| File name: | Universal.zip |
| Full analysis: | https://app.any.run/tasks/08a4c01e-ca79-425d-802a-c7bd01dcf0eb |
| Verdict: | Malicious activity |
| Threats: | MetaStealer is an info-stealing malware primarily targeting sensitive data like login credentials, payment details, and browser history. It typically infects systems via phishing emails or malicious downloads and can exfiltrate data to a command and control (C2) server. MetaStealer is known for its stealthy techniques, including evasion and persistence mechanisms, which make it difficult to detect. This malware has been actively used in various cyberattacks, particularly for financial theft and credential harvesting from individuals and organizations. |
| Analysis date: | December 24, 2023, 10:43:38 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | 32D319D9677635F995F4E009DB2E85A1 |
| SHA1: | 4770AF11A733C00EE8C1E7613F64690361F7D9AF |
| SHA256: | 7CE94C2008D904E10DDECB401307F4CB5182B5989D594E416C9891B817C3D356 |
| SSDEEP: | 49152:U9yC2Jml/0DrutWzteuw/t2OoSf1tKqcBBA3XeewDTeRhw9Q/QD8pYBZ7E:Usml/Aach7ZONOxBBA3XaX90QD0GZ7E |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | 0x0009 |
| ZipCompression: | Unknown (99) |
| ZipModifyDate: | 2023:07:17 00:00:54 |
| ZipCRC: | 0xfd8a91ae |
| ZipCompressedSize: | 324146 |
| ZipUncompressedSize: | 981592 |
| ZipFileName: | Universal.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 116 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Universal.zip" | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 1112 | "C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe" | C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Universal.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft .NET Assembly Registration Utility Exit code: 0 Version: 4.8.3761.0 built by: NET48REL1 Modules
MetaStealer(PID) Process(1112) RegAsm.exe C2 (1)138.201.198.8:40128 Botnetcrypto_s Options ErrorMessage Keys XorUnsatiate | |||||||||||||||
| 1628 | "C:\Windows\explorer.exe" | C:\Windows\explorer.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1840 | "C:\Users\admin\Desktop\Universal.exe" | C:\Users\admin\Desktop\Universal.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 3221225477 Modules
| |||||||||||||||
| 1844 | "C:\Users\admin\Desktop\Universal.exe" | C:\Users\admin\Desktop\Universal.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 3221225477 Modules
| |||||||||||||||
| 2060 | "C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\Desktop\AMD_OpenCL_ICD64.dll | C:\Windows\System32\rundll32.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2328 | "C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe" | C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Universal.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft .NET Assembly Registration Utility Exit code: 0 Version: 4.8.3761.0 built by: NET48REL1 Modules
MetaStealer(PID) Process(2328) RegAsm.exe C2 (1)138.201.198.8:40128 Botnetcrypto_s Options ErrorMessage Keys XorUnsatiate | |||||||||||||||
| 2544 | "C:\Users\admin\Desktop\Universal.exe" | C:\Users\admin\Desktop\Universal.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 3221225477 Modules
| |||||||||||||||
| 2780 | "C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\Desktop\AMD_OpenCL_ICD64.dll | C:\Windows\System32\rundll32.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2796 | "C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe" | C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Universal.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft .NET Assembly Registration Utility Exit code: 0 Version: 4.8.3761.0 built by: NET48REL1 Modules
MetaStealer(PID) Process(2796) RegAsm.exe C2 (1)138.201.198.8:40128 Botnetcrypto_s Options ErrorMessage Keys XorUnsatiate | |||||||||||||||
| (PID) Process: | (116) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (116) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (116) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (116) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (116) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
| (PID) Process: | (116) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (116) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (116) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (116) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (116) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin |
| Operation: | write | Name: | Placement |
Value: 2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 116 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb116.13060\Base\LauncherRemediation.008.etl | binary | |
MD5:8BCF7932F4B8D690F65722616AC05DF0 | SHA256:21D3D33548610CC38B91BC3BD4A290C8C7B7438C29B2D40012E7A133D43CBD0B | |||
| 116 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb116.13060\Base\LauncherRemediation.001.etl | binary | |
MD5:5820DCA6B366128CC26955E2DB6A8865 | SHA256:402B88A7856A00ED173E496294CF98AC576F132E40E799BEA4AC0E33B3C84119 | |||
| 116 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb116.13060\Base\LauncherRemediation.004.etl | binary | |
MD5:99E8A4BE1D2460866F5996240CFE8CF7 | SHA256:758C1AD9371ACEFF742D87BCAB491C0D26A63E7C965CD9FA1DAC719140188988 | |||
| 116 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb116.13060\Base\LauncherRemediation.003.etl | binary | |
MD5:A63F9B672CB5E3B753D880253724932B | SHA256:B444E807D51F270B920EA5B3A2241ED47748C4F0317E333F608B2299EDE0478F | |||
| 116 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb116.13060\Base\LauncherRemediation.002.etl | binary | |
MD5:2FAD184377AE44FBAAF7A3F2620EF876 | SHA256:5370A440AAD74307186CFF8C7E3C983B944969509EEABA574D366FFE3CCCF5E7 | |||
| 116 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb116.13060\Base\LauncherRemediation.005.etl | binary | |
MD5:0FA16EF023F31C9015764076041E2194 | SHA256:47761BEE2A236678B57F197B0D333257419FFC31FA82F8B43669B065FD19DB70 | |||
| 116 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb116.13060\Base\LauncherRemediation.006.etl | binary | |
MD5:C67C36E3869C1CF4F19FE6107B1408C7 | SHA256:F55E93A235402833CEDDE122F4E924A354F6AE2A3C79D31CCC78D1DBF20AC3AE | |||
| 116 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb116.13060\Base\LauncherRemediation.010.etl | binary | |
MD5:DB615C2C416AF23D5311ABEF0CB7C0E4 | SHA256:DB5522116998F8856A65E4B175F1FD8DD18CA52264300860657EAB12EA2997CD | |||
| 116 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb116.13060\Base\LauncherRemediation.007.etl | binary | |
MD5:3B23FC85E728278F0B988ABA70DA6FD6 | SHA256:897DF8705B9EDD425CDC94B33E6FF2C411113CC5A8448154E235F717F149C9C9 | |||
| 116 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb116.13060\Base\LauncherRemediation.012.etl | binary | |
MD5:A83388B9A288450CD1D29B40439AD9C7 | SHA256:A1F3FE748517CF21774EE9D8686EDA16F36E2A0E0F9D4369F20A4E0B29547733 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1112 | RegAsm.exe | 138.201.198.8:40128 | — | Hetzner Online GmbH | DE | malicious |
2328 | RegAsm.exe | 138.201.198.8:40128 | — | Hetzner Online GmbH | DE | malicious |
2860 | RegAsm.exe | 138.201.198.8:40128 | — | Hetzner Online GmbH | DE | malicious |
2360 | WerFault.exe | 104.208.16.93:443 | watson.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
2796 | RegAsm.exe | 138.201.198.8:40128 | — | Hetzner Online GmbH | DE | malicious |
3152 | RegAsm.exe | 138.201.198.8:40128 | — | Hetzner Online GmbH | DE | malicious |
Domain | IP | Reputation |
|---|---|---|
dns.msftncsi.com |
| shared |
watson.microsoft.com |
| whitelisted |