| File name: | Specification.zip |
| Full analysis: | https://app.any.run/tasks/f76a2f79-e9fe-4642-afb5-d6a5bd73d080 |
| Verdict: | Malicious activity |
| Threats: | Pony is a malware with two main functions — stealing information and dropping other viruses with different tasks on infected machines. It has been around since 2011, and it still actively attacks users in Europe and America. |
| Analysis date: | November 08, 2019, 16:56:02 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | 60F3ADC8359BDAD9884DE245058768CE |
| SHA1: | 4346DDBCEFA0FA58F1EB12EEE73D3B9F488D99A1 |
| SHA256: | 823A79FD21226D996B4C1090D94616ACC9040C8086856C0C6DADCAFA8EAE5820 |
| SSDEEP: | 1536:FowJXaCeqTmZwbMlE/+pNHc7Y2MO2Gn/jGdEm+C45kmgWBpQD6QS2co0BbqVOk+z:FZXaCehwkEGpNH5a/jgEm0YWjQOQIo0f |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2014:12:15 07:34:25 |
| ZipCRC: | 0xf2b33c2b |
| ZipCompressedSize: | 95159 |
| ZipUncompressedSize: | 209920 |
| ZipFileName: | Specification.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 292 | "C:\Users\admin\AppData\Roaming\Microsoft\Windows\Templates\takshost.exe" | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Templates\takshost.exe | takshost.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: Microsoft® User Profile Service Exit code: 0 Version: 11.42 Modules
| |||||||||||||||
| 952 | "C:\Users\admin\AppData\Roaming\Microsoft\Windows\Templates\takshost.exe" | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Templates\takshost.exe | Specification.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: Microsoft® User Profile Service Exit code: 0 Version: 11.42 Modules
| |||||||||||||||
| 1896 | "C:\Users\admin\AppData\Roaming\Microsoft\ProfSvc.exe" | C:\Users\admin\AppData\Roaming\Microsoft\ProfSvc.exe | AeLookupSvi.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: Microsoft® User Profile Service Exit code: 0 Version: 11.42 Modules
| |||||||||||||||
| 2004 | cmd /c ""C:\Users\admin\AppData\Local\Temp\3830296.bat" "C:\Users\admin\AppData\Roaming\Microsoft\ProfSvc.exe" " | C:\Windows\system32\cmd.exe | — | ProfSvc.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2304 | cmd /c ""C:\Users\admin\AppData\Local\Temp\3830703.bat" "C:\Users\admin\AppData\Roaming\Microsoft\Windows\Templates\takshost.exe" " | C:\Windows\system32\cmd.exe | — | takshost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2328 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2508.19866\Specification.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2508.19866\Specification.exe | WinRAR.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: Microsoft® User Profile Service Exit code: 0 Version: 11.42 Modules
| |||||||||||||||
| 2508 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Specification.zip" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 2812 | "C:\Users\admin\AppData\Roaming\Microsoft\AeLookupSvi.exe" | C:\Users\admin\AppData\Roaming\Microsoft\AeLookupSvi.exe | Specification.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: Application Experience Exit code: 0 Version: 0.0.0.0 Modules
| |||||||||||||||
| 3872 | cmd /c ""C:\Users\admin\AppData\Local\Temp\3816062.bat" "C:\Users\admin\AppData\Local\Temp\Rar$EXa2508.19866\Specification.exe" " | C:\Windows\system32\cmd.exe | — | Specification.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 1 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 3964 | "C:\Users\admin\AppData\Roaming\Microsoft\AeLookupSvi.exe" | C:\Users\admin\AppData\Roaming\Microsoft\AeLookupSvi.exe | ProfSvc.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: Application Experience Exit code: 0 Version: 0.0.0.0 Modules
| |||||||||||||||
| (PID) Process: | (2508) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (2508) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (2508) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2508) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Specification.zip | |||
| (PID) Process: | (2508) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2508) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2508) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2508) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (2508) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (2508) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2328 | Specification.exe | C:\Users\admin\AppData\Roaming\Microsoft\ProfSvc.exe | executable | |
MD5:— | SHA256:— | |||
| 2328 | Specification.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Templates\takshost.exe | executable | |
MD5:— | SHA256:— | |||
| 2328 | Specification.exe | C:\Users\admin\AppData\Roaming\Microsoft\AeLookupSvi.exe | executable | |
MD5:— | SHA256:— | |||
| 2508 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2508.19866\Specification.exe | executable | |
MD5:— | SHA256:— | |||
| 1896 | ProfSvc.exe | C:\Users\admin\AppData\Roaming\Microsoft\AeLookupSvi.exe | executable | |
MD5:— | SHA256:— | |||
| 952 | takshost.exe | C:\Users\admin\AppData\Roaming\Microsoft\AeLookupSvi.exe | executable | |
MD5:— | SHA256:— | |||
| 3968 | Specification.exe | C:\Users\admin\AppData\Local\Temp\3816062.bat | text | |
MD5:3880EEB1C736D853EB13B44898B718AB | SHA256:936D9411D5226B7C5A150ECAF422987590A8870C8E095E1CAA072273041A86E7 | |||
| 292 | takshost.exe | C:\Users\admin\AppData\Local\Temp\3830703.bat | text | |
MD5:3880EEB1C736D853EB13B44898B718AB | SHA256:936D9411D5226B7C5A150ECAF422987590A8870C8E095E1CAA072273041A86E7 | |||
| 3984 | ProfSvc.exe | C:\Users\admin\AppData\Local\Temp\3830296.bat | text | |
MD5:3880EEB1C736D853EB13B44898B718AB | SHA256:936D9411D5226B7C5A150ECAF422987590A8870C8E095E1CAA072273041A86E7 | |||
Domain | IP | Reputation |
|---|---|---|
silverspoontech.co.in |
| unknown |