File name:

GS1000_Ver_1_3_2_97_2019-12-18_Bộ cài và hướng dẫn cài đặt.zip

Full analysis: https://app.any.run/tasks/d34b9c94-9491-4998-93fe-91f12b2cad06
Verdict: Malicious activity
Analysis date: March 20, 2020, 08:05:43
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

15C25401E92BFA93A8C2AC72A2C4E0A8

SHA1:

6BA769A0CB28AD67A65FF7D2A0972B6E989AC4D7

SHA256:

8220672B034AA565E4D85C8A28DAEE18B6C6446DAC712B85F8463284DC0724F1

SSDEEP:

196608:ZPWunqzNGee03HMez9D19S40et++schSXhdX+UiYCXl5AEcG9q1jqbS9tYuuFAgc:ZPWFb1J1QDetj0XHuCCbADG9ok0YtFdc

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • setup.exe (PID: 880)
      • setup.exe (PID: 3376)
      • GS1000.exe (PID: 3744)
      • GS1000.exe (PID: 2868)
      • GS1000.exe (PID: 2296)
    • Loads dropped or rewritten executable

      • regsvr32.exe (PID: 3020)
      • GS1000.exe (PID: 3744)
      • explorer.exe (PID: 372)
    • Registers / Runs the DLL via REGSVR32.EXE

      • MsiExec.exe (PID: 3672)
  • SUSPICIOUS

    • Starts Microsoft Installer

      • setup.exe (PID: 3376)
    • Executed as Windows Service

      • vssvc.exe (PID: 3992)
    • Creates COM task schedule object

      • regsvr32.exe (PID: 3020)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2796)
      • msiexec.exe (PID: 3944)
  • INFO

    • Application launched itself

      • msiexec.exe (PID: 3944)
    • Creates files in the program directory

      • msiexec.exe (PID: 3944)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 3944)
    • Loads dropped or rewritten executable

      • MsiExec.exe (PID: 404)
      • MsiExec.exe (PID: 3672)
      • MsiExec.exe (PID: 2076)
    • Searches for installed software

      • msiexec.exe (PID: 3944)
    • Low-level read access rights to disk partition

      • vssvc.exe (PID: 3992)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2019:12:27 20:16:25
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: GS1000_Ver_1_3_2_97_2019-12-18/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
61
Monitored processes
19
Malicious processes
7
Suspicious processes
2

