File name: | FacturacionNº294922342452 (1).zip |
Full analysis: | https://app.any.run/tasks/2f4f5cad-9c2c-4ca7-be78-d49b2ef3cbb2 |
Verdict: | Malicious activity |
Threats: | Grandoreiro is a Latin American banking trojan first observed in 2016. It targets mostly Spanish-speaking countries, such as Brazil, Spain, Mexico and Peru. This malware is operated as a Malware-as-a-Service (MaaS), which makes it easily accessible for cybercriminals. Besides, it uses advanced techniques to evade detection. |
Analysis date: | December 05, 2023, 23:35:59 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Tags: | |
Indicators: | |
MIME: | application/zip |
File info: | Zip archive data, at least v2.0 to extract |
MD5: | D5DC924DD57DF2DA7BA5BE5477D2FA23 |
SHA1: | 6F879AE088541275D7ADA8664A7CBF6E907C2F70 |
SHA256: | 61557874CE073AB82EE72872F45D9801D34828C684EBFE71671DB10529ABD3C8 |
SSDEEP: | 98304:O0VhF0eF9t0FO2Gr8/bh83NYz7UDxdSDXNotiIjqs0ULhYF8XuenamyCOGk4WFp9:OiptWOxHaFbNnZ |
.zip | | | ZIP compressed archive (100) |
---|
ZipRequiredVersion: | 20 |
---|---|
ZipBitFlag: | - |
ZipCompression: | Deflated |
ZipModifyDate: | 2023:12:04 19:08:42 |
ZipCRC: | 0x9efa2a59 |
ZipCompressedSize: | 3471287 |
ZipUncompressedSize: | 129636352 |
ZipFileName: | Factura CFDI - RFC Emisor 8458 - Serie y Folio JYYE42325507 Ref-ADGP1510 3164.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
280 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
564 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\FacturacionNº294922342452 (1).zip" | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
2624 | "C:\Users\admin\Desktop\Factura CFDI - RFC Emisor 8458 - Serie y Folio JYYE42325507 Ref-ADGP1510 3164.exe" | C:\Users\admin\Desktop\Factura CFDI - RFC Emisor 8458 - Serie y Folio JYYE42325507 Ref-ADGP1510 3164.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: PDF Invalidable document viewer Plugon Exit code: 0 Version: 6.318.7703.2 Modules
| |||||||||||||||
3028 | "C:\Users\admin\Desktop\Factura CFDI - RFC Emisor 8458 - Serie y Folio JYYE42325507 Ref-ADGP1510 3164.exe" | C:\Users\admin\Desktop\Factura CFDI - RFC Emisor 8458 - Serie y Folio JYYE42325507 Ref-ADGP1510 3164.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: PDF Invalidable document viewer Plugon Exit code: 0 Version: 6.318.7703.2 Modules
|
(PID) Process: | (564) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\17F\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (564) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
(PID) Process: | (564) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
(PID) Process: | (564) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
(PID) Process: | (564) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | name |
