File name:

2024-05-03_949c438e4ed541877dce02b38bf593ad_bitrat_cobalt-strike_venus-locker.zip

Full analysis: https://app.any.run/tasks/10989bd5-fad1-46cc-a238-3b4373137f36
Verdict: Malicious activity
Analysis date: December 03, 2024, 14:22:24
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v5.1 to extract, compression method=AES Encrypted
MD5:

9EC155B4EFA9D589D4A92D11F936BD58

SHA1:

0D940745E81E86D3D197329BFB8E3CB25D47465E

SHA256:

804BCE5C672B3BD531CDBB9AED796D36FA8C2D402823E4B4A3A99B13161F2139

SSDEEP:

6144:4Jsi8dhIpvpsYlc3bwb4gVGkzNH0Fa1jdNbyAHPr/pzG1IGQZFUZdl:Gsi+IpBlAWdVGkxH0Fa1jdNeGDtLnAN

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • 2024-05-03_949c438e4ed541877dce02b38bf593ad_bitrat_cobalt-strike_venus-locker.exe (PID: 4724)
    • Executable content was dropped or overwritten

      • 2024-05-03_949c438e4ed541877dce02b38bf593ad_bitrat_cobalt-strike_venus-locker.exe (PID: 4724)
    • The process drops C-runtime libraries

      • 2024-05-03_949c438e4ed541877dce02b38bf593ad_bitrat_cobalt-strike_venus-locker.exe (PID: 4724)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 772)
    • Manual execution by a user

      • 2024-05-03_949c438e4ed541877dce02b38bf593ad_bitrat_cobalt-strike_venus-locker.exe (PID: 4724)
      • notepad.exe (PID: 1944)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 51
ZipBitFlag: 0x0009
ZipCompression: Unknown (99)
ZipModifyDate: 2024:12:03 14:21:58
ZipCRC: 0x759e97a8
ZipCompressedSize: 262588
ZipUncompressedSize: 524800
ZipFileName: 2024-05-03_949c438e4ed541877dce02b38bf593ad_bitrat_cobalt-strike_venus-locker
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
130
Monitored processes
4
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe 2024-05-03_949c438e4ed541877dce02b38bf593ad_bitrat_cobalt-strike_venus-locker.exe conhost.exe no specs notepad.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
772"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\2024-05-03_949c438e4ed541877dce02b38bf593ad_bitrat_cobalt-strike_venus-locker.zipC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
1512\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exe2024-05-03_949c438e4ed541877dce02b38bf593ad_bitrat_cobalt-strike_venus-locker.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1944"C:\WINDOWS\system32\NOTEPAD.EXE" C:\README.txtC:\Windows\System32\notepad.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
4724"C:\Users\admin\Desktop\2024-05-03_949c438e4ed541877dce02b38bf593ad_bitrat_cobalt-strike_venus-locker.exe" C:\Users\admin\Desktop\2024-05-03_949c438e4ed541877dce02b38bf593ad_bitrat_cobalt-strike_venus-locker.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\users\admin\desktop\2024-05-03_949c438e4ed541877dce02b38bf593ad_bitrat_cobalt-strike_venus-locker.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
Total events
2 378
Read events
2 366
Write events
12
Delete events
0

Modification events

(PID) Process:(772) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(772) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(772) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(772) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\2024-05-03_949c438e4ed541877dce02b38bf593ad_bitrat_cobalt-strike_venus-locker.zip
(PID) Process:(772) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(772) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(772) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(772) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(772) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
(PID) Process:(4724) 2024-05-03_949c438e4ed541877dce02b38bf593ad_bitrat_cobalt-strike_venus-locker.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion
Operation:writeName:pbsecGOOD
Value:
TImfZSgtD3HQpVneTc6jtu4HP2LdkDEcuc9IHatkNn0=
Executable files
117
Suspicious files
1 554
Text files
1 172
Unknown types
127

