File name:

AzInfoProtectionViewer_UL.iso

Full analysis: https://app.any.run/tasks/a04e6fb9-1497-462b-bc05-797ec9defe26
Verdict: Malicious activity
Analysis date: July 29, 2020, 23:04:29
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-iso9660-image
File info: ISO 9660 CD-ROM filesystem data '20200728_143623'
MD5:

2AD0D6367ED61B972E7AA87AFBE3F95F

SHA1:

CBC039C86E8480509453617952E7AD3103E03A64

SHA256:

80AA2DFD109397498549082BBE550F53C1502C4E9796BCA0BC8E12E0B09FEB87

SSDEEP:

196608:z4pH2+of7Fr9zpBuZ8RtgmwjQl/+FqQ6E:uH23hpl48Cb6E

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • ScreenConnect.ClientService.exe (PID: 2268)
      • rundll32.exe (PID: 2364)
      • ScreenConnect.WindowsClient.exe (PID: 2796)
      • ScreenConnect.WindowsClient.exe (PID: 2204)
      • AzInfoProtectionViewer_UL.exe (PID: 2660)
    • Application was dropped or rewritten from another process

      • AzInfoProtectionViewer_UL.exe (PID: 1984)
      • AzInfoProtectionViewer_UL.exe (PID: 2660)
      • DotNetInstaller.exe (PID: 2948)
      • ScreenConnect.ClientService.exe (PID: 2268)
      • ScreenConnect.WindowsClient.exe (PID: 2796)
      • ScreenConnect.WindowsClient.exe (PID: 2204)
      • AIPviewer.exe (PID: 3008)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2404)
      • AzInfoProtectionViewer_UL.exe (PID: 1984)
      • AzInfoProtectionViewer_UL.exe (PID: 2660)
      • msiexec.exe (PID: 2668)
      • rundll32.exe (PID: 2364)
    • Creates a software uninstall entry

      • AzInfoProtectionViewer_UL.exe (PID: 2660)
    • Uses RUNDLL32.EXE to load library

      • MsiExec.exe (PID: 3916)
    • Executed as Windows Service

      • ScreenConnect.ClientService.exe (PID: 2268)
    • Creates files in the program directory

      • ScreenConnect.ClientService.exe (PID: 2268)
    • Reads Environment values

      • ScreenConnect.WindowsClient.exe (PID: 2204)
    • Reads CPU info

      • ScreenConnect.WindowsClient.exe (PID: 2204)
    • Starts Microsoft Installer

      • AzInfoProtectionViewer_UL.exe (PID: 2660)
    • Creates files in the user directory

      • AzInfoProtectionViewer_UL.exe (PID: 2660)
    • Modifies the open verb of a shell class

      • msiexec.exe (PID: 2668)
  • INFO

    • Creates files in the program directory

      • msiexec.exe (PID: 2668)
    • Application launched itself

      • msiexec.exe (PID: 2668)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 2668)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.iso | ISO 9660 CD image (27.6)
.atn | Photoshop Action (27.1)
.gmc | Game Music Creator Music (6.1)

EXIF

ISO

System: WIN32
VolumeName: 20200728_143623
VolumeBlockCount: 3203
VolumeBlockSize: 2048
RootDirectoryCreateDate: 1970:01:01 05:00:00+05:00
Software: ULTRAISO V9.7 CD & DVD CREATOR, (C) EZB SYSTEMS, INC.
VolumeCreateDate: 2020:07:28 14:37:05.00+05:00
VolumeModifyDate: 2020:07:28 14:37:05.00+05:00

Composite

VolumeSize: 6.3 MB
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
52
Monitored processes
13
Malicious processes
5
Suspicious processes
4

