File name: | Stefanie Haigis Ausgleich stornierten Buchung Ihrer Bestellung Ebay vom 13.08.2014.zip |
Full analysis: | https://app.any.run/tasks/23a2420b-537e-4e1c-b279-626dab295eaa |
Verdict: | Malicious activity |
Analysis date: | June 19, 2019, 09:02:08 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/zip |
File info: | Zip archive data |
MD5: | 9A8D90246542CDC09960615CFA376385 |
SHA1: | AB7E7D3EE9DB5F2231A665DE1BC11768EEBC3E9D |
SHA256: | 6D5A84A4E53F1F1B55DF1D2080B18FDEEC3849DCEB7234395AF8203046271B8C |
SSDEEP: | 3072:7sKXm7PFj8Tfo4z80y3jbxDZm6MU3+65HLqY2/tPw1:4KXmRj8Tfo4z8xlmRU3HwYStPw1 |
.zip | | | ZIP compressed archive (100) |
---|
ZipRequiredVersion: | 16 |
---|---|
ZipBitFlag: | - |
ZipCompression: | None |
ZipModifyDate: | 2014:08:13 11:05:22 |
ZipCRC: | 0x225a1159 |
ZipCompressedSize: | 98916 |
ZipUncompressedSize: | 98916 |
ZipFileName: | Ausgleich stornierten Zahlung Ihrer Bestellung Ebay vom 13.08.2014.zip |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
2320 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Stefanie Haigis Ausgleich stornierten Buchung Ihrer Bestellung Ebay vom 13.08.2014.zip" | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe |
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Version: 5.60.0 | ||||
2552 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Rar$DIa2320.45216\Ausgleich stornierten Zahlung Ihrer Bestellung Ebay vom 13.08.2014.zip" | C:\Program Files\WinRAR\WinRAR.exe | WinRAR.exe | |
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Version: 5.60.0 | ||||
2900 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Rar$DIa2320.45436\Ausgleich stornierten Zahlung Ihrer Bestellung Ebay vom 13.08.2014.zip" | C:\Program Files\WinRAR\WinRAR.exe | WinRAR.exe | |
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Version: 5.60.0 | ||||
2360 | "C:\Users\admin\AppData\Local\Temp\Rar$DIa2552.46071\Ausgleich 13.08.2014 - Rechtsanwalt Ebay GmbH.com" | C:\Users\admin\AppData\Local\Temp\Rar$DIa2552.46071\Ausgleich 13.08.2014 - Rechtsanwalt Ebay GmbH.com | — | WinRAR.exe |
User: admin Company: VMware Integrity Level: MEDIUM Exit code: 0 Version: 9.3.1.4 | ||||
2648 | "C:\Users\admin\AppData\Local\Temp\Rar$DIa2900.46802\Ausgleich 13.08.2014 - Rechtsanwalt Ebay GmbH.com" | C:\Users\admin\AppData\Local\Temp\Rar$DIa2900.46802\Ausgleich 13.08.2014 - Rechtsanwalt Ebay GmbH.com | — | WinRAR.exe |
User: admin Company: VMware Integrity Level: MEDIUM Exit code: 0 Version: 9.3.1.4 | ||||
1936 | svchost.exe | C:\Windows\system32\svchost.exe | Ausgleich 13.08.2014 - Rechtsanwalt Ebay GmbH.com | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Host Process for Windows Services Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
296 | svchost.exe | C:\Windows\system32\svchost.exe | Ausgleich 13.08.2014 - Rechtsanwalt Ebay GmbH.com | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Host Process for Windows Services Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
2688 | C:\Users\admin\AppData\Local\Temp\bestumpwjf.pre | C:\Users\admin\AppData\Local\Temp\bestumpwjf.pre | — | svchost.exe |
User: admin Company: VMware Integrity Level: MEDIUM Exit code: 0 Version: 9.3.1.4 | ||||
3100 | C:\Users\admin\AppData\Local\Temp\jmoqqetuha.pre | C:\Users\admin\AppData\Local\Temp\jmoqqetuha.pre | — | svchost.exe |
User: admin Company: VMware Integrity Level: MEDIUM Exit code: 0 Version: 9.3.1.4 | ||||
3888 | svchost.exe | C:\Windows\system32\svchost.exe | bestumpwjf.pre | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Host Process for Windows Services Version: 6.1.7600.16385 (win7_rtm.090713-1255) |
PID | Process | Filename | Type | |
---|---|---|---|---|
3888 | svchost.exe | C:\Users\admin\AppData\Roaming\Pkoegbv\qimtkjmn.exe | — | |
MD5:— | SHA256:— | |||
2320 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DIa2320.45436\Ausgleich stornierten Zahlung Ihrer Bestellung Ebay vom 13.08.2014.zip | compressed | |
MD5:D298CD98C102EEE0E7DE7856754226A9 | SHA256:9E3593E1973E2497B79E12A67BC19600F48AB82B8552C9D674790C11230C62DD | |||
2320 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DIa2320.45216\Ausgleich stornierten Zahlung Ihrer Bestellung Ebay vom 13.08.2014.zip | compressed | |
MD5:D298CD98C102EEE0E7DE7856754226A9 | SHA256:9E3593E1973E2497B79E12A67BC19600F48AB82B8552C9D674790C11230C62DD | |||
3888 | svchost.exe | C:\Users\admin\AppData\Local\Temp\~44454134.tmp | binary | |
MD5:F3DDCAC96009D0D3E6E8C0CE5B461DD7 | SHA256:DA531B23F2884A8813C67B45FD3E07FB3BF426DEB735915319A5C069D870C400 | |||
2552 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DIa2552.46071\Ausgleich 13.08.2014 - Rechtsanwalt Ebay GmbH.com | executable | |
MD5:887C83EB2AF7519BFC24A9D81D4FC42C | SHA256:9EDB033189DBDDC3DDF087BEB68B286724312B8F229FE3C21B4C70176072F7EC | |||
2900 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DIa2900.46802\Ausgleich 13.08.2014 - Rechtsanwalt Ebay GmbH.com | executable | |
MD5:887C83EB2AF7519BFC24A9D81D4FC42C | SHA256:9EDB033189DBDDC3DDF087BEB68B286724312B8F229FE3C21B4C70176072F7EC | |||
1936 | svchost.exe | C:\Users\admin\AppData\Local\Temp\bestumpwjf.pre | executable | |
MD5:887C83EB2AF7519BFC24A9D81D4FC42C | SHA256:9EDB033189DBDDC3DDF087BEB68B286724312B8F229FE3C21B4C70176072F7EC | |||
296 | svchost.exe | C:\Users\admin\AppData\Local\Temp\jmoqqetuha.pre | executable | |
MD5:887C83EB2AF7519BFC24A9D81D4FC42C | SHA256:9EDB033189DBDDC3DDF087BEB68B286724312B8F229FE3C21B4C70176072F7EC |