File name:

SopiremInfoextrait.zip

Full analysis: https://app.any.run/tasks/62e4f37b-a102-4a0a-a86e-481bde44e3c2
Verdict: Malicious activity
Analysis date: November 27, 2024, 14:08:32
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
arch-exec
arch-doc
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=store
MD5:

4165B8005D4AA7DEFEC4FA9FC90492CE

SHA1:

6960C3ED07BA39D1BDFAD828B1F80A25AAA285A6

SHA256:

62818FB1152A9DBE3E08C0999850D918A17CD49E1C3E75498B6E170F8E57958C

SSDEEP:

98304:T49iqML7FLN2PMhbqEANMSHQdosswhtATV72zGGIgD+anuS0Jm7k9lMhjsYiOp3J:UkWi

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 1040)
    • Starts Visual C# compiler

      • sdiagnhost.exe (PID: 3400)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • csc.exe (PID: 1212)
      • csc.exe (PID: 3040)
      • csc.exe (PID: 3084)
    • Uses .NET C# to load dll

      • sdiagnhost.exe (PID: 3400)
    • Probably uses Microsoft diagnostics tool to execute malicious payload

      • pcwrun.exe (PID: 1556)
    • The process executes via Task Scheduler

      • SopiremInfoEvalSR3.exe (PID: 3560)
      • SopiremInfoEvalSR3.exe (PID: 992)
    • Uses RUNDLL32.EXE to load library

      • msdt.exe (PID: 3012)
  • INFO

    • Manual execution by a user

      • pcwrun.exe (PID: 1556)
      • SopiremInfoEvalSR3.exe (PID: 2324)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1040)
    • The process uses the downloaded file

      • WinRAR.exe (PID: 1040)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.xpi | Mozilla Firefox browser extension (66.6)
.zip | ZIP compressed archive (33.3)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2024:11:27 14:55:34
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: SopiremInfo/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
56
Monitored processes
14
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe sopireminfoevalsr3.exe pcwrun.exe no specs msdt.exe no specs sdiagnhost.exe no specs csc.exe cvtres.exe no specs csc.exe cvtres.exe no specs csc.exe cvtres.exe no specs rundll32.exe no specs sopireminfoevalsr3.exe no specs sopireminfoevalsr3.exe

Process information

PID
CMD
Path
Indicators
Parent process
992C:\Users\admin\Desktop\SopiremInfo\EvalSR3\SopiremInfoEvalSR3.exe C:\Users\admin\Desktop\SopiremInfo\EvalSR3\SopiremInfoEvalSR3.exetaskeng.exe
User:
admin
Company:
Sopirem
Integrity Level:
MEDIUM
Description:
SopiremInfoSR3
Exit code:
3221226540
Version:
1.0.3685.29490
Modules
Images
c:\users\admin\desktop\sopireminfo\evalsr3\sopireminfoevalsr3.exe
c:\windows\system32\ntdll.dll
1040"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\Downloads\SopiremInfoextrait.zipC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
1208C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\admin\AppData\Local\Temp\RES3C7A.tmp" "c:\Users\admin\AppData\Local\Temp\CSC3C6A.tmp"C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.execsc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft® Resource File To COFF Object Conversion Utility
Exit code:
0
Version:
8.00.50727.5003 (Win7SP1GDR.050727-5400)
Modules
Images
c:\windows\microsoft.net\framework\v2.0.50727\cvtres.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cryptsp.dll
1212"C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe" /noconfig /fullpaths @"C:\Users\admin\AppData\Local\Temp\nmk_wrp0.cmdline"C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe
sdiagnhost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Visual C# Command Line Compiler
Exit code:
0
Version:
8.0.50727.5483 (Win7SP1GDR.050727-5400)
Modules
Images
c:\windows\microsoft.net\framework\v2.0.50727\csc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1236C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\admin\AppData\Local\Temp\RES3E01.tmp" "c:\Users\admin\AppData\Local\Temp\CSC3DF0.tmp"C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.execsc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft® Resource File To COFF Object Conversion Utility
Exit code:
0
Version:
8.00.50727.5003 (Win7SP1GDR.050727-5400)
Modules
Images
c:\windows\microsoft.net\framework\v2.0.50727\cvtres.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cryptsp.dll
1556C:\Windows\system32\pcwrun.exe "C:\Users\admin\Desktop\SopiremInfo\EvalSR3\SopiremInfoEvalSR3.exe"C:\Windows\System32\pcwrun.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Program Compatibility Troubleshooter Invoker
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\pcwrun.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2324"C:\Users\admin\Desktop\SopiremInfo\EvalSR3\SopiremInfoEvalSR3.exe" C:\Users\admin\Desktop\SopiremInfo\EvalSR3\SopiremInfoEvalSR3.exe
explorer.exe
User:
admin
Company:
Sopirem
Integrity Level:
HIGH
Description:
SopiremInfoSR3
Exit code:
0
Version:
1.0.3685.29490
Modules
Images
c:\users\admin\desktop\sopireminfo\evalsr3\sopireminfoevalsr3.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3012C:\Windows\System32\msdt.exe -path C:\Windows\diagnostics\index\PCWDiagnostic.xml -af C:\Users\admin\AppData\Local\Temp\PCW343C.xml /skip TRUEC:\Windows\System32\msdt.exepcwrun.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Diagnostics Troubleshooting Wizard
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msdt.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3040"C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe" /noconfig /fullpaths @"C:\Users\admin\AppData\Local\Temp\aileeha_.cmdline"C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe
sdiagnhost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Visual C# Command Line Compiler
Exit code:
0
Version:
8.0.50727.5483 (Win7SP1GDR.050727-5400)
Modules
Images
c:\windows\microsoft.net\framework\v2.0.50727\csc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3080C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\admin\AppData\Local\Temp\RES3D17.tmp" "c:\Users\admin\AppData\Local\Temp\CSC3D16.tmp"C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.execsc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft® Resource File To COFF Object Conversion Utility
Exit code:
0
Version:
8.00.50727.5003 (Win7SP1GDR.050727-5400)
Modules
Images
c:\windows\microsoft.net\framework\v2.0.50727\cvtres.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cryptsp.dll
Total events
7 682
Read events
7 628
Write events
54
Delete events
0

