File name:

NIO PC英文界面版 V2.1.zip

Full analysis: https://app.any.run/tasks/d1452fb8-ecc4-46fe-a1b4-c72e98ada91b
Verdict: Malicious activity
Analysis date: January 27, 2021, 10:05:47
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract
MD5:

358EA166547946A5749ED253F84FD10F

SHA1:

F00C9EB3100440E4F4389801600B67BB74EA3DBD

SHA256:

824200A881330AFD6866515EE1877D25FCC4E74EBB74ACBE78A241A12BA3F4BA

SSDEEP:

49152:PE3botylWhryjTUmNYq+yd6QDyxSNnLXg1E92Ll5e8bWWO+pjph/Ony7LgU77BA+:8ofYMqtESQI2Lre8bHjdz76IX

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops executable file immediately after starts

      • NIO Smart Announcer.exe (PID: 332)
      • NIO Smart Announcer.exe (PID: 3788)
    • Application was dropped or rewritten from another process

      • NIOCONFIG.EXE (PID: 3892)
      • NIO Smart Announcer.exe (PID: 332)
      • NIO Smart Announcer.exe (PID: 3788)
      • NIO SMART ANNOUNCER.EXE (PID: 1080)
      • NIO SMART ANNOUNCER.EXE (PID: 2952)
      • NIOCONFIG.EXE (PID: 656)
  • SUSPICIOUS

    • Drops a file that was compiled in debug mode

      • WinRAR.exe (PID: 1188)
      • NIO Smart Announcer.exe (PID: 332)
      • NIO Smart Announcer.exe (PID: 3788)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1188)
      • NIO Smart Announcer.exe (PID: 332)
      • NIO Smart Announcer.exe (PID: 3788)
    • Drops a file with a compile date too recent

      • NIO Smart Announcer.exe (PID: 332)
      • NIO Smart Announcer.exe (PID: 3788)
  • INFO

    • Manual execution by user

      • NIO Smart Announcer.exe (PID: 3788)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
45
Monitored processes
7
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start drop and start drop and start drop and start drop and start winrar.exe nio smart announcer.exe nio smart announcer.exe no specs nioconfig.exe nio smart announcer.exe nio smart announcer.exe no specs nioconfig.exe

Process information

PID
CMD
Path
Indicators
Parent process
332"C:\Users\admin\AppData\Local\Temp\Rar$EXb1188.30772\NIO PC英文界面版 V2.1\NIO PC\NIO Smart Announcer.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb1188.30772\NIO PC英文界面版 V2.1\NIO PC\NIO Smart Announcer.exe
WinRAR.exe
User:
admin
Company:
广州尼罗电子科技有限公司
Integrity Level:
MEDIUM
Description:
NIO Smart Announcer
Exit code:
1
Version:
1.0.0.1
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb1188.30772\nio pc英文界面版 v2.1\nio pc\nio smart announcer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
656"C:\Users\admin\AppData\Local\Temp\NIOCONFIG.EXE" C:\Users\admin\AppData\Local\Temp\NIOCONFIG.EXE
NIO Smart Announcer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Exit code:
3762504530
Version:
0.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\nioconfig.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1080"C:\Users\admin\AppData\Local\Temp\NIO SMART ANNOUNCER.EXE" C:\Users\admin\AppData\Local\Temp\NIO SMART ANNOUNCER.EXENIO Smart Announcer.exe
User:
admin
Company:
广州尼罗电子科技有限公司
Integrity Level:
MEDIUM
Description:
NIO Smart Announcer
Exit code:
3221225547
Version:
1.0.0.1
Modules
Images
c:\users\admin\appdata\local\temp\nio smart announcer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msimg32.dll
1188"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\NIO PC英文界面版 V2.1.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2952"C:\Users\admin\AppData\Local\Temp\NIO SMART ANNOUNCER.EXE" C:\Users\admin\AppData\Local\Temp\NIO SMART ANNOUNCER.EXENIO Smart Announcer.exe
User:
admin
Company:
广州尼罗电子科技有限公司
Integrity Level:
MEDIUM
Description:
NIO Smart Announcer
Exit code:
0
Version:
1.0.0.1
Modules
Images
c:\users\admin\appdata\local\temp\nio smart announcer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msimg32.dll
3788"C:\Users\admin\Desktop\NIO PC\NIO Smart Announcer.exe" C:\Users\admin\Desktop\NIO PC\NIO Smart Announcer.exe
explorer.exe
User:
admin
Company:
广州尼罗电子科技有限公司
Integrity Level:
MEDIUM
Description:
NIO Smart Announcer
Exit code:
1
Version:
1.0.0.1
Modules
Images
c:\users\admin\desktop\nio pc\nio smart announcer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3892"C:\Users\admin\AppData\Local\Temp\NIOCONFIG.EXE" C:\Users\admin\AppData\Local\Temp\NIOCONFIG.EXE
NIO Smart Announcer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Exit code:
3762504530
Version:
0.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\nioconfig.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
1 197
Read events
1 162
Write events
34
Delete events
1

Modification events

(PID) Process:(1188) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1188) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1188) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1188) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\NIO PC英文界面版 V2.1.zip
(PID) Process:(1188) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1188) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1188) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1188) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1188) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
(PID) Process:(1188) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
Executable files
8
Suspicious files
4
Text files
53
Unknown types
1

Dropped files

PID
Process
Filename
Type
1188WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb1188.30772\NIO PC英文界面版 V2.1\NIO PC\app.conftext
MD5:
SHA256:
1188WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb1188.30772\NIO PC英文界面版 V2.1\NIO PC\imgs\btn_1007_2.bmpimage
MD5:
SHA256:
1188WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb1188.30772\NIO PC英文界面版 V2.1\NIO PC\data\usrdata.sxbinary
MD5:
SHA256:
1188WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb1188.30772\NIO PC英文界面版 V2.1\NIO PC\imgs\btn_1007_0.bmpimage
MD5:
SHA256:
1188WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb1188.30772\NIO PC英文界面版 V2.1\NIO PC\data\ttsdata.sxbinary
MD5:
SHA256:
1188WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb1188.30772\NIO PC英文界面版 V2.1\NIO PC\imgs\btn_1006_1.bmpimage
MD5:
SHA256:
1188WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb1188.30772\NIO PC英文界面版 V2.1\NIO PC\DllCrypt.dllexecutable
MD5:
SHA256:
1188WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb1188.30772\NIO PC英文界面版 V2.1\NIO PC\imgs\btn_1006_2.bmpimage
MD5:
SHA256:
1188WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb1188.30772\NIO PC英文界面版 V2.1\NIO PC\imgs\btn_1006_0.bmpimage
MD5:
SHA256:
1188WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb1188.30772\NIO PC英文界面版 V2.1\NIO PC\imgs\btn_1007_1.bmpimage
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
Process
Message
NIO Smart Announcer.exe
C:\Users\admin\AppData\Local\Temp\NIO SMART ANNOUNCER.EXE
NIO Smart Announcer.exe
C:\Users\admin\AppData\Local\Temp\NIOCONFIG.EXE
NIO Smart Announcer.exe
C:\Users\admin\AppData\Local\Temp\NIO SMART ANNOUNCER.EXE
NIO Smart Announcer.exe
C:\Users\admin\AppData\Local\Temp\NIOCONFIG.EXE