Behavior graph

Click at the process to see the details
drop and start start drop and start drop and start winrar.exe azinfoprotectionviewer_ul.exe azinfoprotectionviewer_ul.exe dotnetinstaller.exe no specs msiexec.exe msiexec.exe msiexec.exe no specs rundll32.exe msiexec.exe no specs screenconnect.clientservice.exe screenconnect.windowsclient.exe no specs screenconnect.windowsclient.exe no specs aipviewer.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1984"C:\Users\admin\AppData\Local\Temp\Rar$EXa2404.22334\AzInfoProtectionViewer_UL.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2404.22334\AzInfoProtectionViewer_UL.exe
WinRAR.exe
User:
admin
Company:
Mícrosoft Corp
Integrity Level:
MEDIUM
Description:
Azure Information Protection Viewer
Exit code:
0
Version:
2.7.99
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2404.22334\azinfoprotectionviewer_ul.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2204"C:\Program Files\ScreenConnect Client (b360c71a7afdc807)\ScreenConnect.WindowsClient.exe" "RunRole" "a3c8cafe-450b-4030-ad95-d25c6462972f" "System"C:\Program Files\ScreenConnect Client (b360c71a7afdc807)\ScreenConnect.WindowsClient.exeScreenConnect.ClientService.exe
User:
SYSTEM
Company:
ScreenConnect Software
Integrity Level:
SYSTEM
Description:
ScreenConnect Client
Exit code:
0
Version:
20.7.29386.7502
Modules
Images
c:\program files\screenconnect client (b360c71a7afdc807)\screenconnect.windowsclient.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2268"C:\Program Files\ScreenConnect Client (b360c71a7afdc807)\ScreenConnect.ClientService.exe" "?e=Access&y=Guest&h=instance-o68c56-relay.screenconnect.com&p=443&s=5230c9ff-0686-43c9-890f-c578e02e08ce&k=BgIAAACkAABSU0ExAAgAAAEAAQClnp4EH4ENPsHzmynT1ZP4k4K%2f3vTBNHGQBIhql3YJJzJSAek4i2mLSIClMJLHhmKbS6trA8WMKJNIa2gUuegXMjkvWDgdUeOiD5wFD%2f1YiR5jhu3YPfWw2Sib%2fPFjOjCQRxP3esILMIORex0IhKF4UkOFWT2PtbvYwRC0%2bpuaVDfdDEG4IEY0WueB4%2bZo%2fPdnun0rcOjIK4ZwB6NzsCa%2fQdsTRPDLu8H%2bCUtDbEKXDDm8y5ipVCCGLO7%2bZeo2pYdbKVa2U27SO8%2bK0vfkX9ldgHIzVx%2bkWnonlp%2fKLc3PS3xdeqZeElF%2b0UQ9DYbCXOpHpbRDHyvG1MiWJmwCjoTh&t=&c=&c=&c=&c=&c=&c=&c=&c="C:\Program Files\ScreenConnect Client (b360c71a7afdc807)\ScreenConnect.ClientService.exe
services.exe
User:
SYSTEM
Integrity Level:
SYSTEM
Exit code:
0
Version:
20.7.29386.7502
Modules
Images
c:\program files\screenconnect client (b360c71a7afdc807)\screenconnect.clientservice.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2364rundll32.exe "C:\Windows\Installer\MSIC42B.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_902265 1 ScreenConnect.InstallerActions!ScreenConnect.ClientInstallerActions.FixupServiceArgumentsC:\Windows\system32\rundll32.exe
MsiExec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
2404"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\AzInfoProtectionViewer_UL.iso"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2660C:\Users\admin\AppData\Local\Temp\{C75B9CD0-DA0B-4C4B-A3C0-E89D5DFF1603}\AzInfoProtectionViewer_UL.exe -package:"C:\Users\admin\AppData\Local\Temp\Rar$EXa2404.22334\AzInfoProtectionViewer_UL.exe" -no_selfdeleter -IS_temp -media_path:"C:\Users\admin\AppData\Local\Temp\{C75B9CD0-DA0B-4C4B-A3C0-E89D5DFF1603}\Disk1\" -tempdisk1folder:"C:\Users\admin\AppData\Local\Temp\{C75B9CD0-DA0B-4C4B-A3C0-E89D5DFF1603}\" -IS_OriginalLauncher:"C:\Users\admin\AppData\Local\Temp\{C75B9CD0-DA0B-4C4B-A3C0-E89D5DFF1603}\Disk1\AzInfoProtectionViewer_UL.exe"C:\Users\admin\AppData\Local\Temp\{C75B9CD0-DA0B-4C4B-A3C0-E89D5DFF1603}\AzInfoProtectionViewer_UL.exe
AzInfoProtectionViewer_UL.exe
User:
admin
Company:
Mícrosoft Corp
Integrity Level:
MEDIUM
Description:
Azure Information Protection Viewer
Exit code:
0
Version:
2.7.99
Modules
Images
c:\users\admin\appdata\local\temp\{c75b9cd0-da0b-4c4b-a3c0-e89d5dff1603}\azinfoprotectionviewer_ul.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2668C:\Windows\system32\msiexec.exe /VC:\Windows\system32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2776C:\Windows\system32\MsiExec.exe -Embedding 52DDC13351DCD01CA15CD03C992446DB M Global\MSI0000C:\Windows\system32\MsiExec.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2796"C:\Program Files\ScreenConnect Client (b360c71a7afdc807)\ScreenConnect.WindowsClient.exe" "RunRole" "11a3804b-304b-445a-9f8e-4cc55f34ad5f" "User"C:\Program Files\ScreenConnect Client (b360c71a7afdc807)\ScreenConnect.WindowsClient.exeScreenConnect.ClientService.exe
User:
admin
Company:
ScreenConnect Software
Integrity Level:
MEDIUM
Description:
ScreenConnect Client
Exit code:
0
Version:
20.7.29386.7502
Modules
Images
c:\program files\screenconnect client (b360c71a7afdc807)\screenconnect.windowsclient.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2948"C:\Users\admin\AppData\Local\Temp\{0FA36514-2D0E-44D2-A53B-48063370BB78}\DotNetInstaller.exe" "C:\Users\admin\AppData\Roaming\AzureInfo\AIPviewer.exe"C:\Users\admin\AppData\Local\Temp\{0FA36514-2D0E-44D2-A53B-48063370BB78}\DotNetInstaller.exeAzInfoProtectionViewer_UL.exe
User:
admin
Company:
Flexera Software LLC
Integrity Level:
MEDIUM
Description:
DotNetInstaller
Exit code:
0
Version:
25.0.0.764
Modules
Images
c:\users\admin\appdata\local\temp\{0fa36514-2d0e-44d2-a53b-48063370bb78}\dotnetinstaller.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
1 223
Read events
1 064
Write events
147
Delete events
12

