| download: | laragon.7z |
| Full analysis: | https://app.any.run/tasks/43f2f580-7d60-4d3f-81a0-0d1630406c0d |
| Verdict: | Malicious activity |
| Analysis date: | September 17, 2020, 14:27:32 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-7z-compressed |
| File info: | 7-zip archive data, version 0.4 |
| MD5: | 17FE3DCC017D22590C18EDD1C194EE54 |
| SHA1: | 056A5368EDB55F5A36A94132A009F8D359970907 |
| SHA256: | 65837D2C9DAF0994345746A7B405A2A728CC422F15CB8F858F919E68D1F82C02 |
| SSDEEP: | 393216:DaqCzcb4uozq3y2ts52j0OZ7u1X2e9ul8voWVFWDkdawHcoApHjnD4m:eTzcb4NQsXOiR2e9CLW4kddHcoApH/ |
| .7z | | | 7-Zip compressed archive (v0.4) (57.1) |
|---|---|---|
| .7z | | | 7-Zip compressed archive (gen) (42.8) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 672 | C:\Users\admin\AppData\Local\Temp\laragon\bin\php\php-5.4.9-nts-Win32-VC9-x86\php-cgi.exe -b localhost:9002 | C:\Users\admin\AppData\Local\Temp\laragon\bin\php\php-5.4.9-nts-Win32-VC9-x86\php-cgi.exe | — | laragon.exe | |||||||||||
User: admin Company: The PHP Group Integrity Level: MEDIUM Description: CGI / FastCGI Exit code: 0 Version: 5.4.9 Modules
| |||||||||||||||
| 780 | C:\Users\admin\AppData\Local\Temp\laragon\bin\mysql\mysql-5.1.72-win32\bin\mysqladmin -u root create Welcome | C:\Users\admin\AppData\Local\Temp\laragon\bin\mysql\mysql-5.1.72-win32\bin\mysqladmin.exe | cmd.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 1840 | "C:\Users\admin\AppData\Local\Temp\laragon\laragon.exe" | C:\Users\admin\AppData\Local\Temp\laragon\laragon.exe | — | explorer.exe | |||||||||||
User: admin Company: Le Ngoc Khoa Integrity Level: MEDIUM Description: Laragon Exit code: 0 Version: 3.3.1.0 Modules
| |||||||||||||||
| 2076 | C:\Users\admin\AppData\Local\Temp\laragon\bin\nginx\nginx-1.14.0\nginx -p "C:\Users\admin\AppData\Local\Temp\laragon\bin\nginx\nginx-1.14.0" | C:\Users\admin\AppData\Local\Temp\laragon\bin\nginx\nginx-1.14.0\nginx.exe | — | laragon.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 2344 | C:\Users\admin\AppData\Local\Temp\laragon\bin\php\php-5.4.9-nts-Win32-VC9-x86\php-cgi.exe -b localhost:9001 | C:\Users\admin\AppData\Local\Temp\laragon\bin\php\php-5.4.9-nts-Win32-VC9-x86\php-cgi.exe | — | laragon.exe | |||||||||||
User: admin Company: The PHP Group Integrity Level: MEDIUM Description: CGI / FastCGI Exit code: 0 Version: 5.4.9 Modules
| |||||||||||||||
| 2484 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\laragon.7z" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 2624 | C:\Users\admin\AppData\Local\Temp\laragon\bin\mysql\mysql-5.1.72-win32\bin\mysqld --log-error=C:\Users\admin\AppData\Local\Temp\laragon\bin\mysql\mysql-5.1.72-win32\data\mysqld.log | C:\Users\admin\AppData\Local\Temp\laragon\bin\mysql\mysql-5.1.72-win32\bin\mysqld.exe | — | laragon.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 3532 | cmd.exe /C C:\Users\admin\AppData\Local\Temp\laragon\bin\laragon\utils\curl.exe -L "https://wordpress.org/latest.zip" -o C:\Users\admin\AppData\Local\Temp\laragon\tmp\downloads\20200917152924.wordpress.latest.zip | C:\Windows\system32\cmd.exe | — | laragon.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 3664 | C:\Users\admin\AppData\Local\Temp\laragon\bin\nginx\nginx-1.14.0\nginx -p "C:\Users\admin\AppData\Local\Temp\laragon\bin\nginx\nginx-1.14.0" | C:\Users\admin\AppData\Local\Temp\laragon\bin\nginx\nginx-1.14.0\nginx.exe | — | nginx.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 3772 | cmd.exe /C C:\Users\admin\AppData\Local\Temp\laragon\bin\mysql\mysql-5.1.72-win32\bin\mysqladmin -u root create Welcome | C:\Windows\system32\cmd.exe | — | laragon.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| (PID) Process: | (2484) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (2484) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (2484) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2484) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\laragon.7z | |||
| (PID) Process: | (2484) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2484) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2484) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2484) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (2484) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\laragon | |||
| (PID) Process: | (2484) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin |
| Operation: | write | Name: | Placement |
Value: 2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFCF000000630000008F04000058020000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2484 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\laragon\bin\cmder\config\settings | text | |
MD5:— | SHA256:— | |||
| 2484 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\laragon\bin\cmder\cmder.bat | text | |
MD5:— | SHA256:— | |||
| 2484 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\laragon\bin\cmder\vendor\init.bat | text | |
MD5:— | SHA256:— | |||
| 2484 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\laragon\bin\cmder\config\.history | text | |
MD5:— | SHA256:— | |||
| 2484 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\laragon\bin\cmder\vendor\clink\clink.bat | text | |
MD5:— | SHA256:— | |||
| 2484 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\laragon\bin\cmder\vendor\clink\clink.lua | text | |
MD5:— | SHA256:— | |||
| 2484 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\laragon\bin\composer\composer.phar | ovpn | |
MD5:— | SHA256:— | |||
| 2484 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\laragon\bin\cmder\config\user-aliases.cmd | text | |
MD5:— | SHA256:— | |||
| 2484 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\laragon\bin\cmder\bin\alias.bat | text | |
MD5:E016C0ED8CF45544D76069692C3D5F4F | SHA256:F77BAE996A6A8E3870C9776063D189B96608872CE1EED5EDE500F4DE037FB1FA | |||
| 2484 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\laragon\bin\cmder\vendor\profile3.ps1 | text | |
MD5:35819D17E06A28B8B727EB94D0362DDE | SHA256:CA3F8AA23AA89847E3814CA345BD2C1FCA1BE8DEDC1DE6F605FB10EE964F5AE1 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4040 | curl.exe | 198.143.164.252:443 | wordpress.org | SingleHop, Inc. | US | unknown |
Domain | IP | Reputation |
|---|---|---|
wordpress.org |
| whitelisted |