File name:

TotalAV_Setup (1).exe (1).zip

Full analysis: https://app.any.run/tasks/e2a316c8-18ca-45e6-bbac-f47e0aff37b0
Verdict: Malicious activity
Threats:

Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.

Analysis date: January 24, 2022, 18:46:11
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
stealer
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

B4CFDE815F9C43EBBA38AAE5B601EF9D

SHA1:

5E5A76A79E7215CBBD192F7FC1747D31E189E512

SHA256:

6CFC218F6AD0B370366B980C6471762BE4760C36C00A3496762522DA6708AA3E

SSDEEP:

393216:n6RnM1LO4+nUlaLrQ7sVwFEZbp+xdp1gxN:6RMUSliqMwk0gxN

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • TotalAV_Setup (1).exe (PID: 2208)
      • TotalAV_Setup (1).exe (PID: 2720)
      • subinacl.exe (PID: 2796)
      • SecurityService.exe (PID: 1512)
      • TotalAV.exe (PID: 2560)
      • SecurityService.exe (PID: 1320)
      • TotalAV.exe (PID: 4084)
    • Drops executable file immediately after starts

      • TotalAV_Setup (1).exe (PID: 2208)
    • Loads dropped or rewritten executable

      • TotalAV_Setup (1).exe (PID: 2208)
      • SecurityService.exe (PID: 1320)
    • Stealing of credential data

      • TotalAV.exe (PID: 2560)
    • Changes settings of System certificates

      • TotalAV.exe (PID: 2560)
  • SUSPICIOUS

    • Checks supported languages

      • WinRAR.exe (PID: 3900)
      • TotalAV_Setup (1).exe (PID: 2208)
      • ns6707.tmp (PID: 3736)
      • ns67E3.tmp (PID: 2368)
      • ns6851.tmp (PID: 1412)
      • ns692E.tmp (PID: 3572)
      • ns7823.tmp (PID: 1320)
      • TotalAV.exe (PID: 2560)
      • SecurityService.exe (PID: 1512)
      • subinacl.exe (PID: 2796)
      • SecurityService.exe (PID: 1320)
      • ns68BF.tmp (PID: 2996)
      • TotalAV.exe (PID: 4084)
    • Reads the computer name

      • WinRAR.exe (PID: 3900)
      • TotalAV_Setup (1).exe (PID: 2208)
      • SecurityService.exe (PID: 1512)
      • subinacl.exe (PID: 2796)
      • TotalAV.exe (PID: 2560)
      • SecurityService.exe (PID: 1320)
      • TotalAV.exe (PID: 4084)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3900)
      • TotalAV_Setup (1).exe (PID: 2208)
      • SecurityService.exe (PID: 1320)
      • TotalAV.exe (PID: 2560)
    • Creates a directory in Program Files

      • TotalAV_Setup (1).exe (PID: 2208)
      • TotalAV.exe (PID: 2560)
      • SecurityService.exe (PID: 1512)
      • SecurityService.exe (PID: 1320)
    • Starts application with an unusual extension

      • TotalAV_Setup (1).exe (PID: 2208)
    • Uses TASKKILL.EXE to kill process

      • ns6707.tmp (PID: 3736)
      • ns67E3.tmp (PID: 2368)
      • ns6851.tmp (PID: 1412)
      • ns68BF.tmp (PID: 2996)
    • Creates files in the program directory

      • TotalAV_Setup (1).exe (PID: 2208)
      • SecurityService.exe (PID: 1512)
      • TotalAV.exe (PID: 2560)
      • SecurityService.exe (PID: 1320)
    • Drops a file that was compiled in debug mode

      • TotalAV_Setup (1).exe (PID: 2208)
      • SecurityService.exe (PID: 1320)
      • TotalAV.exe (PID: 2560)
    • Drops a file with too old compile date

      • TotalAV_Setup (1).exe (PID: 2208)
    • Drops a file with a compile date too recent