Value: 120 | |||
(PID) Process: | (564) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | size |
Value: 80 | |||
(PID) Process: | (564) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | type |
Value: 120 | |||
(PID) Process: | (564) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | mtime |
Value: 100 |
PID | Process | Filename | Type | |
---|---|---|---|---|
564 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa564.35760\Factura CFDI - RFC Emisor 8458 - Serie y Folio JYYE42325507 Ref-ADGP1510 3164.exe | — | |
MD5:— | SHA256:— |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
2624 | Factura CFDI - RFC Emisor 8458 - Serie y Folio JYYE42325507 Ref-ADGP1510 3164.exe | GET | 200 | 208.95.112.1:80 | http://ip-api.com/json | unknown | binary | 292 b | — |
2624 | Factura CFDI - RFC Emisor 8458 - Serie y Folio JYYE42325507 Ref-ADGP1510 3164.exe | GET | 200 | 208.95.112.1:80 | http://ip-api.com/json | unknown | binary | 292 b | — |
2624 | Factura CFDI - RFC Emisor 8458 - Serie y Folio JYYE42325507 Ref-ADGP1510 3164.exe | GET | 200 | 208.95.112.1:80 | http://ip-api.com/json | unknown | binary | 292 b | — |
2624 | Factura CFDI - RFC Emisor 8458 - Serie y Folio JYYE42325507 Ref-ADGP1510 3164.exe | GET | 200 | 208.95.112.1:80 | http://ip-api.com/json | unknown | binary | 292 b | — |
2624 | Factura CFDI - RFC Emisor 8458 - Serie y Folio JYYE42325507 Ref-ADGP1510 3164.exe | GET | 200 | 208.95.112.1:80 | http://ip-api.com/json | unknown | binary | 292 b | — |
2624 | Factura CFDI - RFC Emisor 8458 - Serie y Folio JYYE42325507 Ref-ADGP1510 3164.exe | GET | — | 18.231.180.195:18942 | http://18.231.180.195:18942/yflMLs.xml | unknown | — | — | — |
2624 | Factura CFDI - RFC Emisor 8458 - Serie y Folio JYYE42325507 Ref-ADGP1510 3164.exe | GET | 200 | 18.231.180.195:4318 | http://18.231.180.195:4318/@*CPG@$,G*GQ)GUU$TS$@TS@)$U,),QX*)TPQW,GQ@%25,W,*$TXXVWXS%25C@P%25PX,,Q*$QWCX@X*WXQV@,WTGQCCP$QSWC$,CQC$@T)G%25SGPU%25GSP*XXUV,,XU,,WSTCG%25W)CXCT**UTGS$PW)@S$@SGX)X,,))G*,TQPC*)PQW$GUUCU,*UW*QGG*PUX$QWVGS)WTUW))V)TQC@WWPWQW%25W,@WP)CU)@VP,PUUPCCSPV*WV%25P$@PST@XPVQXC@VSP$@@GPG*)G),QG$GU,$QSCPWU*,XXVSV,PSP*PUP*%25@)XVX@V*PU@%25S,QTQX@VW$XT)W*VC@W,)QCCV%25%25UU$*W$,@XPXQVG,*Q,@CU@C%25)W),%25TU*$TGXGG*CU%25C@%25S@UW%25CG@UVCG,%25T)Q)@TVGQ)G*PQGC@)S*)GQ%25U*QU@,PTU**X*WU@P@CVTSWP@P$@UTW)Q@PWP@%25@$XSTUQPVQ$CT%25GU$,QTCSPCPW%25%25Q$CT)SGU@C%25$QWCSPSCGSV%25$U@$*G%25)S)U*TTW))WG*WQT,STXXPTWTTX@)SWG%25SGU*$P*VS%25CUP,WS*C)%25XQCCG$WUT,$X,GQ$UQXCSPX,$QW,$WX$%25SCPT@*SW$UQW@T@*Q%25V$T@W@%25TQQ,TQ%25C,%25XWUWVV)*STU%25TQ$,GXWWC*QV)@CCPCQVC)%25%25SUX)SQ*$SQ*P%25P@)P@%25T@V,CQWP%25C)CG,*CT%25*SU,CWPTPC@UVXC%25CS$WUVP,VU)WQCC@CGW@X,WP$CW,)$W,@,)C)P@*W$%25$V$)GUTV*TG*QU,C*CXCTC$GVVP)PSX,GT)T,@*V*)XTWUP,CXUQTPUP,@$)SSW,,XQXCU@P*$PT*VS$VUT,%25WC%25TS,,VQX,VQUCG,*TSUT | unknown | text | 790 b | — |
