| File name: | !@uncherrr!.zip |
| Full analysis: | https://app.any.run/tasks/dd02cb4e-20cb-4d72-8471-8ad6f7145fb8 |
| Verdict: | Malicious activity |
| Threats: | Stealc is a stealer malware that targets victims’ sensitive data, which it exfiltrates from browsers, messaging apps, and other software. The malware is equipped with advanced features, including fingerprinting, control panel, evasion mechanisms, string obfuscation, etc. Stealc establishes persistence and communicates with its C2 server through HTTP POST requests. |
| Analysis date: | August 09, 2024, 17:45:38 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v1.0 to extract, compression method=store |
| MD5: | 9BB52E5C7ED736E4F9A5452C85E08BA9 |
| SHA1: | 39CC5DD3CE8597A9B774F85F3F23187341FE658A |
| SHA256: | 7078F23E3D24F2D72E83BDF10212B2C47BA7D5C5DBE057846AC65D4FF5777E61 |
| SSDEEP: | 98304:tsdEchxlSFKMZBVzCncxofX8SPGls3YE80Ge4rkFq69z3gzP5FOB/uNmQ2Es8kOF:PDRxTNQuUOGtg |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 10 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | None |
| ZipModifyDate: | 2024:08:08 10:46:46 |
| ZipCRC: | 0xde55b3aa |
| ZipCompressedSize: | 9161534 |
| ZipUncompressedSize: | 9161534 |
| ZipFileName: | I@uncherr.rar |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 208 | "C:\WINDOWS\system32\taskmgr.exe" /0 | C:\Windows\System32\Taskmgr.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Task Manager Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1140 | "C:\Program Files\Mozilla Firefox\firefox.exe" | C:\Program Files\Mozilla Firefox\firefox.exe | — | explorer.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 1288 | "C:\Users\admin\Desktop\I@uncherr.exe" | C:\Users\admin\Desktop\I@uncherr.exe | — | explorer.exe | |||||||||||
User: admin Company: High Motion Software Integrity Level: MEDIUM Description: ImBatch (64-bit) Setup Exit code: 666 Version: 7, 6, 1, 0 Modules
| |||||||||||||||
| 1748 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=4620 -childID 2 -isForBrowser -prefsHandle 4616 -prefMapHandle 4612 -prefsLen 36263 -prefMapSize 244343 -jsInitHandle 1508 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {3aee649a-7647-4595-9c06-1d78cf4efb41} 7072 "\\.\pipe\gecko-crash-server-pipe.7072" 194e2579a10 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Version: 123.0 Modules
| |||||||||||||||
| 2080 | "C:\WINDOWS\system32\taskmgr.exe" /0 | C:\Windows\System32\Taskmgr.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Task Manager Exit code: 3221226540 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2464 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5444 -childID 3 -isForBrowser -prefsHandle 5436 -prefMapHandle 5432 -prefsLen 31161 -prefMapSize 244343 -jsInitHandle 1508 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {9b5c3ea9-de9f-42dc-a6c2-c05bc23430a0} 7072 "\\.\pipe\gecko-crash-server-pipe.7072" 194e39f6690 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Version: 123.0 Modules
| |||||||||||||||
| 2580 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=4888 -childID 6 -isForBrowser -prefsHandle 4940 -prefMapHandle 4936 -prefsLen 31242 -prefMapSize 244343 -jsInitHandle 1508 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {26382a72-59e0-40ef-85cb-7e4385e6dfb7} 7072 "\\.\pipe\gecko-crash-server-pipe.7072" 194e2e97a10 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Version: 123.0 Modules
| |||||||||||||||
| 3356 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=1916 -parentBuildID 20240213221259 -prefsHandle 1844 -prefMapHandle 1824 -prefsLen 30537 -prefMapSize 244343 -appDir "C:\Program Files\Mozilla Firefox\browser" - {9f332cc4-0ebb-4200-8bda-2db1fe24fbe1} 7072 "\\.\pipe\gecko-crash-server-pipe.7072" 194dbcd6710 gpu | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Version: 123.0 Modules
| |||||||||||||||
| 3812 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=2968 -childID 1 -isForBrowser -prefsHandle 2920 -prefMapHandle 2976 -prefsLen 30953 -prefMapSize 244343 -jsInitHandle 1508 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {6326f7d2-8980-4be5-9bfa-ae2c8c2e02bc} 7072 "\\.\pipe\gecko-crash-server-pipe.7072" 194e174e150 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Version: 123.0 Modules
| |||||||||||||||
| 3916 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=3004 -parentBuildID 20240213221259 -sandboxingKind 0 -prefsHandle 5332 -prefMapHandle 4804 -prefsLen 34713 -prefMapSize 244343 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {c95dd33a-9134-401e-ae49-320ea51afb25} 7072 "\\.\pipe\gecko-crash-server-pipe.7072" 194e4613d10 utility | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Version: 123.0 Modules