      • TotalAV_Setup (1).exe (PID: 2208)
    • Creates a software uninstall entry

      • TotalAV_Setup (1).exe (PID: 2208)
    • Reads Environment values

      • TotalAV.exe (PID: 2560)
    • Adds / modifies Windows certificates

      • TotalAV.exe (PID: 2560)
    • Executed as Windows Service

      • SecurityService.exe (PID: 1320)
    • Creates files in the user directory

      • TotalAV.exe (PID: 2560)
    • Removes files from Windows directory

      • SecurityService.exe (PID: 1320)
    • Creates files in the driver directory

      • SecurityService.exe (PID: 1320)
    • Creates files in the Windows directory

      • SecurityService.exe (PID: 1320)
  • INFO

    • Checks supported languages

      • taskkill.exe (PID: 4060)
      • taskkill.exe (PID: 3152)
      • taskkill.exe (PID: 2892)
      • taskkill.exe (PID: 1236)
      • WISPTIS.EXE (PID: 2436)
    • Reads the computer name

      • taskkill.exe (PID: 3152)
      • taskkill.exe (PID: 4060)
      • taskkill.exe (PID: 1236)
      • WISPTIS.EXE (PID: 2436)
      • taskkill.exe (PID: 2892)
    • Reads settings of System Certificates

      • TotalAV.exe (PID: 2560)
      • SecurityService.exe (PID: 1320)
    • Checks Windows Trust Settings

      • SecurityService.exe (PID: 1320)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: TotalAV_Setup (1).exe
ZipUncompressedSize: 14584656
ZipCompressedSize: 14478649
ZipCRC: 0x782498d3
ZipModifyDate: 2021:03:02 20:41:05
ZipCompression: Deflated
ZipBitFlag: 0x0009
ZipRequiredVersion: 20
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
68
Monitored processes
20
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start drop and start start drop and start winrar.exe totalav_setup (1).exe no specs totalav_setup (1).exe ns6707.tmp no specs taskkill.exe no specs ns67e3.tmp no specs taskkill.exe no specs ns6851.tmp no specs taskkill.exe no specs ns68bf.tmp no specs taskkill.exe no specs ns692e.tmp no specs ns7823.tmp no specs securityservice.exe no specs subinacl.exe no specs totalav.exe wisptis.exe no specs wisptis.exe no specs securityservice.exe totalav.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1236"taskkill" /f /T /IM "PasswordExtension.Win.exe"C:\Windows\system32\taskkill.exens68BF.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
1320"C:\Users\admin\AppData\Local\Temp\nsk5AB2.tmp\ns7823.tmp" "C:\Program Files\TotalAV\SecurityService.exe" "--install"C:\Users\admin\AppData\Local\Temp\nsk5AB2.tmp\ns7823.tmpTotalAV_Setup (1).exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\nsk5ab2.tmp\ns7823.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1320"C:\Program Files\TotalAV\SecurityService.exe"C:\Program Files\TotalAV\SecurityService.exe
services.exe
User:
SYSTEM
Company:
TotalAV
Integrity Level:
SYSTEM
Description:
TotalAV Ultimate Antivirus Service
Exit code:
0
Version:
4.14.31.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\program files\totalav\securityservice.exe
c:\windows\system32\kernelbase.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1412"C:\Users\admin\AppData\Local\Temp\nsk5AB2.tmp\ns6851.tmp" "taskkill" /f /T /IM "Update.Win.exe"C:\Users\admin\AppData\Local\Temp\nsk5AB2.tmp\ns6851.tmpTotalAV_Setup (1).exe
User:
admin
Integrity Level:
HIGH
Exit code:
128
Modules
Images
c:\users\admin\appdata\local\temp\nsk5ab2.tmp\ns6851.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1512"C:\Program Files\TotalAV\SecurityService.exe" "--install"C:\Program Files\TotalAV\SecurityService.exens7823.tmp
User:
admin
Company:
TotalAV
Integrity Level:
HIGH
Description:
TotalAV Ultimate Antivirus Service
Exit code:
0
Version:
4.14.31.0
Modules
Images
c:\program files\totalav\securityservice.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2208"C:\Users\admin\AppData\Local\Temp\Rar$EXb3900.14040\TotalAV_Setup (1).exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb3900.14040\TotalAV_Setup (1).exe
WinRAR.exe
User:
admin
Integrity Level:
HIGH
Description:
TotalAV Ultimate Antivirus Installer
Exit code:
0
Version:
4.14.31.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb3900.14040\totalav_setup (1).exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
2368"C:\Users\admin\AppData\Local\Temp\nsk5AB2.tmp\ns67E3.tmp" "taskkill" /f /T /IM "avupdate.exe"C:\Users\admin\AppData\Local\Temp\nsk5AB2.tmp\ns67E3.tmpTotalAV_Setup (1).exe
User:
admin
Integrity Level:
HIGH
Exit code:
128
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\users\admin\appdata\local\temp\nsk5ab2.tmp\ns67e3.tmp
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2436"C:\Windows\SYSTEM32\WISPTIS.EXE" /ManualLaunch;C:\Windows\SYSTEM32\WISPTIS.EXETotalAV.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Pen and Touch Input Component
Exit code:
24
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\wisptis.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
2560"C:\Program Files\TotalAV\TotalAV.exe" --installedC:\Program Files\TotalAV\TotalAV.exe
TotalAV_Setup (1).exe
User:
admin
Company:
TotalAV
Integrity Level:
HIGH
Description:
TotalAV Ultimate Antivirus User Interface
Exit code:
0
Version:
4.14.31.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\totalav\totalav.exe
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2720"C:\Users\admin\AppData\Local\Temp\Rar$EXb3900.14040\TotalAV_Setup (1).exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb3900.14040\TotalAV_Setup (1).exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Description:
TotalAV Ultimate Antivirus Installer
Exit code:
3221226540
Version:
4.14.31.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb3900.14040\totalav_setup (1).exe
c:\windows\system32\ntdll.dll
Total events
13 627
Read events
13 471
Write events
156
Delete events
0

