File name:

ImgBurn.zip

Full analysis: https://app.any.run/tasks/18153b0b-e1ed-4253-b004-4c366bd10d40
Verdict: Malicious activity
Analysis date: July 27, 2022, 10:55:56
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

BA232A02FC590880B55AC9AF0B240BF2

SHA1:

62AB7BE1FF6465A5FFD85E00ACF0707AF476F001

SHA256:

69773A222C5AB575DFB91B4DC1B7A3EA27740791098F210DADE9254074924C18

SSDEEP:

98304:u2xmRB6BvN99d4l43owKkOU3DqFTC9vYTVEUGE7/y/QLh80G9bt9ocNv:7xLT9gK3obUTqFOraymGJt6ev

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops executable file immediately after starts

      • ImgBurn.exe (PID: 1228)
      • WinRAR.exe (PID: 2072)
      • rdffv35y.zvw.exe (PID: 2424)
      • rdffv35y.zvw.tmp (PID: 3152)
    • Application was dropped or rewritten from another process

      • ImgBurn.exe (PID: 1228)
      • walliant.exe (PID: 2296)
    • Changes settings of System certificates

      • ImgBurn.exe (PID: 1228)
      • saBSI.exe (PID: 3536)
    • Actions looks like stealing of personal data

      • ImgBurn.exe (PID: 1228)
    • Loads dropped or rewritten executable

      • ImgBurn.exe (PID: 1228)
      • walliant.exe (PID: 2296)
    • Changes the autorun value in the registry

      • rdffv35y.zvw.tmp (PID: 3152)
  • SUSPICIOUS

    • Checks supported languages

      • WinRAR.exe (PID: 2072)
      • ImgBurn.exe (PID: 1228)
      • rdffv35y.zvw.exe (PID: 2424)
      • rdffv35y.zvw.tmp (PID: 3152)
      • saBSI.exe (PID: 3536)
      • walliant.exe (PID: 2296)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2072)
      • ImgBurn.exe (PID: 1228)
      • rdffv35y.zvw.exe (PID: 2424)
      • rdffv35y.zvw.tmp (PID: 3152)
    • Drops a file with a compile date too recent

      • WinRAR.exe (PID: 2072)
      • ImgBurn.exe (PID: 1228)
      • rdffv35y.zvw.exe (PID: 2424)
      • rdffv35y.zvw.tmp (PID: 3152)
    • Reads the computer name

      • WinRAR.exe (PID: 2072)
      • ImgBurn.exe (PID: 1228)
      • rdffv35y.zvw.tmp (PID: 3152)
      • walliant.exe (PID: 2296)
      • saBSI.exe (PID: 3536)
    • Reads the Windows organization settings

      • ImgBurn.exe (PID: 1228)
      • rdffv35y.zvw.tmp (PID: 3152)
    • Reads Environment values

      • ImgBurn.exe (PID: 1228)
      • walliant.exe (PID: 2296)
    • Reads Windows owner or organization settings

      • ImgBurn.exe (PID: 1228)
      • rdffv35y.zvw.tmp (PID: 3152)
    • Adds / modifies Windows certificates

      • ImgBurn.exe (PID: 1228)
      • saBSI.exe (PID: 3536)
    • Creates files in the program directory

      • saBSI.exe (PID: 3536)
    • Reads Microsoft Outlook installation path

      • walliant.exe (PID: 2296)
    • Reads internet explorer settings

      • walliant.exe (PID: 2296)
    • Searches for installed software

      • ImgBurn.exe (PID: 1228)
  • INFO

    • Manual execution by user

      • ImgBurn.exe (PID: 1228)
      • taskmgr.exe (PID: 1444)
      • taskmgr.exe (PID: 2368)
    • Checks Windows Trust Settings

      • ImgBurn.exe (PID: 1228)
      • walliant.exe (PID: 2296)
      • saBSI.exe (PID: 3536)
    • Reads settings of System Certificates

      • ImgBurn.exe (PID: 1228)
      • rdffv35y.zvw.tmp (PID: 3152)
      • saBSI.exe (PID: 3536)
      • walliant.exe (PID: 2296)
    • Checks supported languages

      • taskmgr.exe (PID: 1444)
      • taskmgr.exe (PID: 2368)
    • Reads the computer name

      • taskmgr.exe (PID: 1444)
      • taskmgr.exe (PID: 2368)
    • Application was dropped or rewritten from another process

      • rdffv35y.zvw.tmp (PID: 3152)
    • Creates a software uninstall entry

      • rdffv35y.zvw.tmp (PID: 3152)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: ImgBurn.exe
ZipUncompressedSize: 3997984
ZipCompressedSize: 3966110
ZipCRC: 0x577d0711
ZipModifyDate: 2022:07:27 12:05:07
ZipCompression: Deflated
ZipBitFlag: -
ZipRequiredVersion: 20
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
48
Monitored processes
8
Malicious processes
4
Suspicious processes
2

