File name:

Danh sach khach hang dien may khu vuc HCM.rar

Full analysis: https://app.any.run/tasks/86752e19-20a8-4149-a8ac-e83811d6f018
Verdict: Malicious activity
Analysis date: October 20, 2020, 10:17:32
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

14164D213CC365BE86CE2A1277932FEE

SHA1:

1535BFA1009C3E368282A6241303BD74C6364031

SHA256:

7B4006D56E6BE16572BD796D47064644EE45251DE40178CB40E6071DD4932FAF

SSDEEP:

49152:L0y7N0Tz+v/kPbzD4CbunENVf9PshSESgx5XAlvZ:aT6U3cCbv/EhSELx6

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads the Task Scheduler COM API

      • Danh sach khach hang dien may khu vuc HCM.exe (PID: 2720)
    • Application was dropped or rewritten from another process

      • Danh sach khach hang dien may khu vuc HCM.exe (PID: 2720)
    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 3092)
      • Danh sach khach hang dien may khu vuc HCM.exe (PID: 2720)
  • SUSPICIOUS

    • Executed via COM

      • explorer.exe (PID: 4008)
    • Creates files in the program directory

      • Danh sach khach hang dien may khu vuc HCM.exe (PID: 2720)
    • Reads Environment values

      • Danh sach khach hang dien may khu vuc HCM.exe (PID: 2720)
    • Starts Microsoft Office Application

      • explorer.exe (PID: 4008)
    • Executable content was dropped or overwritten

      • Danh sach khach hang dien may khu vuc HCM.exe (PID: 2720)
  • INFO

    • Manual execution by user

      • Danh sach khach hang dien may khu vuc HCM.exe (PID: 2720)
    • Reads Microsoft Office registry keys

      • WINWORD.EXE (PID: 2584)
    • Creates files in the user directory

      • WINWORD.EXE (PID: 2584)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
43
Monitored processes
6
Malicious processes
0
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe no specs danh sach khach hang dien may khu vuc hcm.exe explorer.exe no specs explorer.exe no specs winword.exe no specs searchprotocolhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2584"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\Desktop\Danh sach khach hang dien may khu vuc HCM\Danh sach khach hang dien may khu vuc HCM.docx"C:\Program Files\Microsoft Office\Office14\WINWORD.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Word
Exit code:
0
Version:
14.0.6024.1000
Modules
Images
c:\program files\microsoft office\office14\winword.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
2720"C:\Users\admin\Desktop\Danh sach khach hang dien may khu vuc HCM\Danh sach khach hang dien may khu vuc HCM.exe" C:\Users\admin\Desktop\Danh sach khach hang dien may khu vuc HCM\Danh sach khach hang dien may khu vuc HCM.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Office Word
Exit code:
0
Version:
12.0.4518.1014
Modules
Images
c:\users\admin\desktop\danh sach khach hang dien may khu vuc hcm\danh sach khach hang dien may khu vuc hcm.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
c:\windows\system32\msvcrt.dll
c:\users\admin\desktop\danh sach khach hang dien may khu vuc hcm\wwlib.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2740"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Danh sach khach hang dien may khu vuc HCM.rar"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
3092"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe6_ Global\UsGthrCtrlFltPipeMssGthrPipe6 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3780explorer.exe "Danh sach khach hang dien may khu vuc HCM.docx"C:\Windows\explorer.exeDanh sach khach hang dien may khu vuc HCM.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
4008C:\Windows\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -EmbeddingC:\Windows\explorer.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\systemroot\system32\ntdll.dll
c:\windows\explorer.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
2 694
Read events
1 627
Write events
929
Delete events
138

Modification events

(PID) Process:(2740) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2740) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2740) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2740) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Danh sach khach hang dien may khu vuc HCM.rar
(PID) Process:(2740) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2740) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2740) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2740) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2720) Danh sach khach hang dien may khu vuc HCM.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Notepad\dienmay\43322037578455514834
Operation:writeName:CleanDisk
Value:
C:\Users\admin\Desktop\Danh sach khach hang dien may khu vuc HCM\Danh sach khach hang dien may khu vuc HCM.exe|C:\Users\admin\Desktop\Danh sach khach hang dien may khu vuc HCM\wwlib.dll|
(PID) Process:(4008) explorer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.docx\OpenWithProgids
Operation:writeName:Word.Document.12
Value:
Executable files
2
Suspicious files
1
Text files
4
Unknown types
4

Dropped files

PID
Process
Filename
Type
2740WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2740.41492\Danh sach khach hang dien may khu vuc HCM\Danh sach khach hang dien may khu vuc HCM.exe
MD5:
SHA256:
2740WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2740.41492\Danh sach khach hang dien may khu vuc HCM\wwlib.dll
MD5:
SHA256:
2584WINWORD.EXEC:\Users\admin\AppData\Local\Temp\CVR96C6.tmp.cvr
MD5:
SHA256:
2584WINWORD.EXEC:\Users\admin\Desktop\Danh sach khach hang dien may khu vuc HCM\~$nh sach khach hang dien may khu vuc HCM.docxpgc
MD5:
SHA256:
2584WINWORD.EXEC:\Users\admin\AppData\Roaming\Microsoft\Templates\~$Normal.dotmpgc
MD5:
SHA256:
2584WINWORD.EXEC:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\Danh sach khach hang dien may khu vuc HCM.docx.LNKlnk
MD5:
SHA256:
2720Danh sach khach hang dien may khu vuc HCM.exeC:\ProgramData\Notepad\config\dienmay\43322037578455514834\wwlib.dllexecutable
MD5:
SHA256:
2720Danh sach khach hang dien may khu vuc HCM.exeC:\Users\admin\Desktop\Danh sach khach hang dien may khu vuc HCM\Danh sach khach hang dien may khu vuc HCM.docxdocument
MD5:
SHA256:
2584WINWORD.EXEC:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\index.dattext
MD5:
SHA256:
2720Danh sach khach hang dien may khu vuc HCM.exeC:\ProgramData\Notepad\config\dienmay\43322037578455514834\DropboxUpdates.exeexecutable
MD5:CEAA5817A65E914AA178B28F12359A46
SHA256:6C959CFB001FBB900958441DFD8B262FB33E052342948BAB338775D3E83EF7F7
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
1
DNS requests
2
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2720
Danh sach khach hang dien may khu vuc HCM.exe
185.161.210.189:443
node.podzone.org
Serverius Holding B.V.
NL
unknown

DNS requests

Domain
IP
Reputation
node.podzone.org
  • 185.161.210.189
unknown

Threats

No threats detected
No debug info