3C432FDAC028804E96956CEF0

SSDEEP:

12288:bt6Wrvetkac4U0fUI1BThJu0b03pCSoLeaqf48Y3tbH96EjLCidacYOF7:pJLetkac4UchJu0b03pFoLU8596EHCif

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • 合作流程及合同.pif (PID: 3976)
    • DUPZOM was detected

      • 合作流程及合同.pif (PID: 3976)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3624)
  • INFO

    • Manual execution by user

      • 合作流程及合同.pif (PID: 3976)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.7z | 7-Zip compressed archive (gen) (100)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
34
Monitored processes
2
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe #DUPZOM 合作流程及合同.pif

Process information

PID
CMD
Path
Indicators
Parent process
3624"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\病毒样本.7z"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
3976"C:\Users\admin\Desktop\合作流程及合同.pif" C:\Users\admin\Desktop\合作流程及合同.pif
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Total events
473
Read events
431
Write events
42
Delete events
0

Modification events

(PID) Process:(3624) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3624) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3624) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\70\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3624) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
(PID) Process:(3624) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\病毒样本.7z
(PID) Process:(3624) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3624) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3624) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3624) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3624) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\70\52C64B7E
Operation:writeName:@C:\Windows\System32\acppage.dll,-6005
Value:
Shortcut to MS-DOS Program
Executable files
1
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
3624WinRAR.exeC:\Users\admin\Desktop\合作流程及合同.pifexecutable
MD5:F3FA82D545A34E17506F8950A74BD9DC
SHA256:14C550CD8D8885374154E135CE23B20B40D49D1EF63BF9251568CE48DC2B835A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
9
DNS requests
0
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3976
合作流程及合同.pif
GET
122.114.10.240:9999
http://122.114.10.240:9999/Consys21.dll
CN
malicious
3976
合作流程及合同.pif
GET
122.114.10.240:9999
http://122.114.10.240:9999/Consys21.dll
CN
malicious
3976
合作流程及合同.pif
GET
122.114.10.240:9999
http://122.114.10.240:9999/Consys21.dll
CN
malicious
3976
合作流程及合同.pif
GET
122.114.10.240:9999
http://122.114.10.240:9999/Consys21.dll
CN
malicious
3976
合作流程及合同.pif
GET
122.114.10.240:9999
http://122.114.10.240:9999/Consys21.dll
CN
malicious
3976
合作流程及合同.pif
GET
122.114.10.240:9999
http://122.114.10.240:9999/Consys21.dll
CN
malicious
3976
合作流程及合同.pif
GET
122.114.10.240:9999
http://122.114.10.240:9999/Consys21.dll
CN
malicious
3976
合作流程及合同.pif
GET
122.114.10.240:9999
http://122.114.10.240:9999/Consys21.dll
CN
malicious
3976
合作流程及合同.pif
GET
122.114.10.240:9999
http://122.114.10.240:9999/Consys21.dll
CN
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3976
合作流程及合同.pif
122.114.10.240:9999
CHINA UNICOM China169 Backbone
CN
malicious

DNS requests

No data

Threats

Found threats are available for the paid subscriptions
1 ETPRO signatures available at the full report
Process
Message
合作流程及合同.pif
ÏÂÔØ
合作流程及合同.pif
ÏÂÔØ
合作流程及合同.pif
ÏÂÔØ
合作流程及合同.pif
ÏÂÔØ
合作流程及合同.pif
ÏÂÔØ
合作流程及合同.pif
ÏÂÔØ
合作流程及合同.pif
ÏÂÔØ
合作流程及合同.pif
ÏÂÔØ
合作流程及合同.pif
ÏÂÔØ