| File name: | ZIP-Password-IS-951951______VmProtect.zip |
| Full analysis: | https://app.any.run/tasks/f8d41113-dd73-4d61-b68c-ee94b82967b6 |
| Verdict: | Malicious activity |
| Threats: | A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection. |
| Analysis date: | January 15, 2022, 02:52:07 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | EFE9E1BFE8405AE27DFADA0D189F44CA |
| SHA1: | EFD3770EDCEBC03E5437945B50C0D784576F29E9 |
| SHA256: | 659FE37447FF0D6A6B470144E321829140D3B4AAB03488AAC75C6571CAD87CED |
| SSDEEP: | 98304:35W4nrEUX8K2qry24uzoTG04RPD9KRI0NBmDlWUKa+T4lmG+g8ILBVQaGKyHEsRw:35WW8QrFLJhKO0/0lxA4lm1acaykOwya |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipFileName: | 149_setupInstaller.exe |
|---|---|
| ZipUncompressedSize: | 5847902 |
| ZipCompressedSize: | 5835653 |
| ZipCRC: | 0x8f8191d0 |
| ZipModifyDate: | 2022:01:15 04:30:21 |
| ZipCompression: | Deflated |
| ZipBitFlag: | 0x0001 |
| ZipRequiredVersion: | 20 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 356 | 61e231afbd0ff_Sat0275ca378161.exe | C:\Users\admin\AppData\Local\Temp\7zS8F245514\61e231afbd0ff_Sat0275ca378161.exe | — | cmd.exe | |||||||||||
User: admin Company: DCloud Integrity Level: HIGH Description: HBuilder X Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 532 | "C:\Windows\system32\cmd.exe" /c ping 127.0.0.1 && del "C:\Users\admin\AppData\Local\Temp\7zS8F245514\61e231ad0641a_Sat02817ac1e8.exe" >> NUL | C:\Windows\system32\cmd.exe | — | 61e231ad0641a_Sat02817ac1e8.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 560 | C:\Users\admin\AppData\Local\Temp\61e231c208b88_Sat021d6cb0.exe | C:\Users\admin\AppData\Local\Temp\61e231c208b88_Sat021d6cb0.exe | 61e231c208b88_Sat021d6cb0.exe | ||||||||||||
User: admin Company: Installer Integrity Level: HIGH Description: Installer Exit code: 0 Version: 6.3.0.8 Modules
| |||||||||||||||
| 564 | C:\Windows\system32\cmd.exe /c 61e231c7536eb_Sat028b7251.exe | C:\Windows\system32\cmd.exe | — | setup_install.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 3 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 576 | "C:\Users\admin\AppData\Local\Temp\22b3368b-da1a-4cd8-924a-4d0abaff18f1.exe" | C:\Users\admin\AppData\Local\Temp\22b3368b-da1a-4cd8-924a-4d0abaff18f1.exe | 61e231c2c70ca_Sat02e1a7ed.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 684 | "C:\Users\admin\AppData\Local\Temp\Rar$EXb2280.29416\149_setupInstaller.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXb2280.29416\149_setupInstaller.exe | — | WinRAR.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| 684 | "C:\Users\admin\AppData\Local\Temp\c2001101-5d15-47d7-997d-9d9bd627547e.exe" | C:\Users\admin\AppData\Local\Temp\c2001101-5d15-47d7-997d-9d9bd627547e.exe | 61e231c2c70ca_Sat02e1a7ed.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: gdffgsdfsd Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 760 | "C:\Users\admin\AppData\Local\Temp\setup_installer.exe" | C:\Users\admin\AppData\Local\Temp\setup_installer.exe | 149_setupInstaller.exe | ||||||||||||
User: admin Company: Igor Pavlov Integrity Level: HIGH Description: 7z Setup SFX Exit code: 0 Version: 19.00 Modules
| |||||||||||||||
