File name:

Album_One_Night_Stand_Shen_Zhi.zip.7z

Full analysis: https://app.any.run/tasks/4430c5b5-852a-43f0-98c5-5232162eb1e5
Verdict: Malicious activity
Analysis date: February 10, 2023, 08:52:23
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-7z-compressed
File info: 7-zip archive data, version 0.4
MD5:

7F53CFB6ED94AF0CD73934D5F72B4EE9

SHA1:

F00B17CCFBF75BCFF15A4B783E457D22C9D8ECCE

SHA256:

753EBF5903AE5C3BF37FCE217DB2798E4C7E2BC62441A705A2E61CB521127779

SSDEEP:

393216:GDkICJAtKcrVB9jeZT0SszB6L+WjBSUjc:GDtPbr3Yd0Ssw+3UA

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • IMG_1483_One_Night_Stand_Shen_Zhi - Dang_Dae_Hyun_Studio - By_Dook_Man_Shik_Photographer.exe (PID: 3104)
      • IMG_1129_One_Night_Stand_Shen_Zhi - Dang_Dae_Hyun_Studio - By_Dook_Man_Shik_Photographer.exe (PID: 2188)
      • IMG_1354_One_Night_Stand_Shen_Zhi - Dang_Dae_Hyun_Studio - By_Dook_Man_Shik_Photographer.exe (PID: 1128)
      • IMG_4459_One_Night_Stand_Shen_Zhi - Dang_Dae_Hyun_Studio - By_Dook_Man_Shik_Photographer.exe (PID: 3312)
  • SUSPICIOUS

    • Application launched itself

      • WinRAR.exe (PID: 2324)
    • Drops 7-zip archiver for unpacking

      • WinRAR.exe (PID: 2696)
    • Reads settings of System Certificates

      • IMG_1483_One_Night_Stand_Shen_Zhi - Dang_Dae_Hyun_Studio - By_Dook_Man_Shik_Photographer.exe (PID: 3104)
      • IMG_4459_One_Night_Stand_Shen_Zhi - Dang_Dae_Hyun_Studio - By_Dook_Man_Shik_Photographer.exe (PID: 3312)
  • INFO

    • Checks supported languages

      • IMG_1483_One_Night_Stand_Shen_Zhi - Dang_Dae_Hyun_Studio - By_Dook_Man_Shik_Photographer.exe (PID: 3104)
      • wmpnscfg.exe (PID: 3688)
      • IMG_1129_One_Night_Stand_Shen_Zhi - Dang_Dae_Hyun_Studio - By_Dook_Man_Shik_Photographer.exe (PID: 2188)
      • IMG_1354_One_Night_Stand_Shen_Zhi - Dang_Dae_Hyun_Studio - By_Dook_Man_Shik_Photographer.exe (PID: 1128)
      • IMG_4459_One_Night_Stand_Shen_Zhi - Dang_Dae_Hyun_Studio - By_Dook_Man_Shik_Photographer.exe (PID: 3312)
    • Reads the computer name

      • IMG_1483_One_Night_Stand_Shen_Zhi - Dang_Dae_Hyun_Studio - By_Dook_Man_Shik_Photographer.exe (PID: 3104)
      • wmpnscfg.exe (PID: 3688)
      • IMG_1354_One_Night_Stand_Shen_Zhi - Dang_Dae_Hyun_Studio - By_Dook_Man_Shik_Photographer.exe (PID: 1128)
      • IMG_1129_One_Night_Stand_Shen_Zhi - Dang_Dae_Hyun_Studio - By_Dook_Man_Shik_Photographer.exe (PID: 2188)
      • IMG_4459_One_Night_Stand_Shen_Zhi - Dang_Dae_Hyun_Studio - By_Dook_Man_Shik_Photographer.exe (PID: 3312)
    • The process checks LSA protection

      • IMG_1483_One_Night_Stand_Shen_Zhi - Dang_Dae_Hyun_Studio - By_Dook_Man_Shik_Photographer.exe (PID: 3104)
      • wmpnscfg.exe (PID: 3688)
      • IMG_4459_One_Night_Stand_Shen_Zhi - Dang_Dae_Hyun_Studio - By_Dook_Man_Shik_Photographer.exe (PID: 3312)
    • Reads the machine GUID from the registry

      • IMG_1483_One_Night_Stand_Shen_Zhi - Dang_Dae_Hyun_Studio - By_Dook_Man_Shik_Photographer.exe (PID: 3104)
      • wmpnscfg.exe (PID: 3688)
      • IMG_4459_One_Night_Stand_Shen_Zhi - Dang_Dae_Hyun_Studio - By_Dook_Man_Shik_Photographer.exe (PID: 3312)
    • Creates files in the program directory

