File name:

ImgBurn.zip

Full analysis: https://app.any.run/tasks/18153b0b-e1ed-4253-b004-4c366bd10d40
Verdict: Malicious activity
Analysis date: July 27, 2022, 10:55:56
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

BA232A02FC590880B55AC9AF0B240BF2

SHA1:

62AB7BE1FF6465A5FFD85E00ACF0707AF476F001

SHA256:

69773A222C5AB575DFB91B4DC1B7A3EA27740791098F210DADE9254074924C18

SSDEEP:

98304:u2xmRB6BvN99d4l43owKkOU3DqFTC9vYTVEUGE7/y/QLh80G9bt9ocNv:7xLT9gK3obUTqFOraymGJt6ev

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops executable file immediately after starts

      • WinRAR.exe (PID: 2072)
      • ImgBurn.exe (PID: 1228)
      • rdffv35y.zvw.exe (PID: 2424)
      • rdffv35y.zvw.tmp (PID: 3152)
    • Application was dropped or rewritten from another process

      • ImgBurn.exe (PID: 1228)
      • walliant.exe (PID: 2296)
    • Changes settings of System certificates

      • ImgBurn.exe (PID: 1228)
      • saBSI.exe (PID: 3536)
    • Actions looks like stealing of personal data

      • ImgBurn.exe (PID: 1228)
    • Loads dropped or rewritten executable

      • ImgBurn.exe (PID: 1228)
      • walliant.exe (PID: 2296)
    • Changes the autorun value in the registry

      • rdffv35y.zvw.tmp (PID: 3152)
  • SUSPICIOUS

    • Reads the computer name

      • WinRAR.exe (PID: 2072)
      • ImgBurn.exe (PID: 1228)
      • rdffv35y.zvw.tmp (PID: 3152)
      • walliant.exe (PID: 2296)
      • saBSI.exe (PID: 3536)
    • Checks supported languages

      • ImgBurn.exe (PID: 1228)
      • rdffv35y.zvw.exe (PID: 2424)
      • rdffv35y.zvw.tmp (PID: 3152)
      • walliant.exe (PID: 2296)
      • saBSI.exe (PID: 3536)
      • WinRAR.exe (PID: 2072)
    • Drops a file with a compile date too recent

      • WinRAR.exe (PID: 2072)
      • ImgBurn.exe (PID: 1228)
      • rdffv35y.zvw.exe (PID: 2424)
      • rdffv35y.zvw.tmp (PID: 3152)
    • Reads Windows owner or organization settings

      • ImgBurn.exe (PID: 1228)
      • rdffv35y.zvw.tmp (PID: 3152)
    • Adds / modifies Windows certificates

      • ImgBurn.exe (PID: 1228)
      • saBSI.exe (PID: 3536)
    • Executable content was dropped or overwritten

      • ImgBurn.exe (PID: 1228)
      • rdffv35y.zvw.exe (PID: 2424)
      • rdffv35y.zvw.tmp (PID: 3152)
      • WinRAR.exe (PID: 2072)
    • Reads Environment values

      • ImgBurn.exe (PID: 1228)
      • walliant.exe (PID: 2296)
    • Reads the Windows organization settings

      • ImgBurn.exe (PID: 1228)
      • rdffv35y.zvw.tmp (PID: 3152)
    • Creates files in the program directory

      • saBSI.exe (PID: 3536)
    • Reads internet explorer settings

      • walliant.exe (PID: 2296)
    • Reads Microsoft Outlook installation path

      • walliant.exe (PID: 2296)
    • Searches for installed software

      • ImgBurn.exe (PID: 1228)
  • INFO

    • Manual execution by user

      • ImgBurn.exe (PID: 1228)
      • taskmgr.exe (PID: 1444)
      • taskmgr.exe (PID: 2368)
    • Checks Windows Trust Settings

      • ImgBurn.exe (PID: 1228)
      • walliant.exe (PID: 2296)
      • saBSI.exe (PID: 3536)
    • Reads settings of System Certificates

      • ImgBurn.exe (PID: 1228)
      • rdffv35y.zvw.tmp (PID: 3152)
      • walliant.exe (PID: 2296)
      • saBSI.exe (PID: 3536)
    • Checks supported languages

      • taskmgr.exe (PID: 1444)
      • taskmgr.exe (PID: 2368)
    • Reads the computer name

      • taskmgr.exe (PID: 2368)
      • taskmgr.exe (PID: 1444)
    • Application was dropped or rewritten from another process

      • rdffv35y.zvw.tmp (PID: 3152)
    • Creates a software uninstall entry

      • rdffv35y.zvw.tmp (PID: 3152)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: ImgBurn.exe
ZipUncompressedSize: 3997984
ZipCompressedSize: 3966110
ZipCRC: 0x577d0711
ZipModifyDate: 2022:07:27 12:05:07
ZipCompression: Deflated
ZipBitFlag: -
ZipRequiredVersion: 20
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
48
Monitored processes
8
Malicious processes
4
Suspicious processes
2

