| File name: | your_file.zip |
| Full analysis: | https://app.any.run/tasks/3aa7f9ec-a622-49f8-beeb-48cc871a2c5d |
| Verdict: | Malicious activity |
| Analysis date: | January 21, 2024, 03:25:13 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | C661D74D59CE778783E81968549E5F44 |
| SHA1: | F56626C19DB62C17E74FA15151626D68877824AC |
| SHA256: | 65FA77C5EFB0B01B7E7D959B1A058DD5EEECB9C5BC505BBDF4648C43A56CE50E |
| SSDEEP: | 98304:8jLf3ybjIOkhotuVNoW+x2Rw4H0DgD5CfsuL4vScBIofrYQMYzffu4tv3ECp2yY7:SBVs3Ws |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2024:01:20 22:38:32 |
| ZipCRC: | 0xc9e9bb69 |
| ZipCompressedSize: | 3415 |
| ZipUncompressedSize: | 782838 |
| ZipFileName: | password.jpg |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 124 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2308 --field-trial-handle=1324,i,9521769580893620097,17395907571657435531,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 128 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\your_file.zip" | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 148 | "C:\Users\admin\Desktop\passfab-for-zip.exe" | C:\Users\admin\Desktop\passfab-for-zip.exe | explorer.exe | ||||||||||||
User: admin Company: PassFab, Inc. Integrity Level: HIGH Description: PassFab for ZIP Setup Exit code: 1 Version: Modules
| |||||||||||||||
| 324 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=1428 --field-trial-handle=1324,i,9521769580893620097,17395907571657435531,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 664 | "C:\Program Files\PassFab for ZIP\john\plan1\zip2john.exe" "C:\ziptmp.zip" | C:\Program Files\PassFab for ZIP\john\plan1\zip2john.exe | — | cmd.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 884 | "C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Desktop\your_file.zip" C:\Users\admin\Desktop\your_file\ | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 956 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --use-gl=angle --use-angle=swiftshader-webgl --mojo-platform-channel-handle=1484 --field-trial-handle=1324,i,9521769580893620097,17395907571657435531,131072 /prefetch:2 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 980 | "C:\Users\admin\Desktop\passfab-for-zip.exe" | C:\Users\admin\Desktop\passfab-for-zip.exe | — | explorer.exe | |||||||||||
User: admin Company: PassFab, Inc. Integrity Level: MEDIUM Description: PassFab for ZIP Setup Exit code: 3221226540 Version: Modules
| |||||||||||||||
| 1232 | "C:\Windows\System32\cmd.exe" /c ""C:\Program Files\PassFab for ZIP\john\plan1\zip2john.exe" "C:\ziptmp.zip" > "C:\Users\admin\AppData\Local\Temp\temp.hash"" | C:\Windows\System32\cmd.exe | — | PassFab for ZIP.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1264 | "C:\Users\admin\Desktop\passfab-for-zip.exe" | C:\Users\admin\Desktop\passfab-for-zip.exe | explorer.exe | ||||||||||||
User: admin Company: PassFab, Inc. Integrity Level: HIGH Description: PassFab for ZIP Setup Exit code: 1 Version: Modules
| |||||||||||||||
| (PID) Process: | (128) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (128) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (128) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (128) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (128) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
| (PID) Process: | (128) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (128) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (128) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (128) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (128) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin |
| Operation: | write | Name: | Placement |
Value: 2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2112 | passfab-for-zip.exe | C:\Users\admin\AppData\Local\Temp\is-P8999.tmp\passfab-for-zip.tmp | executable | |
MD5:507B5870D106E5746C4A1328DD008973 | SHA256:244891F4A30401C8727B72D10F081E340EE147972E3C86A403B7C8674C876B32 | |||
| 1956 | passfab-for-zip.exe | C:\Users\admin\AppData\Local\Temp\is-I8IEB.tmp\passfab-for-zip.tmp | executable | |
MD5:507B5870D106E5746C4A1328DD008973 | SHA256:244891F4A30401C8727B72D10F081E340EE147972E3C86A403B7C8674C876B32 | |||
| 2916 | passfab-for-zip.tmp | C:\Program Files\PassFab for ZIP\is-0H007.tmp | executable | |
MD5:22E71692E58F514E97000F1917C1D690 | SHA256:C89DC5B66FBD310F0A12B0A0F0606A37BA5268B53523208E384090E97DE194A3 | |||
| 2916 | passfab-for-zip.tmp | C:\Program Files\PassFab for ZIP\errordump.dll | executable | |
MD5:1DB13A9006CEE9C055A10E0EF0EDB6A4 | SHA256:4FE09AFDB3BF9E4AE3692D978D9CCF94908E0DA4FF609FB7872CEFB025E438D9 | |||
| 2916 | passfab-for-zip.tmp | C:\Program Files\PassFab for ZIP\unins000.exe | executable | |
MD5:F37284AE127C415D4EAD3AC3A756FBBA | SHA256:F258523CA0F1728634E4A6014DA952511DD6B17C8E52B3B661CD6E2462C11C4F | |||
