URL:

http://95.141.193.17/noload2/files/063/rsload.net.FolderSizes.rar

Full analysis: https://app.any.run/tasks/e5fcb69e-0e44-4b3d-893d-f551dc63079a
Verdict: Malicious activity
Analysis date: November 01, 2019, 06:45:42
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

6A04ACCEFFE88E862B238D170B25978B

SHA1:

792ED824EFF58F08915A23E2C2C6AA2AA3F66D2F

SHA256:

85E85B578B6C025EE39FB28E212B8BBDBEF7BC62D07816D6AA5759F639473342

SSDEEP:

3:N1Kwg5nLLQSpxUVBef90RC2mMoMOn:Cwg5L0SpaBNoL

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • keygen.exe (PID: 3316)
      • FolderSizes.exe (PID: 2764)
    • Loads dropped or rewritten executable

      • -RSLOAD.NET-fs9-setup.exe (PID: 2716)
      • MsiExec.exe (PID: 3268)
      • FolderSizes.exe (PID: 2764)
    • Changes settings of System certificates

      • -RSLOAD.NET-fs9-setup.exe (PID: 2716)
    • Loads the Task Scheduler DLL interface

      • -RSLOAD.NET-fs9-setup.exe (PID: 2716)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3636)
      • -RSLOAD.NET-fs9-setup.exe (PID: 2716)
      • msiexec.exe (PID: 3080)
    • Creates files in the user directory

      • -RSLOAD.NET-fs9-setup.exe (PID: 2716)
      • FolderSizes.exe (PID: 2764)
    • Application launched itself

      • -RSLOAD.NET-fs9-setup.exe (PID: 2716)
    • Executed as Windows Service

      • vssvc.exe (PID: 3352)
    • Creates COM task schedule object

      • MsiExec.exe (PID: 3268)
    • Reads Environment values

      • MsiExec.exe (PID: 2540)
      • MsiExec.exe (PID: 2968)
    • Starts CMD.EXE for commands execution

      • MsiExec.exe (PID: 2540)
    • Creates files in the Windows directory

      • msiexec.exe (PID: 3080)
    • Starts application with an unusual extension

      • cmd.exe (PID: 3824)
  • INFO

    • Application launched itself

      • iexplore.exe (PID: 532)
      • msiexec.exe (PID: 3080)
    • Changes internet zones settings

      • iexplore.exe (PID: 532)
    • Reads settings of System Certificates

      • iexplore.exe (PID: 532)
    • Reads Internet Cache Settings

      • iexplore.exe (PID: 3244)
      • iexplore.exe (PID: 532)
    • Manual execution by user

      • -RSLOAD.NET-fs9-setup.exe (PID: 3308)
      • keygen.exe (PID: 3316)
      • WinRAR.exe (PID: 3636)
      • -RSLOAD.NET-fs9-setup.exe (PID: 2716)
    • Loads dropped or rewritten executable

      • MsiExec.exe (PID: 2968)
      • MsiExec.exe (PID: 3196)
      • MsiExec.exe (PID: 2540)
    • Searches for installed software

      • msiexec.exe (PID: 3080)
    • Low-level read access rights to disk partition

      • vssvc.exe (PID: 3352)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 3080)
    • Creates files in the program directory

      • MsiExec.exe (PID: 2540)
      • msiexec.exe (PID: 3080)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
65
Monitored processes
18
Malicious processes
3
Suspicious processes
3

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe winrar.exe no specs winrar.exe keygen.exe no specs -rsload.net-fs9-setup.exe no specs -rsload.net-fs9-setup.exe msiexec.exe msiexec.exe no specs -rsload.net-fs9-setup.exe no specs vssvc.exe no specs msiexec.exe no specs msiexec.exe cmd.exe no specs chcp.com no specs cmd.exe no specs msiexec.exe no specs foldersizes.exe

