| File name: | Kaid Engineering Specification.pdf |
| Full analysis: | https://app.any.run/tasks/18ff22b1-10fd-423f-a3d5-dc135594d88f |
| Verdict: | Malicious activity |
| Analysis date: | July 27, 2023, 08:35:39 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v4, os: Win32 |
| MD5: | 0042E12574365B4B27CAEDE16D694C6B |
| SHA1: | 90320B89207B9A896790CF7368F583361ABDE429 |
| SHA256: | 71FE3093993FA5D6B23DF288C2DD0B61BAAC409929050A7CFA140F8AAEB346B8 |
| SSDEEP: | 12288:262V39bFOSKEI/22+tU0+1q4Kn6+BiIE1toN4bu2JUZWyNLSss7:W9bFtK4htlgq4S6+BtE8Mu2JUQyNLSsa |
| .rar | | | RAR compressed archive (v-4.x) (58.3) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (41.6) |
| ArchivedFileName: | Kaid Engineering Specification.exe |
|---|---|
| PackingMethod: | Normal |
| ModifyDate: | 2023:07:25 07:32:04 |
| OperatingSystem: | Win32 |
| UncompressedSize: | 571904 |
| CompressedSize: | 556192 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 348 | "C:\Users\admin\Desktop\Kaid Engineering Specification.pdf\Kaid Engineering Specification.exe" | C:\Users\admin\Desktop\Kaid Engineering Specification.pdf\Kaid Engineering Specification.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Exit code: 0 Version: 0.0.0.0 Modules
| |||||||||||||||
| 616 | "C:\Users\admin\Desktop\Kaid Engineering Specification.pdf\Kaid Engineering Specification.exe" | C:\Users\admin\Desktop\Kaid Engineering Specification.pdf\Kaid Engineering Specification.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Exit code: 0 Version: 0.0.0.0 Modules
| |||||||||||||||
| 1000 | "C:\Windows\System32\cmd.exe" | C:\Windows\System32\cmd.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1100 | "C:\Users\admin\Desktop\Kaid Engineering Specification.pdf\Kaid Engineering Specification.exe" | C:\Users\admin\Desktop\Kaid Engineering Specification.pdf\Kaid Engineering Specification.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: Exit code: 0 Version: 0.0.0.0 Modules
| |||||||||||||||
| 1324 | C:\Windows\Explorer.EXE | C:\Windows\explorer.exe | — | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1760 | "C:\Users\admin\Desktop\Kaid Engineering Specification.pdf\Kaid Engineering Specification.exe" | C:\Users\admin\Desktop\Kaid Engineering Specification.pdf\Kaid Engineering Specification.exe | — | Kaid Engineering Specification.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Exit code: 0 Version: 0.0.0.0 Modules
| |||||||||||||||
| 2020 | "C:\Users\admin\Desktop\Kaid Engineering Specification.pdf\Kaid Engineering Specification.exe" | C:\Users\admin\Desktop\Kaid Engineering Specification.pdf\Kaid Engineering Specification.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Exit code: 0 Version: 0.0.0.0 Modules
| |||||||||||||||
| 2164 | "C:\Users\admin\Desktop\Kaid Engineering Specification.pdf\Kaid Engineering Specification.exe" | C:\Users\admin\Desktop\Kaid Engineering Specification.pdf\Kaid Engineering Specification.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Exit code: 0 Version: 0.0.0.0 Modules
| |||||||||||||||
| 2572 | "C:\Windows\System32\wlanext.exe" | C:\Windows\System32\wlanext.exe | — | Kaid Engineering Specification.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Wireless LAN 802.11 Extensibility Framework Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2772 | "C:\Users\admin\Desktop\Kaid Engineering Specification.pdf\Kaid Engineering Specification.exe" | C:\Users\admin\Desktop\Kaid Engineering Specification.pdf\Kaid Engineering Specification.exe | — | Kaid Engineering Specification.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Exit code: 0 Version: 0.0.0.0 Modules
| |||||||||||||||
