| File name: | Album_One_Night_Stand_Shen_Zhi.zip.7z |
| Full analysis: | https://app.any.run/tasks/4430c5b5-852a-43f0-98c5-5232162eb1e5 |
| Verdict: | Malicious activity |
| Analysis date: | February 10, 2023, 08:52:23 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-7z-compressed |
| File info: | 7-zip archive data, version 0.4 |
| MD5: | 7F53CFB6ED94AF0CD73934D5F72B4EE9 |
| SHA1: | F00B17CCFBF75BCFF15A4B783E457D22C9D8ECCE |
| SHA256: | 753EBF5903AE5C3BF37FCE217DB2798E4C7E2BC62441A705A2E61CB521127779 |
| SSDEEP: | 393216:GDkICJAtKcrVB9jeZT0SszB6L+WjBSUjc:GDtPbr3Yd0Ssw+3UA |
| .7z | | | 7-Zip compressed archive (v0.4) (57.1) |
|---|---|---|
| .7z | | | 7-Zip compressed archive (gen) (42.8) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1128 | "C:\Users\admin\Desktop\IMG_1354_One_Night_Stand_Shen_Zhi - Dang_Dae_Hyun_Studio - By_Dook_Man_Shik_Photographer.exe" | C:\Users\admin\Desktop\IMG_1354_One_Night_Stand_Shen_Zhi - Dang_Dae_Hyun_Studio - By_Dook_Man_Shik_Photographer.exe | — | Explorer.EXE | |||||||||||
User: admin Company: Western Digital Technologies, Inc. Integrity Level: MEDIUM Description: WD Sync Service Exit code: 0 Version: 1.0.6698.8728 Modules
| |||||||||||||||
| 2188 | "C:\Users\admin\Desktop\IMG_1129_One_Night_Stand_Shen_Zhi - Dang_Dae_Hyun_Studio - By_Dook_Man_Shik_Photographer.exe" | C:\Users\admin\Desktop\IMG_1129_One_Night_Stand_Shen_Zhi - Dang_Dae_Hyun_Studio - By_Dook_Man_Shik_Photographer.exe | Explorer.EXE | ||||||||||||
User: admin Company: Western Digital Technologies, Inc. Integrity Level: MEDIUM Description: WD Sync Service Exit code: 3762504530 Version: 1.0.6698.8728 Modules
| |||||||||||||||
| 2324 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\Album_One_Night_Stand_Shen_Zhi.zip.7z" | C:\Program Files\WinRAR\WinRAR.exe | — | Explorer.EXE | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 2696 | "C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\Rar$DIb2324.14502\Album_One_Night_Stand_Shen_Zhi.zip | C:\Program Files\WinRAR\WinRAR.exe | WinRAR.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 3104 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2696.15534\IMG_1483_One_Night_Stand_Shen_Zhi - Dang_Dae_Hyun_Studio - By_Dook_Man_Shik_Photographer.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2696.15534\IMG_1483_One_Night_Stand_Shen_Zhi - Dang_Dae_Hyun_Studio - By_Dook_Man_Shik_Photographer.exe | WinRAR.exe | ||||||||||||
User: admin Company: Western Digital Technologies, Inc. Integrity Level: MEDIUM Description: WD Sync Service Exit code: 3221225477 Version: 1.0.6698.8728 Modules
| |||||||||||||||
| 3312 | "C:\Users\admin\Desktop\IMG_4459_One_Night_Stand_Shen_Zhi - Dang_Dae_Hyun_Studio - By_Dook_Man_Shik_Photographer.exe" | C:\Users\admin\Desktop\IMG_4459_One_Night_Stand_Shen_Zhi - Dang_Dae_Hyun_Studio - By_Dook_Man_Shik_Photographer.exe | Explorer.EXE | ||||||||||||
User: admin Company: Western Digital Technologies, Inc. Integrity Level: MEDIUM Description: WD Sync Service Exit code: 0 Version: 1.0.6698.8728 Modules
| |||||||||||||||
| 3688 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | Explorer.EXE | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (2324) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (2324) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (2324) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\16D\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2324) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (2324) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (2324) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (2324) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\Album_One_Night_Stand_Shen_Zhi.zip.7z | |||
