analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

2.zip

Full analysis: https://app.any.run/tasks/d6f798bf-12e4-4320-b6a6-1302af94a978
Verdict: Malicious activity
Analysis date: May 20, 2019, 13:14:02
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

DFDC4DB6FBDFD854FE2B4CF25F5EB3E8

SHA1:

092300E64693BE11421595A8BAC4CA5120B8F7A5

SHA256:

7D5B4AAEEBD78B5ABC9FE5E73F8719DEEE73F24071EDEE397BD512669013C805

SSDEEP:

49152:ipQeenJFF9CNTQ7nMZwwS3fQoq0AOVylsNK5YHFVs:lhnJzMTQqwwEfQoq0yzYc

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 2920)
      • PSN Software By Daniel VIP.exe (PID: 3252)
      • explorer.exe (PID: 2044)
      • PSN Software By Daniel VIP.exe (PID: 3940)
    • Application was dropped or rewritten from another process

      • PSN Software By Daniel VIP.exe (PID: 3252)
      • PSN Software By Daniel VIP.exe (PID: 3940)
    • Changes settings of System certificates

      • PSN Software By Daniel VIP.exe (PID: 3940)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • PSN Software By Daniel VIP.exe (PID: 3252)
    • Creates files in the user directory

      • explorer.exe (PID: 2044)
    • Reads Environment values

      • PSN Software By Daniel VIP.exe (PID: 3940)
    • Adds / modifies Windows certificates

      • PSN Software By Daniel VIP.exe (PID: 3940)
    • Reads Internet Cache Settings

      • explorer.exe (PID: 2044)
  • INFO

    • Manual execution by user

      • PSN Software By Daniel VIP.exe (PID: 3252)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: AgileDotNet.VMRuntime.dll
ZipUncompressedSize: 161280
ZipCompressedSize: 31402
ZipCRC: 0x015edf16
ZipModifyDate: 2019:03:13 12:53:25
ZipCompression: Deflated
ZipBitFlag: -
ZipRequiredVersion: 20
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
42
Monitored processes
6
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start drop and start winrar.exe no specs searchprotocolhost.exe no specs psn software by daniel vip.exe explorer.exe no specs notepad.exe no specs psn software by daniel vip.exe

Process information

PID
CMD
Path
Indicators
Parent process
2716"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\2.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
2920"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe5_ Global\UsGthrCtrlFltPipeMssGthrPipe5 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
3252"C:\Users\admin\Desktop\PSN Software By Daniel VIP.exe" C:\Users\admin\Desktop\PSN Software By Daniel VIP.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
PSN Software
Exit code:
4294967295
Version:
7.0.0.0
2044C:\Windows\Explorer.EXEC:\Windows\explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
3572"C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\ERROR.txtC:\Windows\system32\NOTEPAD.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
3940"C:\Users\admin\Desktop\PSN Software By Daniel VIP.exe" C:\Users\admin\Desktop\PSN Software By Daniel VIP.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
PSN Software
Exit code:
4294967295
Version:
7.0.0.0
Total events
3 225
Read events
3 135
Write events
0
Delete events
0

Modification events

No data
Executable files
6
Suspicious files
0
Text files
2
Unknown types
4

Dropped files

PID
Process
Filename
Type
2716WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2716.6844\AgileDotNet.VMRuntime.dll
MD5:
SHA256:
2716WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2716.6844\Newtonsoft.Json.dll
MD5:
SHA256:
2716WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2716.6844\PSN Software By Daniel VIP.exe
MD5:
SHA256:
2716WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2716.6844\ReVMRuntime.dll
MD5:
SHA256:
2716WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2716.6844\xNet.dll
MD5:
SHA256:
3252PSN Software By Daniel VIP.exeC:\Users\admin\Desktop\ERROR.txttext
MD5:3E01A9CA062E8C7807522BFB2F1BEE1D
SHA256:25BA4FD4887F439BEF1796CA3DD9BD47D17718B0E0A8C38F2A58DEF211B98BEB
2044explorer.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\1b4dd67f29cb1962.automaticDestinations-msautomaticdestinations-ms
MD5:C90961D5F4E01A5AAE2AE8F3B693E0B5
SHA256:864C098C421DF9C218795ED4FFE3B3B555650B4FA0B3C0E5E2DFCFD784B442AF
2044explorer.exeC:\Users\admin\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012019052020190521\index.datdat
MD5:E12CDF7785EE4A32857B1E0100050811
SHA256:CCF7F90BBE89FD030E00A7D072C3DE0D95B40A98EE6CC599C89F0244C3C13D13
2044explorer.exeC:\Users\admin\Desktop\AgileDotNet.VMRuntime.dllexecutable
MD5:11D0C20EBE0410F44841AFAC8EB0DE15
SHA256:E1310FE3CE461D52BB5D5CC753532888CBE171F081D2E90CE476C30559FF890B
2044explorer.exeC:\Users\admin\Desktop\PSN Software By Daniel VIP.exeexecutable
MD5:0A87DF5CED3CA23F19F00A425EF91A55
SHA256:4C939570FDD770694CAFFB1B382B42C1308BD64C776E74A6696EDA253ECAE9ED
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
5
DNS requests
4
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3940
PSN Software By Daniel VIP.exe
GET
212.8.246.138:80
http://vm512363.had.su/2.txt
NL
suspicious
3940
PSN Software By Daniel VIP.exe
GET
301
172.217.18.110:80
http://google.com/
US
html
219 b
whitelisted
3940
PSN Software By Daniel VIP.exe
GET
302
216.58.207.68:80
http://www.google.com/
US
html
231 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3940
PSN Software By Daniel VIP.exe
172.217.18.110:80
Google Inc.
US
whitelisted
3940
PSN Software By Daniel VIP.exe
212.8.246.138:80
vm512363.had.su
ITL Company
NL
suspicious
3940
PSN Software By Daniel VIP.exe
216.58.207.68:80
www.google.com
Google Inc.
US
whitelisted
3252
PSN Software By Daniel VIP.exe
172.217.18.110:80
Google Inc.
US
whitelisted
3940
PSN Software By Daniel VIP.exe
216.58.207.68:443
www.google.com
Google Inc.
US
whitelisted

DNS requests

Domain
IP
Reputation
dns.msftncsi.com
  • 131.107.255.255
shared
www.google.com
  • 216.58.207.68
whitelisted
vm512363.had.su
  • 212.8.246.138
suspicious

Threats

PID
Process
Class
Message
Potentially Bad Traffic
ET DNS Query for .su TLD (Soviet Union) Often Malware Related
3940
PSN Software By Daniel VIP.exe
Potentially Bad Traffic
ET POLICY HTTP Request to .su TLD (Soviet Union) Often Malware Related
No debug info