analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

Live Radio Pro Tab_5da0756ca78bf[1].exe.zip

Full analysis: https://app.any.run/tasks/0528c092-5245-43ed-8a23-06ceff794b89
Verdict: Malicious activity
Analysis date: October 14, 2019, 19:07:58
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

664D3495E8900E7E8605CEA24DB238C0

SHA1:

B03CC7C0016D61C606BD6EF35BF8574A42AEDD56

SHA256:

757503262E623F28E526BBF14756F5A613056B8BEC0457286B00733456E627B7

SSDEEP:

12288:T5AYeRwkZcwM9i0iVrtKXBkLrbWHEYb7BLRjVn6mddGXfuPGuJKA:TyPRDcX40iQGABLRjV6vfuPXwA

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • Live Radio Pro Tab_5da0756ca78bf[1].exe (PID: 892)
      • Live Radio Pro Tab_5da0756ca78bf[1].exe (PID: 3836)
    • Application was dropped or rewritten from another process

      • Live Radio Pro Tab_5da0756ca78bf[1].exe (PID: 892)
      • Live Radio Pro Tab_5da0756ca78bf[1].exe (PID: 3836)
      • Email Access Online.exe (PID: 3868)
    • Changes the autorun value in the registry

      • Live Radio Pro Tab_5da0756ca78bf[1].exe (PID: 3836)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Live Radio Pro Tab_5da0756ca78bf[1].exe (PID: 892)
      • Live Radio Pro Tab_5da0756ca78bf[1].exe (PID: 3836)
    • Creates a software uninstall entry

      • Email Access Online.exe (PID: 3868)
      • Live Radio Pro Tab_5da0756ca78bf[1].exe (PID: 3836)
    • Creates files in the user directory

      • Email Access Online.exe (PID: 3868)
    • Reads internet explorer settings

      • Email Access Online.exe (PID: 3868)
    • Starts Internet Explorer

      • Email Access Online.exe (PID: 3868)
    • Executed via COM

      • FlashUtil32_26_0_0_131_ActiveX.exe (PID: 3140)
  • INFO

    • Manual execution by user

      • Live Radio Pro Tab_5da0756ca78bf[1].exe (PID: 892)
      • Live Radio Pro Tab_5da0756ca78bf[1].exe (PID: 3836)
    • Reads Internet Cache Settings

      • IEXPLORE.EXE (PID: 4084)
    • Changes internet zones settings

      • IEXPLORE.EXE (PID: 2456)
    • Reads internet explorer settings

      • IEXPLORE.EXE (PID: 4084)
    • Creates files in the user directory

      • FlashUtil32_26_0_0_131_ActiveX.exe (PID: 3140)
      • IEXPLORE.EXE (PID: 4084)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: Live Radio Pro Tab_5da0756ca78bf[1].exe
ZipUncompressedSize: 789480
ZipCompressedSize: 750745
ZipCRC: 0xfef74738
ZipModifyDate: 2019:10:14 18:59:02
ZipCompression: Deflated
ZipBitFlag: 0x0009
ZipRequiredVersion: 20
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
42
Monitored processes
7
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
start drop and start winrar.exe no specs live radio pro tab_5da0756ca78bf[1].exe live radio pro tab_5da0756ca78bf[1].exe email access online.exe iexplore.exe iexplore.exe flashutil32_26_0_0_131_activex.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2528"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Live Radio Pro Tab_5da0756ca78bf[1].exe.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
892"C:\Users\admin\Desktop\Live Radio Pro Tab_5da0756ca78bf[1].exe" C:\Users\admin\Desktop\Live Radio Pro Tab_5da0756ca78bf[1].exe
explorer.exe
User:
admin
Company:
Better Cloud Solutions LTD
Integrity Level:
MEDIUM
Description:
Desktop web search
Exit code:
1
Version:
3.6.0.1
3836"C:\Users\admin\Desktop\Live Radio Pro Tab_5da0756ca78bf[1].exe" C:\Users\admin\Desktop\Live Radio Pro Tab_5da0756ca78bf[1].exe
explorer.exe
User:
admin
Company:
Better Cloud Solutions LTD
Integrity Level:
MEDIUM
Description:
Desktop web search
Exit code:
0
Version:
3.6.0.1
3868"C:\Users\admin\AppData\Local\Email Access Online\Email Access Online.exe" /firstrunC:\Users\admin\AppData\Local\Email Access Online\Email Access Online.exe
Live Radio Pro Tab_5da0756ca78bf[1].exe
User:
admin
Company:
Better Cloud Solutions LTD
Integrity Level:
MEDIUM
Description:
Desktop web search
Version:
3.6.0.1
2456"C:\Program Files\Internet Explorer\IEXPLORE.EXE" http://results.hemailaccessonline.com/s?uid=7ce42b2c-83ca-4350-9603-a9aaeee50b9a&uc=20191014&source=-lp0-bb8-sbe&i_id=email_&ap=appfocus1C:\Program Files\Internet Explorer\IEXPLORE.EXE
Email Access Online.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
1
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
4084"C:\Program Files\Internet Explorer\IEXPLORE.EXE" SCODEF:2456 CREDAT:71937C:\Program Files\Internet Explorer\IEXPLORE.EXE
IEXPLORE.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
3140C:\Windows\system32\Macromed\Flash\FlashUtil32_26_0_0_131_ActiveX.exe -EmbeddingC:\Windows\system32\Macromed\Flash\FlashUtil32_26_0_0_131_ActiveX.exesvchost.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
MEDIUM
Description:
Adobe® Flash® Player Installer/Uninstaller 26.0 r0
Exit code:
0
Version:
26,0,0,131
Total events
1 569
Read events
1 422
Write events
0
Delete events
0

