File name:

CCMaker v1.3.6.zip

Full analysis: https://app.any.run/tasks/dcbc0806-2bc7-43e4-8710-4a65d542e0a2
Verdict: Malicious activity
Analysis date: June 26, 2019, 01:39:59
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

37E01DFE80B102323B5A21DCBD8A0D49

SHA1:

C87BAC2978AEDB3EDC13C54B3CAA180528D31E0D

SHA256:

803CB45EE1909E8B42B8240BB6C3BA3A4F81FA7748A84006439BECAC78DF128A

SSDEEP:

49152:q8ozDfxC3aDnsawumKPFTykbRXCYXme/0qgCV0HgMxO3/fui/4jpEMazzgx:q8ozk3An5wnq1bRe+eCV0M3ugMaz0x

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • CCMaker.exe (PID: 1560)
      • CCMaker.exe (PID: 2908)
    • Changes settings of System certificates

      • CCMaker.tmp (PID: 3916)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1012)
      • CCMaker.tmp (PID: 3916)
      • CCMaker.exe (PID: 1560)
    • Reads the Windows organization settings

      • CCMaker.tmp (PID: 3916)
    • Adds / modifies Windows certificates

      • CCMaker.tmp (PID: 3916)
    • Reads Windows owner or organization settings

      • CCMaker.tmp (PID: 3916)
  • INFO

    • Manual execution by user

      • CCMaker.exe (PID: 2908)
      • CCMaker.exe (PID: 1560)
    • Application was dropped or rewritten from another process

      • CCMaker.tmp (PID: 3916)
    • Loads dropped or rewritten executable

      • CCMaker.tmp (PID: 3916)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0808
ZipCompression: Deflated
ZipModifyDate: 2018:03:26 10:14:06
ZipCRC: 0xe4752f4b
ZipCompressedSize: 2793597
ZipUncompressedSize: 2882647
ZipFileName: CCMaker v1.3.6/CCMaker.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
40
Monitored processes
4
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start drop and start winrar.exe ccmaker.exe no specs ccmaker.exe ccmaker.tmp

Process information

PID
CMD
Path
Indicators
Parent process
1012"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\CCMaker v1.3.6.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
1560"C:\Users\admin\Desktop\CCMaker v1.3.6\CCMaker.exe" C:\Users\admin\Desktop\CCMaker v1.3.6\CCMaker.exe
explorer.exe
User:
admin
Company:
Pendejo Software
Integrity Level:
HIGH
Description:
CCMaker
Exit code:
0
Version:
1.3.6
Modules
Images
c:\users\admin\desktop\ccmaker v1.3.6\ccmaker.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2908"C:\Users\admin\Desktop\CCMaker v1.3.6\CCMaker.exe" C:\Users\admin\Desktop\CCMaker v1.3.6\CCMaker.exeexplorer.exe
User:
admin
Company:
Pendejo Software
Integrity Level:
MEDIUM
Description:
CCMaker
Exit code:
3221226540
Version:
1.3.6
Modules
Images
c:\users\admin\desktop\ccmaker v1.3.6\ccmaker.exe
c:\systemroot\system32\ntdll.dll
3916"C:\Users\admin\AppData\Local\Temp\is-MLNAL.tmp\CCMaker.tmp" /SL5="$301D0,2152483,169984,C:\Users\admin\Desktop\CCMaker v1.3.6\CCMaker.exe" C:\Users\admin\AppData\Local\Temp\is-MLNAL.tmp\CCMaker.tmp
CCMaker.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-mlnal.tmp\ccmaker.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
Total events
533
Read events
483
Write events
50
Delete events
0

Modification events

(PID) Process:(1012) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1012) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1012) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1012) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\CCMaker v1.3.6.zip
(PID) Process:(1012) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1012) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1012) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1012) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1012) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
(PID) Process:(1012) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\General
Operation:writeName:LastFolder
Value:
C:\Users\admin\AppData\Local\Temp
Executable files
5
Suspicious files
0
Text files
4
Unknown types
0

Dropped files

PID
Process
Filename
Type
3916CCMaker.tmpC:\Users\admin\AppData\Local\Temp\is-G2P69.tmp\NEW.PNG
MD5:
SHA256:
3916CCMaker.tmpC:\Users\admin\AppData\Local\Temp\is-G2P69.tmp\ffc.xml.partial
MD5:
SHA256:
3916CCMaker.tmpC:\Users\admin\AppData\Local\Temp\is-G2P69.tmp\ffc.xml
MD5:
SHA256:
3916CCMaker.tmpC:\Users\admin\AppData\Local\Temp\is-G2P69.tmp\group.png.partial
MD5:
SHA256:
3916CCMaker.tmpC:\Users\admin\AppData\Local\Temp\is-G2P69.tmp\group.png
MD5:
SHA256:
1012WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1012.22870\CCMaker v1.3.6\CCMaker.md5text
MD5:
SHA256:
3916CCMaker.tmpC:\Users\admin\AppData\Local\Temp\is-G2P69.tmp\7-zip32.dllexecutable
MD5:3EC079B620BFD16CFDABB17C86CDB14E
SHA256:1AEF0B307388747ED75D3907D128D9EC382777970A1962E3A7BA9015123E411C
3916CCMaker.tmpC:\Users\admin\AppData\Local\Temp\is-G2P69.tmp\_isetup\_shfoldr.dllexecutable
MD5:92DC6EF532FBB4A5C3201469A5B5EB63
SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87
1012WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1012.22870\CCMaker v1.3.6\CCMaker.exeexecutable
MD5:8245FB097BE69F9204BACBC431C77E9E
SHA256:2B4B5EB89FE8A52F93A2E2D484E5B00BBCD706E04D3919C42619FDE1FADFB99E
1560CCMaker.exeC:\Users\admin\AppData\Local\Temp\is-MLNAL.tmp\CCMaker.tmpexecutable
MD5:5E74B852A8E6B62494464A25A86E9C05
SHA256:473BF28C3F87A5C7D8404B763E528B448C5C2975765D65876BE0C4D3A615DC76
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
21
DNS requests
3
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3916
CCMaker.tmp
34.235.69.62:443
prod-rel-ffc-ccm.oobesaas.adobe.com
Amazon.com, Inc.
US
unknown
34.235.69.62:443
prod-rel-ffc-ccm.oobesaas.adobe.com
Amazon.com, Inc.
US
unknown
3916
CCMaker.tmp
52.216.179.19:443
adobe-oobe-prod-data-store-ue1.s3.amazonaws.com
Amazon.com, Inc.
US
unknown

DNS requests

Domain
IP
Reputation
prod-rel-ffc-ccm.oobesaas.adobe.com
  • 34.235.69.62
  • 34.237.97.192
  • 34.233.13.207
  • 34.235.105.209
  • 35.169.159.195
  • 52.0.229.69
  • 35.169.227.248
  • 35.174.215.88
whitelisted
adobe-oobe-prod-data-store-ue1.s3.amazonaws.com
  • 52.216.179.19
shared

Threats

No threats detected
Process
Message
CCMaker.tmp
Extra call to Release() !!!
CCMaker.tmp
Extra call to Release() !!!