File name: | Request for Quotation (RFQ#196).zip |
Full analysis: | https://app.any.run/tasks/bea22325-6ae8-42ca-a15e-daeb7a11341f |
Verdict: | Malicious activity |
Analysis date: | December 06, 2022, 00:10:44 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/zip |
File info: | Zip archive data, at least v2.0 to extract |
MD5: | D69DC6569B385C0467185D002E252D89 |
SHA1: | 25938A66CCE0078C76A15F351CBD19C8FCC2B081 |
SHA256: | 80239619C4CA44380C6269873A5B6B695585CCFCF278E0F2C72698658A3A6FD8 |
SSDEEP: | 49152:pZL1zufKjTpcSPBeJJTXAlSr1/2ueI1HEafmKIDBsuN3FcTuYx/uEjF5RX:/RzvjTCVAlet2XmHxfmKIPNYx/RX |
.zip | | | ZIP compressed archive (100) |
---|
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
856 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Request for Quotation (RFQ#196).zip" | C:\Program Files\WinRAR\WinRAR.exe | — | Explorer.EXE |
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Version: 5.91.0 | ||||
1868 | "C:\Users\admin\AppData\Local\Temp\Rar$EXb856.405\Proforma Invoice and Bank swift-REG.PI-0086547654.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXb856.405\Proforma Invoice and Bank swift-REG.PI-0086547654.exe | WinRAR.exe | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: DiskPart Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) | ||||
2796 | attrib +h . | C:\Windows\system32\attrib.exe | — | Proforma Invoice and Bank swift-REG.PI-0086547654.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Attribute Utility Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
1880 | icacls . /grant Everyone:F /T /C /Q | C:\Windows\system32\icacls.exe | — | Proforma Invoice and Bank swift-REG.PI-0086547654.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
2092 | taskdl.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb856.405\taskdl.exe | — | Proforma Invoice and Bank swift-REG.PI-0086547654.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: SQL Client Configuration Utility EXE Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
1444 | C:\Windows\system32\cmd.exe /c 144021670285528.bat | C:\Windows\system32\cmd.exe | — | Proforma Invoice and Bank swift-REG.PI-0086547654.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 1 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) | ||||
3044 | cscript.exe //nologo m.vbs | C:\Windows\system32\cscript.exe | — | cmd.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft ® Console Based Script Host Exit code: 0 Version: 5.8.7600.16385 | ||||
1812 | taskdl.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb856.405\taskdl.exe | — | Proforma Invoice and Bank swift-REG.PI-0086547654.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: SQL Client Configuration Utility EXE Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
320 | @[email protected] co | C:\Users\admin\AppData\Local\Temp\Rar$EXb856.405\@[email protected] | Proforma Invoice and Bank swift-REG.PI-0086547654.exe | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Load PerfMon Counters Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
2092 | cmd.exe /c start /b @[email protected] vs | C:\Windows\system32\cmd.exe | — | Proforma Invoice and Bank swift-REG.PI-0086547654.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) |
(PID) Process: | (856) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtBMP |
Value: | |||
(PID) Process: | (856) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtIcon |
Value: | |||
(PID) Process: | (856) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\16D\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (856) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
(PID) Process: | (856) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
(PID) Process: | (856) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Request for Quotation (RFQ#196).zip | |||
(PID) Process: | (856) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | name |
Value: 120 | |||
(PID) Process: | (856) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | size |
Value: 80 | |||
(PID) Process: | (856) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | type |
Value: 120 | |||
(PID) Process: | (856) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | mtime |
Value: 100 |
PID | Process | Filename | Type | |
---|---|---|---|---|
1868 | Proforma Invoice and Bank swift-REG.PI-0086547654.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb856.405\msg\m_chinese (traditional).wnry | text | |
MD5:2EFC3690D67CD073A9406A25005F7CEA | SHA256:5C7F6AD1EC4BC2C8E2C9C126633215DABA7DE731AC8B12BE10CA157417C97F3A | |||
1868 | Proforma Invoice and Bank swift-REG.PI-0086547654.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb856.405\msg\m_french.wnry | text | |
MD5:4E57113A6BF6B88FDD32782A4A381274 | SHA256:9BD38110E6523547AED50617DDC77D0920D408FAEED2B7A21AB163FDA22177BC | |||
1868 | Proforma Invoice and Bank swift-REG.PI-0086547654.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb856.405\msg\m_greek.wnry | text | |
MD5:FB4E8718FEA95BB7479727FDE80CB424 | SHA256:E13CC9B13AA5074DC45D50379ECEB17EE39A0C2531AB617D93800FE236758CA9 | |||
1868 | Proforma Invoice and Bank swift-REG.PI-0086547654.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb856.405\msg\m_italian.wnry | text | |
MD5:30A200F78498990095B36F574B6E8690 | SHA256:49F2C739E7D9745C0834DC817A71BF6676CCC24A4C28DCDDF8844093AAB3DF07 | |||
1868 | Proforma Invoice and Bank swift-REG.PI-0086547654.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb856.405\b.wnry | image | |
MD5:C17170262312F3BE7027BC2CA825BF0C | SHA256:D5E0E8694DDC0548D8E6B87C83D50F4AB85C1DEBADB106D6A6A794C3E746F4FA | |||
1868 | Proforma Invoice and Bank swift-REG.PI-0086547654.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb856.405\msg\m_danish.wnry | text | |
MD5:2C5A3B81D5C4715B7BEA01033367FCB5 | SHA256:A75BB44284B9DB8D702692F84909A7E23F21141866ADF3DB888042E9109A1CB6 | |||
1868 | Proforma Invoice and Bank swift-REG.PI-0086547654.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb856.405\msg\m_dutch.wnry | text | |
MD5:7A8D499407C6A647C03C4471A67EAAD7 | SHA256:2C95BEF914DA6C50D7BDEDEC601E589FBB4FDA24C4863A7260F4F72BD025799C | |||
1868 | Proforma Invoice and Bank swift-REG.PI-0086547654.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb856.405\c.wnry | abr | |
MD5:AE08F79A0D800B82FCBE1B43CDBDBEFC | SHA256:055C7760512C98C8D51E4427227FE2A7EA3B34EE63178FE78631FA8AA6D15622 | |||
1868 | Proforma Invoice and Bank swift-REG.PI-0086547654.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb856.405\msg\m_bulgarian.wnry | text | |
MD5:95673B0F968C0F55B32204361940D184 | SHA256:40B37E7B80CF678D7DD302AAF41B88135ADE6DDF44D89BDBA19CF171564444BD | |||
1868 | Proforma Invoice and Bank swift-REG.PI-0086547654.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb856.405\msg\m_japanese.wnry | text | |
MD5:B77E1221F7ECD0B5D696CB66CDA1609E | SHA256:7E491E7B48D6E34F916624C1CDA9F024E86FCBEC56ACDA35E27FA99D530D017E |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
3752 | taskhsvc.exe | 154.35.175.225:443 | — | RETHEMHOSTING | US | malicious |
3752 | taskhsvc.exe | 195.154.164.243:443 | — | Online S.a.s. | FR | suspicious |
3752 | taskhsvc.exe | 178.162.194.210:80 | — | Leaseweb Deutschland GmbH | DE | suspicious |