Modification events

No data
Executable files
9
Suspicious files
7
Text files
100
Unknown types
11

Dropped files

PID
Process
Filename
Type
2528WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb2528.10559\Live Radio Pro Tab_5da0756ca78bf[1].exe
MD5:
SHA256:
3836Live Radio Pro Tab_5da0756ca78bf[1].exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\email[1].json
MD5:
SHA256:
3836Live Radio Pro Tab_5da0756ca78bf[1].exeC:\Users\admin\AppData\Local\Temp\Cab2999.tmp
MD5:
SHA256:
3836Live Radio Pro Tab_5da0756ca78bf[1].exeC:\Users\admin\AppData\Local\Temp\Tar299A.tmp
MD5:
SHA256:
3836Live Radio Pro Tab_5da0756ca78bf[1].exeC:\Users\admin\AppData\Local\Temp\Cab299B.tmp
MD5:
SHA256:
3836Live Radio Pro Tab_5da0756ca78bf[1].exeC:\Users\admin\AppData\Local\Temp\Tar299C.tmp
MD5:
SHA256:
3836Live Radio Pro Tab_5da0756ca78bf[1].exeC:\Users\admin\AppData\Local\Temp\Cab2A1A.tmp
MD5:
SHA256:
3836Live Radio Pro Tab_5da0756ca78bf[1].exeC:\Users\admin\AppData\Local\Temp\Tar2A1B.tmp
MD5:
SHA256:
3836Live Radio Pro Tab_5da0756ca78bf[1].exeC:\Users\admin\AppData\Local\Temp\nsw1610.tmp\ping
MD5:
SHA256:
3836Live Radio Pro Tab_5da0756ca78bf[1].exeC:\Users\admin\AppData\Local\Temp\nsw160F.tmp
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
16
TCP/UDP connections
56
DNS requests
20
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3836
Live Radio Pro Tab_5da0756ca78bf[1].exe
GET
200
3.19.196.51:80
http://websearchdl.com/Content/kits/sbui/widgets/email/email.json?useragent=SB&user_id=&source=-lp0-bb8-sbe&traffic_source=&subid=20191014&implementation_id=email_
US
text
441 b
suspicious
3868
Email Access Online.exe
GET
404
3.19.196.51:80
http://searchbardistro.com/cgi/adk/chrdlid.cgi?dfn=Email%20Access%20Online&err=6
US
html
141 b
suspicious
3836
Live Radio Pro Tab_5da0756ca78bf[1].exe
GET
200
93.184.221.240:80
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
US
compressed
57.0 Kb
whitelisted
3868
Email Access Online.exe
GET
404
3.19.196.51:80
http://websearchdl.com/Content/kits/SBVersion.json?distSubId3=3.6.0.1
US
binary
20 b
suspicious
4084
IEXPLORE.EXE
GET
302
52.202.4.117:80
http://results.hemailaccessonline.com/?uc=20191014&ap=appfocus1&source=-lp0-bb8-sbe&uid=7ce42b2c-83ca-4350-9603-a9aaeee50b9a&i_id=email_1&page=newtab
US
html
287 b
malicious
3868
Email Access Online.exe
GET
200
3.19.196.51:80
http://websearchdl.com/Content/kits/rotate_strings.json?useragent=SB&user_id=7ce42b2c-83ca-4350-9603-a9aaeee50b9a&source=-lp0-bb8-sbe&traffic_source=appfocus1&subid=20191014&implementation_id=email_
US
text
437 b
suspicious
2456
IEXPLORE.EXE
GET
200
204.79.197.200:80
http://www.bing.com/favicon.ico
US
image
237 b
whitelisted
3868
Email Access Online.exe
GET
302
52.202.4.117:80
http://results.hemailaccessonline.com/s?uid=7ce42b2c-83ca-4350-9603-a9aaeee50b9a&uc=20191014&source=-lp0-bb8-sbe&i_id=email_&ap=appfocus1&query=sbinit
US
html
157 b
malicious
4084
IEXPLORE.EXE
GET
302
52.202.4.117:80
http://results.hemailaccessonline.com/s?uid=7ce42b2c-83ca-4350-9603-a9aaeee50b9a&uc=20191014&source=-lp0-bb8-sbe&i_id=email_&ap=appfocus1
US
html
249 b
malicious
3836
Live Radio Pro Tab_5da0756ca78bf[1].exe
GET
200
35.168.129.108:80
http://imp.hemailaccessonline.com/impression.do?useragent=NSIS&user_id=7ce42b2c-83ca-4350-9603-a9aaeee50b9a&source=-lp0-bb8-sbe&traffic_source=appfocus1&subid=20191014&implementation_id=email_&event=sbe_offer_accepted
US
image
109 b
suspicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
892
Live Radio Pro Tab_5da0756ca78bf[1].exe
3.19.196.51:80
searchbardistro.com
US
unknown
3836
Live Radio Pro Tab_5da0756ca78bf[1].exe
93.184.221.240:80
www.download.windowsupdate.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
3836
Live Radio Pro Tab_5da0756ca78bf[1].exe
3.19.196.51:443
searchbardistro.com
US
unknown
3836
Live Radio Pro Tab_5da0756ca78bf[1].exe
35.168.129.108:80
imp.hemailaccessonline.com
Amazon.com, Inc.
US
suspicious
3836
Live Radio Pro Tab_5da0756ca78bf[1].exe
3.19.196.51:80
searchbardistro.com
US
unknown
3868
Email Access Online.exe
3.19.196.51:80
searchbardistro.com
US
unknown
3836
Live Radio Pro Tab_5da0756ca78bf[1].exe
13.35.254.82:80
x.ss2.us
US
suspicious
892
Live Radio Pro Tab_5da0756ca78bf[1].exe
3.13.88.241:80
searchbardistro.com
US
unknown
3868
Email Access Online.exe
35.168.129.108:80
imp.hemailaccessonline.com
Amazon.com, Inc.
US
suspicious
4084
IEXPLORE.EXE
52.202.4.117:80
results.hemailaccessonline.com
Amazon.com, Inc.
US
malicious