Modification events

(PID) Process:(3900) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3900) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3900) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3900) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(3900) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3900) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\TotalAV_Setup (1).exe (1).zip
(PID) Process:(3900) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3900) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3900) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3900) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
180
Suspicious files
77
Text files
38
Unknown types
56

Dropped files

PID
Process
Filename
Type
2208TotalAV_Setup (1).exeC:\Users\admin\AppData\Local\Temp\TotalAV.7z
MD5:
SHA256:
2208TotalAV_Setup (1).exeC:\Users\admin\AppData\Local\Temp\nsk5AB2.tmp\nsDialogs.dllexecutable
MD5:B3070CF20DB659FDFB3CB2ED38130E8D
SHA256:F2C1409FAF2952C1C91F4B5495158EF5C7D1A1DB6EEA4A18F163574BD52FCAD0
2208TotalAV_Setup (1).exeC:\Users\admin\AppData\Local\Temp\nsk5AB2.tmp\nsis7z.dllexecutable
MD5:D3850D9EF1D81D2EE2E0A1583E3292F8
SHA256:47EE083861B20A03A751593073DFB533A0AA447833BFB190A73732C7EFB2A2B2
2208TotalAV_Setup (1).exeC:\Users\admin\AppData\Local\Temp\nsk5AB2.tmp\ns68BF.tmpexecutable
MD5:B5A1F9DC73E2944A388A61411BDD8C70
SHA256:288100583F65A2B7ACFC0C7E231C0E268C58D3067675543F627C01E82F6FD884
2208TotalAV_Setup (1).exeC:\Users\admin\AppData\Local\Temp\nsk5AB2.tmp\ns67E3.tmpexecutable
MD5:B5A1F9DC73E2944A388A61411BDD8C70
SHA256:288100583F65A2B7ACFC0C7E231C0E268C58D3067675543F627C01E82F6FD884
2208TotalAV_Setup (1).exeC:\Users\admin\AppData\Local\Temp\nsk5AB2.tmp\ns6707.tmpexecutable
MD5:B5A1F9DC73E2944A388A61411BDD8C70
SHA256:288100583F65A2B7ACFC0C7E231C0E268C58D3067675543F627C01E82F6FD884
2208TotalAV_Setup (1).exeC:\Users\admin\AppData\Local\Temp\nsk5AB2.tmp\ns692E.tmpexecutable
MD5:B5A1F9DC73E2944A388A61411BDD8C70
SHA256:288100583F65A2B7ACFC0C7E231C0E268C58D3067675543F627C01E82F6FD884
2208TotalAV_Setup (1).exeC:\Program Files\TotalAV\ovpn\openvpn_down.battext
MD5:08BAE2DE82FA4FB579F707376D440056
SHA256:6CAB17FEE12D3A2C43EB4D7C3A790CDBD7FC9AFC6B0C6D60DBBB61594F6CEC74
2208TotalAV_Setup (1).exeC:\Users\admin\AppData\Local\Temp\nsk5AB2.tmp\nsRandom.dllexecutable
MD5:AB467B8DFAA660A0F0E5B26E28AF5735
SHA256:DB267D9920395B4BADC48DE04DF99DFD21D579480D103CAE0F48E6578197FF73
