File name:

AquaSnap.Pro.1.23.7_fu11.zip

Full analysis: https://app.any.run/tasks/e287eca3-6774-4707-82f0-578ce783c721
Verdict: Malicious activity
Analysis date: March 23, 2024, 22:46:16
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=store
MD5:

E743B5FD981668A51D4AA618D90B0A34

SHA1:

1B8074CFFA3EB4D44521364DE3AE842E1E429AF4

SHA256:

74B05BB9EB2B9E05882750007C786904B5CB48BDCC5767E39850359D9664F81C

SSDEEP:

98304:XQAI1vue8m+7WqHniSQSa92Do+cgVf+6ysy2JpemiZLvenoheuD330sNcIW9Gzho:W9SPLz5UqY7Y

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • aquasnap.v.1.23.7-patch.exe (PID: 2744)
      • WinRAR.exe (PID: 3956)
  • SUSPICIOUS

    • Searches for installed software

      • msiexec.exe (PID: 116)
    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 3956)
      • AquaSnap.Updater.exe (PID: 3760)
    • Executes as Windows Service

      • VSSVC.exe (PID: 2960)
    • Executable content was dropped or overwritten

      • aquasnap.v.1.23.7-patch.exe (PID: 2744)
    • Creates file in the systems drive root

      • aquasnap.v.1.23.7-patch.exe (PID: 2744)
    • Reads the Internet Settings

      • aquasnap.v.1.23.7-patch.exe (PID: 2744)
      • AquaSnap.Updater.exe (PID: 3760)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3956)
      • msiexec.exe (PID: 116)
    • Drops the executable file immediately after the start

      • msiexec.exe (PID: 116)
    • Reads security settings of Internet Explorer

      • msiexec.exe (PID: 116)
    • Reads the software policy settings

      • msiexec.exe (PID: 116)
    • Checks supported languages

      • aquasnap.v.1.23.7-patch.exe (PID: 2744)
      • AquaSnap.Updater.exe (PID: 3760)
    • Create files in a temporary directory

      • aquasnap.v.1.23.7-patch.exe (PID: 2744)
    • Reads the computer name

      • aquasnap.v.1.23.7-patch.exe (PID: 2744)
      • AquaSnap.Updater.exe (PID: 3760)
    • Reads the machine GUID from the registry

      • AquaSnap.Updater.exe (PID: 3760)
      • aquasnap.v.1.23.7-patch.exe (PID: 2744)
    • Creates files in the program directory

      • aquasnap.v.1.23.7-patch.exe (PID: 2744)
    • Manual execution by a user

      • taskmgr.exe (PID: 1028)
    • Checks proxy server information

      • AquaSnap.Updater.exe (PID: 3760)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2024:03:23 23:45:50
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: AquaSnap.Pro.1.23.7_fu11/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
56
Monitored processes
7
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe msiexec.exe vssvc.exe no specs aquasnap.v.1.23.7-patch.exe no specs aquasnap.v.1.23.7-patch.exe aquasnap.updater.exe taskmgr.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
116"C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\Rar$EXa3956.47130\AquaSnap.Pro.1.23.7_fu11\AquaSnap.msi" C:\Windows\System32\msiexec.exe
WinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1028"C:\Windows\system32\taskmgr.exe" /4C:\Windows\System32\taskmgr.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Task Manager
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskmgr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2644"C:\Users\admin\AppData\Local\Temp\Rar$EXa3956.47786\AquaSnap.Pro.1.23.7_fu11\aquasnap.v.1.23.7-patch.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3956.47786\AquaSnap.Pro.1.23.7_fu11\aquasnap.v.1.23.7-patch.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3956.47786\aquasnap.pro.1.23.7_fu11\aquasnap.v.1.23.7-patch.exe
c:\windows\system32\ntdll.dll
2744"C:\Users\admin\AppData\Local\Temp\Rar$EXa3956.47786\AquaSnap.Pro.1.23.7_fu11\aquasnap.v.1.23.7-patch.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3956.47786\AquaSnap.Pro.1.23.7_fu11\aquasnap.v.1.23.7-patch.exe
WinRAR.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3956.47786\aquasnap.pro.1.23.7_fu11\aquasnap.v.1.23.7-patch.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\temp\dup2patcher.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2960C:\Windows\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3760"C:\Program Files\AquaSnap\AquaSnap.Updater.exe" -a 0 -i 0 -n AquaSnap -c 1.23.7 -v https://www.nurgo-software.com/version/aquasnap -d https://www.nurgo-software.com/download/AquaSnap.msi -w https://www.nurgo-software.com/company/news?utm_source=AquaSnap&utm_medium=applicationC:\Program Files\AquaSnap\AquaSnap.Updater.exe
AquaSnap.Daemon.exe
User:
admin
Company:
Nurgo Software
Integrity Level:
MEDIUM
Description:
Nurgo Updater
Exit code:
0
Version:
1, 3, 1, 0
Modules
Images
c:\program files\aquasnap\aquasnap.updater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winspool.drv
3956"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\AquaSnap.Pro.1.23.7_fu11.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
16 728
Read events
16 353
Write events
354
Delete events
21