| (PID) Process: | (1324) explorer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks\{C8E6F269-B90A-4053-A3BE-499AFCEC98C4}.check.0 |
| Operation: | write | Name: | CheckSetting |
Value: 01000000D08C9DDF0115D1118C7A00C04FC297EB01000000F6D6788197A75D498472ACE88906AC8D00000000020000000000106600000001000020000000B1EA574F7E85D7FEFB00EDA3CD9BFD3125C297A135EDE02346F73C42C3388CA0000000000E8000000002000020000000AC81DC01D6640A783B09BD6CB20296D2ECDECBC876DAAA0BF9156B0CE56C0C3F30000000C1108EFC4A9E9B251BC8934C0AD891AEC0C1B25B6C750347F965AD2814FBD4276B82A010999047FC8D864034142115F440000000ED0A7D536C1A814C73FCEBA2DABE773ADDEDB64F7C42614DD60DCA8F8C9B170D0F318CEEA064708FE5CAD41E502BFD0632B0137E949C3E6DA8EAD541C63EEB1A | |||
| (PID) Process: | (1324) explorer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (1324) explorer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count |
| Operation: | write | Name: | {Q65231O0-O2S1-4857-N4PR-N8R7P6RN7Q27}\pzq.rkr |
Value: 000000001900000012000000948C0D00000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFFD09F0C16CA63D90100000000 | |||
| (PID) Process: | (1324) explorer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count |
| Operation: | write | Name: | HRZR_PGYFRFFVBA |
Value: 000000007C010000BE020000FDAD42013F0000004A0000008E0F0D004D006900630072006F0073006F00660074002E0049006E007400650072006E00650074004500780070006C006F007200650072002E00440065006600610075006C007400000028003E004000A4E75102B8E651020000000000000000000000000000080274E45102000008026CE25102000000000000D26CFFFFFFFF705911750000000000000000A4E251027C900D75000400000000000008E35102FFFFFFFF38EA7000FFFFFFFF080A7400D80E740030EA7000D4E25102F7AF3D7680D0707614F05102081D3E76E4613E766820700008E351020000000071000000BBF2CB00E8E25102A1693E766820700008E351020000000014E551023F613E766820700008E3510200000400000000800400000026E4510298E351025DA5147726E45102D26E147779A51477D6794D7526E4510210E65102000100006400610072E3510226E451026F0061006D0069006E0067005C006D006900630072006F0073006F0066007400CCE351023400000080E35102DE70310033003300350033003800310030003000F8E551025A000000A0E351021DA71477D6610E02D4E351025A00000010E651025C00000011000000104F7000084F7000F8E55102C4E3510220E40000D7F3CB00D0E351025E903E7620E45102D4E3510203943E760000000064561802FCE35102A9933E7664561802A8E45102D8511802BD933E7600000000D8511802A8E4510204E45102000000007D00000053B960004D006900630072006F0073006F00660074002E00570069006E0064006F00770073002E0043006F006E00740072006F006C00500061006E0065006C000000000001000000514FD77683091EC682020000B03724000000000000000000000000008CE6790020E77900F8E879001368DC7667A0B0B0FEFFFFFF514FD776620099748400050082020000010000000000000000000000B03724008CFF98748400050001000000FFFFFFFFFFFFFFFFE0C3D77691C4D7764E000000000000000000000000000000C4E67900A8C0987418EB79001368DC76672BB0B0E43724004EC4D776FE50D7760000000088F4987484000500C11000000000000000000000144EAC0001000000FFFFFFFFC11000000C00000088F49874840005003028D70080E77900EA53D776004EAC00804CAC000000000080E7790024CED776088000007D2FD776504498740880000084000500FCFFFFFF0D000000E84324001100000090511D0088511D000C00000038871EC6D8E7790020E8000031FE1EC6D4E779005E90ED7620E879005C5800005DFE1EC6E8E77900929BED7660580D024C06000000E87900D0530D020CE879001100000090511D0088511D0000E87900F0530D0270E8000085F11EC620E879005E90ED7670E8790024E879000394ED76000000005C580D024CE87900A993ED765C580D02F8E87900D0530D02BD93ED7600000000D0530D02F8E8790054E87900000000007D00000053B960004D006900630072006F0073006F00660074002E00570069006E0064006F00770073002E0043006F006E00740072006F006C00500061006E0065006C000000000001000000514FD77683091EC682020000B03724000000000000000000000000008CE6790020E77900F8E879001368DC7667A0B0B0FEFFFFFF514FD776620099748400050082020000010000000000000000000000B03724008CFF98748400050001000000FFFFFFFFFFFFFFFFE0C3D77691