File name: | Request for Quotation (RFQ#196).zip |
Full analysis: | https://app.any.run/tasks/92e84910-a14b-45ad-9438-c6eb1b9912a7 |
Verdict: | Malicious activity |
Analysis date: | December 05, 2022, 18:01:18 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/zip |
File info: | Zip archive data, at least v2.0 to extract |
MD5: | D69DC6569B385C0467185D002E252D89 |
SHA1: | 25938A66CCE0078C76A15F351CBD19C8FCC2B081 |
SHA256: | 80239619C4CA44380C6269873A5B6B695585CCFCF278E0F2C72698658A3A6FD8 |
SSDEEP: | 49152:pZL1zufKjTpcSPBeJJTXAlSr1/2ueI1HEafmKIDBsuN3FcTuYx/uEjF5RX:/RzvjTCVAlet2XmHxfmKIPNYx/RX |
.zip | | | ZIP compressed archive (100) |
---|
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
2056 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Request for Quotation (RFQ#196).zip" | C:\Program Files\WinRAR\WinRAR.exe | — | Explorer.EXE | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
1812 | "C:\Program Files\WinRAR\WinRAR.exe" | C:\Program Files\WinRAR\WinRAR.exe | Explorer.EXE | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Version: 5.91.0 Modules
| |||||||||||||||
3232 | "C:\Users\admin\AppData\Local\Temp\Rar$EXb1812.44850\Proforma Invoice and Bank swift-REG.PI-0086547654.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXb1812.44850\Proforma Invoice and Bank swift-REG.PI-0086547654.exe | WinRAR.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: DiskPart Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
3140 | attrib +h . | C:\Windows\system32\attrib.exe | — | Proforma Invoice and Bank swift-REG.PI-0086547654.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Attribute Utility Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
3044 | icacls . /grant Everyone:F /T /C /Q | C:\Windows\system32\icacls.exe | — | Proforma Invoice and Bank swift-REG.PI-0086547654.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
3244 | taskdl.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb1812.44850\taskdl.exe | — | Proforma Invoice and Bank swift-REG.PI-0086547654.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: SQL Client Configuration Utility EXE Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
3476 | C:\Windows\system32\cmd.exe /c 23531670263471.bat | C:\Windows\system32\cmd.exe | — | Proforma Invoice and Bank swift-REG.PI-0086547654.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 1 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
3280 | cscript.exe //nologo m.vbs | C:\Windows\system32\cscript.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft ® Console Based Script Host Exit code: 0 Version: 5.8.7600.16385 Modules
| |||||||||||||||
2992 | taskdl.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb1812.44850\taskdl.exe | — | Proforma Invoice and Bank swift-REG.PI-0086547654.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: SQL Client Configuration Utility EXE Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
1128 | @[email protected] co | C:\Users\admin\AppData\Local\Temp\Rar$EXb1812.44850\@[email protected] | Proforma Invoice and Bank swift-REG.PI-0086547654.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Load PerfMon Counters Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
|
PID | Process | Filename | Type | |
---|---|---|---|---|
3232 | Proforma Invoice and Bank swift-REG.PI-0086547654.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb1812.44850\msg\m_czech.wnry | text | |
MD5:537EFEECDFA94CC421E58FD82A58BA9E | SHA256:5AFA4753AFA048C6D6C39327CE674F27F5F6E5D3F2A060B7A8AED61725481150 | |||
3232 | Proforma Invoice and Bank swift-REG.PI-0086547654.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb1812.44850\msg\m_chinese (traditional).wnry | text | |
MD5:2EFC3690D67CD073A9406A25005F7CEA | SHA256:5C7F6AD1EC4BC2C8E2C9C126633215DABA7DE731AC8B12BE10CA157417C97F3A | |||
3232 | Proforma Invoice and Bank swift-REG.PI-0086547654.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb1812.44850\msg\m_dutch.wnry | text | |
MD5:7A8D499407C6A647C03C4471A67EAAD7 | SHA256:2C95BEF914DA6C50D7BDEDEC601E589FBB4FDA24C4863A7260F4F72BD025799C | |||
3232 | Proforma Invoice and Bank swift-REG.PI-0086547654.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb1812.44850\msg\m_filipino.wnry | text | |
MD5:08B9E69B57E4C9B966664F8E1C27AB09 | SHA256:D8489F8C16318E524B45DE8B35D7E2C3CD8ED4821C136F12F5EF3C9FC3321324 | |||
3232 | Proforma Invoice and Bank swift-REG.PI-0086547654.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb1812.44850\msg\m_danish.wnry | text | |
MD5:2C5A3B81D5C4715B7BEA01033367FCB5 | SHA256:A75BB44284B9DB8D702692F84909A7E23F21141866ADF3DB888042E9109A1CB6 | |||
1812 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb1812.44850\Proforma Invoice and Bank swift-REG.PI-0086547654.exe | executable | |
MD5:84C82835A5D21BBCF75A61706D8AB549 | SHA256:ED01EBFBC9EB5BBEA545AF4D01BF5F1071661840480439C6E5BABE8E080E41AA | |||
3232 | Proforma Invoice and Bank swift-REG.PI-0086547654.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb1812.44850\msg\m_croatian.wnry | text | |
MD5:17194003FA70CE477326CE2F6DEEB270 | SHA256:3F33734B2D34CCE83936CE99C3494CD845F1D2C02D7F6DA31D42DFC1CA15A171 | |||
3232 | Proforma Invoice and Bank swift-REG.PI-0086547654.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb1812.44850\msg\m_chinese (simplified).wnry | text | |
MD5:0252D45CA21C8E43C9742285C48E91AD | SHA256:845D0E178AEEBD6C7E2A2E9697B2BF6CF02028C50C288B3BA88FE2918EA2834A | |||
3232 | Proforma Invoice and Bank swift-REG.PI-0086547654.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb1812.44850\msg\m_greek.wnry | text | |
MD5:FB4E8718FEA95BB7479727FDE80CB424 | SHA256:E13CC9B13AA5074DC45D50379ECEB17EE39A0C2531AB617D93800FE236758CA9 | |||
3232 | Proforma Invoice and Bank swift-REG.PI-0086547654.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb1812.44850\b.wnry | image | |
MD5:C17170262312F3BE7027BC2CA825BF0C | SHA256:D5E0E8694DDC0548D8E6B87C83D50F4AB85C1DEBADB106D6A6A794C3E746F4FA |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
4052 | taskhsvc.exe | 83.212.99.68:443 | — | National Infrastructures for Research and Technology S.A. | GR | suspicious |
4052 | taskhsvc.exe | 154.35.175.225:443 | — | RETHEMHOSTING | US | malicious |
4052 | taskhsvc.exe | 204.8.156.142:443 | — | BGP-AS | US | suspicious |
4052 | taskhsvc.exe | 198.255.21.2:443 | — | COGENT-174 | US | suspicious |
PID | Process | Class | Message |
---|---|---|---|
4052 | taskhsvc.exe | Misc Attack | ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 220 |
4052 | taskhsvc.exe | Misc Attack | ET TOR Known Tor Exit Node Traffic group 85 |
4052 | taskhsvc.exe | Misc Attack | ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 85 |
4052 | taskhsvc.exe | Misc Attack | ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 349 |