File name:

atiflash_293 (21).zip

Full analysis: https://app.any.run/tasks/2f593097-c4b2-496f-bcd8-8a3934875573
Verdict: Malicious activity
Threats:

Remote access trojans (RATs) are a type of malware that enables attackers to establish complete to partial control over infected computers. Such malicious programs often have a modular design, offering a wide range of functionalities for conducting illicit activities on compromised systems. Some of the most common features of RATs include access to the users’ data, webcam, and keystrokes. This malware is often distributed through phishing emails and links.

Analysis date: February 02, 2021, 21:09:57
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
trojan
rat
remcos
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract
MD5:

73C84AD2F30AD65B78573C007D4F4399

SHA1:

B4E14E74E4DCA3115FA3662D06D0A2E8B798BC92

SHA256:

6454B2F33AEDB5C4750B4AC1EDB760ADB17C665C62009EF841A9F1719B1FF00C

SSDEEP:

49152:OWcnYJnveNsHsX3KVIGdYlBB1I9DYhlgKfFHX4vmRbIacq9qnLBayxDUKufGf:OxY19HeaViBB5wgemRbPkNayhPxf

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • ATIWinflash 2.9.3.exe (PID: 2960)
      • ATIWinflash 2.9.3.exe (PID: 1088)
      • ATIWinflash 2.9.3.exe (PID: 1828)
      • ATIWinflash.exe (PID: 3260)
      • Window Check Manager.exe (PID: 3564)
    • Loads dropped or rewritten executable

      • ATIWinflash.exe (PID: 3260)
    • Runs app for hidden code execution

      • notepad.exe (PID: 3228)
    • Changes settings of System certificates

      • notepad.exe (PID: 3228)
    • Loads the Task Scheduler DLL interface

      • notepad.exe (PID: 3012)
    • REMCOS was detected

      • notepad.exe (PID: 3012)
    • Connects to CnC server

      • notepad.exe (PID: 3012)
  • SUSPICIOUS

    • Application launched itself

      • ATIWinflash 2.9.3.exe (PID: 2960)
      • ATIWinflash 2.9.3.exe (PID: 1088)
      • notepad.exe (PID: 3228)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1108)
      • ATIWinflash 2.9.3.exe (PID: 1828)
      • notepad.exe (PID: 3012)
    • Drops a file with too old compile date

      • WinRAR.exe (PID: 1108)
      • ATIWinflash 2.9.3.exe (PID: 1828)
    • Reads the Windows organization settings

      • ATIWinflash 2.9.3.exe (PID: 1088)
      • ATIWinflash 2.9.3.exe (PID: 1828)
    • Reads Windows owner or organization settings

      • ATIWinflash 2.9.3.exe (PID: 1828)
      • ATIWinflash 2.9.3.exe (PID: 1088)
    • Drops a file with a compile date too recent

      • ATIWinflash 2.9.3.exe (PID: 1828)
    • Starts CMD.EXE for commands execution

      • notepad.exe (PID: 3228)
    • Adds / modifies Windows certificates

      • notepad.exe (PID: 3228)
    • Creates files in the Windows directory

      • notepad.exe (PID: 3012)
    • Creates files in the user directory

      • notepad.exe (PID: 3012)
    • Drops a file that was compiled in debug mode

      • WinRAR.exe (PID: 1108)
      • ATIWinflash 2.9.3.exe (PID: 1828)
    • Creates files in the program directory

      • ATIWinflash 2.9.3.exe (PID: 1828)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2021:01:24 11:59:02
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: atiflash_293/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
49
Monitored processes
13
Malicious processes
7
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start drop and start drop and start winrar.exe atiwinflash 2.9.3.exe no specs atiwinflash 2.9.3.exe atiwinflash 2.9.3.exe atiwinflash.exe no specs window check manager.exe no specs notepad.exe cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs #REMCOS notepad.exe