Behavior graph

Click at the process to see the details
drop and start drop and start start winrar.exe setup.exe no specs setup.exe msiexec.exe no specs msiexec.exe msiexec.exe no specs vssvc.exe no specs acrord32.exe no specs acrord32.exe no specs acrord32.exe no specs acrord32.exe no specs msiexec.exe no specs regsvr32.exe no specs regsvr32.exe no specs gs1000.exe no specs msiexec.exe no specs gs1000.exe gs1000.exe explorer.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
372C:\Windows\Explorer.EXEC:\Windows\explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\winanr.dll
c:\windows\system32\wshtcpip.dll
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
404C:\Windows\system32\MsiExec.exe -Embedding 6303A1592EA75EB7E1A75F85CFC00990 CC:\Windows\system32\MsiExec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
572"C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\Rar$EXa2796.40343\GS1000_Ver_1_3_2_97_2019-12-18\gs1000_server_standard_1.3.2.97.msi" C:\Windows\System32\msiexec.exesetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
880"C:\Users\admin\AppData\Local\Temp\Rar$EXa2796.40343\GS1000_Ver_1_3_2_97_2019-12-18\setup.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2796.40343\GS1000_Ver_1_3_2_97_2019-12-18\setup.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2796.40343\gs1000_ver_1_3_2_97_2019-12-18\setup.exe
c:\systemroot\system32\ntdll.dll
1460"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe" --type=renderer "C:\Users\admin\AppData\Local\Temp\Rar$DIa2796.42673\Edited_GS1000 Server Administrator 's Manual.pdf"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exeAcroRd32.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe Acrobat Reader DC
Exit code:
1
Version:
15.23.20070.215641
Modules
Images
c:\program files\adobe\acrobat reader dc\reader\acrord32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1520"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe" "C:\Users\admin\AppData\Local\Temp\Rar$DIa2796.42673\Edited_GS1000 Server Administrator 's Manual.pdf"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exeWinRAR.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
MEDIUM
Description:
Adobe Acrobat Reader DC
Exit code:
1
Version:
15.23.20070.215641
Modules
Images
c:\program files\adobe\acrobat reader dc\reader\acrord32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1800"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe" --type=renderer "C:\Users\admin\AppData\Local\Temp\Rar$DIa2796.42004\GS1000_Revision_History_EN.pdf"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exeAcroRd32.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe Acrobat Reader DC
Exit code:
1
Version:
15.23.20070.215641
Modules
Images
c:\program files\adobe\acrobat reader dc\reader\acrord32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2076C:\Windows\system32\MsiExec.exe -Embedding 53151B51516C7805F4858156FAA4C126C:\Windows\system32\MsiExec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2296"C:\Program Files\BKC Corporation\GS1000 Server\GS1000.exe" -init -silentC:\Program Files\BKC Corporation\GS1000 Server\GS1000.exe
MsiExec.exe
User:
admin
Company:
Ingenico Group
Integrity Level:
HIGH
Description:
GS1000 Server
Exit code:
0
Version:
1.3.2.97
Modules
Images
c:\program files\bkc corporation\gs1000 server\gs1000.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wkscli.dll
2484"C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\BKC Corporation\Common Files\gmi8583c.dll"C:\Windows\system32\regsvr32.exeMsiExec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft(C) Register Server
Exit code:
4
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
4 128
Read events
3 328
Write events
773
Delete events
27

Modification events

(PID) Process:(2796) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2796) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2796) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2796) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\GS1000_Ver_1_3_2_97_2019-12-18_Bộ cài và hướng dẫn cài đặt.zip
(PID) Process:(2796) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2796) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2796) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2796) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(372) explorer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.zip\OpenWithList
Operation:writeName:a
Value:
WinRAR.exe
(PID) Process:(372) explorer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.zip\OpenWithList
Operation:writeName:MRUList
Value:
a
Executable files
23
Suspicious files
12
Text files
3
Unknown types
10

Dropped files

PID
Process
Filename
Type
2796WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2796.40343\GS1000_Ver_1_3_2_97_2019-12-18\GS1000_Server_Standard_1.3.2.97.msi
MD5:
SHA256:
572msiexec.exeC:\Users\admin\AppData\Local\Temp\MSIA9E4.tmp
MD5:
SHA256:
1800AcroRd32.exeC:\Users\admin\AppData\Local\Adobe\Acrobat\DC\Cache\AdobeFnt16.lst.1800
MD5:
SHA256:
1800AcroRd32.exeC:\Users\admin\AppData\Local\Adobe\Acrobat\DC\AdobeFnt16.lst.1800
MD5:
SHA256:
3944msiexec.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
3944msiexec.exeC:\Windows\Installer\a70cd4.msi
MD5:
SHA256:
3944msiexec.exeC:\Users\admin\AppData\Local\Temp\~DF4DE82A6610B1B9B8.TMP
MD5:
SHA256:
2796WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DIa2796.42673\Edited_GS1000 Server Administrator 's Manual.pdfpdf
MD5:
SHA256:
2796WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2796.40343\GS1000_Ver_1_3_2_97_2019-12-18\Edited_GS1000 Server Administrator 's Manual.pdfpdf
MD5:
SHA256:
3944msiexec.exeC:\System Volume Information\SPP\snapshot-2binary
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
Process
Message
GS1000.exe
Client List :0
GS1000.exe
Routes List :16
GS1000.exe
OnUseSoft