Modification events

(PID) Process:(3956) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3956) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3956) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3956) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3956) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3956) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(3956) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\AquaSnap.Pro.1.23.7_fu11.zip
(PID) Process:(3956) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3956) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3956) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
10
Suspicious files
0
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
3956WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3956.47130\AquaSnap.Pro.1.23.7_fu11\aquasnap.v.1.23.7-patch.exeexecutable
MD5:03776C8EEB278152AA0EC9EA2236F786
SHA256:EB83E461D97B7E94A81A49CD4D0643EFD24FD092BBFF917F4B19689B77078117
3956WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3956.47786\AquaSnap.Pro.1.23.7_fu11\aquasnap.v.1.23.7-patch.exeexecutable
MD5:03776C8EEB278152AA0EC9EA2236F786
SHA256:EB83E461D97B7E94A81A49CD4D0643EFD24FD092BBFF917F4B19689B77078117
116msiexec.exeC:\Users\admin\AppData\Local\Temp\MSI407F.tmpexecutable
MD5:FAB4AA95C57F441B701BE7C2E81EE370
SHA256:8AD1084DE9A734B2D5C86F472F671CC324632B3A6CA5AAA0C360D93D4D08E148
3956WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3956.47786\AquaSnap.Pro.1.23.7_fu11\AquaSnap.msiexecutable
MD5:1E9330577F725E21A55ABCE5B4210E07
SHA256:8E014F0DF8E13C6706C7B34C08AA18DF2B3B1B465F8FCC847ED76A90CA86C6CE
3956WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3956.47130\AquaSnap.Pro.1.23.7_fu11\AquaSnap.msiexecutable
MD5:1E9330577F725E21A55ABCE5B4210E07
SHA256:8E014F0DF8E13C6706C7B34C08AA18DF2B3B1B465F8FCC847ED76A90CA86C6CE
3956WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3956.47786\AquaSnap.Pro.1.23.7_fu11\igorca.txttext
MD5:D10E8B28A0C6B4ED0F4C1C1F1075C085
SHA256:AB90557ACC3F82FA717E620D0A2138416A0AED1461AB7B028DE5DF28236D6CA6
2744aquasnap.v.1.23.7-patch.exeC:\Program Files\AquaSnap\AquaSnap.Configurator.exe.BAKexecutable
MD5:F68E9193DD43256242201ECD6AF367AA
SHA256:975D6CE219852C1E08F26CD3DDE69C0B325C18EE73BDA3A745A97E541E39D918
116msiexec.exeC:\Users\admin\AppData\Local\Temp\MSI72DA.tmpexecutable
MD5:D773D9BD091E712DF7560F576DA53DE8
SHA256:E0DB1804CF53ED4819ED70CB35C67680CE1A77573EFDED86E6DAC81010CE55E7
2744aquasnap.v.1.23.7-patch.exeC:\Program Files\AquaSnap\AquaSnap.Daemon.exe.BAKexecutable
MD5:EE2B54C585DCCA14C369F0B9E30CDFD7
SHA256:0D8178F2B23C3CA77DAC6C6371E52B876050F24B3E4893B115AC8222A9CC3860
2744aquasnap.v.1.23.7-patch.exeC:\Users\admin\AppData\Local\Temp\dup2patcher.dllexecutable
MD5:FEE17233F12CFC9186BD4765ED19E08B
SHA256:8B931466BDDF3C21CF34244EEBB305C85206AC5BE4657F2D89FA67A1A6C73F5B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
11
DNS requests
6
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1592
AquaSnap.Daemon.exe
GET
304
23.216.77.69:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?097adf30b6b5b9c1
unknown
unknown
1592
AquaSnap.Daemon.exe
GET
200
172.217.16.131:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
unknown
binary
1.41 Kb
unknown
1592
AquaSnap.Daemon.exe
GET
200
172.217.16.131:80
http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFNZazTHGPUBUGY%3D
unknown
binary
724 b
unknown
1592
AquaSnap.Daemon.exe
GET
200
172.217.16.131:80
http://ocsp.pki.goog/gts1c3/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEQD6BeWhIbleexId20FpK0af
unknown
binary
472 b
unknown
1080
svchost.exe
GET
200
23.216.77.80:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?9e294a7a0d3799e6
unknown
compressed
67.5 Kb
unknown
1080
svchost.exe
GET
304
23.216.77.80:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?e2ddf83a2417bb20
unknown
compressed
67.5 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
224.0.0.252:5355
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
1592
AquaSnap.Daemon.exe
142.250.186.72:443
ssl.google-analytics.com
GOOGLE
US
unknown
1592
AquaSnap.Daemon.exe
23.216.77.69:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
1592
AquaSnap.Daemon.exe
172.217.16.131:80
ocsp.pki.goog
GOOGLE
US
whitelisted
3760
AquaSnap.Updater.exe
46.105.204.10:443
www.nurgo-software.com
OVH SAS
FR
unknown
1080
svchost.exe
23.216.77.80:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown

DNS requests

Domain
IP
Reputation
ssl.google-analytics.com
  • 142.250.186.72
whitelisted
ctldl.windowsupdate.com
  • 23.216.77.69
  • 23.216.77.81
  • 23.216.77.45
  • 23.216.77.80
  • 23.216.77.44
whitelisted
ocsp.pki.goog
  • 172.217.16.131
whitelisted
www.nurgo-software.com
  • 46.105.204.10
unknown
dns.msftncsi.com
  • 131.107.255.255
shared

Threats

No threats detected
No debug info