File name:

Live Radio Pro Tab_5da0756ca78bf[1].exe.zip

Full analysis: https://app.any.run/tasks/0528c092-5245-43ed-8a23-06ceff794b89
Verdict: Malicious activity
Analysis date: October 14, 2019, 19:07:58
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

664D3495E8900E7E8605CEA24DB238C0

SHA1:

B03CC7C0016D61C606BD6EF35BF8574A42AEDD56

SHA256:

757503262E623F28E526BBF14756F5A613056B8BEC0457286B00733456E627B7

SSDEEP:

12288:T5AYeRwkZcwM9i0iVrtKXBkLrbWHEYb7BLRjVn6mddGXfuPGuJKA:TyPRDcX40iQGABLRjV6vfuPXwA

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • Live Radio Pro Tab_5da0756ca78bf[1].exe (PID: 892)
      • Live Radio Pro Tab_5da0756ca78bf[1].exe (PID: 3836)
    • Application was dropped or rewritten from another process

      • Live Radio Pro Tab_5da0756ca78bf[1].exe (PID: 892)
      • Live Radio Pro Tab_5da0756ca78bf[1].exe (PID: 3836)
      • Email Access Online.exe (PID: 3868)
    • Changes the autorun value in the registry

      • Live Radio Pro Tab_5da0756ca78bf[1].exe (PID: 3836)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Live Radio Pro Tab_5da0756ca78bf[1].exe (PID: 892)
      • Live Radio Pro Tab_5da0756ca78bf[1].exe (PID: 3836)
    • Creates a software uninstall entry

      • Email Access Online.exe (PID: 3868)
      • Live Radio Pro Tab_5da0756ca78bf[1].exe (PID: 3836)
    • Creates files in the user directory

      • Email Access Online.exe (PID: 3868)
    • Starts Internet Explorer

      • Email Access Online.exe (PID: 3868)
    • Reads internet explorer settings

      • Email Access Online.exe (PID: 3868)
    • Executed via COM

      • FlashUtil32_26_0_0_131_ActiveX.exe (PID: 3140)
  • INFO

    • Manual execution by user

      • Live Radio Pro Tab_5da0756ca78bf[1].exe (PID: 892)
      • Live Radio Pro Tab_5da0756ca78bf[1].exe (PID: 3836)
    • Changes internet zones settings

      • IEXPLORE.EXE (PID: 2456)
    • Reads Internet Cache Settings

      • IEXPLORE.EXE (PID: 4084)
    • Reads internet explorer settings

      • IEXPLORE.EXE (PID: 4084)
    • Creates files in the user directory

      • IEXPLORE.EXE (PID: 4084)
      • FlashUtil32_26_0_0_131_ActiveX.exe (PID: 3140)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0009
ZipCompression: Deflated
ZipModifyDate: 2019:10:14 18:59:02
ZipCRC: 0xfef74738
ZipCompressedSize: 750745
ZipUncompressedSize: 789480
ZipFileName: Live Radio Pro Tab_5da0756ca78bf[1].exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
42
Monitored processes
7
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
start drop and start winrar.exe no specs live radio pro tab_5da0756ca78bf[1].exe live radio pro tab_5da0756ca78bf[1].exe email access online.exe iexplore.exe iexplore.exe flashutil32_26_0_0_131_activex.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
892"C:\Users\admin\Desktop\Live Radio Pro Tab_5da0756ca78bf[1].exe" C:\Users\admin\Desktop\Live Radio Pro Tab_5da0756ca78bf[1].exe
explorer.exe
User:
admin
Company:
Better Cloud Solutions LTD
Integrity Level:
MEDIUM
Description:
Desktop web search
Exit code:
1
Version:
3.6.0.1
Modules
Images
c:\users\admin\desktop\live radio pro tab_5da0756ca78bf[1].exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
2456"C:\Program Files\Internet Explorer\IEXPLORE.EXE" http://results.hemailaccessonline.com/s?uid=7ce42b2c-83ca-4350-9603-a9aaeee50b9a&uc=20191014&source=-lp0-bb8-sbe&i_id=email_&ap=appfocus1C:\Program Files\Internet Explorer\IEXPLORE.EXE
Email Access Online.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
1
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
2528"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Live Radio Pro Tab_5da0756ca78bf[1].exe.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3140C:\Windows\system32\Macromed\Flash\FlashUtil32_26_0_0_131_ActiveX.exe -EmbeddingC:\Windows\system32\Macromed\Flash\FlashUtil32_26_0_0_131_ActiveX.exesvchost.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
MEDIUM
Description:
Adobe® Flash® Player Installer/Uninstaller 26.0 r0
Exit code:
0
Version:
26,0,0,131
Modules
Images
c:\windows\system32\macromed\flash\flashutil32_26_0_0_131_activex.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3836"C:\Users\admin\Desktop\Live Radio Pro Tab_5da0756ca78bf[1].exe" C:\Users\admin\Desktop\Live Radio Pro Tab_5da0756ca78bf[1].exe
explorer.exe
User:
admin
Company:
Better Cloud Solutions LTD
Integrity Level:
MEDIUM
Description:
Desktop web search
Exit code:
0
Version:
3.6.0.1
Modules
Images
c:\users\admin\desktop\live radio pro tab_5da0756ca78bf[1].exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
3868"C:\Users\admin\AppData\Local\Email Access Online\Email Access Online.exe" /firstrunC:\Users\admin\AppData\Local\Email Access Online\Email Access Online.exe
Live Radio Pro Tab_5da0756ca78bf[1].exe
User:
admin
Company:
Better Cloud Solutions LTD
Integrity Level:
MEDIUM
Description:
Desktop web search
Exit code:
0
Version:
3.6.0.1
Modules
Images
c:\users\admin\appdata\local\email access online\email access online.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
4084"C:\Program Files\Internet Explorer\IEXPLORE.EXE" SCODEF:2456 CREDAT:71937C:\Program Files\Internet Explorer\IEXPLORE.EXE
IEXPLORE.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
1 569
Read events
1 422
Write events
146
Delete events
1

