File name:

ec_menu.zip

Full analysis: https://app.any.run/tasks/eb4ce0d7-2a04-4882-b79d-7aadbd5a862c
Verdict: Malicious activity
Analysis date: March 09, 2024, 17:57:11
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=store
MD5:

C472C9E110BFAACE6DDF6B5CE2E9EEE9

SHA1:

89B08E81167875D5F192CA5AE3784BE9ED727B45

SHA256:

8768E32F7FF059F758BAC2A66624D1A38FD87EDAA9985506E35E86EA286AE21A

SSDEEP:

49152:BPTTrusELxOdiBad+6vqZSwwJ2fvqRf8Yh+Foc6i6bmFFfZhiaiRkRQmFieLO43f:BPDHcxOdi8nqqJ23qRf81+c16bmF1Zwe

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 3672)
      • EcMenu.exe (PID: 3992)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • EcMenu.exe (PID: 2852)
      • EcMenu.exe (PID: 1900)
    • Reads the Internet Settings

      • EcMenu.exe (PID: 2852)
      • EcMenu.exe (PID: 1900)
    • Application launched itself

      • EcMenu.exe (PID: 2852)
      • EcMenu.exe (PID: 1900)
    • Executable content was dropped or overwritten

      • EcMenu.exe (PID: 3992)
  • INFO

    • Reads the computer name

      • EcMenu.exe (PID: 2852)
      • EcMenu.exe (PID: 3992)
      • EcMenu.exe (PID: 3684)
      • EcMenu.exe (PID: 1900)
      • EcMenu.exe (PID: 2128)
      • nircmd_X86.exe (PID: 3036)
      • EcMenu.exe (PID: 3544)
    • Checks supported languages

      • EcMenu.exe (PID: 2852)
      • EcMenu.exe (PID: 3992)
      • EcMenu.exe (PID: 1900)
      • EcMenu.exe (PID: 3684)
      • EcMenu.exe (PID: 2128)
      • nircmd_X86.exe (PID: 3036)
      • EcMenu.exe (PID: 3544)
    • Reads mouse settings

      • EcMenu.exe (PID: 2852)
      • EcMenu.exe (PID: 3992)
      • EcMenu.exe (PID: 3684)
      • EcMenu.exe (PID: 1900)
      • EcMenu.exe (PID: 2128)
      • EcMenu.exe (PID: 3544)
    • Create files in a temporary directory

      • EcMenu.exe (PID: 2852)
      • EcMenu.exe (PID: 3992)
      • EcMenu.exe (PID: 3684)
      • EcMenu.exe (PID: 1900)
      • EcMenu.exe (PID: 2128)
      • EcMenu.exe (PID: 3544)
    • Manual execution by a user

      • EcMenu.exe (PID: 2852)
      • EcMenu.exe (PID: 1900)
      • EcMenu.exe (PID: 3684)
      • nircmd_X86.exe (PID: 3036)
      • EcMenu.exe (PID: 2128)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3672)
    • Creates files in the program directory

      • EcMenu.exe (PID: 3992)
    • Reads the machine GUID from the registry

      • EcMenu.exe (PID: 3992)
      • EcMenu.exe (PID: 2128)
    • NirSoft software is detected