2624 | Factura CFDI - RFC Emisor 8458 - Serie y Folio JYYE42325507 Ref-ADGP1510 3164.exe | GET | 200 | 18.231.180.195:4318 | http://18.231.180.195:4318/PX$GS%25P@)V)%25XGQ),XQXC@V,%25WQ@$%25GXT%25XUT$TCG*,XXTWUW@TGWWSWCS)P%25W*WQC,$XUXSTXU$)*XSG$,GQ$,GQGP*$CQW@C)QVP$TQ@$)U@$TQXPS%25QVPG*WG%25QQV$S$PXSU@,$T,S**,X%25U$*GTQ)PCQ,GWXW*%25,VG,CTX))QT,XT%25%25W%25U*PTWTX)SUU,PU*$,XCSQ*XSG@%25W$%25PXQW%25SP$%25VP%25CU*@V$XTP%25PUSPW)*G),TSX)PS$QV%25)UT*,SS$QUU,,X@XSW@XST)S$)SC,TV%25CV,@U,$TTQ%25*TV%25%25Q)$SQ$PP*U%25PQP@SW%25W@SP$ST%25Q*$CUV,*XXUGC,S*$@Q,,@QS**Q)$,G,,TVC%25$W,%25,XWGGW**)XCGUSP$WX*XPTC%25VSVP))TQ%25C%25CQ$WUP)Q@PVX)@*,QW,QQQPSPG,QT,TGQC$UUX$GP@$)*%25XWT*TWGVSWSSV,W@GCCV)$QGQ,UXQXVQP*)QGCVCQ)@W)V$CQ)S%25USUPP@PU)$SC,XWQ%25,TW)@T$VTW%25GX%25XU,@QUT,UT,)@T*GQCUC$VXGWGS%25Q)P@*GXVXW$,TW)%25TG%25W,GC$XUP$XU%25PT@,SG$W,CX*Q*$WTP@T,)T%25X@TVTUQW$WX$TC*WT$)TGP@PV%25C*S*%25UV,WQVQVQ*@QT%25TTPT,*XQ%25$PSP,*QQCXVC%25)W@WU%25P@@*UW)X)QV,USC@U@S,%25UQP)%25QQ$PU,WUX,)X,QCCVPWPP%25$QCCP@CGS$XXUVPQ%25W%25@WQW@WSW%25VVW,$GUG)XP,*%25Q,PXCSSG*XTXSUPQ%25S@GQ@,CU,$,X,Q@,)XQX,WGS,PTPP$WTT%25TQ@P,*QTVV*PTP$PU$P*@,VC$VTVT*S,@WP%25)%25XQWX)GSGW*,CW*SS@U)@@S*PUS$TWTGU,*US)@Q@,$WWVW)*VQG%25$)TTSP%25P@QPU*USX$TTGG*@Q)%25)PXPUPPSPCVP*WSX,@GC@WV%25@WW%25@VGPSTPQ,)TPT%25TGWS*)U*P,@*SV)VWV%25TVT*QW$W%25%25@Q$@WS%25WUS$SXWTC%25GTUTQ)@Q*PS*$XSXXW)X$@USWG$,UX,),U,,%25TQWV$GTV*,QT%25GPX%25PVSCU@U)%25U,$VX,V@PV$%25GP%25%25U*,@TX%25STP)S@GVV$XV,@,*WT$VW)P*WU$,GUWCC)USU*WXTWUUUC*)@%25CXWUTC)VGPV)@T*TTXSSX,GQS,CV,CUV%25PW$TVTWP%25TS%25PG$PXQGT*VXQXVWXXXU@$WXTXVVST@%25VX%25Q$,XST*PV)*ST%25SXP%25PQ@T%25%25Q@$@G)$PQCPX))GP$CG$,TQX)%25VX@CUU@GG$ | unknown | text | 50 b | — |
2624 | Factura CFDI - RFC Emisor 8458 - Serie y Folio JYYE42325507 Ref-ADGP1510 3164.exe | GET | 200 | 18.231.180.195:157 | http://18.231.180.195:157/WPT))SSX$WU)**V%25P$GTV)$,TT*PV*PX%25%25SVSW%25@V$CQ$@TCGPWTGX@X%25UUSPUCSSV$PXPXVTGU%25@XWX*@XUX%25U%25*)XWUV$%25XQT)W%25,*QQ$U,P*P**QUX,US*%25GQUPV*SCP,WS%25*TUP$UU)@PC)GX)@XUVUTWU,P$@%25@,USC)GU,%25TVV$$XST@*GSQ$)G*W,@W*)Q@$TUV$QXXVX$CGU,GTXXVVG*VUQ)*%25)U*@USV@TS*C@VTGTSC$%25S@@SX$CUX,CQW$)GCGV**VC,UX@WX@S)*@CGWVPCG,,TS%25%25TS%25$TQS,$UTGQWVS*VXP)W@X,,X%25UQP),UXQU$GQU,@WCGQ@S)*TQX,))V$,,TXT)T*QGC)GU%25,VC$SSPG,%25Q*CU$WX%25GU%25QUQ@VS$CGCC$TU$)*SX,UTWUQ$)V%25%25*T*W)X,US,VT)WSWU)VQ*$@QT@V%25VU*CV*VSSPV)W$G%25CU)PQ@SSU,CQX%25V)UX$WXWWWQVQ@@%25)U$TU*@WV*C$*GQS$VTWWWV$CS,PX,*UWP,)GUX@PC%25VTCCG%25*UQC,*C$CGCV@SCCP,*XWTXXGXSCC$*TVV*GT$XQU,PCP,S%25P%25@CS$CQ,VQ@CTG)VT%25)))VQQSW%25%25%25QT%25)QSP*%25GW@)@U,%25$Q)$ST%25TVSXV%25*XU$,GQQ,PX$W,),T,GUW$*CXXXXU,CGS$%25TG$VWWWU*C,CG,*Q%25@))VV%25XTWS%25*@P)UWG%25T*VGPW,GV)GVS$VUQ%25TQ%25,%25VU*SUWC@,CUQ,CQCPUCGSCC%25S@SVT@W)%25$VS,VV,C**@X@VTW$,UQ)$U%25$TXQSU@C,CXUQWPSCVP,)QU)@*V@@@GPCTVQ*WG%25G%25VP*GQ%25@)@@)UGSV)*UUX*TTV@UVU*TX,UTCT,GUS,,XWW@@@Q,,VXGQP%25$US,XTTSSPWP@PX)$SSC%25CVC@CG*)SV$*QU,CUSP$CSW*VS*QU$)S@TPW)%25Q$PGQ)VT,)QW,S)C%25%25TQW%25Q)CS%25CWGV*TQT,UTP)CQ$CQ)*GVW)%25CQ,$)WV%25GUQ$WX$TV%25VTQTU))Q%25PW*@U@C)V$*GQXP@QUP$,USP,UVQ%25*S%25G)S*CT*GSXX*SS*CX@TWWC%25W)PV@P,%25P)PVV*PXTQ,CUS*$USS%25GQVCX@$%25*GW)PWVSQ)XTCUC,CTTG$,,U@,,TTQT$GTTQX$PXPWW*CQ*CTGVW,QX$*TSGVGPG%25PC)*TXXGSQ*GTSX$*XW@GS%25XQVCU$ST,XWUP$XU$PQ%25UPV@,WQSS%25@V$*,VSW)VC@UWVW,$CTSWWGW$WGXWX*CTSQTPQV%25$,XSXUTQVU,@GUPX | unknown | text | 50 b | — |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | unknown |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | unknown |
2624 | Factura CFDI - RFC Emisor 8458 - Serie y Folio JYYE42325507 Ref-ADGP1510 3164.exe | 208.95.112.1:80 | ip-api.com | TUT-AS | US | unknown |
2624 | Factura CFDI - RFC Emisor 8458 - Serie y Folio JYYE42325507 Ref-ADGP1510 3164.exe | 18.231.180.195:4318 | delaybor.myphotos.cc | AMAZON-02 | BR | unknown |
2624 | Factura CFDI - RFC Emisor 8458 - Serie y Folio JYYE42325507 Ref-ADGP1510 3164.exe | 18.231.180.195:18942 | delaybor.myphotos.cc | AMAZON-02 | BR | unknown |
2624 | Factura CFDI - RFC Emisor 8458 - Serie y Folio JYYE42325507 Ref-ADGP1510 3164.exe | 18.231.180.195:157 | delaybor.myphotos.cc | AMAZON-02 | BR | unknown |
Domain | IP | Reputation |
---|---|---|
ip-api.com |
| unknown |
delaybor.myphotos.cc |
| unknown |
PID | Process | Class | Message |
---|---|---|---|
— | — | Potential Corporate Privacy Violation | AV POLICY Internal Host Retrieving External IP Address (ip-api. com) |
— | — | Device Retrieving External IP Address Detected | ET POLICY External IP Lookup ip-api.com |
— | — | Device Retrieving External IP Address Detected | ET POLICY External IP Lookup ip-api.com |
— | — | Potential Corporate Privacy Violation | AV POLICY Internal Host Retrieving External IP Address (ip-api. com) |
— | — | Potential Corporate Privacy Violation | AV POLICY Internal Host Retrieving External IP Address (ip-api. com) |
— | — | Device Retrieving External IP Address Detected | ET POLICY External IP Lookup ip-api.com |
— | — | Potential Corporate Privacy Violation | AV POLICY Internal Host Retrieving External IP Address (ip-api. com) |
— | — | Device Retrieving External IP Address Detected | ET POLICY External IP Lookup ip-api.com |
— | — | Potential Corporate Privacy Violation | AV POLICY Internal Host Retrieving External IP Address (ip-api. com) |
— | — | Device Retrieving External IP Address Detected | ET POLICY External IP Lookup ip-api.com |