Modification events

(PID) Process:(2528) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2528) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2528) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2528) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Live Radio Pro Tab_5da0756ca78bf[1].exe.zip
(PID) Process:(2528) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2528) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2528) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2528) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2528) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
(PID) Process:(892) Live Radio Pro Tab_5da0756ca78bf[1].exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Live Radio Pro Tab_5da0756ca78bf[1]_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
Executable files
9
Suspicious files
7
Text files
100
Unknown types
11

Dropped files

PID
Process
Filename
Type
2528WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb2528.10559\Live Radio Pro Tab_5da0756ca78bf[1].exe
MD5:
SHA256:
3836Live Radio Pro Tab_5da0756ca78bf[1].exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\email[1].json
MD5:
SHA256:
3836Live Radio Pro Tab_5da0756ca78bf[1].exeC:\Users\admin\AppData\Local\Temp\Cab2999.tmp
MD5:
SHA256:
3836Live Radio Pro Tab_5da0756ca78bf[1].exeC:\Users\admin\AppData\Local\Temp\Tar299A.tmp
MD5:
SHA256:
3836Live Radio Pro Tab_5da0756ca78bf[1].exeC:\Users\admin\AppData\Local\Temp\Cab299B.tmp
MD5:
SHA256:
3836Live Radio Pro Tab_5da0756ca78bf[1].exeC:\Users\admin\AppData\Local\Temp\Tar299C.tmp
MD5:
SHA256:
3836Live Radio Pro Tab_5da0756ca78bf[1].exeC:\Users\admin\AppData\Local\Temp\Cab2A1A.tmp
MD5:
SHA256:
3836Live Radio Pro Tab_5da0756ca78bf[1].exeC:\Users\admin\AppData\Local\Temp\Tar2A1B.tmp
MD5:
SHA256:
3836Live Radio Pro Tab_5da0756ca78bf[1].exeC:\Users\admin\AppData\Local\Temp\nsw1610.tmp\ping
MD5:
SHA256:
3836Live Radio Pro Tab_5da0756ca78bf[1].exeC:\Users\admin\AppData\Local\Temp\nsw160F.tmp
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
16
TCP/UDP connections
56
DNS requests
20
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3868
Email Access Online.exe
GET
200
3.19.196.51:80
http://websearchdl.com/Content/kits/rotate_strings.json?useragent=SB&user_id=7ce42b2c-83ca-4350-9603-a9aaeee50b9a&source=-lp0-bb8-sbe&traffic_source=appfocus1&subid=20191014&implementation_id=email_
US
text
437 b
suspicious
4084
IEXPLORE.EXE
GET
302
52.202.4.117:80
http://results.hemailaccessonline.com/s?uid=7ce42b2c-83ca-4350-9603-a9aaeee50b9a&uc=20191014&source=-lp0-bb8-sbe&i_id=email_&ap=appfocus1
US
html
249 b
malicious
3836
Live Radio Pro Tab_5da0756ca78bf[1].exe
GET
200
3.19.196.51:80
http://websearchdl.com/Content/kits/sbui/widgets/email/email.json?useragent=SB&user_id=&source=-lp0-bb8-sbe&traffic_source=&subid=20191014&implementation_id=email_
US
text
441 b
suspicious
3868
Email Access Online.exe
GET
302
52.202.4.117:80
http://results.hemailaccessonline.com/s?uid=7ce42b2c-83ca-4350-9603-a9aaeee50b9a&uc=20191014&source=-lp0-bb8-sbe&i_id=email_&ap=appfocus1&query=sbinit
US
html
157 b
malicious
892
Live Radio Pro Tab_5da0756ca78bf[1].exe
GET
404
3.13.88.241:80
http://searchbardistro.com/cgi/adk/chrdlid.cgi?dfn=Live%20Radio%20Pro%20Tab_5da0756ca78bf[1].exe&err=2
US
html
178 b
suspicious
3836
Live Radio Pro Tab_5da0756ca78bf[1].exe
GET
200
13.35.254.82:80
http://x.ss2.us/x.cer
US
der
1.27 Kb
whitelisted
3868
Email Access Online.exe
GET
404
3.19.196.51:80
http://searchbardistro.com/cgi/adk/chrdlid.cgi?dfn=Email%20Access%20Online&err=6
US
html
141 b
suspicious
3836
Live Radio Pro Tab_5da0756ca78bf[1].exe
GET
404
3.19.196.51:80
http://searchbardistro.com/cgi/adk/chrdlid.cgi?dfn=Live%20Radio%20Pro%20Tab_5da0756ca78bf[1].exe&err=2
US
html
178 b
suspicious
4084
IEXPLORE.EXE
GET
302
52.202.4.117:80
http://results.hemailaccessonline.com/?uc=20191014&ap=appfocus1&source=-lp0-bb8-sbe&uid=7ce42b2c-83ca-4350-9603-a9aaeee50b9a&i_id=email_1&page=newtab
US
html
287 b
malicious
3836
Live Radio Pro Tab_5da0756ca78bf[1].exe
GET
200
35.168.129.108:80
http://imp.hemailaccessonline.com/impression.do?useragent=NSIS&user_id=7ce42b2c-83ca-4350-9603-a9aaeee50b9a&source=-lp0-bb8-sbe&traffic_source=appfocus1&subid=20191014&implementation_id=email_&event=sbe_offer_accepted
US
image
109 b
suspicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
892
Live Radio Pro Tab_5da0756ca78bf[1].exe
3.19.196.51:80
searchbardistro.com
US
unknown
3836
Live Radio Pro Tab_5da0756ca78bf[1].exe
3.19.196.51:443
searchbardistro.com
US
unknown
3836
Live Radio Pro Tab_5da0756ca78bf[1].exe
35.168.129.108:80
imp.hemailaccessonline.com
Amazon.com, Inc.
US
suspicious
892
Live Radio Pro Tab_5da0756ca78bf[1].exe
3.13.88.241:80
searchbardistro.com
US
unknown
3868
Email Access Online.exe
52.202.4.117:80
results.hemailaccessonline.com
Amazon.com, Inc.
US
malicious
3868
Email Access Online.exe
35.168.129.108:80
imp.hemailaccessonline.com
Amazon.com, Inc.
US
suspicious
4084
IEXPLORE.EXE
52.202.4.117:80
results.hemailaccessonline.com
Amazon.com, Inc.
US
malicious
4084
IEXPLORE.EXE
52.30.52.254:443
appfocus.go2cloud.org
Amazon.com, Inc.
IE
suspicious
4084
IEXPLORE.EXE
209.197.3.15:443
maxcdn.bootstrapcdn.com
Highwinds Network Group, Inc.
US
whitelisted
4084
IEXPLORE.EXE
3.226.11.65:443
thenewscentral.org
US
unknown

