File name:

Lucio Dalla - Discografia Completa.zip

Full analysis: https://app.any.run/tasks/30929401-e6df-4ec7-a853-df426baae2be
Verdict: Malicious activity
Analysis date: July 02, 2019, 09:36:15
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract
MD5:

D32301D9CC1DC61056D83F8D51C119E9

SHA1:

BDDEC906B008CB12D1CE816E165A4D075FE02826

SHA256:

744F8CD95A99A7AEA95D33DFBCABDEFFE1397FBF95161A28C642ACBD16F96BB0

SSDEEP:

98304:wbEwGxyUOn/JaYYaeY+dM6YydmOQ1zYuuUBb53+munE0dMp1oHnXZetvRfuODYNX:y2WkYfj+uwyzYRUlh+vzWnoHavRfuOzq

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Lucio Dalla - Discografia Completa.exe (PID: 1244)
  • SUSPICIOUS

    • Starts CMD.EXE for commands execution

      • WScript.exe (PID: 2608)
    • Executable content was dropped or overwritten

      • cmd.exe (PID: 3816)
      • WinRAR.exe (PID: 2032)
      • Lucio Dalla - Discografia Completa.exe (PID: 1244)
    • Executes scripts

      • Lucio Dalla - Discografia Completa.exe (PID: 1244)
  • INFO

    • Manual execution by user

      • Lucio Dalla - Discografia Completa.exe (PID: 1244)
      • WinRAR.exe (PID: 2032)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2017:10:26 19:46:04
ZipCRC: 0x9e9287f8
ZipCompressedSize: 6549824
ZipUncompressedSize: 6549824
ZipFileName: Lucio Dalla - Discografia Completa.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
40
Monitored processes
5
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs winrar.exe lucio dalla - discografia completa.exe wscript.exe no specs cmd.exe

Process information

PID
CMD
Path
Indicators
Parent process
1244"C:\Users\admin\Desktop\Lucio Dalla - Discografia Completa\Lucio Dalla - Discografia Completa.exe" C:\Users\admin\Desktop\Lucio Dalla - Discografia Completa\Lucio Dalla - Discografia Completa.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\lucio dalla - discografia completa\lucio dalla - discografia completa.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2032"C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Desktop\Lucio Dalla - Discografia Completa.zip" "C:\Users\admin\Desktop\Lucio Dalla - Discografia Completa\"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2608"C:\Windows\System32\WScript.exe" "C:\Users\admin\AppData\Local\Temp\RarSFX0\run.vbs" C:\Windows\System32\WScript.exeLucio Dalla - Discografia Completa.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Windows Based Script Host
Exit code:
0
Version:
5.8.7600.16385
Modules
Images
c:\windows\system32\wscript.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3348"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\Lucio Dalla - Discografia Completa.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3816cmd /c ""C:\Users\admin\AppData\Local\Temp\RarSFX0\installer.bat" "C:\Windows\System32\cmd.exe
WScript.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
1 103
Read events
1 070
Write events
33
Delete events
0

Modification events

(PID) Process:(3348) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3348) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3348) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3348) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\Lucio Dalla - Discografia Completa.zip
(PID) Process:(3348) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3348) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3348) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3348) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3348) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
(PID) Process:(3348) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\General
Operation:writeName:LastFolder
Value:
C:\Users\admin\Desktop
Executable files
24
Suspicious files
6
Text files
15
Unknown types
0

Dropped files

PID
Process
Filename
Type
2032WinRAR.exeC:\Users\admin\Desktop\Lucio Dalla - Discografia Completa\Lucio Dalla - Discografia Completa.exeexecutable
MD5:
SHA256:
1244Lucio Dalla - Discografia Completa.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\setuptext
MD5:
SHA256:
1244Lucio Dalla - Discografia Completa.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\006.tmptext
MD5:707889E7678A187F86817CF34DCCEC0A
SHA256:950DBB768A6230AF688907C22A147F6B01AD147002A3EB75F50649F6D2C4FFFC
1244Lucio Dalla - Discografia Completa.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\005.tmpexecutable
MD5:53A60793BF8A3F8C4335232BF98613B8
SHA256:936E44D41EDEFF6C009C53CF476C9D9F0FA4986817F912943CF47842F60AD878
1244Lucio Dalla - Discografia Completa.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\007.tmptext
MD5:596B9DCD1BCD23D29D1A83C194591119
SHA256:368792A61F159179269F1497A667C93AD3CA688FEB5F02E0DC4BD52EC7E9AC8F
1244Lucio Dalla - Discografia Completa.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\008.tmpexecutable
MD5:EF29134D5ABB8D5676B6E5AD42469FBD
SHA256:4BA286A2580A2A2B7EE696B13B0A04B59F82B04D5441B50D715A1C5F860E5253
1244Lucio Dalla - Discografia Completa.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\002.tmpexecutable
MD5:A51D90F2F9394F5EA0A3ACAE3BD2B219
SHA256:AC9674FEB8F2FAD20C1E046DE67F899419276AE79A60E8CC021A4BF472AE044F
1244Lucio Dalla - Discografia Completa.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\013.tmpbinary
MD5:3D597678765359281E4BC1C66AC4002B
SHA256:F6C23885384BF52A52FF48D718BF7A4825D1FF9708FBAE35FF1A35C153AEC1FC
3816cmd.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\007.battext
MD5:596B9DCD1BCD23D29D1A83C194591119
SHA256:368792A61F159179269F1497A667C93AD3CA688FEB5F02E0DC4BD52EC7E9AC8F
1244Lucio Dalla - Discografia Completa.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\003.tmpexecutable
MD5:04AD4B80880B32C94BE8D0886482C774
SHA256:A1E1D1F0FFF4FCCCFBDFA313F3BDFEA4D3DFE2C2D9174A615BBC39A0A6929338
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info