| 924 | C:\Windows\system32\svchost.exe -k netsvcs | C:\Windows\system32\svchost.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 984 | C:\Windows\system32\cmd.exe /c powershell -inputformat none -outputformat none -NonInteractive -Command Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable | C:\Windows\system32\cmd.exe | — | setup_install.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 1 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| (PID) Process: | (2280) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (2280) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (2280) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2280) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (2280) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (2280) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\ZIP-Password-IS-951951______VmProtect.zip | |||
| (PID) Process: | (2280) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2280) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2280) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2280) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3628 | 149_setupInstaller.exe | C:\Users\admin\AppData\Local\Temp\nsi1E93.tmp | — | |
MD5:— | SHA256:— | |||
| 2280 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb2280.29416\PASSWORD-IS-951951.txt | text | |
MD5:— | SHA256:— | |||
| 2280 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb2280.29416\149_setupInstaller.exe | executable | |
MD5:— | SHA256:— | |||
| 760 | setup_installer.exe | C:\Users\admin\AppData\Local\Temp\7zS8F245514\16422138324989.exe | text | |
MD5:— | SHA256:— | |||
| 760 | setup_installer.exe | C:\Users\admin\AppData\Local\Temp\7zS8F245514\61e231af132e7_Sat020ee35cf.exe | executable | |
MD5:— | SHA256:— | |||
| 760 | setup_installer.exe | C:\Users\admin\AppData\Local\Temp\7zS8F245514\61e231ad0641a_Sat02817ac1e8.exe | executable | |
MD5:— | SHA256:— | |||
| 760 | setup_installer.exe | C:\Users\admin\AppData\Local\Temp\7zS8F245514\61e231ae18706_Sat028e900d3.exe | executable | |
MD5:— | SHA256:— | |||
| 760 | setup_installer.exe | C:\Users\admin\AppData\Local\Temp\7zS8F245514\61e231b0801f9_Sat02dabcd2901f.exe | executable | |
MD5:— | SHA256:— | |||
| 3628 | 149_setupInstaller.exe | C:\Users\admin\AppData\Local\Temp\setup_installer.exe | executable | |
MD5:— | SHA256:— | |||
| 760 | setup_installer.exe | C:\Users\admin\AppData\Local\Temp\7zS8F245514\16422138329109.exe | text | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1688 | 61e231b2a394a_Sat02fc0e52.tmp | HEAD | 200 | 93.189.42.32:80 | http://noplayboy.com/77.exe | RU | — | — | malicious |
3520 | 61e231b18bfb5_Sat022d459aaa7.exe | GET | 200 | 104.21.5.208:80 | http://wfsdragon.ru/api/setStats.php | US | text | 15 b | malicious |
3520 | 61e231b18bfb5_Sat022d459aaa7.exe | GET | 400 | 45.144.225.57:80 | http://45.144.225.57/server.txt | unknown | html | 301 b | malicious |
3520 | 61e231b18bfb5_Sat022d459aaa7.exe | GET | 400 | 212.193.30.45:80 | http://212.193.30.45/proxies.txt | RU | html | 301 b | malicious |
2608 | 61e231c7536eb_Sat028b7251.exe | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAWAJn8G8pVTNI4cGFpe7i4%3D | US | der | 471 b | whitelisted |
3520 | 61e231b18bfb5_Sat022d459aaa7.exe | GET | 400 | 2.56.59.42:80 | http://2.56.59.42/base/api/statistics.php | unknown | html | 326 b | malicious |