Behavior graph

Click at the process to see the details
start drop and start drop and start winrar.exe imgburn.exe taskmgr.exe no specs taskmgr.exe no specs rdffv35y.zvw.exe rdffv35y.zvw.tmp walliant.exe sabsi.exe

Process information

PID
CMD
Path
Indicators
Parent process
1228"C:\Users\admin\Desktop\ImgBurn.exe" C:\Users\admin\Desktop\ImgBurn.exe
Explorer.EXE
User:
admin
Company:
DG001
Integrity Level:
HIGH
Description:
Software Installation
Exit code:
0
Version:
6.94.0.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\desktop\imgburn.exe
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
1444"C:\Windows\system32\taskmgr.exe" /4C:\Windows\system32\taskmgr.exeExplorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Task Manager
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskmgr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
2072"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\ImgBurn.zip"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2296"C:\Users\admin\AppData\Local\Programs\Walliant\walliant.exe"C:\Users\admin\AppData\Local\Programs\Walliant\walliant.exe
rdffv35y.zvw.tmp
User:
admin
Company:
Walliant
Integrity Level:
HIGH
Description:
Walliant
Exit code:
0
Version:
1.0.1.2
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\users\admin\appdata\local\programs\walliant\walliant.exe
c:\windows\system32\mscoree.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2368"C:\Windows\system32\taskmgr.exe" /4C:\Windows\system32\taskmgr.exeExplorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Task Manager
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskmgr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2424"C:\Users\admin\AppData\Local\Temp\rdffv35y.zvw.exe" /VERYSILENT /SUPPRESSMSGBOXES /NOCANCEL /NORESTARTC:\Users\admin\AppData\Local\Temp\rdffv35y.zvw.exe
ImgBurn.exe
User:
admin
Company:
Walliant
Integrity Level:
HIGH
Description:
Walliant Setup
Exit code:
0
Version:
1.0.1.2
Modules
Images
c:\users\admin\appdata\local\temp\rdffv35y.zvw.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3152"C:\Users\admin\AppData\Local\Temp\is-PKFSB.tmp\rdffv35y.zvw.tmp" /SL5="$60130,4511977,830464,C:\Users\admin\AppData\Local\Temp\rdffv35y.zvw.exe" /VERYSILENT /SUPPRESSMSGBOXES /NOCANCEL /NORESTARTC:\Users\admin\AppData\Local\Temp\is-PKFSB.tmp\rdffv35y.zvw.tmp
rdffv35y.zvw.exe
User:
admin
Company:
Walliant
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\appdata\local\temp\is-pkfsb.tmp\rdffv35y.zvw.tmp
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3536"saBSI.exe" /affid 91212 PaidDistribution=true InstallID=e1724775-af4c-4897-ac02-ea70a23d245a subID=EFC:\Users\admin\AppData\Local\Temp\ImgBurn.exe_1658922980\saBSI.exe
ImgBurn.exe
User:
admin
Company:
McAfee, LLC
Integrity Level:
HIGH
Description:
McAfee WebAdvisor(bootstrap installer)
Exit code:
4294967295
Version:
4,1,1,663
Modules
Images
c:\users\admin\appdata\local\temp\imgburn.exe_1658922980\sabsi.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\shell32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
Total events
21 502
Read events
21 322
Write events
174
Delete events
6

Modification events

(PID) Process:(2072) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2072) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2072) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2072) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(2072) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2072) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\ImgBurn.zip
(PID) Process:(2072) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2072) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2072) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2072) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
24
Suspicious files
1
Text files
35
Unknown types
2