Process information

PID
CMD
Path
Indicators
Parent process
532"C:\Program Files\Internet Explorer\iexplore.exe" "http://95.141.193.17/noload2/files/063/rsload.net.FolderSizes.rar"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
1
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
1316/C "C:\Users\admin\AppData\Local\Temp\{D8C16C35-4617-4AEE-B20C-8503DE14FBCE}.bat"C:\Windows\system32\cmd.exeMsiExec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2540C:\Windows\system32\MsiExec.exe -Embedding 20CEE9ABA585AAA7764657C15F006E99 M Global\MSI0000C:\Windows\system32\MsiExec.exe
msiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2716"C:\Users\admin\Desktop\-RSLOAD.NET-fs9-setup.exe" C:\Users\admin\Desktop\-RSLOAD.NET-fs9-setup.exe
explorer.exe
User:
admin
Company:
Key Metric Software
Integrity Level:
HIGH
Description:
FolderSizes 9 Installer
Exit code:
0
Version:
9.0.250
Modules
Images
c:\users\admin\desktop\-rsload.net-fs9-setup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imm32.dll
2764"C:\Program Files\Key Metric Software\FolderSizes 9\FolderSizes.exe" C:\Program Files\Key Metric Software\FolderSizes 9\FolderSizes.exe
MsiExec.exe
User:
admin
Company:
Key Metric Software, LLC.
Integrity Level:
HIGH
Description:
FolderSizes
Exit code:
0
Version:
9.0.250.0
Modules
Images
c:\program files\key metric software\foldersizes 9\foldersizes.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\vssapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\atl.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
2968C:\Windows\system32\MsiExec.exe -Embedding 9F15F4B217C0DF81512442D0D5DC156E CC:\Windows\system32\MsiExec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3008chcp 65001 C:\Windows\system32\chcp.comcmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Change CodePage Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\chcp.com
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3080C:\Windows\system32\msiexec.exe /VC:\Windows\system32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3164"C:\Users\admin\Desktop\-RSLOAD.NET-fs9-setup.exe" /i "C:\Users\admin\AppData\Roaming\Key Metric Software\FolderSizes 9 9.0.250\install\CAA5C13\fs9-setup.msi" AI_EUIMSI=1 APPDIR="C:\Program Files\Key Metric Software\FolderSizes 9" SHORTCUTDIR="C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FolderSizes 9" SECONDSEQUENCE="1" CLIENTPROCESSID="2716" CHAINERUIPROCESSID="2716Chainer" ACTION="INSTALL" EXECUTEACTION="INSTALL" CLIENTUILEVEL="0" ADDLOCAL="AI32BitFiles,AIOtherFiles,FolderSizes,ShellContext" ALLUSERS="1" PRIMARYFOLDER="APPDIR" ROOTDRIVE="C:\" AI_SETUPEXEPATH="C:\Users\admin\Desktop\-RSLOAD.NET-fs9-setup.exe" SETUPEXEDIR="C:\Users\admin\Desktop\" EXE_CMD_LINE="/exenoupdates /forcecleanup " AI_SETUPEXEPATH_ORIGINAL="C:\Users\admin\Desktop\-RSLOAD.NET-fs9-setup.exe" TARGETDIR="C:\" AI_INSTALL="1"C:\Users\admin\Desktop\-RSLOAD.NET-fs9-setup.exe-RSLOAD.NET-fs9-setup.exe
User:
admin
Company:
Key Metric Software
Integrity Level:
HIGH
Description:
FolderSizes 9 Installer
Exit code:
0
Version:
9.0.250
Modules
Images
c:\users\admin\desktop\-rsload.net-fs9-setup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imm32.dll
3196C:\Windows\system32\MsiExec.exe -Embedding 525E86BAFBC9A0DB23245EADD529A543C:\Windows\system32\MsiExec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
2 769
Read events
2 216
Write events
537
Delete events
16

Modification events

(PID) Process:(532) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(532) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(532) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(532) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones
Operation:writeName:SecuritySafe
Value:
1
(PID) Process:(532) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(532) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
4600000092000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
(PID) Process:(532) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Recovery\Active
Operation:writeName:{421BB927-FC73-11E9-AB41-5254004A04AF}
Value:
0
(PID) Process:(532) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Type
Value:
4
(PID) Process:(532) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Count
Value:
2
(PID) Process:(532) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Time
Value:
E3070B000500010006002D003A00C801
Executable files
23
Suspicious files
6
Text files
78
Unknown types
7