| |||||||||||||||
| (PID) Process: | (6556) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (6556) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (6556) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\GoogleChromeEnterpriseBundle64.zip | |||
| (PID) Process: | (6556) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\!@uncherrr!.zip | |||
| (PID) Process: | (6556) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (6556) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (6556) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (6556) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (7036) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (7036) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6556 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa6556.37409\I@uncherr.rar | — | |
MD5:— | SHA256:— | |||
| 7036 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb7036.38288\I@uncherr.exe | — | |
MD5:— | SHA256:— | |||
| 1288 | I@uncherr.exe | C:\Users\Public\Libraries\aikco.scif | — | |
MD5:— | SHA256:— | |||
| 1288 | I@uncherr.exe | C:\Users\Public\Libraries\ppbab.scif | — | |
MD5:— | SHA256:— | |||
| 7036 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb7036.38288\I@uncherr\VBoxHostChannel.dll | executable | |
MD5:BF8CF948740F9DBEBED169AB8FA4CBE6 | SHA256:B2723D1B22A498A7BD59A807A1B97E6B03C00FBDA53D3A9715C95B224A2BDB3F | |||
| 7036 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb7036.38288\I@uncherr\VBoxProxyStub.dll | executable | |
MD5:166F9409EC301BD79860933CBB8B6708 | SHA256:74DBEA34D5B2C424281719DF754BD1E4A28CC3C03759CC1D38E23B8FC120A7FD | |||
| 1288 | I@uncherr.exe | C:\Users\admin\AppData\Local\Temp\jsii-runtime.609804816\lib\program.js | text | |
MD5:BF41580C1454743386E48083EF7CDB9C | SHA256:B4BF248DDDF226E8F1DEFBD12125F5AE683F37C6DF976E31CC4A8B3201EFE80D | |||
| 7036 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb7036.38288\I@uncherr\VBoxSupLib.dll | executable | |
MD5:9636CD28F536DD3FB438C866F28610A9 | SHA256:34E8BD19A7DD241A1275A3CF77A8A59A7DF1FC529F864F92D8548CC7E0429B26 | |||
| 208 | Taskmgr.exe | C:\Users\admin\AppData\Local\D3DSCache\3534848bb9f4cb71\F4EB2D6C-ED2B-4BDD-AD9D-F913287E6768.lock | text | |
MD5:F49655F856ACB8884CC0ACE29216F511 | SHA256:7852FCE59C67DDF1D6B8B997EAA1ADFAC004A9F3A91C37295DE9223674011FBA | |||
| 7036 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb7036.38288\I@uncherr\VBoxProxyStub-x86.dll | executable | |
MD5:6D3C7D2E108CBB7B5389F51FF68BCB9A | SHA256:53ED3512437FBEB4277C24790CE67DB048F81B60C3669765541495EF88056B88 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
5336 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
5924 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
7144 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
6260 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
6296 | BitLockerToGo.exe | GET | 200 | 45.152.115.5:80 | http://45.152.115.5/ | unknown | — | — | unknown |
6296 | BitLockerToGo.exe | POST | 200 | 45.152.115.5:80 | http://45.152.115.5/587ec30955d49a9c.php | unknown | — | — | unknown |
7072 | firefox.exe | POST | 200 | 184.24.77.67:80 | http://r10.o.lencr.org/ | unknown | — | — | unknown |
7072 | firefox.exe | POST | 200 | 184.24.77.67:80 | http://r10.o.lencr.org/ | unknown | — | — | unknown |
7072 | firefox.exe | POST | 200 | 184.24.77.67:80 | http://r10.o.lencr.org/ | unknown | — | — | unknown |
7072 | firefox.exe | POST | 200 | 142.250.186.99:80 | http://o.pki.goog/wr2 | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
1108 | svchost.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1420 | RUXIMICS.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
— | — | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
3888 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
5336 | SearchApp.exe | 104.126.37.178:443 | www.bing.com | Akamai International B.V. | DE | unknown |
5336 | SearchApp.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
3260 | svchost.exe | 40.115.3.253:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
5924 | svchost.exe | 20.190.159.68:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
www.bing.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
login.live.com |
| whitelisted |
th.bing.com |
| whitelisted |
fd.api.iris.microsoft.com |
| whitelisted |
arc.msn.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
6296 | BitLockerToGo.exe | Malware Command and Control Activity Detected | STEALER [ANY.RUN] Stealc HTTP POST Request |
6296 | BitLockerToGo.exe | Malware Command and Control Activity Detected | ET MALWARE [SEKOIA.IO] Win32/Stealc C2 Check-in |