Behavior graph

Click at the process to see the details
start drop and start drop and start winrar.exe imgburn.exe taskmgr.exe no specs taskmgr.exe no specs rdffv35y.zvw.exe rdffv35y.zvw.tmp walliant.exe sabsi.exe

Process information

PID
CMD
Path
Indicators
Parent process
1228"C:\Users\admin\Desktop\ImgBurn.exe" C:\Users\admin\Desktop\ImgBurn.exe
Explorer.EXE
User:
admin
Company:
DG001
Integrity Level:
HIGH
Description:
Software Installation
Exit code:
0
Version:
6.94.0.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\desktop\imgburn.exe
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
1444"C:\Windows\system32\taskmgr.exe" /4C:\Windows\system32\taskmgr.exeExplorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Task Manager
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskmgr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
2072"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\ImgBurn.zip"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2296"C:\Users\admin\AppData\Local\Programs\Walliant\walliant.exe"C:\Users\admin\AppData\Local\Programs\Walliant\walliant.exe
rdffv35y.zvw.tmp
User:
admin
Company:
Walliant
Integrity Level:
HIGH
Description:
Walliant
Exit code:
0
Version:
1.0.1.2
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\users\admin\appdata\local\programs\walliant\walliant.exe
c:\windows\system32\mscoree.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2368"C:\Windows\system32\taskmgr.exe" /4C:\Windows\system32\taskmgr.exeExplorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Task Manager
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskmgr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2424"C:\Users\admin\AppData\Local\Temp\rdffv35y.zvw.exe" /VERYSILENT /SUPPRESSMSGBOXES /NOCANCEL /NORESTARTC:\Users\admin\AppData\Local\Temp\rdffv35y.zvw.exe
ImgBurn.exe
User:
admin
Company:
Walliant
Integrity Level:
HIGH
Description:
Walliant Setup
Exit code:
0
Version:
1.0.1.2
Modules
Images
c:\users\admin\appdata\local\temp\rdffv35y.zvw.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3152"C:\Users\admin\AppData\Local\Temp\is-PKFSB.tmp\rdffv35y.zvw.tmp" /SL5="$60130,4511977,830464,C:\Users\admin\AppData\Local\Temp\rdffv35y.zvw.exe" /VERYSILENT /SUPPRESSMSGBOXES /NOCANCEL /NORESTARTC:\Users\admin\AppData\Local\Temp\is-PKFSB.tmp\rdffv35y.zvw.tmp
rdffv35y.zvw.exe
User:
admin
Company:
Walliant
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\appdata\local\temp\is-pkfsb.tmp\rdffv35y.zvw.tmp
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3536"saBSI.exe" /affid 91212 PaidDistribution=true InstallID=e1724775-af4c-4897-ac02-ea70a23d245a subID=EFC:\Users\admin\AppData\Local\Temp\ImgBurn.exe_1658922980\saBSI.exe
ImgBurn.exe
User:
admin
Company:
McAfee, LLC
Integrity Level:
HIGH
Description:
McAfee WebAdvisor(bootstrap installer)
Exit code:
4294967295
Version:
4,1,1,663
Modules
Images
c:\users\admin\appdata\local\temp\imgburn.exe_1658922980\sabsi.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\shell32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
Total events
21 502
Read events
21 322
Write events
174
Delete events
6

Modification events

(PID) Process:(2072) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2072) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2072) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2072) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(2072) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2072) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\ImgBurn.zip
(PID) Process:(2072) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2072) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2072) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2072) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
24
Suspicious files
1
Text files
35
Unknown types
2

