| File name: | AzInfoProtectionViewer_UL.iso |
| Full analysis: | https://app.any.run/tasks/a04e6fb9-1497-462b-bc05-797ec9defe26 |
| Verdict: | Malicious activity |
| Analysis date: | July 29, 2020, 23:04:29 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-iso9660-image |
| File info: | ISO 9660 CD-ROM filesystem data '20200728_143623' |
| MD5: | 2AD0D6367ED61B972E7AA87AFBE3F95F |
| SHA1: | CBC039C86E8480509453617952E7AD3103E03A64 |
| SHA256: | 80AA2DFD109397498549082BBE550F53C1502C4E9796BCA0BC8E12E0B09FEB87 |
| SSDEEP: | 196608:z4pH2+of7Fr9zpBuZ8RtgmwjQl/+FqQ6E:uH23hpl48Cb6E |
| .iso | | | ISO 9660 CD image (27.6) |
|---|---|---|
| .atn | | | Photoshop Action (27.1) |
| .gmc | | | Game Music Creator Music (6.1) |
| System: | WIN32 |
|---|---|
| VolumeName: | 20200728_143623 |
| VolumeBlockCount: | 3203 |
| VolumeBlockSize: | 2048 |
| RootDirectoryCreateDate: | 1970:01:01 05:00:00+05:00 |
| Software: | ULTRAISO V9.7 CD & DVD CREATOR, (C) EZB SYSTEMS, INC. |
| VolumeCreateDate: | 2020:07:28 14:37:05.00+05:00 |
| VolumeModifyDate: | 2020:07:28 14:37:05.00+05:00 |
| VolumeSize: | 6.3 MB |
|---|
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1984 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2404.22334\AzInfoProtectionViewer_UL.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2404.22334\AzInfoProtectionViewer_UL.exe | WinRAR.exe | ||||||||||||
User: admin Company: Mícrosoft Corp Integrity Level: MEDIUM Description: Azure Information Protection Viewer Exit code: 0 Version: 2.7.99 Modules
| |||||||||||||||
| 2204 | "C:\Program Files\ScreenConnect Client (b360c71a7afdc807)\ScreenConnect.WindowsClient.exe" "RunRole" "a3c8cafe-450b-4030-ad95-d25c6462972f" "System" | C:\Program Files\ScreenConnect Client (b360c71a7afdc807)\ScreenConnect.WindowsClient.exe | — | ScreenConnect.ClientService.exe | |||||||||||
User: SYSTEM Company: ScreenConnect Software Integrity Level: SYSTEM Description: ScreenConnect Client Exit code: 0 Version: 20.7.29386.7502 Modules
| |||||||||||||||
| 2268 | "C:\Program Files\ScreenConnect Client (b360c71a7afdc807)\ScreenConnect.ClientService.exe" "?e=Access&y=Guest&h=instance-o68c56-relay.screenconnect.com&p=443&s=5230c9ff-0686-43c9-890f-c578e02e08ce&k=BgIAAACkAABSU0ExAAgAAAEAAQClnp4EH4ENPsHzmynT1ZP4k4K%2f3vTBNHGQBIhql3YJJzJSAek4i2mLSIClMJLHhmKbS6trA8WMKJNIa2gUuegXMjkvWDgdUeOiD5wFD%2f1YiR5jhu3YPfWw2Sib%2fPFjOjCQRxP3esILMIORex0IhKF4UkOFWT2PtbvYwRC0%2bpuaVDfdDEG4IEY0WueB4%2bZo%2fPdnun0rcOjIK4ZwB6NzsCa%2fQdsTRPDLu8H%2bCUtDbEKXDDm8y5ipVCCGLO7%2bZeo2pYdbKVa2U27SO8%2bK0vfkX9ldgHIzVx%2bkWnonlp%2fKLc3PS3xdeqZeElF%2b0UQ9DYbCXOpHpbRDHyvG1MiWJmwCjoTh&t=&c=&c=&c=&c=&c=&c=&c=&c=" | C:\Program Files\ScreenConnect Client (b360c71a7afdc807)\ScreenConnect.ClientService.exe | services.exe | ||||||||||||
User: SYSTEM Integrity Level: SYSTEM Exit code: 0 Version: 20.7.29386.7502 Modules
| |||||||||||||||
| 2364 | rundll32.exe "C:\Windows\Installer\MSIC42B.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_902265 1 ScreenConnect.InstallerActions!ScreenConnect.ClientInstallerActions.FixupServiceArguments | C:\Windows\system32\rundll32.exe | MsiExec.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2404 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\AzInfoProtectionViewer_UL.iso" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 2660 | C:\Users\admin\AppData\Local\Temp\{C75B9CD0-DA0B-4C4B-A3C0-E89D5DFF1603}\AzInfoProtectionViewer_UL.exe -package:"C:\Users\admin\AppData\Local\Temp\Rar$EXa2404.22334\AzInfoProtectionViewer_UL.exe" -no_selfdeleter -IS_temp -media_path:"C:\Users\admin\AppData\Local\Temp\{C75B9CD0-DA0B-4C4B-A3C0-E89D5DFF1603}\Disk1\" -tempdisk1folder:"C:\Users\admin\AppData\Local\Temp\{C75B9CD0-DA0B-4C4B-A3C0-E89D5DFF1603}\" -IS_OriginalLauncher:"C:\Users\admin\AppData\Local\Temp\{C75B9CD0-DA0B-4C4B-A3C0-E89D5DFF1603}\Disk1\AzInfoProtectionViewer_UL.exe" | C:\Users\admin\AppData\Local\Temp\{C75B9CD0-DA0B-4C4B-A3C0-E89D5DFF1603}\AzInfoProtectionViewer_UL.exe | AzInfoProtectionViewer_UL.exe | ||||||||||||
User: admin Company: Mícrosoft Corp Integrity Level: MEDIUM Description: Azure Information Protection Viewer Exit code: 0 Version: 2.7.99 Modules