      • IMG_1483_One_Night_Stand_Shen_Zhi - Dang_Dae_Hyun_Studio - By_Dook_Man_Shik_Photographer.exe (PID: 3104)
    • Loads dropped or rewritten executable

      • IMG_1483_One_Night_Stand_Shen_Zhi - Dang_Dae_Hyun_Studio - By_Dook_Man_Shik_Photographer.exe (PID: 3104)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 3688)
      • IMG_1129_One_Night_Stand_Shen_Zhi - Dang_Dae_Hyun_Studio - By_Dook_Man_Shik_Photographer.exe (PID: 2188)
      • IMG_1354_One_Night_Stand_Shen_Zhi - Dang_Dae_Hyun_Studio - By_Dook_Man_Shik_Photographer.exe (PID: 1128)
      • IMG_4459_One_Night_Stand_Shen_Zhi - Dang_Dae_Hyun_Studio - By_Dook_Man_Shik_Photographer.exe (PID: 3312)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2696)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 2696)
    • Drops a file that was compiled in debug mode

      • WinRAR.exe (PID: 2696)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.7z | 7-Zip compressed archive (v0.4) (57.1)
.7z | 7-Zip compressed archive (gen) (42.8)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
50
Monitored processes
7
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start drop and start winrar.exe no specs winrar.exe img_1483_one_night_stand_shen_zhi - dang_dae_hyun_studio - by_dook_man_shik_photographer.exe wmpnscfg.exe no specs img_1129_one_night_stand_shen_zhi - dang_dae_hyun_studio - by_dook_man_shik_photographer.exe img_1354_one_night_stand_shen_zhi - dang_dae_hyun_studio - by_dook_man_shik_photographer.exe no specs img_4459_one_night_stand_shen_zhi - dang_dae_hyun_studio - by_dook_man_shik_photographer.exe

Process information

PID
CMD
Path
Indicators
Parent process
1128"C:\Users\admin\Desktop\IMG_1354_One_Night_Stand_Shen_Zhi - Dang_Dae_Hyun_Studio - By_Dook_Man_Shik_Photographer.exe" C:\Users\admin\Desktop\IMG_1354_One_Night_Stand_Shen_Zhi - Dang_Dae_Hyun_Studio - By_Dook_Man_Shik_Photographer.exeExplorer.EXE
User:
admin
Company:
Western Digital Technologies, Inc.
Integrity Level:
MEDIUM
Description:
WD Sync Service
Exit code:
0
Version:
1.0.6698.8728
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\desktop\img_1354_one_night_stand_shen_zhi - dang_dae_hyun_studio - by_dook_man_shik_photographer.exe
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2188"C:\Users\admin\Desktop\IMG_1129_One_Night_Stand_Shen_Zhi - Dang_Dae_Hyun_Studio - By_Dook_Man_Shik_Photographer.exe" C:\Users\admin\Desktop\IMG_1129_One_Night_Stand_Shen_Zhi - Dang_Dae_Hyun_Studio - By_Dook_Man_Shik_Photographer.exe
Explorer.EXE
User:
admin
Company:
Western Digital Technologies, Inc.
Integrity Level:
MEDIUM
Description:
WD Sync Service
Exit code:
3762504530
Version:
1.0.6698.8728
Modules
Images
c:\users\admin\desktop\img_1129_one_night_stand_shen_zhi - dang_dae_hyun_studio - by_dook_man_shik_photographer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\rpcrt4.dll
2324"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\Album_One_Night_Stand_Shen_Zhi.zip.7z"C:\Program Files\WinRAR\WinRAR.exeExplorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2696"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\Rar$DIb2324.14502\Album_One_Night_Stand_Shen_Zhi.zipC:\Program Files\WinRAR\WinRAR.exe
WinRAR.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
3104"C:\Users\admin\AppData\Local\Temp\Rar$EXa2696.15534\IMG_1483_One_Night_Stand_Shen_Zhi - Dang_Dae_Hyun_Studio - By_Dook_Man_Shik_Photographer.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2696.15534\IMG_1483_One_Night_Stand_Shen_Zhi - Dang_Dae_Hyun_Studio - By_Dook_Man_Shik_Photographer.exe
WinRAR.exe
User:
admin
Company:
Western Digital Technologies, Inc.
Integrity Level:
MEDIUM
Description:
WD Sync Service
Exit code:
3221225477
Version:
1.0.6698.8728
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2696.15534\img_1483_one_night_stand_shen_zhi - dang_dae_hyun_studio - by_dook_man_shik_photographer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3312"C:\Users\admin\Desktop\IMG_4459_One_Night_Stand_Shen_Zhi - Dang_Dae_Hyun_Studio - By_Dook_Man_Shik_Photographer.exe" C:\Users\admin\Desktop\IMG_4459_One_Night_Stand_Shen_Zhi - Dang_Dae_Hyun_Studio - By_Dook_Man_Shik_Photographer.exe
Explorer.EXE
User:
admin
Company:
Western Digital Technologies, Inc.
Integrity Level:
MEDIUM
Description:
WD Sync Service
Exit code:
0
Version:
1.0.6698.8728
Modules
Images
c:\users\admin\desktop\img_4459_one_night_stand_shen_zhi - dang_dae_hyun_studio - by_dook_man_shik_photographer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3688"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeExplorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ole32.dll
Total events
14 082
Read events
13 962
Write events
114
Delete events
6