Dropped files

PID
Process
Filename
Type
2072WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2072.2964\ImgBurn.exeexecutable
MD5:
SHA256:
1228ImgBurn.exeC:\Users\admin\AppData\Local\DG001\ImgBurn.exe_Url_twyl0s1clbu3bhh3f44yjwotvtyg1qvy\1.1.0.6075\user.configxml
MD5:C76D70D8440A273C2B2A2764F33323B8
SHA256:8F6658DFB498D9BC831670DFFD055D850D327A2DEFD82E1F24416316B037135D
1228ImgBurn.exeC:\Users\admin\AppData\Local\Temp\b0798393d0554967284c5503d2e1a4da\ServiceHide.dllexecutable
MD5:
SHA256:
1228ImgBurn.exeC:\Users\admin\AppData\Local\Temp\ImgBurn.exe_1658922980\Resources\images\default-icon.pngimage
MD5:7F410BD2D7E90D9EE9FB7F8C54E47217
SHA256:79C47E8E1392A418B120F1E29C4C8BDD2627BE3379ACFE61E362D421C997DD95
1228ImgBurn.exeC:\Users\admin\AppData\Local\Temp\ImgBurn.exe_1658922980\Resources\tis\EventHandler.tistext
MD5:1116D7747130F4552A91E61A3A6000B1
SHA256:5C09C6784F3FDC4A6B2998C4C9E02E366265EE5314C0F982859825576DC0EAFD
1228ImgBurn.exeC:\Users\admin\AppData\Local\Temp\ImgBurn.exe_1658922980\Resources\images\check-purple.pngimage
MD5:972E9DD362307298692B2B743CD478AE
SHA256:8D17866A26D8317DA7D2366C7F6A24605A8B9576556DE3C643047F5720347587
1228ImgBurn.exeC:\Users\admin\AppData\Local\Temp\ImgBurn.exe_1658922980\Resources\images\placeholder.pngimage
MD5:4881DE56578B0D0663230BAB239C6F4E
SHA256:63E9050C56A7B79829DD02C0487004EB36A90A668F3F2CBF74B6A412BDFDE140
1228ImgBurn.exeC:\Users\admin\AppData\Local\Temp\ImgBurn.exe_1658922980\Resources\images\loader.gifimage
MD5:2B26F73D382AB69F3914A7D9FDA97B0F
SHA256:A6A0B05B1D5C52303DD3E9E2F9CDA1E688A490FBE84EA0D6E22A051AB6EFD643
1228ImgBurn.exeC:\Users\admin\AppData\Local\Temp\ImgBurn.exe_1658922980\Resources\tis\TranslateOfferTemplate.tistext
MD5:551029A3E046C5ED6390CC85F632A689
SHA256:7B8C76A85261C5F9E40E49F97E01A14320E9B224FF3D6AF8286632CA94CF96F8
1228ImgBurn.exeC:\Users\admin\AppData\Local\Temp\b0798393d0554967284c5503d2e1a4da\ServiceHide.Net.dllexecutable
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
37
DNS requests
18
Threats
8

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1228
ImgBurn.exe
HEAD
200
104.17.178.102:80
http://webcompanion.com/nano_download.php?partner=DG200801
US
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1228
ImgBurn.exe
104.16.235.79:443
h2oapi.adaware.com
Cloudflare Inc
US
shared
1228
ImgBurn.exe
104.18.88.101:443
flow.lavasoft.com
Cloudflare Inc
US
shared
1228
ImgBurn.exe
104.21.57.77:443
walliant.com
Cloudflare Inc
US
malicious
1228
ImgBurn.exe
50.28.15.212:443
files.dddload.net
Liquid Web, L.L.C
US
malicious
2296
walliant.exe
188.114.96.3:443
cheverel.net
Cloudflare Inc
US
malicious
3536
saBSI.exe
23.35.236.229:443
sadownload.mcafee.com
Zayo Bandwidth Inc
US
suspicious
2296
walliant.exe
104.16.124.96:443
www.cloudflare.com
Cloudflare Inc
US
suspicious
3536
saBSI.exe
54.200.67.7:443
apis.mosaic.analytics.awscommon.mcafee.com
Amazon.com, Inc.
US
unknown
2296
walliant.exe
2.21.20.148:443
img-prod-cms-rt-microsoft-com.akamaized.net
NTT America, Inc.
DE
suspicious
3536
saBSI.exe
104.208.16.0:443
cu1pehnswad01.servicebus.windows.net
Microsoft Corporation
US
unknown

DNS requests

Domain
IP
Reputation
h2oapi.adaware.com
  • 104.16.235.79
  • 104.16.236.79
malicious
www.google.com
  • 142.250.184.196
malicious
flow.lavasoft.com
  • 104.18.88.101
  • 104.18.87.101
whitelisted
sos.adaware.com
  • 104.16.235.79
  • 104.16.236.79
whitelisted
net.geo.opera.com
  • 185.26.182.111
  • 185.26.182.112
whitelisted
bits.avcdn.net
  • 23.35.229.27
whitelisted
sdl.adaware.com
  • 104.16.235.79
  • 104.16.236.79
whitelisted
webcompanion.com
  • 104.17.178.102
  • 104.17.177.102
malicious
walliant.com
  • 104.21.57.77
  • 172.67.189.175
malicious
files.dddload.net
  • 50.28.15.212
suspicious

Threats

PID
Process
Class
Message
3536
saBSI.exe
Potentially Bad Traffic
ET INFO TLS Handshake Failure
3536
saBSI.exe
Potentially Bad Traffic
ET INFO TLS Handshake Failure
6 ETPRO signatures available at the full report
Process
Message
ImgBurn.exe
Error: File not found - genericsetup.wrappers.sciter:console.tis
ImgBurn.exe
at sciter:init-script.tis
ImgBurn.exe
ImgBurn.exe
ImgBurn.exe
file:resources/tis/TranslateOfferTemplate.tis(82) : warning :'async' does not contain any 'await'
ImgBurn.exe
Error: File not found - genericsetup.wrappers.sciter:console.tis
ImgBurn.exe
at sciter:init-script.tis
ImgBurn.exe
ImgBurn.exe
ImgBurn.exe
file:resources/tis/TranslateOfferTemplate.tis(82) : warning :'async' does not contain any 'await'