| File name: | f2aa78d80a8ce3124036c8ab8614ff99-sample.zip |
| Full analysis: | https://app.any.run/tasks/d7a8b6e2-5b8c-4016-ba9a-c06357b57a14 |
| Verdict: | Malicious activity |
| Analysis date: | July 29, 2021, 13:51:18 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | 4756D00CAF4F6533815AF5A16FB3B00D |
| SHA1: | 0AB197A00E9828D41001FBF72E297CFCAB0CA02F |
| SHA256: | 7B7BDD2C0D6B7C517924FC8298E063EA873DECF3239AB75FD69658343794060D |
| SSDEEP: | 196608:Vqg1YYGqvWMwH81cvGfVY2Kwg+stzHrB3PLA2O8/nTFGJeOYyzsZK+FLxMHOgwYA:Tmo+MwH8CoYkgtt7lc2Ocn5GJezyAK+n |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipFileName: | FileZilla_3.55.0_win64_sponsored-setup.exe |
|---|---|
| ZipUncompressedSize: | 11419136 |
| ZipCompressedSize: | 11391556 |
| ZipCRC: | 0x91acee94 |
| ZipModifyDate: | 2021:07:29 13:50:18 |
| ZipCompression: | Deflated |
| ZipBitFlag: | 0x0009 |
| ZipRequiredVersion: | 20 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1348 | "C:\Program Files\FileZilla FTP Client\uninstall.exe" /frominstall /keepstartmenudir _?=C:\Program Files\FileZilla FTP Client | C:\Program Files\FileZilla FTP Client\uninstall.exe | FileZilla_3.55.0_win64_sponsored-setup.exe | ||||||||||||
User: admin Company: Tim Kosse Integrity Level: HIGH Description: FileZilla FTP Client Exit code: 0 Version: 3.51.0 Modules
| |||||||||||||||
| 2492 | "C:\Users\admin\Desktop\FileZilla_3.55.0_win64_sponsored-setup.exe" /UAC:4017E /NCRC | C:\Users\admin\Desktop\FileZilla_3.55.0_win64_sponsored-setup.exe | FileZilla_3.55.0_win64_sponsored-setup.exe | ||||||||||||
User: admin Company: Tim Kosse Integrity Level: HIGH Description: FileZilla FTP Client Exit code: 0 Version: 3.55.0 Modules
| |||||||||||||||
| 2740 | "C:\Users\admin\Desktop\FileZilla_3.55.0_win64_sponsored-setup.exe" | C:\Users\admin\Desktop\FileZilla_3.55.0_win64_sponsored-setup.exe | Explorer.EXE | ||||||||||||
User: admin Company: Tim Kosse Integrity Level: MEDIUM Description: FileZilla FTP Client Exit code: 0 Version: 3.55.0 Modules
| |||||||||||||||
| 3908 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\f2aa78d80a8ce3124036c8ab8614ff99-sample.zip" | C:\Program Files\WinRAR\WinRAR.exe | Explorer.EXE | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| (PID) Process: | (3908) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3908) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3908) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3908) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (3908) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\f2aa78d80a8ce3124036c8ab8614ff99-sample.zip | |||
| (PID) Process: | (3908) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3908) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3908) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3908) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (3908) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface |
| Operation: | write | Name: | ShowPassword |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3908 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb3908.36435\FileZilla_3.55.0_win64_sponsored-setup.exe | executable | |
MD5:— | SHA256:— | |||
| 2740 | FileZilla_3.55.0_win64_sponsored-setup.exe | C:\Users\admin\AppData\Local\Temp\nso2282.tmp\UAC.dll | executable | |
MD5:ADB29E6B186DAA765DC750128649B63D | SHA256:2F7F8FC05DC4FD0D5CDA501B47E4433357E887BBFED7292C028D99C73B52DC08 | |||
| 2492 | FileZilla_3.55.0_win64_sponsored-setup.exe | C:\Program Files\FileZilla FTP Client\filezilla.exe | executable | |
MD5:— | SHA256:— | |||
| 2492 | FileZilla_3.55.0_win64_sponsored-setup.exe | C:\Program Files\FileZilla FTP Client\fzsftp.exe | executable | |
MD5:— | SHA256:— | |||
| 2492 | FileZilla_3.55.0_win64_sponsored-setup.exe | C:\Program Files\FileZilla FTP Client\fzstorj.exe | executable | |
MD5:— | SHA256:— | |||
| 1348 | uninstall.exe | C:\Users\admin\AppData\Local\Temp\nsn5EEF.tmp\UserInfo.dll | executable | |
MD5:9EB662F3B5FBDA28BFFE020E0AB40519 | SHA256:9AA388C7DE8E96885ADCB4325AF871B470AC50EDB60D4B0D876AD43F5332FFD1 | |||
| 1348 | uninstall.exe | C:\Users\admin\AppData\Local\Temp\nsx5EDE.tmp | binary | |
MD5:6BC4A8D48B7247DDB3A81FB363E967B8 | SHA256:6D601EBBFA6448DB2020162BFD871D78691EB87F5FA671207A41B954068DA2D9 | |||
| 1348 | uninstall.exe | C:\Users\admin\AppData\Local\Temp\nsn5EEF.tmp\System.dll | executable | |
MD5:0D7AD4F45DC6F5AA87F606D0331C6901 | SHA256:3EB38AE99653A7DBC724132EE240F6E5C4AF4BFE7C01D31D23FAF373F9F2EACA | |||
| 2492 | FileZilla_3.55.0_win64_sponsored-setup.exe | C:\Program Files\FileZilla FTP Client\GPL.html | html | |
MD5:11E176C5E0120EE94E365F999084BCE8 | SHA256:F7E89C1EDBBEF8BC837B47C48113A2416F1AF0CFC2B2218DA39085465EA1045C | |||
| 2740 | FileZilla_3.55.0_win64_sponsored-setup.exe | C:\Users\admin\AppData\Local\Temp\nso2282.tmp\System.dll | executable | |
MD5:0D7AD4F45DC6F5AA87F606D0331C6901 | SHA256:3EB38AE99653A7DBC724132EE240F6E5C4AF4BFE7C01D31D23FAF373F9F2EACA | |||