Process information

PID
CMD
Path
Indicators
Parent process
912"C:\Windows\system32\cmd.exe"C:\Windows\system32\cmd.exenotepad.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
1088"C:\Users\admin\AppData\Local\Temp\Rar$EXa1108.6572\atiflash_293\ATIWinflash 2.9.3.exe" /SPAWNWND=$2017E /NOTIFYWND=$2017E C:\Users\admin\AppData\Local\Temp\Rar$EXa1108.6572\atiflash_293\ATIWinflash 2.9.3.exe
ATIWinflash 2.9.3.exe
User:
admin
Company:
amd_vbflashWin MFC Application 2.9.3
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
1
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa1108.6572\atiflash_293\atiwinflash 2.9.3.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1108"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\atiflash_293 (21).zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
1828"C:\Users\admin\AppData\Local\Temp\Rar$EXa1108.6572\atiflash_293\ATIWinflash 2.9.3.exe" /VERYSILENTC:\Users\admin\AppData\Local\Temp\Rar$EXa1108.6572\atiflash_293\ATIWinflash 2.9.3.exe
ATIWinflash 2.9.3.exe
User:
admin
Company:
amd_vbflashWin MFC Application 2.9.3
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa1108.6572\atiflash_293\atiwinflash 2.9.3.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2692"C:\Windows\system32\cmd.exe"C:\Windows\system32\cmd.exenotepad.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
2764"C:\Windows\system32\cmd.exe"C:\Windows\system32\cmd.exenotepad.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
2784"C:\Windows\system32\cmd.exe"C:\Windows\system32\cmd.exenotepad.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
2940"C:\Windows\system32\cmd.exe"C:\Windows\system32\cmd.exenotepad.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
2960"C:\Users\admin\AppData\Local\Temp\Rar$EXa1108.6572\atiflash_293\ATIWinflash 2.9.3.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa1108.6572\atiflash_293\ATIWinflash 2.9.3.exeWinRAR.exe
User:
admin
Company:
amd_vbflashWin MFC Application 2.9.3
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
1
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa1108.6572\atiflash_293\atiwinflash 2.9.3.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3012"C:\Windows\system32\notepad.exe"C:\Windows\system32\notepad.exe
notepad.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
Total events
1 591
Read events
1 535
Write events
46
Delete events
10

Modification events

(PID) Process:(1108) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1108) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1108) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1108) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\atiflash_293 (21).zip
(PID) Process:(1108) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1108) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1108) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1108) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1108) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(1108) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
Executable files
40
Suspicious files
6
Text files
2
Unknown types
2

Dropped files

PID
Process
Filename
Type
1108WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1108.6572\atiflash_293\ATIWinflashdef.dllexecutable
MD5:739B233AB4F9CC9EB5C1616509413E54
SHA256:7664D4A2EA7E73A8A239A1A83390A05E9D06DDC774227644A10F1254D2198899
1108WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1108.6572\atiflash_293\ATIWinflashenu.dllexecutable
MD5:2441FE5E3FEC2BE00123233D6719DB09
SHA256:6C4CD77B3FA02696B2FC034248BBCBB83A8B85D09D4A9875F1595569A97197BB
1828ATIWinflash 2.9.3.exeC:\Users\admin\AppData\Local\Temp\is-62IJT.tmp
MD5:
SHA256:
1108WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1108.6572\atiflash_293\ATIWinflashita.dllexecutable
MD5:4E6900FAC24EFFFD0FD50AEEA7702112
SHA256:3DC786F23A84D1C8CB7391B06538D1F21AD603017393B21C7D3B6055624185D9
1828ATIWinflash 2.9.3.exeC:\Users\admin\AppData\Local\Temp\is-NVIGL.tmp
MD5:
SHA256:
1108WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1108.6572\atiflash_293\ATIWinflashptb.dllexecutable
MD5:FA153A8C80B024DFCE699707F631AE32
SHA256:DFD1771114ABEE8D5EB4C929FA269362379EDD9C9AF8D6DD1C98B583E7170936
1828ATIWinflash 2.9.3.exeC:\Users\admin\AppData\Local\Temp\is-FGJTP.tmp
MD5:
SHA256:
1108WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1108.6572\atiflash_293\ATIWinflashdeu.dllexecutable
MD5:84825185269248903E6011A10922A423
SHA256:C824D26A901CDE5B2BE6B71FF3F8E440B3549DB43B4ACAAD2235EA0D4EE33D8B
1828ATIWinflash 2.9.3.exeC:\Users\admin\AppData\Local\Temp\is-EBCHH.tmp
MD5:
SHA256:
1108WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1108.6572\atiflash_293\ATIWinflash 2.9.3.exeexecutable
MD5:E2F393553181BC39208AF4EA719358F3
SHA256:0BE1E5C9B2D1F4D187331A40701D0259CF173A3F4D55EF84AF7E6FB7AFA17C91
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
4
DNS requests
2
Threats
7

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3228
notepad.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAH9o%2BtuynXIiEOLckvPvJE%3D
US
der
471 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
151.101.120.193:443
i.imgur.com
Fastly
US
malicious
3228
notepad.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
3228
notepad.exe
151.101.120.193:443
i.imgur.com
Fastly
US
malicious
3012
notepad.exe
37.1.218.181:5854
Leaseweb Deutschland GmbH
DE
malicious

DNS requests

Domain
IP
Reputation
i.imgur.com
  • 151.101.120.193
malicious
ocsp.digicert.com
  • 93.184.220.29
whitelisted

Threats

PID
Process
Class
Message
3012
notepad.exe
A Network Trojan was detected
REMOTE [PTsecurity] Backdoor.Win32/Remcos RAT connection
6 ETPRO signatures available at the full report
No debug info