Dropped files

PID
Process
Filename
Type
47242024-05-03_949c438e4ed541877dce02b38bf593ad_bitrat_cobalt-strike_venus-locker.exeC:\$WinREAgent\Backup\Winre.wim.trinitylock
MD5:
SHA256:
47242024-05-03_949c438e4ed541877dce02b38bf593ad_bitrat_cobalt-strike_venus-locker.exeC:\$WinREAgent\Scratch\update.wim.trinitylock
MD5:
SHA256:
47242024-05-03_949c438e4ed541877dce02b38bf593ad_bitrat_cobalt-strike_venus-locker.exeC:\README.txttext
MD5:71F92AB1EEFFD743BE89E7AFB7C62E4A
SHA256:EEEFE3240B93045FE662382931C2BCEE278B5FF741AD854E14AD1D40ADA1D0D9
772WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb772.11016\2024-05-03_949c438e4ed541877dce02b38bf593ad_bitrat_cobalt-strike_venus-lockerexecutable
MD5:949C438E4ED541877DCE02B38BF593AD
SHA256:36696BA25BDC8DF0612B638430A70E5FF6C5F9E75517AD401727BE03B26D8EC4
47242024-05-03_949c438e4ed541877dce02b38bf593ad_bitrat_cobalt-strike_venus-locker.exeC:\$WinREAgent\Backup\boot.sdi.trinitylocksdi
MD5:22D9945B4AAE36DD59620A918F2E65F4
SHA256:CD2C00CE027687CE4A8BDC967F26A8AB82F651C9BECD703658BA282EC49702BD
47242024-05-03_949c438e4ed541877dce02b38bf593ad_bitrat_cobalt-strike_venus-locker.exeC:\bootTel.dat.trinitylockbinary
MD5:5C95D04D8A6FEF2C823E9538BD0A1B38
SHA256:FDD46368879C37E8002FE3CD17BF800A066B3D5A870DCE8B8D69D19C4513D485
47242024-05-03_949c438e4ed541877dce02b38bf593ad_bitrat_cobalt-strike_venus-locker.exeC:\$WinREAgent\Backup\location.txt.trinitylocktext
MD5:F09B8CA2E0F41BA2270F6EF5062BB1A8
SHA256:E4C22462C0619D55326E12995176E7A5D14C16E1F6791F0F8C7E55034AAB1D35
47242024-05-03_949c438e4ed541877dce02b38bf593ad_bitrat_cobalt-strike_venus-locker.exeC:\$WinREAgent\Backup\ReAgent.xml.trinitylockxml
MD5:CC8F4479ACCDAD829F622369C1C91BB2
SHA256:2B50529F157707DE79A76B39344CD2526EB015B3CDA5727CC010537AA3CBF084
47242024-05-03_949c438e4ed541877dce02b38bf593ad_bitrat_cobalt-strike_venus-locker.exeC:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.dll.trinitylock
MD5:
SHA256:
47242024-05-03_949c438e4ed541877dce02b38bf593ad_bitrat_cobalt-strike_venus-locker.exe
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
41
DNS requests
20
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4712
MoUsoCoreWorker.exe
GET
200
23.48.23.178:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
6236
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6932
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6932
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2380
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4712
MoUsoCoreWorker.exe
23.48.23.178:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4712
MoUsoCoreWorker.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5064
SearchApp.exe
104.126.37.123:443
www.bing.com
Akamai International B.V.
DE
whitelisted
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
4
System
192.168.100.255:138
whitelisted
1176
svchost.exe
20.190.159.75:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1176
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 51.124.78.146
  • 51.104.136.2
whitelisted
crl.microsoft.com
  • 23.48.23.178
  • 23.48.23.159
  • 23.48.23.168
  • 23.48.23.181
  • 23.48.23.156
  • 23.48.23.174
  • 23.48.23.161
  • 23.48.23.167
  • 23.48.23.177
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
google.com
  • 216.58.206.78
whitelisted
www.bing.com
  • 104.126.37.123
  • 104.126.37.136
  • 104.126.37.185
  • 104.126.37.153
  • 104.126.37.186
  • 104.126.37.139
  • 104.126.37.131
  • 104.126.37.130
  • 104.126.37.137
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 20.190.159.75
  • 20.190.159.4
  • 40.126.31.69
  • 40.126.31.71
  • 20.190.159.2
  • 20.190.159.0
  • 40.126.31.73
  • 20.190.159.73
whitelisted
go.microsoft.com
  • 23.213.166.81
whitelisted
arc.msn.com
  • 20.223.36.55
whitelisted
fd.api.iris.microsoft.com
  • 20.103.156.88
whitelisted

Threats

No threats detected
No debug info