Modification events

(PID) Process:(2324) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2324) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2324) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16D\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2324) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(2324) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2324) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(2324) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\Album_One_Night_Stand_Shen_Zhi.zip.7z
(PID) Process:(2324) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2324) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2324) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
156
Suspicious files
2
Text files
6
Unknown types
0

Dropped files

PID
Process
Filename
Type
2696WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2696.15534\wcontent
MD5:
SHA256:
2324WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DIb2324.14502\Album_One_Night_Stand_Shen_Zhi.zipcompressed
MD5:
SHA256:
2696WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2696.15534\IMG_6905_One_Night_Stand_Shen_Zhi - Dang_Dae_Hyun_Studio - By_Dook_Man_Shik_Photographer.exeexecutable
MD5:37932FD952D6D845927F25F42CB3C628
SHA256:CB807472BB6D4D1113FCBC209D6A08FA80FF9E53C83B1AA37F9D6F549AFFD68C
2696WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2696.15534\IMG_8349_One_Night_Stand_Shen_Zhi - Dang_Dae_Hyun_Studio - By_Dook_Man_Shik_Photographer.exeexecutable
MD5:37932FD952D6D845927F25F42CB3C628
SHA256:CB807472BB6D4D1113FCBC209D6A08FA80FF9E53C83B1AA37F9D6F549AFFD68C
2696WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2696.15534\IMG_6776_One_Night_Stand_Shen_Zhi - Dang_Dae_Hyun_Studio - By_Dook_Man_Shik_Photographer.exeexecutable
MD5:37932FD952D6D845927F25F42CB3C628
SHA256:CB807472BB6D4D1113FCBC209D6A08FA80FF9E53C83B1AA37F9D6F549AFFD68C
2696WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2696.15534\IMG_8507_One_Night_Stand_Shen_Zhi - Dang_Dae_Hyun_Studio - By_Dook_Man_Shik_Photographer.exeexecutable
MD5:37932FD952D6D845927F25F42CB3C628
SHA256:CB807472BB6D4D1113FCBC209D6A08FA80FF9E53C83B1AA37F9D6F549AFFD68C
2696WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2696.15534\IMG_7214_One_Night_Stand_Shen_Zhi - Dang_Dae_Hyun_Studio - By_Dook_Man_Shik_Photographer.exeexecutable
MD5:37932FD952D6D845927F25F42CB3C628
SHA256:CB807472BB6D4D1113FCBC209D6A08FA80FF9E53C83B1AA37F9D6F549AFFD68C
2696WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2696.15534\IMG_8109_One_Night_Stand_Shen_Zhi - Dang_Dae_Hyun_Studio - By_Dook_Man_Shik_Photographer.exeexecutable
MD5:37932FD952D6D845927F25F42CB3C628
SHA256:CB807472BB6D4D1113FCBC209D6A08FA80FF9E53C83B1AA37F9D6F549AFFD68C
2696WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2696.15534\IMG_8922_One_Night_Stand_Shen_Zhi - Dang_Dae_Hyun_Studio - By_Dook_Man_Shik_Photographer.exeexecutable
MD5:37932FD952D6D845927F25F42CB3C628
SHA256:CB807472BB6D4D1113FCBC209D6A08FA80FF9E53C83B1AA37F9D6F549AFFD68C
2696WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2696.15534\IMG_6218_One_Night_Stand_Shen_Zhi - Dang_Dae_Hyun_Studio - By_Dook_Man_Shik_Photographer.exeexecutable
MD5:37932FD952D6D845927F25F42CB3C628
SHA256:CB807472BB6D4D1113FCBC209D6A08FA80FF9E53C83B1AA37F9D6F549AFFD68C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
2
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3384
WerFault.exe
104.208.16.93:443
watson.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
suspicious

DNS requests

Domain
IP
Reputation
watson.microsoft.com
  • 104.208.16.93
whitelisted

Threats

No threats detected
No debug info