| |||||||||||||||
| 2668 | C:\Windows\system32\msiexec.exe /V | C:\Windows\system32\msiexec.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2776 | C:\Windows\system32\MsiExec.exe -Embedding 52DDC13351DCD01CA15CD03C992446DB M Global\MSI0000 | C:\Windows\system32\MsiExec.exe | — | msiexec.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2796 | "C:\Program Files\ScreenConnect Client (b360c71a7afdc807)\ScreenConnect.WindowsClient.exe" "RunRole" "11a3804b-304b-445a-9f8e-4cc55f34ad5f" "User" | C:\Program Files\ScreenConnect Client (b360c71a7afdc807)\ScreenConnect.WindowsClient.exe | — | ScreenConnect.ClientService.exe | |||||||||||
User: admin Company: ScreenConnect Software Integrity Level: MEDIUM Description: ScreenConnect Client Exit code: 0 Version: 20.7.29386.7502 Modules
| |||||||||||||||
| 2948 | "C:\Users\admin\AppData\Local\Temp\{0FA36514-2D0E-44D2-A53B-48063370BB78}\DotNetInstaller.exe" "C:\Users\admin\AppData\Roaming\AzureInfo\AIPviewer.exe" | C:\Users\admin\AppData\Local\Temp\{0FA36514-2D0E-44D2-A53B-48063370BB78}\DotNetInstaller.exe | — | AzInfoProtectionViewer_UL.exe | |||||||||||
User: admin Company: Flexera Software LLC Integrity Level: MEDIUM Description: DotNetInstaller Exit code: 0 Version: 25.0.0.764 Modules
| |||||||||||||||
| (PID) Process: | (2404) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (2404) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (2404) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\132\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2404) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\AzInfoProtectionViewer_UL.iso | |||
| (PID) Process: | (2404) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2404) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2404) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2404) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (2404) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (2404) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1984 | AzInfoProtectionViewer_UL.exe | C:\Users\admin\AppData\Local\Temp\{C75B9CD0-DA0B-4C4B-A3C0-E89D5DFF1603}\Disk1\setup.exe | — | |
MD5:— | SHA256:— | |||
| 2660 | AzInfoProtectionViewer_UL.exe | C:\Users\admin\AppData\Local\Temp\{0FA36514-2D0E-44D2-A53B-48063370BB78}\{91207D76-070E-4EE4-A823-73999F5D2A7D}\set8CA1.tmp | — | |
MD5:— | SHA256:— | |||
| 2660 | AzInfoProtectionViewer_UL.exe | C:\Users\admin\AppData\Local\Temp\{0FA36514-2D0E-44D2-A53B-48063370BB78}\{91207D76-070E-4EE4-A823-73999F5D2A7D}\lic8CA2.tmp | — | |
MD5:— | SHA256:— | |||
| 2660 | AzInfoProtectionViewer_UL.exe | C:\Users\admin\AppData\Local\Temp\{0FA36514-2D0E-44D2-A53B-48063370BB78}\{91207D76-070E-4EE4-A823-73999F5D2A7D}\Fon8CB3.tmp | — | |
MD5:— | SHA256:— | |||
| 2660 | AzInfoProtectionViewer_UL.exe | C:\Users\admin\AppData\Local\Temp\{0FA36514-2D0E-44D2-A53B-48063370BB78}\{91207D76-070E-4EE4-A823-73999F5D2A7D}\DIF8CB4.tmp | — | |
MD5:— | SHA256:— | |||
| 2660 | AzInfoProtectionViewer_UL.exe | C:\Users\admin\AppData\Local\Temp\{0FA36514-2D0E-44D2-A53B-48063370BB78}\cor8CB5.tmp | — | |
MD5:— | SHA256:— | |||
| 2660 | AzInfoProtectionViewer_UL.exe | C:\Users\admin\AppData\Local\Temp\{0FA36514-2D0E-44D2-A53B-48063370BB78}\dot8CC6.tmp | — | |
MD5:— | SHA256:— | |||
| 2660 | AzInfoProtectionViewer_UL.exe | C:\Users\admin\AppData\Local\Temp\{0FA36514-2D0E-44D2-A53B-48063370BB78}\dot8CD6.tmp | — | |
MD5:— | SHA256:— | |||
| 1984 | AzInfoProtectionViewer_UL.exe | C:\Users\admin\AppData\Local\Temp\{C75B9CD0-DA0B-4C4B-A3C0-E89D5DFF1603}\Disk1\data1.cab | compressed | |
MD5:— | SHA256:— | |||
| 2660 | AzInfoProtectionViewer_UL.exe | C:\Users\admin\AppData\Local\Temp\{0FA36514-2D0E-44D2-A53B-48063370BB78}\{91207D76-070E-4EE4-A823-73999F5D2A7D}\Str8CD7.tmp | — | |
MD5:— | SHA256:— | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2268 | ScreenConnect.ClientService.exe | 5.135.244.182:443 | instance-o68c56-relay.screenconnect.com | OVH SAS | FR | unknown |
Domain | IP | Reputation |
|---|---|---|
instance-o68c56-relay.screenconnect.com |
| unknown |