DNS requests

Domain
IP
Reputation
searchbardistro.com
  • 3.19.196.51
  • 3.13.88.241
suspicious
websearchdl.com
  • 3.19.196.51
  • 3.13.88.241
suspicious
x.ss2.us
  • 13.35.254.82
  • 13.35.254.54
  • 13.35.254.34
  • 13.35.254.176
whitelisted
www.download.windowsupdate.com
  • 93.184.221.240
whitelisted
imp.hemailaccessonline.com
  • 35.168.129.108
  • 35.173.75.18
unknown
results.hemailaccessonline.com
  • 52.202.4.117
  • 52.21.190.170
malicious
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
appfocus.go2cloud.org
  • 52.30.52.254
  • 52.50.109.222
  • 54.72.199.154
shared
thenewscentral.org
  • 3.226.11.65
  • 35.169.196.216
suspicious
ajax.googleapis.com
  • 172.217.21.202
  • 216.58.205.234
  • 172.217.22.10
  • 172.217.18.10
  • 172.217.18.170
  • 172.217.23.138
  • 172.217.23.106
  • 216.58.207.42
  • 216.58.207.74
  • 172.217.16.170
  • 172.217.22.42
  • 172.217.16.202
  • 172.217.18.106
whitelisted

Threats

PID
Process
Class
Message
3836
Live Radio Pro Tab_5da0756ca78bf[1].exe
Potentially Bad Traffic
ET USER_AGENTS Observed Suspicious UA (NSIS_Inetc (Mozilla))
3836
Live Radio Pro Tab_5da0756ca78bf[1].exe
Misc activity
SUSPICIOUS [PTsecurity] Suspicious HTTP header - Sometimes used by hostile installer
892
Live Radio Pro Tab_5da0756ca78bf[1].exe
Potentially Bad Traffic
ET USER_AGENTS Observed Suspicious UA (NSIS_Inetc (Mozilla))
892
Live Radio Pro Tab_5da0756ca78bf[1].exe
Misc activity
SUSPICIOUS [PTsecurity] Suspicious HTTP header - Sometimes used by hostile installer
No debug info