File name:

ChilledWindows.exe.zip

Full analysis: https://app.any.run/tasks/49f2a7c6-3385-4f8d-99f5-add15e118d96
Verdict: No threats detected
Analysis date: May 03, 2018, 12:11:34
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

293C8958EFF7FE7D60E7D37EFC3E76D9

SHA1:

76CC9A70EDB88927FE6E0E21F0A0CA2E5C2D4E05

SHA256:

65B17A9371158451E0534CC68962956F2CFAADDC5EC2A17E0A304401C83A954D

SSDEEP:

98304:/wlRowHsj9t+00T+X2VO5UyjDpV28b+rK4GiPPZxhXt:iwRtO8Z/2NrhGiPxxhXt

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • ChilledWindows.exe (PID: 2824)
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Loads the .NET runtime environment

      • ChilledWindows.exe (PID: 2824)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: ChilledWindows.exe
ZipUncompressedSize: 4578304
ZipCompressedSize: 4396139
ZipCRC: 0xc13279ae
ZipModifyDate: 2018:05:03 14:08:09
ZipCompression: Deflated
ZipBitFlag: 0x0001
ZipRequiredVersion: 788
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
36
Monitored processes
3
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start 7zfm.exe chilledwindows.exe no specs taskmgr.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3520"C:\Program Files\7-Zip\7zFM.exe" "C:\Users\admin\Desktop\ChilledWindows.exe.zip"C:\Program Files\7-Zip\7zFM.exe
explorer.exe
User:
admin
Company:
Igor Pavlov
Integrity Level:
MEDIUM
Description:
7-Zip File Manager
Version:
16.04
Modules
Images
c:\program files\7-zip\7zfm.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2824"C:\Users\admin\AppData\Local\Temp\7zO0CD45E8F\ChilledWindows.exe" C:\Users\admin\AppData\Local\Temp\7zO0CD45E8F\ChilledWindows.exe7zFM.exe
User:
admin
Company:
GAMELASTER
Integrity Level:
MEDIUM
Description:
ChilledWindows
Exit code:
3221225547
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\7zo0cd45e8f\chilledwindows.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1792"C:\Windows\system32\taskmgr.exe" /4C:\Windows\system32\taskmgr.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Task Manager
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskmgr.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
811
Read events
768
Write events
42
Delete events
1

Modification events

(PID) Process:(3520) 7zFM.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(3520) 7zFM.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(2824) ChilledWindows.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Operation:writeName:Name
Value:
ChilledWindows.exe
(PID) Process:(2824) ChilledWindows.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(2824) ChilledWindows.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(2824) ChilledWindows.exeKey:HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
Operation:writeName:LastScreensaverSetThreadExecutionState
Value:
2147483648
(PID) Process:(2824) ChilledWindows.exeKey:HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
Operation:writeName:LastScreensaverState
Value:
4
(PID) Process:(2824) ChilledWindows.exeKey:HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
Operation:writeName:AutoMetadataCurrentDownloadCount
Value:
0
(PID) Process:(2824) ChilledWindows.exeKey:HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
Operation:writeName:AutoMetadataCurrent500ServerErrorCount
Value:
0
(PID) Process:(2824) ChilledWindows.exeKey:HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
Operation:writeName:AutoMetadataCurrent503ServerErrorCount
Value:
0
Executable files
1
Suspicious files
1
Text files
0
Unknown types
1

Dropped files

PID
Process
Filename
Type
2824ChilledWindows.exeC:\Users\admin\AppData\Local\Microsoft\Media Player\CurrentDatabase_372.wmdbbinary
MD5:87D5CF4AB3B643B0B603C66ECEFF9C01
SHA256:1B9106FE6BD6FE70A57A709CB942D15BB6C2EFE26EFA5EB4F931F32D5737EC97
35207zFM.exeC:\Users\admin\AppData\Local\Temp\7zO0CD45E8F\ChilledWindows.exeexecutable
MD5:6A4853CD0584DC90067E15AFB43C4962
SHA256:CCB9502BF8BA5BECF8B758CA04A5625C30B79E2D10D2677CC43AE4253E1288EC
2824ChilledWindows.exeC:\Users\admin\AppData\Local\Temp\7zO0CD45E8F\chilledwindows.mp4m4v
MD5:698DDCAEC1EDCF1245807627884EDF9C
SHA256:CDE975F975D21EDB2E5FAA505205AB8A2C5A565BA1FF8585D1F0E372B2A1D78B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info