| (PID) Process: | (2324) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2324) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2324) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2696 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2696.15534\wcontent | — | |
MD5:— | SHA256:— | |||
| 2324 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DIb2324.14502\Album_One_Night_Stand_Shen_Zhi.zip | compressed | |
MD5:— | SHA256:— | |||
| 2696 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2696.15534\IMG_6905_One_Night_Stand_Shen_Zhi - Dang_Dae_Hyun_Studio - By_Dook_Man_Shik_Photographer.exe | executable | |
MD5:37932FD952D6D845927F25F42CB3C628 | SHA256:CB807472BB6D4D1113FCBC209D6A08FA80FF9E53C83B1AA37F9D6F549AFFD68C | |||
| 2696 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2696.15534\IMG_8349_One_Night_Stand_Shen_Zhi - Dang_Dae_Hyun_Studio - By_Dook_Man_Shik_Photographer.exe | executable | |
MD5:37932FD952D6D845927F25F42CB3C628 | SHA256:CB807472BB6D4D1113FCBC209D6A08FA80FF9E53C83B1AA37F9D6F549AFFD68C | |||
| 2696 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2696.15534\IMG_6776_One_Night_Stand_Shen_Zhi - Dang_Dae_Hyun_Studio - By_Dook_Man_Shik_Photographer.exe | executable | |
MD5:37932FD952D6D845927F25F42CB3C628 | SHA256:CB807472BB6D4D1113FCBC209D6A08FA80FF9E53C83B1AA37F9D6F549AFFD68C | |||
| 2696 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2696.15534\IMG_8507_One_Night_Stand_Shen_Zhi - Dang_Dae_Hyun_Studio - By_Dook_Man_Shik_Photographer.exe | executable | |
MD5:37932FD952D6D845927F25F42CB3C628 | SHA256:CB807472BB6D4D1113FCBC209D6A08FA80FF9E53C83B1AA37F9D6F549AFFD68C | |||
| 2696 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2696.15534\IMG_7214_One_Night_Stand_Shen_Zhi - Dang_Dae_Hyun_Studio - By_Dook_Man_Shik_Photographer.exe | executable | |
MD5:37932FD952D6D845927F25F42CB3C628 | SHA256:CB807472BB6D4D1113FCBC209D6A08FA80FF9E53C83B1AA37F9D6F549AFFD68C | |||
| 2696 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2696.15534\IMG_8109_One_Night_Stand_Shen_Zhi - Dang_Dae_Hyun_Studio - By_Dook_Man_Shik_Photographer.exe | executable | |
MD5:37932FD952D6D845927F25F42CB3C628 | SHA256:CB807472BB6D4D1113FCBC209D6A08FA80FF9E53C83B1AA37F9D6F549AFFD68C | |||
| 2696 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2696.15534\IMG_8922_One_Night_Stand_Shen_Zhi - Dang_Dae_Hyun_Studio - By_Dook_Man_Shik_Photographer.exe | executable | |
MD5:37932FD952D6D845927F25F42CB3C628 | SHA256:CB807472BB6D4D1113FCBC209D6A08FA80FF9E53C83B1AA37F9D6F549AFFD68C | |||
| 2696 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2696.15534\IMG_6218_One_Night_Stand_Shen_Zhi - Dang_Dae_Hyun_Studio - By_Dook_Man_Shik_Photographer.exe | executable | |
MD5:37932FD952D6D845927F25F42CB3C628 | SHA256:CB807472BB6D4D1113FCBC209D6A08FA80FF9E53C83B1AA37F9D6F549AFFD68C | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3384 | WerFault.exe | 104.208.16.93:443 | watson.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | suspicious |
Domain | IP | Reputation |
|---|---|---|
watson.microsoft.com |
| whitelisted |