| 2916 | passfab-for-zip.tmp | C:\Program Files\PassFab for ZIP\is-42RQR.tmp | executable | |
MD5:1E2D2D7BFD4C99923DEFBBA57EA6A939 | SHA256:7C826F84BAC8BEECEDD61203A73B891986722BC137B11C001EF7485846FD2732 | |||
| 2916 | passfab-for-zip.tmp | C:\Program Files\PassFab for ZIP\is-4RM8I.tmp | text | |
MD5:24DF3D2EAD9720670E32F52B088F4BE7 | SHA256:F42EEA598FB2481311578DEE7F38AE3506E8A4B5994009685D1AA242930A1CDC | |||
| 2916 | passfab-for-zip.tmp | C:\Users\admin\AppData\Local\Temp\is-GN0SL.tmp\SoftwareLog1.dll | executable | |
MD5:5F236BC79AF30D9A703E76CF06458CEC | SHA256:639892E93EEE182EAC88CE1BE23DF1A3C01130686C32D47F85728E6B332602D5 | |||
| 2916 | passfab-for-zip.tmp | C:\Program Files\PassFab for ZIP\deviceQuery.exe | executable | |
MD5:6CCC9CCC39AC097D0C9B21B8F0453C03 | SHA256:22F5347B955388F6514A2B4AF6AB71102E33ACCAD9C1D5BEA1FA1C88114B1A4B | |||
| 2916 | passfab-for-zip.tmp | C:\Program Files\PassFab for ZIP\BugSplatRc.dll | executable | |
MD5:22E71692E58F514E97000F1917C1D690 | SHA256:C89DC5B66FBD310F0A12B0A0F0606A37BA5268B53523208E384090E97DE194A3 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2916 | passfab-for-zip.tmp | GET | 301 | 104.18.24.249:80 | http://www.tenorshare.com/downloads/service/softwarelog.txt | unknown | html | 245 b | unknown |
2916 | passfab-for-zip.tmp | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAhflMAthXvozBT%2FU%2B2iPio%3D | US | binary | 471 b | unknown |
2916 | passfab-for-zip.tmp | GET | 200 | 93.184.221.240:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?65611f51d605a421 | GB | compressed | 4.66 Kb | unknown |
2916 | passfab-for-zip.tmp | GET | 301 | 104.18.24.249:80 | http://www.tenorshare.com/downloads/service/softwarelog.txt | unknown | html | 245 b | unknown |
2916 | passfab-for-zip.tmp | GET | 521 | 172.67.179.206:8080 | http://recoverlostpassword.com:8080/AddUserInfo?guid=55AA7432-8372-4E18-B48D-A5C70714DC78&IP=192.168.100.57&ComputerName=USER-PC&SystemVersion=Windows%207%20x32&Location=Germany&City=Frankfurt%20am%20Main&OutIP=87.249.132.40 | US | html | 6.72 Kb | unknown |
2916 | passfab-for-zip.tmp | GET | 200 | 208.95.112.1:80 | http://ip-api.com/csv | US | text | 155 b | unknown |
2916 | passfab-for-zip.tmp | GET | — | 172.67.179.206:8080 | http://recoverlostpassword.com:8080/AddUserInfo?guid=D0F3F69D-6D5F-447E-B885-882E1ADFE3C1&IP=192.168.100.57&ComputerName=USER-PC&SystemVersion=Windows%207%20x32&Location=Germany&City=Frankfurt%20am%20Main&OutIP=87.249.132.40 | US | — | — | unknown |
2916 | passfab-for-zip.tmp | GET | 301 | 104.18.24.249:80 | http://www.tenorshare.com/downloads/service/softwarelog.txt | unknown | html | 245 b | unknown |
2916 | passfab-for-zip.tmp | GET | — | 172.67.179.206:8080 | http://recoverlostpassword.com:8080/AddUserInfo?guid=9513A371-FFB6-41D6-B34F-6E9BFCA10E64&IP=192.168.100.57&ComputerName=USER-PC&SystemVersion=Windows%207%20x32&Location=Germany&City=Frankfurt%20am%20Main&OutIP=87.249.132.40 | US | — | — | unknown |
3248 | PassFab for ZIP.exe | POST | 200 | 142.250.185.78:80 | http://www.google-analytics.com/collect | US | image | 35 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2916 | passfab-for-zip.tmp | 104.18.24.249:80 | www.tenorshare.com | CLOUDFLARENET | — | unknown |
2916 | passfab-for-zip.tmp | 104.18.24.249:443 | www.tenorshare.com | CLOUDFLARENET | — | unknown |
2916 | passfab-for-zip.tmp | 93.184.221.240:80 | ctldl.windowsupdate.com | EDGECAST | GB | whitelisted |
2916 | passfab-for-zip.tmp | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
2916 | passfab-for-zip.tmp | 208.95.112.1:80 | ip-api.com | TUT-AS | US | unknown |
2916 | passfab-for-zip.tmp | 172.67.179.206:8080 | recoverlostpassword.com | CLOUDFLARENET | US | unknown |
3248 | PassFab for ZIP.exe | 142.250.185.78:80 | www.google-analytics.com | GOOGLE | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
www.tenorshare.com |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
ip-api.com |
| shared |
recoverlostpassword.com |
| whitelisted |
www.google-analytics.com |
| whitelisted |
cbs.passfab.com |
| unknown |
config.edge.skype.com |
| whitelisted |
edge.microsoft.com |
| whitelisted |
nav-edge.smartscreen.microsoft.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2916 | passfab-for-zip.tmp | Potential Corporate Privacy Violation | ET POLICY Unsupported/Fake Windows NT Version 5.0 |
2916 | passfab-for-zip.tmp | Potential Corporate Privacy Violation | ET POLICY Unsupported/Fake Windows NT Version 5.0 |
2916 | passfab-for-zip.tmp | Potential Corporate Privacy Violation | AV POLICY Internal Host Retrieving External IP Address (ip-api. com) |
2916 | passfab-for-zip.tmp | Device Retrieving External IP Address Detected | ET POLICY External IP Lookup ip-api.com |