2608 | 61e231c7536eb_Sat028b7251.exe | GET | 200 | 93.184.220.29:80 | http://statuse.digitalcertvalidation.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRJrF0xYA49jC3D83fgDGesaUkzIQQUf9OZ86BHDjEAVlYijrfMnt3KAYoCEAYJR5FkG19ljPHMaGsuvmc%3D | US | der | 471 b | whitelisted |
2920 | 61e231ad0641a_Sat02817ac1e8.exe | GET | 200 | 92.123.224.113:80 | http://r3.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRI2smg%2ByvTLU%2Fw3mjS9We3NfmzxAQUFC6zF7dYVsuuUAlA5h%2BvnYsUwsYCEgPRApfVsPmQefP8%2BOlu%2BSG2vQ%3D%3D | unknown | der | 503 b | shared |
3412 | 61e231b686514_Sat020f28d97695.exe | GET | 301 | 91.107.126.191:80 | http://web-stat.biz/stats/1.php?pub=/mixtwo&badparam=NOPE | RU | html | 162 b | malicious |
2080 | 61e231c8a77c0_Sat021d76eef2.exe | GET | 301 | 148.251.234.83:80 | http://iplogger.org/1dnc57 | DE | html | 162 b | shared |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3324 | setup_install.exe | 172.67.164.34:80 | kelenxz.xyz | — | US | malicious |
2608 | 61e231c7536eb_Sat028b7251.exe | 149.28.253.196:443 | www.listincode.com | — | US | suspicious |
3520 | 61e231b18bfb5_Sat022d459aaa7.exe | 212.193.30.45:80 | — | — | RU | malicious |
3520 | 61e231b18bfb5_Sat022d459aaa7.exe | 104.23.98.190:443 | pastebin.com | Cloudflare Inc | US | malicious |
2920 | 61e231ad0641a_Sat02817ac1e8.exe | 148.251.234.83:443 | iplogger.org | Hetzner Online GmbH | DE | malicious |
1324 | 61e231afbd0ff_Sat0275ca378161.exe | 172.67.188.70:443 | v.xyzgamev.com | — | US | suspicious |
3436 | 61e231c2c70ca_Sat02e1a7ed.exe | 104.21.88.113:443 | dpcapps.me | Cloudflare Inc | US | unknown |
3520 | 61e231b18bfb5_Sat022d459aaa7.exe | 45.144.225.57:80 | — | — | — | malicious |
3412 | 61e231b686514_Sat020f28d97695.exe | 91.107.126.191:80 | web-stat.biz | Domain names registrar REG.RU, Ltd | RU | malicious |
1324 | 61e231afbd0ff_Sat0275ca378161.exe | 13.107.4.50:80 | ctldl.windowsupdate.com | Microsoft Corporation | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
kelenxz.xyz |
| malicious |
www.listincode.com |
| whitelisted |
v.xyzgamev.com |
| suspicious |
iplogger.org |
| shared |
web-stat.biz |
| malicious |
pastebin.com |
| malicious |
whatisart.top |
| suspicious |
noplayboy.com |
| malicious |
dpcapps.me |
| malicious |
ctldl.windowsupdate.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
3324 | setup_install.exe | Potentially Bad Traffic | AV INFO HTTP Request to a *.xyz domain |
— | — | Potentially Bad Traffic | ET INFO Observed DNS Query to .biz TLD |
3520 | 61e231b18bfb5_Sat022d459aaa7.exe | Potentially Bad Traffic | ET INFO Terse Request for .txt - Likely Hostile |
3520 | 61e231b18bfb5_Sat022d459aaa7.exe | Potentially Bad Traffic | ET INFO Terse Request for .txt - Likely Hostile |
— | — | Potentially Bad Traffic | ET DNS Query to a *.top domain - Likely Hostile |
— | — | Potentially Bad Traffic | ET INFO Observed DNS Query to .biz TLD |
3520 | 61e231b18bfb5_Sat022d459aaa7.exe | A Network Trojan was detected | ET MALWARE User-Agent (???) |
3412 | 61e231b686514_Sat020f28d97695.exe | A Network Trojan was detected | ET TROJAN GCleaner Downloader Activity M5 |
2080 | 61e231c8a77c0_Sat021d76eef2.exe | Potentially Bad Traffic | ET INFO TLS Handshake Failure |
2080 | 61e231c8a77c0_Sat021d76eef2.exe | Potentially Bad Traffic | ET INFO TLS Handshake Failure |