File name:

setup-pixinsight-1.8-e3ddy_84423825107294.zip

Full analysis: https://app.any.run/tasks/abc5ea50-96b0-4352-9d8a-35bb02b1dba5
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: September 28, 2020, 09:12:43
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
adware
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

E21C979F31240356606C9735A2D76F2F

SHA1:

27E8F7070157FB401D2D99ED484314B23798DD20

SHA256:

63930DE8D9481BE63D83463B5A85F2F2025B55494FB8911DFE68985CE254468A

SSDEEP:

393216:s3EvVceBHoANLWzA1Z8v2SSPrUmqXPkvtli:f9vBHRNSkxvqfAM

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads the Task Scheduler COM API

      • .exe (PID: 2164)
    • Application was dropped or rewritten from another process

      • setup-pixinsight-1.8-e3ddy_84423825107294.exe (PID: 1856)
      • setup-pixinsight-1.8-e3ddy_84423825107294.exe (PID: 3444)
      • .exe (PID: 2164)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1500)
    • Application launched itself

      • setup-pixinsight-1.8-e3ddy_84423825107294.exe (PID: 3444)
  • INFO

    • Manual execution by user

      • explorer.exe (PID: 3376)
    • Reads settings of System Certificates

      • .exe (PID: 2164)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2020:04:27 08:41:10
ZipCRC: 0x913218b6
ZipCompressedSize: 1271521
ZipUncompressedSize: 2798456
ZipFileName: .exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
47
Monitored processes
5
Malicious processes
0
Suspicious processes
2

Behavior graph

Click at the process to see the details
drop and start drop and start start winrar.exe explorer.exe no specs .exe setup-pixinsight-1.8-e3ddy_84423825107294.exe no specs setup-pixinsight-1.8-e3ddy_84423825107294.exe

Process information

PID
CMD
Path
Indicators
Parent process
1500"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\setup-pixinsight-1.8-e3ddy_84423825107294.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
1856"C:\Users\admin\AppData\Local\Temp\Rar$EXa1500.24829\setup-pixinsight-1.8-e3ddy_84423825107294.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa1500.24829\setup-pixinsight-1.8-e3ddy_84423825107294.exe
setup-pixinsight-1.8-e3ddy_84423825107294.exe
User:
admin
Company:
Jorfsop
Integrity Level:
HIGH
Description:
Killa Ton
Exit code:
0
Version:
3.2.8.258
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa1500.24829\setup-pixinsight-1.8-e3ddy_84423825107294.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
2164"C:\Users\admin\AppData\Local\Temp\Rar$EXa1500.23705\.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa1500.23705\.exe
WinRAR.exe
User:
admin
Company:
Sysinternals - www.sysinternals.com
Integrity Level:
MEDIUM
Description:
Sysinternals Process Explorer
Exit code:
0
Version:
16.32
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa1500.23705\.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
3376"C:\Windows\explorer.exe" C:\Windows\explorer.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3444"C:\Users\admin\AppData\Local\Temp\Rar$EXa1500.24829\setup-pixinsight-1.8-e3ddy_84423825107294.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa1500.24829\setup-pixinsight-1.8-e3ddy_84423825107294.exeWinRAR.exe
User:
admin
Company:
Jorfsop
Integrity Level:
MEDIUM
Description:
Killa Ton
Exit code:
0
Version:
3.2.8.258
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa1500.24829\setup-pixinsight-1.8-e3ddy_84423825107294.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
Total events
1 421
Read events
1 392
Write events
29
Delete events
0

Modification events

(PID) Process:(1500) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1500) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1500) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1500) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\setup-pixinsight-1.8-e3ddy_84423825107294.zip
(PID) Process:(1500) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1500) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1500) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1500) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1500) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\setup-pixinsight-1.8-e3ddy_84423825107294
(PID) Process:(1500) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
Executable files
6
Suspicious files
5
Text files
0
Unknown types
3

Dropped files

PID
Process
Filename
Type
2164.exeC:\Users\admin\AppData\Local\Temp\PROCEXP152.SYS
MD5:
SHA256:
2164.exeC:\Users\admin\AppData\Local\Temp\Cab7779.tmp
MD5:
SHA256:
2164.exeC:\Users\admin\AppData\Local\Temp\Tar7789.tmp
MD5:
SHA256:
2164.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\F90F18257CBB4D84216AC1E1F3BB2C76der
MD5:
SHA256:
1500WinRAR.exeC:\Users\admin\AppData\Local\Temp\setup-pixinsight-1.8-e3ddy_84423825107294\setup-pixinsight-1.8-e3ddy_84423825107294.exeexecutable
MD5:
SHA256:
2164.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\696F3DE637E6DE85B458996D49D759ADder
MD5:
SHA256:
1500WinRAR.exeC:\Users\admin\AppData\Local\Temp\setup-pixinsight-1.8-e3ddy_84423825107294\.exeexecutable
MD5:907D7E58EDEA108B21F69780C75F32A9
SHA256:C567D353E35A8D90D2A214E78313BF8C9A18E95A942715A3FD1AC944BFF1296F
1500WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1500.24829\.exeexecutable
MD5:907D7E58EDEA108B21F69780C75F32A9
SHA256:C567D353E35A8D90D2A214E78313BF8C9A18E95A942715A3FD1AC944BFF1296F
2164.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B8CC409ACDBF2A2FE04C56F2875B1FD6der
MD5:5E275DB761AA5A23AC651AF8F6C4A000
SHA256:3B9B2F75B724FE5354D24A0EF729B8A2AAA8A9313166EAFB1F73B07CF1A745EF
2164.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\696F3DE637E6DE85B458996D49D759ADbinary
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
4
DNS requests
2
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2164
.exe
GET
200
88.221.110.114:80
http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl
unknown
der
781 b
whitelisted
2164
.exe
GET
200
88.221.110.114:80
http://crl.microsoft.com/pki/crl/products/MicrosoftTimeStampPCA.crl
unknown
der
550 b
whitelisted
1856
setup-pixinsight-1.8-e3ddy_84423825107294.exe
POST
172.67.188.36:80
http://opengolad.com/v2/events
US
malicious
1856
setup-pixinsight-1.8-e3ddy_84423825107294.exe
POST
172.67.188.36:80
http://opengolad.com/v2/events
US
malicious
2164
.exe
GET
200
88.221.110.114:80
http://crl.microsoft.com/pki/crl/products/WinPCA.crl
unknown
der
530 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1856
setup-pixinsight-1.8-e3ddy_84423825107294.exe
172.67.188.36:80
opengolad.com
US
malicious
2164
.exe
88.221.110.114:80
crl.microsoft.com
Akamai International B.V.
unknown

DNS requests

Domain
IP
Reputation
crl.microsoft.com
  • 88.221.110.114
  • 88.221.110.122
whitelisted
opengolad.com
  • 172.67.188.36
  • 104.27.182.150
  • 104.27.183.150
unknown

Threats

PID
Process
Class
Message
1856
setup-pixinsight-1.8-e3ddy_84423825107294.exe
Misc activity
ADWARE [PTsecurity] Possible DownloadAssistant
1856
setup-pixinsight-1.8-e3ddy_84423825107294.exe
Misc activity
ADWARE [PTsecurity] DownloadAssistant
1856
setup-pixinsight-1.8-e3ddy_84423825107294.exe
Misc activity
ADWARE [PTsecurity] Possible DownloadAssistant
1856
setup-pixinsight-1.8-e3ddy_84423825107294.exe
Misc activity
ADWARE [PTsecurity] DownloadAssistant
No debug info