Modification events

(PID) Process:(1040) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1040) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1040) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1040) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(1040) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(1040) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(1040) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Downloads\SopiremInfoextrait.zip
(PID) Process:(1040) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1040) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1040) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
11
Suspicious files
10
Text files
38
Unknown types
2

Dropped files

PID
Process
Filename
Type
1040WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1040.33954\SopiremInfo\EvalSR3\fr\SopiremInfoSR3.chmchm
MD5:9406B6E7A1220086D561D101C2414748
SHA256:CA9399F263A27DE1BB37B6A2FA5DA21F6F76CBA32984048F3502B3916BA8950F
1040WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1040.33954\SopiremInfo\EvalSR3\es\Simulateur.resources.dllexecutable
MD5:A184B077058B4B850CD2B2495C3AEAEB
SHA256:71E30EE579B0B27CC6C577955B4E70A9BD0E5188F47DD629408FE1070E1061D5
1040WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1040.33954\SopiremInfo\EvalSR3\en\Simulateur.resources.dllexecutable
MD5:0426854C6C8A56FA6358F5F94ED4EBF5
SHA256:FD719514D15742439DD7182C24B6E2AED78CFB4B4B17C3BDE3D42F82748840CE
1040WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1040.33954\SopiremInfo\EvalSR3\en\SopiremInfoSR3.chmchm
MD5:9A20D79C1129EC10B64A408D4AFE7BA2
SHA256:1B42DBAE1AA9C656823BB6D930784309519C26F13800B1F39CF03BF4CA167B5A
1040WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1040.33954\SopiremInfo\EvalSR3\param.xmlxml
MD5:2A1102F16F1DABAE7065DE99D73E6BB1
SHA256:403392131D26E0AD84F95E4493E08C552064DA209A5A66102EEF6BC77C8B1945
1040WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1040.33954\SopiremInfo\EvalSR3\tp\tp01_02.xmlxml
MD5:B39364A584BFAB4995151B3600118C28
SHA256:899D34D6CD45E2637571CEF5622CBE824BFB383D5060B2936B4124AD5536BA9D
1040WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1040.33954\SopiremInfo\EvalSR3\tp\tp02_02.xmlxml
MD5:58645012FFC45D7264CD3D218DE7059B
SHA256:6615CE3A19C6939A7D78BE71998CA656E600FDC1366B9033C4E678E666915408
1040WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1040.33954\SopiremInfo\EvalSR3\en\Licence.rtftext
MD5:9D1A37FD1642F29E5F2932EA5BDDCB84
SHA256:0248FFCFA66C27FDFC1A375E1EC005BCB2F4C18FF5EFE772DFC73BA53D2F5A86
1040WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1040.33954\SopiremInfo\EvalSR3\tp\tp02_01.xmlxml
MD5:6151E2E836758BA139F25B96D9124FCB
SHA256:5CC28F83C37AE204C4D93A509BD2AAD4F9555822D42C4AF3F810C832863BABA8
1040WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1040.33954\SopiremInfo\EvalSR3\tp\tp02_03.xmlxml
MD5:C62822B51C8CCDBDE722CD3D2706219D
SHA256:9061B84CC473DDBA3BD1B3599403A9C3BA5A544CEF85F2DACA8CC940CEF62F1A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
5
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:138
whitelisted
1108
svchost.exe
224.0.0.252:5355
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.206
whitelisted

Threats

No threats detected
Process
Message
csc.exe
*** HR originated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\copyout.cpp, line 1302
csc.exe
*** HR originated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\copyout.cpp, line 1302
csc.exe
*** HR originated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\copyout.cpp, line 1302
csc.exe
*** HR originated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\copyout.cpp, line 1302
csc.exe
*** HR propagated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
csc.exe
*** HR propagated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
csc.exe
*** HR propagated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
csc.exe
*** HR propagated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
csc.exe
*** HR propagated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
csc.exe
*** HR propagated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144