      • nircmd_X86.exe (PID: 3036)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2023:08:14 12:27:08
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: EcMenu_v1.6/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
53
Monitored processes
8
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe ecmenu.exe no specs ecmenu.exe ecmenu.exe no specs ecmenu.exe no specs ecmenu.exe ecmenu.exe no specs nircmd_x86.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1900"C:\Users\admin\Desktop\EcMenu_v1.6\EcMenu.exe" C:\Users\admin\Desktop\EcMenu_v1.6\EcMenu.exeexplorer.exe
User:
admin
Company:
www.sordum.org
Integrity Level:
MEDIUM
Description:
Easy Context Menu
Exit code:
0
Version:
1.6.0.0
Modules
Images
c:\users\admin\desktop\ecmenu_v1.6\ecmenu.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\version.dll
2128"C:\Program Files\Easy Context Menu\EcMenu.exe" /TempCleanC:\program files\easy context menu\EcMenu.exeexplorer.exe
User:
admin
Company:
www.sordum.org
Integrity Level:
MEDIUM
Description:
Easy Context Menu
Exit code:
0
Version:
1.6.0.0
Modules
Images
c:\program files\easy context menu\ecmenu.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\version.dll
2852"C:\Users\admin\Desktop\EcMenu_v1.6\EcMenu.exe" C:\Users\admin\Desktop\EcMenu_v1.6\EcMenu.exeexplorer.exe
User:
admin
Company:
www.sordum.org
Integrity Level:
MEDIUM
Description:
Easy Context Menu
Exit code:
0
Version:
1.6.0.0
Modules
Images
c:\users\admin\desktop\ecmenu_v1.6\ecmenu.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\version.dll
3036"C:\Program Files\Easy Context Menu\Files\nircmd\nircmd_X86.exe" emptybinC:\Program Files\Easy Context Menu\Files\nircmd\nircmd_X86.exeexplorer.exe
User:
admin
Company:
NirSoft
Integrity Level:
MEDIUM
Description:
NirCmd
Exit code:
0
Version:
2.75
Modules
Images
c:\program files\easy context menu\files\nircmd\nircmd_x86.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3544"C:\Users\admin\Desktop\EcMenu_v1.6\EcMenu.exe" /IsAdmin C:\Users\admin\Desktop\EcMenu_v1.6\EcMenu.exe
EcMenu.exe
User:
admin
Company:
www.sordum.org
Integrity Level:
HIGH
Description:
Easy Context Menu
Exit code:
0
Version:
1.6.0.0
Modules
Images
c:\users\admin\desktop\ecmenu_v1.6\ecmenu.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\version.dll
3672"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\ec_menu.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3684"C:\Program Files\Easy Context Menu\EcMenu.exe" /ChangeAttributes "C:\Users\admin\Desktop\EcMenu_v1.6\EcMenu.exe"C:\program files\easy context menu\EcMenu.exeexplorer.exe
User:
admin
Company:
www.sordum.org
Integrity Level:
MEDIUM
Description:
Easy Context Menu
Exit code:
0
Version:
1.6.0.0
Modules
Images
c:\program files\easy context menu\ecmenu.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\version.dll
3992"C:\Users\admin\Desktop\EcMenu_v1.6\EcMenu.exe" /IsAdmin C:\Users\admin\Desktop\EcMenu_v1.6\EcMenu.exe
EcMenu.exe
User:
admin
Company:
www.sordum.org
Integrity Level:
HIGH
Description:
Easy Context Menu
Exit code:
0
Version:
1.6.0.0
Modules
Images
c:\users\admin\desktop\ecmenu_v1.6\ecmenu.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\version.dll
Total events
7 232
Read events
7 137
Write events
89
Delete events
6

Modification events

(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3672) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\ec_menu.zip
(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
7
Suspicious files
5
Text files
23
Unknown types
3

Dropped files

PID
Process
Filename
Type
3672WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3672.2832\EcMenu_v1.6\Files\nircmd\NirCmd.chmchm
MD5:66729EFE2819E71C060AF7FD49732C28
SHA256:E050308C4A297F637A848109D719C65A62F6AB6ED0D854D026CC2DF257515D32
3672WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3672.2832\EcMenu_v1.6\Files\StickyNotes\StickyNotes.vbstext
MD5:6036AF57C7A434A72C39D0E35BE4C02C
SHA256:8266312E9C7249E8D840F8B4E587DE90BCFD433B00E08CA81EBF092BD8FD5C57
3672WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3672.2832\EcMenu_v1.6\EcMenu_x64.exeexecutable
MD5:D4CAE9981946B6E2FB1CF52EEDD10261
SHA256:4FC2CCF80F1DA2B3DB3F1E03A343865E255A176637FBB39B4DFE790692C7E250
3672WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3672.2832\EcMenu_v1.6\Files\Items.initext
MD5:788C708762FCA4C7CE003DC8022A660C
SHA256:233977792BE2ED7211A73AB6B0C11DD1629019E5AAB941149EEDF1035C7C5B0F
3672WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3672.2832\EcMenu_v1.6\Files\SnippingTool\SnippingTool.icoimage
MD5:DBCF83361A0C5F09FA8B3014BBAAE632
SHA256:08EFD54155921539E1EF66EC2D621224E0AEEFD35FFC1D71E2E51BF9CC86F9E7
3672WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3672.2832\EcMenu_v1.6\Files\EcMenu.initext
MD5:F420A0C948D6A7A3BAA1435EC4361877
SHA256:020C5B1E96E9284B381C110DF01BCF87B59B0A36D202CF3834F5C55435BD7A06
3992EcMenu.exeC:\Program Files\Easy Context Menu\Files\Items.initext
MD5:788C708762FCA4C7CE003DC8022A660C
SHA256:233977792BE2ED7211A73AB6B0C11DD1629019E5AAB941149EEDF1035C7C5B0F
2852EcMenu.exeC:\Users\admin\AppData\Local\Temp\aut1A2A.tmpbinary
MD5:E873276B8D3FA211A9621B1F2D967487
SHA256:BCCAB2B3C0F71B39A51D44121074A48C67D8D456E850B0A1E0C30FEE62E5960B
3672WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3672.2832\EcMenu_v1.6\Files\SnippingTool\SnippingTool.vbstext
MD5:198E2203276744B37ED3327009580034
SHA256:5922D78FA3E417E7C6287E88A2A50D2CB5F51C3CB22C5DEABF854F2A8B90867D
3992EcMenu.exeC:\Program Files\Easy Context Menu\Files\EcMenu.initext
MD5:F420A0C948D6A7A3BAA1435EC4361877
SHA256:020C5B1E96E9284B381C110DF01BCF87B59B0A36D202CF3834F5C55435BD7A06
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
224.0.0.252:5355
unknown
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info