File name: | Request for Quotation (RFQ#196).zip |
Full analysis: | https://app.any.run/tasks/090699dd-828d-4af6-9890-79a973919cd1 |
Verdict: | Malicious activity |
Threats: | WannaCry is a famous Ransomware that utilizes the EternalBlue exploit. This malware is known for infecting at least 200,000 computers worldwide and it continues to be an active and dangerous threat. |
Analysis date: | December 06, 2022, 02:34:17 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Tags: | |
Indicators: | |
MIME: | application/zip |
File info: | Zip archive data, at least v2.0 to extract |
MD5: | D69DC6569B385C0467185D002E252D89 |
SHA1: | 25938A66CCE0078C76A15F351CBD19C8FCC2B081 |
SHA256: | 80239619C4CA44380C6269873A5B6B695585CCFCF278E0F2C72698658A3A6FD8 |
SSDEEP: | 49152:pZL1zufKjTpcSPBeJJTXAlSr1/2ueI1HEafmKIDBsuN3FcTuYx/uEjF5RX:/RzvjTCVAlet2XmHxfmKIPNYx/RX |
.zip | | | ZIP compressed archive (100) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
2436 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Request for Quotation (RFQ#196).zip" | C:\Program Files\WinRAR\WinRAR.exe | — | Explorer.EXE | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Version: 5.91.0 Modules
| |||||||||||||||
3624 | "C:\Users\admin\AppData\Local\Temp\Rar$EXb2436.7157\Proforma Invoice and Bank swift-REG.PI-0086547654.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXb2436.7157\Proforma Invoice and Bank swift-REG.PI-0086547654.exe | WinRAR.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: DiskPart Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
3756 | attrib +h . | C:\Windows\system32\attrib.exe | — | Proforma Invoice and Bank swift-REG.PI-0086547654.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Attribute Utility Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
3772 | icacls . /grant Everyone:F /T /C /Q | C:\Windows\system32\icacls.exe | — | Proforma Invoice and Bank swift-REG.PI-0086547654.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
1412 | taskdl.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb2436.7157\taskdl.exe | — | Proforma Invoice and Bank swift-REG.PI-0086547654.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: SQL Client Configuration Utility EXE Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
2500 | C:\Windows\system32\cmd.exe /c 19951670294099.bat | C:\Windows\system32\cmd.exe | — | Proforma Invoice and Bank swift-REG.PI-0086547654.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 1 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
2576 | cscript.exe //nologo m.vbs | C:\Windows\system32\cscript.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft ® Console Based Script Host Exit code: 0 Version: 5.8.7600.16385 Modules
| |||||||||||||||
3532 | taskdl.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb2436.7157\taskdl.exe | — | Proforma Invoice and Bank swift-REG.PI-0086547654.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: SQL Client Configuration Utility EXE Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
3252 | "C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\Desktop\naturaltheir.rtf.WNCRY | C:\Windows\system32\rundll32.exe | — | Explorer.EXE | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
4004 | @[email protected] co | C:\Users\admin\AppData\Local\Temp\Rar$EXb2436.7157\@[email protected].exe | Proforma Invoice and Bank swift-REG.PI-0086547654.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Load PerfMon Counters Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
|
(PID) Process: | (2436) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtBMP |
Value: | |||
(PID) Process: | (2436) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtIcon |
Value: | |||
(PID) Process: | (2436) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\16D\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (2436) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
(PID) Process: | (2436) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
(PID) Process: | (2436) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Request for Quotation (RFQ#196).zip | |||
(PID) Process: | (2436) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | name |
Value: 120 | |||
(PID) Process: | (2436) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | size |
Value: 80 | |||
(PID) Process: | (2436) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | type |
Value: 120 | |||
(PID) Process: | (2436) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | mtime |
Value: 100 |
PID | Process | Filename | Type | |
---|---|---|---|---|
3624 | Proforma Invoice and Bank swift-REG.PI-0086547654.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb2436.7157\msg\m_french.wnry | text | |
MD5:4E57113A6BF6B88FDD32782A4A381274 | SHA256:9BD38110E6523547AED50617DDC77D0920D408FAEED2B7A21AB163FDA22177BC | |||
2436 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Request for Quotation (RFQ#196)\Proforma Invoice and Bank swift-REG.PI-0086547654.exe | executable | |
MD5:84C82835A5D21BBCF75A61706D8AB549 | SHA256:ED01EBFBC9EB5BBEA545AF4D01BF5F1071661840480439C6E5BABE8E080E41AA | |||
2436 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb2436.7157\Proforma Invoice and Bank swift-REG.PI-0086547654.exe | executable | |
MD5:84C82835A5D21BBCF75A61706D8AB549 | SHA256:ED01EBFBC9EB5BBEA545AF4D01BF5F1071661840480439C6E5BABE8E080E41AA | |||
3624 | Proforma Invoice and Bank swift-REG.PI-0086547654.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb2436.7157\msg\m_japanese.wnry | text | |
MD5:B77E1221F7ECD0B5D696CB66CDA1609E | SHA256:7E491E7B48D6E34F916624C1CDA9F024E86FCBEC56ACDA35E27FA99D530D017E | |||
3624 | Proforma Invoice and Bank swift-REG.PI-0086547654.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb2436.7157\msg\m_chinese (traditional).wnry | text | |
MD5:2EFC3690D67CD073A9406A25005F7CEA | SHA256:5C7F6AD1EC4BC2C8E2C9C126633215DABA7DE731AC8B12BE10CA157417C97F3A | |||
3624 | Proforma Invoice and Bank swift-REG.PI-0086547654.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb2436.7157\msg\m_czech.wnry | text | |
MD5:537EFEECDFA94CC421E58FD82A58BA9E | SHA256:5AFA4753AFA048C6D6C39327CE674F27F5F6E5D3F2A060B7A8AED61725481150 | |||
3624 | Proforma Invoice and Bank swift-REG.PI-0086547654.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb2436.7157\msg\m_german.wnry | text | |
MD5:3D59BBB5553FE03A89F817819540F469 | SHA256:2ADC900FAFA9938D85CE53CB793271F37AF40CF499BCC454F44975DB533F0B61 | |||
3624 | Proforma Invoice and Bank swift-REG.PI-0086547654.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb2436.7157\msg\m_chinese (simplified).wnry | text | |
MD5:0252D45CA21C8E43C9742285C48E91AD | SHA256:845D0E178AEEBD6C7E2A2E9697B2BF6CF02028C50C288B3BA88FE2918EA2834A | |||
3624 | Proforma Invoice and Bank swift-REG.PI-0086547654.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb2436.7157\msg\m_finnish.wnry | text | |
MD5:35C2F97EEA8819B1CAEBD23FEE732D8F | SHA256:1ADFEE058B98206CB4FBE1A46D3ED62A11E1DEE2C7FF521C1EEF7C706E6A700E | |||
3624 | Proforma Invoice and Bank swift-REG.PI-0086547654.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb2436.7157\msg\m_croatian.wnry | text | |
MD5:17194003FA70CE477326CE2F6DEEB270 | SHA256:3F33734B2D34CCE83936CE99C3494CD845F1D2C02D7F6DA31D42DFC1CA15A171 |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
3144 | taskhsvc.exe | 199.254.238.52:443 | — | RISEUP | US | malicious |
3144 | taskhsvc.exe | 144.76.26.175:9011 | — | Hetzner Online GmbH | DE | unknown |