download:

PBDownForce0331.zip

Full analysis: https://app.any.run/tasks/71b5b6d9-869f-456d-921a-621a12add028
Verdict: Malicious activity
Analysis date: May 25, 2020, 17:32:22
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract
MD5:

B3758F97DC1F0219F2048F5ECA6F8F02

SHA1:

7875C6C5C4AEB38E937EA3FE39024794BC411049

SHA256:

728A4FA634115788AAFB0309EBC63A6462CA83DFC53AB3A12FF856D279C7531E

SSDEEP:

49152:B6XhFlFPYLv8vf8EIwTqtADbTnfndql4mMfRBtjXhA5wO5pT:oRjlYzWEEIwTqtADHnfy4BlXhmp

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • PBDownForce.exe (PID: 4052)
      • PBDownForce.exe (PID: 2092)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • PBDownForce.exe (PID: 4052)
      • WinRAR.exe (PID: 3232)
    • Low-level read access rights to disk partition

      • PBDownForce.exe (PID: 4052)
  • INFO

    • Manual execution by user

      • PBDownForce.exe (PID: 2092)
      • PBDownForce.exe (PID: 4052)
      • WinRAR.exe (PID: 3328)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2014:03:01 12:02:05
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: PBDownForce0331/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
50
Monitored processes
4
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe winrar.exe no specs pbdownforce.exe pbdownforce.exe

Process information

PID
CMD
Path
Indicators
Parent process
2092"C:\Users\admin\Desktop\PBDownForce0331\PBDownForce.exe" C:\Users\admin\Desktop\PBDownForce0331\PBDownForce.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
PB DownForce
Exit code:
4294967295
Version:
0.3.3.1
Modules
Images
c:\users\admin\desktop\pbdownforce0331\pbdownforce.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3232"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\PBDownForce0331.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3328"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\PBDownForce0331.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
4052"C:\Users\admin\Desktop\PBDownForce0331\PBDownForce.exe" C:\Users\admin\Desktop\PBDownForce0331\PBDownForce.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
PB DownForce
Exit code:
0
Version:
0.3.3.1
Modules
Images
c:\users\admin\desktop\pbdownforce0331\pbdownforce.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
Total events
650
Read events
610
Write events
40
Delete events
0

Modification events

(PID) Process:(3232) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3232) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3232) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12D\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3232) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12D\52C64B7E
Operation:writeName:@C:\Windows\system32\NetworkExplorer.dll,-1
Value:
Network
(PID) Process:(3328) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3328) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3232) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\PBDownForce0331.zip
(PID) Process:(3232) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3232) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3232) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
2
Suspicious files
1
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
3232WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3232.30674\PBDownForce0331\configbinary
MD5:
SHA256:
3232WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3232.30674\PBDownForce0331\LICENCEtext
MD5:946A543244815AB9FDAE8ECB552FDD10
SHA256:E90AD5EB7F1983EBDFFEF26A18AF0611525581BECC178685D0C594A08B2E5E37
3232WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3232.30674\PBDownForce0331\READMEtext
MD5:9A14BE8F38CB9F20DC7E00F3DBC56F99
SHA256:3A025C5284F6C4ACF6265064EEBAD8FE5A5BF264AC6D1E9238130D648B712B95
4052PBDownForce.exeC:\Users\admin\AppData\Local\Temp\PHQ57DE.tmpexecutable
MD5:3E0B17C188F0EB599F34D218B734CCF1
SHA256:EAB88277FCBA17C2CC33AD24E6EC4DC114A9A70A4E880822AE9524334492F504
3232WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3232.30674\PBDownForce0331\PBDownForce.exeexecutable
MD5:D8F05FAF3075DCFF55593D1A6B757C1D
SHA256:E0B916612D2C68DFCF7BEBD04DB8BA74E3CF3C194DB608FA93600301029D0AC4
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
Process
Message
PBDownForce.exe
PB DownForce 0.3.3.1 Copyright © 2006-2007 by Christopher 'Trundle' Schmidt http://trundle.gamedev.de/ WARNING: this computer program is protected by copyright law and international treaties. Unauthorized reproduction or distribution of this program, or any portion of it, may result in severe civil and criminal penalties, and will be prosecuted to the maximum extent possible under the law.
PBDownForce.exe
PB DownForce 0.3.3.1 Copyright © 2006-2007 by Christopher 'Trundle' Schmidt http://trundle.gamedev.de/ WARNING: this computer program is protected by copyright law and international treaties. Unauthorized reproduction or distribution of this program, or any portion of it, may result in severe civil and criminal penalties, and will be prosecuted to the maximum extent possible under the law.