C4D7764E000000000000000000000000000000C4E67900A8C0987418EB79001368DC76672BB0B0E43724004EC4D776FE50D7760000000088F4987484000500C11000000000000000000000144EAC0001000000FFFFFFFFC11000000C00000088F49874840005003028D70080E77900EA53D776004EAC00804CAC000000000080E7790024CED776088000007D2FD776504498740880000084000500FCFFFFFF0D000000E84324001100000090511D0088511D000C00000038871EC6D8E7790020E8000031FE1EC6D4E779005E90ED7620E879005C5800005DFE1EC6E8E77900929BED7660580D024C06000000E87900D0530D020CE879001100000090511D0088511D0000E87900F0530D0270E8000085F11EC620E879005E90ED7670E8790024E879000394ED76000000005C580D024CE87900A993ED765C580D02F8E87900D0530D02BD93ED7600000000D0530D02F8E8790054E87900 | |||
| (PID) Process: | (1324) explorer.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3156) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3156) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3156) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3156) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3156) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 616 | Kaid Engineering Specification.exe | C:\Users\admin\AppData\Local\Temp\tmp66FF.tmp | xml | |
MD5:4FA0A822F9A661C1B6FE6FBEC5E0D02C | SHA256:716670EB9C326B21C883D7572AE61F55D2F015E40F11ED187E38FF77E9656950 | |||
| 2020 | Kaid Engineering Specification.exe | C:\Users\admin\AppData\Local\Temp\tmp8B9E.tmp | xml | |
MD5:4FA0A822F9A661C1B6FE6FBEC5E0D02C | SHA256:716670EB9C326B21C883D7572AE61F55D2F015E40F11ED187E38FF77E9656950 | |||
| 1100 | Kaid Engineering Specification.exe | C:\Users\admin\AppData\Roaming\JzzTGxSQGhNIhQ.exe | executable | |
MD5:1B3C5B35C45523F594F2A6C44A0FE3D6 | SHA256:400ACD7ADBC2A02D40EAFD6F1840DA99D2A14DEC1E0BA53AD5C6A2894E8CA08C | |||
| 2824 | Kaid Engineering Specification.exe | C:\Users\admin\AppData\Local\Temp\tmpA476.tmp | xml | |
MD5:4FA0A822F9A661C1B6FE6FBEC5E0D02C | SHA256:716670EB9C326B21C883D7572AE61F55D2F015E40F11ED187E38FF77E9656950 | |||
| 1324 | explorer.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\1b4dd67f29cb1962.automaticDestinations-ms | automaticdestinations-ms | |
MD5:807851F77931E91E42E2644268EE5860 | SHA256:784D6085772F2FF5E72719CAE88A9F9231FD3530C8AC598B316086A826DC9C75 | |||
| 1100 | Kaid Engineering Specification.exe | C:\Users\admin\AppData\Local\Temp\tmp54A0.tmp | xml | |
MD5:4FA0A822F9A661C1B6FE6FBEC5E0D02C | SHA256:716670EB9C326B21C883D7572AE61F55D2F015E40F11ED187E38FF77E9656950 | |||
| 348 | Kaid Engineering Specification.exe | C:\Users\admin\AppData\Local\Temp\tmp3C41.tmp | xml | |
MD5:4FA0A822F9A661C1B6FE6FBEC5E0D02C | SHA256:716670EB9C326B21C883D7572AE61F55D2F015E40F11ED187E38FF77E9656950 | |||
| 2164 | Kaid Engineering Specification.exe | C:\Users\admin\AppData\Local\Temp\tmpFBDD.tmp | xml | |
MD5:4FA0A822F9A661C1B6FE6FBEC5E0D02C | SHA256:716670EB9C326B21C883D7572AE61F55D2F015E40F11ED187E38FF77E9656950 | |||
| 3156 | WinRAR.exe | C:\Users\admin\Desktop\Kaid Engineering Specification.pdf\Kaid Engineering Specification.exe | executable | |
MD5:1B3C5B35C45523F594F2A6C44A0FE3D6 | SHA256:400ACD7ADBC2A02D40EAFD6F1840DA99D2A14DEC1E0BA53AD5C6A2894E8CA08C | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1324 | explorer.exe | GET | — | 111.68.6.219:80 | http://www.klfgcq.com/b68g/?GB=nGIr99yqoYi/26BcUYApbrHbR2a+aMRmfK/2EyQ3czkTzAqzq5IA3v+tasMcsCtg31mburWMfU5Oxz/k0lJnt7G+rim1wBTjFP60yfI=&VpqH7=uJAdKzZHflKLsF4 | HK | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2720 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
1084 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
1324 | explorer.exe | 111.68.6.219:80 | www.klfgcq.com | Netsec Limited | HK | unknown |
Domain | IP | Reputation |
|---|---|---|
www.klfgcq.com |
| unknown |