Dropped files

PID
Process
Filename
Type
1228ImgBurn.exeC:\Users\admin\AppData\Local\Temp\b0798393d0554967284c5503d2e1a4da\ServiceHide.Net.dllexecutable
MD5:
SHA256:
1228ImgBurn.exeC:\Users\admin\AppData\Local\Temp\b0798393d0554967284c5503d2e1a4da\ServiceHide.dllexecutable
MD5:
SHA256:
2072WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2072.2964\ImgBurn.exeexecutable
MD5:
SHA256:
1228ImgBurn.exeC:\Users\admin\AppData\Local\Temp\ImgBurn.exe_1658922980\Resources\images\bg.pngimage
MD5:
SHA256:
1228ImgBurn.exeC:\Users\admin\AppData\Local\Temp\ImgBurn.exe_1658922980\Resources\images\default-icon.pngimage
MD5:
SHA256:
1228ImgBurn.exeC:\Users\admin\AppData\Local\Temp\ImgBurn.exe_1658922980\Resources\images\logo-placeholder.pngimage
MD5:
SHA256:
1228ImgBurn.exeC:\Users\admin\AppData\Local\Temp\ImgBurn.exe_1658922980\Resources\images\loader.gifimage
MD5:2B26F73D382AB69F3914A7D9FDA97B0F
SHA256:A6A0B05B1D5C52303DD3E9E2F9CDA1E688A490FBE84EA0D6E22A051AB6EFD643
1228ImgBurn.exeC:\Users\admin\AppData\Local\Temp\ImgBurn.exe_1658922980\Resources\images\placeholder.pngimage
MD5:
SHA256:
1228ImgBurn.exeC:\Users\admin\AppData\Local\Temp\b0798393d0554967284c5503d2e1a4da\sciter32.dllexecutable
MD5:B431083586E39D018E19880AD1A5CE8F
SHA256:B525FDCC32C5A359A7F5738A30EFF0C6390734D8A2C987C62E14C619F99D406B
1228ImgBurn.exeC:\Users\admin\AppData\Local\Temp\ImgBurn.exe_1658922980\Resources\tis\Config.tistext
MD5:BF5328E51E8AB1211C509B5A65AB9972
SHA256:98F22FB45530506548AE320C32EE4939D27017481D2AD0D784AA5516F939545B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
37
DNS requests
18
Threats
8

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1228
ImgBurn.exe
HEAD
200
104.17.178.102:80
http://webcompanion.com/nano_download.php?partner=DG200801
US
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1228
ImgBurn.exe
104.16.235.79:443
h2oapi.adaware.com
Cloudflare Inc
US
shared
1228
ImgBurn.exe
104.18.88.101:443
flow.lavasoft.com
Cloudflare Inc
US
shared
1228
ImgBurn.exe
185.26.182.111:443
net.geo.opera.com
Opera Software AS
whitelisted
3536
saBSI.exe
104.208.16.0:443
cu1pehnswad01.servicebus.windows.net
Microsoft Corporation
US
unknown
2296
walliant.exe
172.67.189.175:443
walliant.com
US
malicious
3152
rdffv35y.zvw.tmp
172.67.189.175:443
walliant.com
US
malicious
2296
walliant.exe
104.16.124.96:443
www.cloudflare.com
Cloudflare Inc
US
suspicious
2296
walliant.exe
188.114.96.3:443
cheverel.net
Cloudflare Inc
US
malicious
3536
saBSI.exe
54.200.67.7:443
apis.mosaic.analytics.awscommon.mcafee.com
Amazon.com, Inc.
US
unknown
3536
saBSI.exe
23.35.236.229:443
sadownload.mcafee.com
Zayo Bandwidth Inc
US
suspicious

DNS requests

Domain
IP
Reputation
h2oapi.adaware.com
  • 104.16.235.79
  • 104.16.236.79
malicious
www.google.com
  • 142.250.184.196
malicious
flow.lavasoft.com
  • 104.18.88.101
  • 104.18.87.101
whitelisted
sos.adaware.com
  • 104.16.235.79
  • 104.16.236.79
whitelisted
net.geo.opera.com
  • 185.26.182.111
  • 185.26.182.112
whitelisted
bits.avcdn.net
  • 23.35.229.27
whitelisted
sdl.adaware.com
  • 104.16.235.79
  • 104.16.236.79
whitelisted
webcompanion.com
  • 104.17.178.102
  • 104.17.177.102
malicious
walliant.com
  • 104.21.57.77
  • 172.67.189.175
malicious
files.dddload.net
  • 50.28.15.212
suspicious

Threats

PID
Process
Class
Message
3536
saBSI.exe
Potentially Bad Traffic
ET INFO TLS Handshake Failure
3536
saBSI.exe
Potentially Bad Traffic
ET INFO TLS Handshake Failure
6 ETPRO signatures available at the full report
Process
Message
ImgBurn.exe
Error: File not found - genericsetup.wrappers.sciter:console.tis
ImgBurn.exe
at sciter:init-script.tis
ImgBurn.exe
ImgBurn.exe
ImgBurn.exe
file:resources/tis/TranslateOfferTemplate.tis(82) : warning :'async' does not contain any 'await'
ImgBurn.exe
Error: File not found - genericsetup.wrappers.sciter:console.tis
ImgBurn.exe
at sciter:init-script.tis
ImgBurn.exe
ImgBurn.exe
ImgBurn.exe
file:resources/tis/TranslateOfferTemplate.tis(82) : warning :'async' does not contain any 'await'