Modification events

(PID) Process:(2404) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2404) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2404) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\132\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2404) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\AzInfoProtectionViewer_UL.iso
(PID) Process:(2404) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2404) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2404) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2404) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2404) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(2404) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
Executable files
26
Suspicious files
15
Text files
20
Unknown types
2

Dropped files

PID
Process
Filename
Type
1984AzInfoProtectionViewer_UL.exeC:\Users\admin\AppData\Local\Temp\{C75B9CD0-DA0B-4C4B-A3C0-E89D5DFF1603}\Disk1\setup.exe
MD5:
SHA256:
2660AzInfoProtectionViewer_UL.exeC:\Users\admin\AppData\Local\Temp\{0FA36514-2D0E-44D2-A53B-48063370BB78}\{91207D76-070E-4EE4-A823-73999F5D2A7D}\set8CA1.tmp
MD5:
SHA256:
2660AzInfoProtectionViewer_UL.exeC:\Users\admin\AppData\Local\Temp\{0FA36514-2D0E-44D2-A53B-48063370BB78}\{91207D76-070E-4EE4-A823-73999F5D2A7D}\lic8CA2.tmp
MD5:
SHA256:
2660AzInfoProtectionViewer_UL.exeC:\Users\admin\AppData\Local\Temp\{0FA36514-2D0E-44D2-A53B-48063370BB78}\{91207D76-070E-4EE4-A823-73999F5D2A7D}\Fon8CB3.tmp
MD5:
SHA256:
2660AzInfoProtectionViewer_UL.exeC:\Users\admin\AppData\Local\Temp\{0FA36514-2D0E-44D2-A53B-48063370BB78}\{91207D76-070E-4EE4-A823-73999F5D2A7D}\DIF8CB4.tmp
MD5:
SHA256:
2660AzInfoProtectionViewer_UL.exeC:\Users\admin\AppData\Local\Temp\{0FA36514-2D0E-44D2-A53B-48063370BB78}\cor8CB5.tmp
MD5:
SHA256:
2660AzInfoProtectionViewer_UL.exeC:\Users\admin\AppData\Local\Temp\{0FA36514-2D0E-44D2-A53B-48063370BB78}\dot8CC6.tmp
MD5:
SHA256:
2660AzInfoProtectionViewer_UL.exeC:\Users\admin\AppData\Local\Temp\{0FA36514-2D0E-44D2-A53B-48063370BB78}\dot8CD6.tmp
MD5:
SHA256:
1984AzInfoProtectionViewer_UL.exeC:\Users\admin\AppData\Local\Temp\{C75B9CD0-DA0B-4C4B-A3C0-E89D5DFF1603}\Disk1\data1.cabcompressed
MD5:
SHA256:
2660AzInfoProtectionViewer_UL.exeC:\Users\admin\AppData\Local\Temp\{0FA36514-2D0E-44D2-A53B-48063370BB78}\{91207D76-070E-4EE4-A823-73999F5D2A7D}\Str8CD7.tmp
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
1
DNS requests
1
Threats
1

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2268
ScreenConnect.ClientService.exe
5.135.244.182:443
instance-o68c56-relay.screenconnect.com
OVH SAS
FR
unknown

DNS requests

Domain
IP
Reputation
instance-o68c56-relay.screenconnect.com
  • 5.135.244.182
unknown

Threats

Found threats are available for the paid subscriptions
1 ETPRO signatures available at the full report
No debug info