Dropped files

PID
Process
Filename
Type
532iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\favicon[1].ico
MD5:
SHA256:
532iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
MD5:
SHA256:
532iexplore.exeC:\Users\admin\AppData\Local\Temp\~DFBAB0997298BD4CC0.TMP
MD5:
SHA256:
3244iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\RIPZUWQN\rsload.net.FolderSizes[1].rar
MD5:
SHA256:
532iexplore.exeC:\Users\admin\Downloads\rsload.net.FolderSizes.rar
MD5:
SHA256:
532iexplore.exeC:\Users\admin\AppData\Local\Temp\~DFA966DDE3C734F77A.TMP
MD5:
SHA256:
532iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{421BB927-FC73-11E9-AB41-5254004A04AF}.dat
MD5:
SHA256:
3784WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3784.45046\keygen-zwt.rar
MD5:
SHA256:
3784WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3784.46469\-RSLOAD.NET-fs9-setup.exe
MD5:
SHA256:
2716-RSLOAD.NET-fs9-setup.exeC:\Users\admin\AppData\Roaming\Key Metric Software\FolderSizes 9 9.0.250\install\holder0.aiph
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
3
DNS requests
2
Threats
3

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3244
iexplore.exe
GET
401
95.141.193.17:80
http://95.141.193.17/noload2/files/063/rsload.net.FolderSizes.rar
RU
html
597 b
malicious
3244
iexplore.exe
GET
200
95.141.193.17:80
http://95.141.193.17/noload2/files/063/rsload.net.FolderSizes.rar
RU
compressed
34.7 Mb
malicious
2716
-RSLOAD.NET-fs9-setup.exe
GET
200
91.199.212.52:80
http://crt.comodoca.com/COMODORSAAddTrustCA.crt
GB
der
1.37 Kb
whitelisted
532
iexplore.exe
GET
200
204.79.197.200:80
http://www.bing.com/favicon.ico
US
image
237 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
532
iexplore.exe
204.79.197.200:80
www.bing.com
Microsoft Corporation
US
whitelisted
2716
-RSLOAD.NET-fs9-setup.exe
91.199.212.52:80
crt.comodoca.com
Comodo CA Ltd
GB
suspicious
3244
iexplore.exe
95.141.193.17:80
Disign-studio Altura, Ltd
RU
malicious

DNS requests

Domain
IP
Reputation
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
crt.comodoca.com
  • 91.199.212.52
whitelisted

Threats

PID
Process
Class
Message
3244
iexplore.exe
Potentially Bad Traffic
ET INFO Dotted Quad Host RAR Request
3244
iexplore.exe
Potentially Bad Traffic
ET INFO Dotted Quad Host RAR Request
3244
iexplore.exe
Potential Corporate Privacy Violation
ET POLICY Outgoing Basic Auth Base64 HTTP Password detected unencrypted
Process
Message
MsiExec.exe
DBGHELP: Symbol Search Path: .
MsiExec.exe
DBGHELP: Symbol Search Path: C:\Windows\system32
MsiExec.exe
DBGHELP: SymSrv load failure: symsrv.dll
MsiExec.exe
DBGHELP: C:\Windows\system32\ResourceCleaner.pdb - file not found
MsiExec.exe
DBGHELP: C:\Windows\system32\tmp\ResourceCleaner.pdb - file not found
MsiExec.exe
DBGHELP: C:\Windows\system32\symbols\tmp\ResourceCleaner.pdb - file not found
MsiExec.exe
DBGHELP: C:\JobRelease\win\Release\custact\x86\ResourceCleaner.pdb - file not found
MsiExec.exe
DBGHELP: MSICE1E - export symbols
MsiExec.exe
DBGHELP: C:\Windows\system32\ntdll.pdb - file not found
MsiExec.exe
DBGHELP: C:\Windows\system32\dll\ntdll.pdb - file not found