File name:

AppNee.com.MSActBackUp.v1.2.6.7z

Full analysis: https://app.any.run/tasks/17c36154-d737-43f5-8405-122c237fee7f
Verdict: Malicious activity
Analysis date: September 30, 2020, 22:09:40
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-7z-compressed
File info: 7-zip archive data, version 0.4
MD5:

1CB4D677F638681DD4D0D2A20115D30A

SHA1:

5F34322AB6C51C624F773D8A5B4FAA41CDA55730

SHA256:

870DC0351365665834A916F4405D7359ACD7380BD8111AECE84E86063CFCBB18

SSDEEP:

6144:TChDxaihaSyTZisTs1ySWjOfcAjkgQyrR3eWpVULaPeZ50ScmYr5BO1xFy7OET4u:yDsihaPskNPikgQUheWnUIDSXYsShlN

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • MSActBackup.exe (PID: 1912)
      • MSActBackup.exe (PID: 1084)
      • pdk.dat (PID: 1692)
      • bin.dat (PID: 3376)
      • pdk.dll (PID: 2908)
    • Loads dropped or rewritten executable

      • cmd.exe (PID: 2952)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2592)
      • pdk.dat (PID: 1692)
      • MSActBackup.exe (PID: 1912)
    • Starts application with an unusual extension

      • cmd.exe (PID: 1788)
      • cmd.exe (PID: 2768)
      • cmd.exe (PID: 2952)
    • Executes scripts

      • cmd.exe (PID: 2328)
    • Starts CMD.EXE for commands execution

      • MSActBackup.exe (PID: 1912)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.7z | 7-Zip compressed archive (v0.4) (57.1)
.7z | 7-Zip compressed archive (gen) (42.8)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
55
Monitored processes
11
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
drop and start drop and start start winrar.exe msactbackup.exe no specs msactbackup.exe cmd.exe no specs pdk.dat cmd.exe no specs bin.dat no specs cmd.exe no specs cscript.exe no specs cmd.exe no specs pdk.dll no specs

Process information

PID
CMD
Path
Indicators
Parent process
1084"C:\Users\admin\AppData\Local\Temp\Rar$EXb2592.13370\MSActBackup.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb2592.13370\MSActBackup.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Description:
MSActBackUp
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb2592.13370\msactbackup.exe
c:\systemroot\system32\ntdll.dll
1692pdk.dat -y -pkmsautoC:\Users\admin\AppData\Local\Temp\pdk.dat
cmd.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\pdk.dat
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1788"C:\Windows\System32\cmd.exe" /c pdk.dat -y -pkmsautoC:\Windows\System32\cmd.exeMSActBackup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1912"C:\Users\admin\AppData\Local\Temp\Rar$EXb2592.13370\MSActBackup.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb2592.13370\MSActBackup.exe
WinRAR.exe
User:
admin
Integrity Level:
HIGH
Description:
MSActBackUp
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb2592.13370\msactbackup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\gdi32.dll
2148cscript.exe MSActBackup.vbs //NoLogoC:\Windows\system32\cscript.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft ® Console Based Script Host
Exit code:
0
Version:
5.8.7600.16385
Modules
Images
c:\windows\system32\cscript.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2328"C:\Windows\System32\cmd.exe" /c cscript.exe MSActBackup.vbs //NoLogoC:\Windows\System32\cmd.exeMSActBackup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2592"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\AppNee.com.MSActBackUp.v1.2.6.7z"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2768"C:\Windows\System32\cmd.exe" /c bin.dat -y -pkmsautoC:\Windows\System32\cmd.exeMSActBackup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2908pdk.dll /nosavereg /IEKeys 0 /WindowsKeys 1 /OfficeKeys 1 /sort 3 /ExtractEdition 1 /stextC:\Users\admin\AppData\Local\Temp\PDK\pdk.dllcmd.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\pdk\pdk.dll
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2952"C:\Windows\System32\cmd.exe" /c pdk.dll /nosavereg /IEKeys 0 /WindowsKeys 1 /OfficeKeys 1 /sort 3 /ExtractEdition 1 /stextC:\Windows\System32\cmd.exeMSActBackup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
514
Read events
497
Write events
17
Delete events
0

Modification events

(PID) Process:(2592) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2592) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2592) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2592) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\AppNee.com.MSActBackUp.v1.2.6.7z
(PID) Process:(2592) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2592) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2592) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2592) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2592) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E
Operation:writeName:@C:\Windows\System32\ieframe.dll,-10046
Value:
Internet Shortcut
(PID) Process:(2592) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E
Operation:writeName:@C:\Windows\system32\notepad.exe,-469
Value:
Text Document
Executable files
3
Suspicious files
0
Text files
4
Unknown types
0

Dropped files

PID
Process
Filename
Type
1912MSActBackup.exeC:\Users\admin\AppData\Local\Temp\pdk.dat
MD5:
SHA256:
2592WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2592.13370\Original source.urltext
MD5:
SHA256:
2592WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2592.13370\Latest version.urltext
MD5:
SHA256:
1912MSActBackup.exeC:\Users\admin\AppData\Local\Temp\bin.datexecutable
MD5:7758B09B145DB821D9BFE5D322BF9576
SHA256:635F4B5106767CC3B82E4D5FFF081A028FBBA08D0FF92C96F1163A34EAB2086C
2592WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2592.13370\MSActBackUp_readme_en.txttext
MD5:2EE066EE807268DA615A0F161A91A904
SHA256:0C5F911A51B2A0FD27B0B479D5507A63891BA72BBCBCADC64828C9C36EDC457B
1692pdk.datC:\Users\admin\AppData\Local\Temp\PDK\pdk.dllexecutable
MD5:572C3A9213B1716851E7E3C971106B01
SHA256:814320CB353BCBD7F5DF3FDB702487B14D1D1784E3AF0F78C31496742A5F97C0
3376bin.datC:\Users\admin\AppData\Local\Temp\bin\MSActBackup.vbstext
MD5:1474147D65A01143DA2E7C4169801A6C
SHA256:41DF74896F1AB540EFA72675B3FECB974AF25ABCEE7B8BB28669D84811DE3AA2
2592WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2592.13370\MSActBackup.exeexecutable
MD5:2AEFFB147C277D7F886B354C03BB8574
SHA256:CE9DDD73750D604072D62C9F7FD110FEE184EA5CF53D7197102C1DE3A861F1F0
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info