| File name: | PayPal Valid Email Checker [v1.0].zip |
| Full analysis: | https://app.any.run/tasks/9261e18c-cfdc-45dd-b1fd-4e0e697972e2 |
| Verdict: | Malicious activity |
| Analysis date: | March 28, 2020, 23:11:51 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v1.0 to extract |
| MD5: | 6115F1C8BFC0B37D43C98174013D9200 |
| SHA1: | 770AEAD2EB7905E7B54F97C7CE26AAAFC7EF5233 |
| SHA256: | 82C4D0736D5AED1DCCE4905FB2BF271D3D06C53F0F5987F51FC86261B7AC94C3 |
| SSDEEP: | 24576:N9ab0vm7+6vVkIkC1bEfIjqrad2uJSjgQN/yAtsU26k:PabX7+A1bEf6JQgQN/yAqV6k |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 10 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | None |
| ZipModifyDate: | 2019:11:08 18:28:12 |
| ZipCRC: | 0x00000000 |
| ZipCompressedSize: | - |
| ZipUncompressedSize: | - |
| ZipFileName: | PayPal Valid Email Checker [v1.0]/ |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 772 | schtasks /create /tn "svchost" /tr "c:\windows\resources\svchost.exe" /sc daily /st 23:17 /f | C:\Windows\system32\schtasks.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1468 | "C:\Users\admin\Desktop\PayPal Valid Email Checker [v1.0]\PayPal Valid Email Checker [v1.0].exe" | C:\Users\admin\Desktop\PayPal Valid Email Checker [v1.0]\PayPal Valid Email Checker [v1.0].exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Version: 1.00 Modules
| |||||||||||||||
| 1760 | c:\windows\resources\spoolsv.exe PR | c:\windows\resources\spoolsv.exe | — | svchost.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Version: 1.00 Modules
| |||||||||||||||
| 2812 | "c:\users\admin\desktop\paypal valid email checker [v1.0]\paypal valid email checker [v1.0].exe " | c:\users\admin\desktop\paypal valid email checker [v1.0]\paypal valid email checker [v1.0].exe | PayPal Valid Email Checker [v1.0].exe | ||||||||||||
User: admin Integrity Level: HIGH Description: AliExpress Valid Email Checker [v1.0] Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 3056 | schtasks /create /tn "svchost" /tr "c:\windows\resources\svchost.exe" /sc daily /st 23:18 /f | C:\Windows\system32\schtasks.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3144 | c:\windows\resources\svchost.exe | c:\windows\resources\svchost.exe | spoolsv.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Version: 1.00 Modules
| |||||||||||||||
| 3168 | "C:\Users\admin\Desktop\PayPal Valid Email Checker [v1.0]\PayPal Valid Email Checker [v1.0].exe" | C:\Users\admin\Desktop\PayPal Valid Email Checker [v1.0]\PayPal Valid Email Checker [v1.0].exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Version: 1.00 Modules
| |||||||||||||||
| 3236 | schtasks /create /tn "svchost" /tr "c:\windows\resources\svchost.exe" /sc daily /st 23:15 /f | C:\Windows\system32\schtasks.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3240 | schtasks /create /tn "svchost" /tr "c:\windows\resources\svchost.exe" /sc daily /st 23:19 /f | C:\Windows\system32\schtasks.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3296 | c:\windows\resources\themes\explorer.exe | c:\windows\resources\themes\explorer.exe | icsys.icn.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Version: 1.00 Modules
| |||||||||||||||
| (PID) Process: | (3596) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3596) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3596) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3596) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\PayPal Valid Email Checker [v1.0].zip | |||
| (PID) Process: | (3596) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3596) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3596) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3596) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (3596) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin |
| Operation: | write | Name: | Placement |
Value: 2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000 | |||
| (PID) Process: | (3596) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\General |
| Operation: | write | Name: | LastFolder |
Value: C:\Users\admin\AppData\Local\Temp | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3596 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3596.238\PayPal Valid Email Checker [v1.0]\Cobisi.Net.Proxy.Net45.dll | — | |
MD5:— | SHA256:— | |||
| 3596 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3596.238\PayPal Valid Email Checker [v1.0]\Leaf.Net.dll | — | |
MD5:— | SHA256:— | |||
| 3596 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3596.238\PayPal Valid Email Checker [v1.0]\MetroFramework.Design.dll | — | |
MD5:— | SHA256:— | |||
| 3596 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3596.238\PayPal Valid Email Checker [v1.0]\MetroFramework.dll | — | |
MD5:— | SHA256:— | |||
| 3596 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3596.238\PayPal Valid Email Checker [v1.0]\MetroFramework.Fonts.dll | — | |
MD5:— | SHA256:— | |||
| 3596 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3596.238\PayPal Valid Email Checker [v1.0]\PayPal Valid Email Checker [v1.0].exe | — | |
MD5:— | SHA256:— | |||
| 3596 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3596.238\PayPal Valid Email Checker [v1.0]\SkinSoft.VisualStyler.dll | — | |
MD5:— | SHA256:— | |||
| 3596 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3596.238\PayPal Valid Email Checker [v1.0]\xNet.dll | — | |
MD5:— | SHA256:— | |||
| 1760 | spoolsv.exe | C:\Users\admin\AppData\Local\Temp\~DFB9F1479AA95351B4.TMP | — | |
MD5:— | SHA256:— | |||
| 3616 | spoolsv.exe | C:\Users\admin\AppData\Local\Temp\~DFB48D70541DB45228.TMP | — | |
MD5:— | SHA256:— | |||