2208TotalAV_Setup (1).exeC:\Program Files\TotalAV\ovpn\openvpn_up.battext
MD5:CD4D223ACDDBD08101A159B17022324B
SHA256:6ED4C6D1BA69E5AAD84434E40F97C39432BE10B903652860F8F16D7861EA79D6
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
10
TCP/UDP connections
9
DNS requests
5
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2560
TotalAV.exe
GET
35.190.63.3:80
http://definition.protected.net/vdf.zip
US
whitelisted
1320
SecurityService.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEA3Q4zdKyVvb%2BmtDSypI7AY%3D
US
der
471 b
whitelisted
2560
TotalAV.exe
GET
35.190.63.3:80
http://definition.protected.net/vdf.zip
US
whitelisted
2560
TotalAV.exe
HEAD
200
35.190.63.3:80
http://definition.protected.net/vdf.zip
US
whitelisted
2560
TotalAV.exe
HEAD
200
35.190.63.3:80
http://definition.protected.net/vdf.zip
US
whitelisted
2560
TotalAV.exe
HEAD
200
35.190.63.3:80
http://definition.protected.net/vdf.zip
US
whitelisted
2560
TotalAV.exe
GET
200
185.172.148.128:80
http://install.protected.net/windows/avirasdk/3.0.0/avira32redist.zip
DE
compressed
15.7 Mb
malicious
1320
SecurityService.exe
GET
200
67.27.158.254:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?909ec6423e6fdc6b
US
compressed
4.70 Kb
whitelisted
1320
SecurityService.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSHRqVSKsocqbcuJkRZwJjSAmttHAQUrWkGcPyAGxazqRiUa5QChl73J4wCEA8DpEdAc3HbUzijkx9jirc%3D
US
der
471 b
whitelisted
1320
SecurityService.exe
GET
200
67.27.158.254:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?e1e9bb3f4a988eb8
US
compressed
59.9 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2560
TotalAV.exe
185.172.148.128:80
install.protected.net
proinity GmbH
DE
malicious
2560
TotalAV.exe
34.117.198.220:443
api.totalav.com
US
unknown
1320
SecurityService.exe
67.27.158.254:80
ctldl.windowsupdate.com
Level 3 Communications, Inc.
US
malicious
1320
SecurityService.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
2560
TotalAV.exe
35.190.63.3:80
definition.protected.net
Google Inc.
US
unknown

DNS requests

Domain
IP
Reputation
install.protected.net
  • 185.172.148.128
malicious
api.totalav.com
  • 34.117.198.220
unknown
ctldl.windowsupdate.com
  • 67.27.158.254
  • 8.241.78.254
  • 8.248.119.254
  • 8.253.95.249
  • 67.26.139.254
whitelisted
ocsp.digicert.com
  • 93.184.220.29
whitelisted
definition.protected.net
  • 35.190.63.3
unknown

Threats

No threats detected
No debug info