download:

pdfas132.zip

Full analysis: https://app.any.run/tasks/22485a2e-60e3-4166-90b6-a7dda9ea219f
Verdict: Malicious activity
Analysis date: June 08, 2018, 04:04:48
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

F880DBB85C129F387CEB2AB1350ABB1F

SHA1:

BE7963EAB45086716A77A93964FD508EC6C716C7

SHA256:

7EE9F0DCD6A320CF5F15718035321AD8E23F4D7E8FD0215ADD560A18D208F5E2

SSDEEP:

24576:FmQ9sZtuWsFFBMjxpeau59ruOc2Q4itXMatKWZICG4nEYFzRreBzLZng9e6S:uGfMyau58rzk0ICG4rZhazLFgUT

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • pdf_as.exe (PID: 3340)
      • Office2Pdf.exe (PID: 572)
      • pdf_as.exe (PID: 2980)
  • SUSPICIOUS

    • Executes scripts

      • Office2Pdf.exe (PID: 572)
    • Executable content was dropped or overwritten

      • 7zFM.exe (PID: 3232)
  • INFO

    • Reads settings of System Certificates

      • pdf_as.exe (PID: 2980)
      • pdf_as.exe (PID: 3340)
    • Reads Microsoft Office registry keys

      • EXCEL.EXE (PID: 2900)
      • EXCEL.EXE (PID: 4012)
      • EXCEL.EXE (PID: 2912)
      • EXCEL.EXE (PID: 504)
    • Dropped object may contain URL's

      • 7zFM.exe (PID: 3232)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2016:03:17 16:53:10
ZipCRC: 0x245130c6
ZipCompressedSize: 1402277
ZipUncompressedSize: 4055040
ZipFileName: itextsharp.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
42
Monitored processes
11
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start drop and start drop and start start 7zfm.exe pdf_as.exe no specs excel.exe no specs excel.exe no specs taskmgr.exe no specs office2pdf.exe no specs wscript.exe no specs pdf_as.exe no specs excel.exe no specs excel.exe no specs notepad.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
504"C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /automation -EmbeddingC:\Program Files\Microsoft Office\Office14\EXCEL.EXEsvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Excel
Exit code:
0
Version:
14.0.6024.1000
Modules
Images
c:\program files\microsoft office\office14\excel.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
572"C:\Users\admin\AppData\Local\Temp\7zO0AC11E06\Office2Pdf.exe" C:\Users\admin\AppData\Local\Temp\7zO0AC11E06\Office2Pdf.exe7zFM.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\7zo0ac11e06\office2pdf.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imm32.dll
2216"C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\AppData\Local\Temp\7zO0ACD2D27\readme.txtC:\Windows\system32\NOTEPAD.EXE7zFM.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2900"C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /automation -EmbeddingC:\Program Files\Microsoft Office\Office14\EXCEL.EXEsvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Excel
Exit code:
0
Version:
14.0.6024.1000
Modules
Images
c:\program files\microsoft office\office14\excel.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2912"C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /automation -EmbeddingC:\Program Files\Microsoft Office\Office14\EXCEL.EXEsvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Excel
Exit code:
0
Version:
14.0.6024.1000
Modules
Images
c:\program files\microsoft office\office14\excel.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2980"C:\Users\admin\AppData\Local\Temp\7zO0AC5CFE6\pdf_as.exe" C:\Users\admin\AppData\Local\Temp\7zO0AC5CFE6\pdf_as.exe7zFM.exe
User:
admin
Integrity Level:
MEDIUM
Description:
pdf_as
Exit code:
0
Version:
1.3.2.36203
Modules
Images
c:\users\admin\appdata\local\temp\7zo0ac5cfe6\pdf_as.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3232"C:\Program Files\7-Zip\7zFM.exe" "C:\Users\admin\AppData\Local\Temp\pdfas132.zip"C:\Program Files\7-Zip\7zFM.exe
explorer.exe
User:
admin
Company:
Igor Pavlov
Integrity Level:
MEDIUM
Description:
7-Zip File Manager
Exit code:
0
Version:
16.04
Modules
Images
c:\program files\7-zip\7zfm.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3308wscript.exe "C:\Users\admin\AppData\Local\Temp\SFC3CBF.tmp.vbs"C:\Windows\system32\wscript.exeOffice2Pdf.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Windows Based Script Host
Exit code:
0
Version:
5.8.7600.16385
Modules
Images
c:\windows\system32\wscript.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3340"C:\Users\admin\AppData\Local\Temp\7zO0AC72B64\pdf_as.exe" C:\Users\admin\AppData\Local\Temp\7zO0AC72B64\pdf_as.exe7zFM.exe
User:
admin
Integrity Level:
MEDIUM
Description:
pdf_as
Exit code:
0
Version:
1.3.2.36203
Modules
Images
c:\users\admin\appdata\local\temp\7zo0ac72b64\pdf_as.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3776"C:\Windows\system32\taskmgr.exe" /4C:\Windows\system32\taskmgr.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Task Manager
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskmgr.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
1 164
Read events
1 085
Write events
66
Delete events
13

Modification events

(PID) Process:(3232) 7zFM.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(3232) 7zFM.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(3340) pdf_as.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\93\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(504) EXCEL.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
Operation:writeName:)>9
Value:
293E3900F8010000010000000000000000000000
(PID) Process:(504) EXCEL.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1033
Value:
Off
(PID) Process:(504) EXCEL.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1033
Value:
On
(PID) Process:(504) EXCEL.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel
Operation:writeName:MTTT
Value:
F80100006CD04DFADDFED30100000000
(PID) Process:(504) EXCEL.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
Operation:delete valueName:)>9
Value:
293E3900F8010000010000000000000000000000
(PID) Process:(504) EXCEL.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems
Operation:delete keyName:
Value:
(PID) Process:(504) EXCEL.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency
Operation:delete keyName:
Value:
Executable files
3
Suspicious files
0
Text files
9
Unknown types
0

Dropped files

PID
Process
Filename
Type
504EXCEL.EXEC:\Users\admin\AppData\Local\Temp\CVR5EA9.tmp.cvr
MD5:
SHA256:
2912EXCEL.EXEC:\Users\admin\AppData\Local\Temp\CVR637B.tmp.cvr
MD5:
SHA256:
2900EXCEL.EXEC:\Users\admin\AppData\Local\Temp\CVRDEFB.tmp.cvr
MD5:
SHA256:
4012EXCEL.EXEC:\Users\admin\AppData\Local\Temp\CVRE052.tmp.cvr
MD5:
SHA256:
32327zFM.exeC:\Users\admin\AppData\Local\Temp\7zO0AC72B64\pdf_as.exeexecutable
MD5:
SHA256:
3340pdf_as.exeC:\Users\admin\AppData\Local\Temp\7zO0AC72B64\pdf_as.initext
MD5:
SHA256:
32327zFM.exeC:\Users\admin\AppData\Local\Temp\7zO0AC11E06\Office2Pdf.exeexecutable
MD5:
SHA256:
572Office2Pdf.exeC:\Users\admin\AppData\Local\Temp\SFC3CBF.tmptext
MD5:
SHA256:
32327zFM.exeC:\Users\admin\AppData\Local\Temp\7zO0AC5CFE6\pdf_as.exeexecutable
MD5:
SHA256:
572Office2Pdf.exeC:\Users\admin\AppData\Local\Temp\SFC3CBF.tmp.vbstext
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info