DNS requests

Domain
IP
Reputation
searchbardistro.com
  • 3.19.196.51
  • 3.13.88.241
suspicious
websearchdl.com
  • 3.19.196.51
  • 3.13.88.241
suspicious
x.ss2.us
  • 13.35.254.82
  • 13.35.254.54
  • 13.35.254.34
  • 13.35.254.176
whitelisted
www.download.windowsupdate.com
  • 93.184.221.240
whitelisted
imp.hemailaccessonline.com
  • 35.168.129.108
  • 35.173.75.18
unknown
results.hemailaccessonline.com
  • 52.202.4.117
  • 52.21.190.170
malicious
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
appfocus.go2cloud.org
  • 52.30.52.254
  • 52.50.109.222
  • 54.72.199.154
shared
thenewscentral.org
  • 3.226.11.65
  • 35.169.196.216
suspicious
ajax.googleapis.com
  • 172.217.21.202
  • 216.58.205.234
  • 172.217.22.10
  • 172.217.18.10
  • 172.217.18.170
  • 172.217.23.138
  • 172.217.23.106
  • 216.58.207.42
  • 216.58.207.74
  • 172.217.16.170
  • 172.217.22.42
  • 172.217.16.202
  • 172.217.18.106
whitelisted

Threats

PID
Process
Class
Message
3836
Live Radio Pro Tab_5da0756ca78bf[1].exe
Potentially Bad Traffic
ET USER_AGENTS Observed Suspicious UA (NSIS_Inetc (Mozilla))
3836
Live Radio Pro Tab_5da0756ca78bf[1].exe
Misc activity
SUSPICIOUS [PTsecurity] Suspicious HTTP header - Sometimes used by hostile installer
892
Live Radio Pro Tab_5da0756ca78bf[1].exe
Potentially Bad Traffic
ET USER_AGENTS Observed Suspicious UA (NSIS_Inetc (Mozilla))
892
Live Radio Pro Tab_5da0756ca78bf[1].exe
Misc activity
SUSPICIOUS [PTsecurity] Suspicious HTTP header - Sometimes used by hostile installer
No debug info