File name:

ec_menu.zip

Full analysis: https://app.any.run/tasks/eb4ce0d7-2a04-4882-b79d-7aadbd5a862c
Verdict: Malicious activity
Analysis date: March 09, 2024, 17:57:11
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=store
MD5:

C472C9E110BFAACE6DDF6B5CE2E9EEE9

SHA1:

89B08E81167875D5F192CA5AE3784BE9ED727B45

SHA256:

8768E32F7FF059F758BAC2A66624D1A38FD87EDAA9985506E35E86EA286AE21A

SSDEEP:

49152:BPTTrusELxOdiBad+6vqZSwwJ2fvqRf8Yh+Foc6i6bmFFfZhiaiRkRQmFieLO43f:BPDHcxOdi8nqqJ23qRf81+c16bmF1Zwe

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 3672)
      • EcMenu.exe (PID: 3992)
  • SUSPICIOUS

    • Application launched itself

      • EcMenu.exe (PID: 2852)
      • EcMenu.exe (PID: 1900)
    • Reads the Internet Settings

      • EcMenu.exe (PID: 2852)
      • EcMenu.exe (PID: 1900)
    • Reads security settings of Internet Explorer

      • EcMenu.exe (PID: 2852)
      • EcMenu.exe (PID: 1900)
    • Executable content was dropped or overwritten

      • EcMenu.exe (PID: 3992)
  • INFO

    • Reads mouse settings

      • EcMenu.exe (PID: 2852)
      • EcMenu.exe (PID: 3992)
      • EcMenu.exe (PID: 3684)
      • EcMenu.exe (PID: 1900)
      • EcMenu.exe (PID: 3544)
      • EcMenu.exe (PID: 2128)
    • Manual execution by a user

      • EcMenu.exe (PID: 2852)
      • EcMenu.exe (PID: 3684)
      • EcMenu.exe (PID: 1900)
      • nircmd_X86.exe (PID: 3036)
      • EcMenu.exe (PID: 2128)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3672)
    • Checks supported languages

      • EcMenu.exe (PID: 2852)
      • EcMenu.exe (PID: 3992)
      • EcMenu.exe (PID: 3684)
      • EcMenu.exe (PID: 1900)
      • EcMenu.exe (PID: 3544)
      • EcMenu.exe (PID: 2128)
      • nircmd_X86.exe (PID: 3036)
    • Reads the computer name

      • EcMenu.exe (PID: 2852)
      • EcMenu.exe (PID: 3992)
      • EcMenu.exe (PID: 3684)
      • EcMenu.exe (PID: 1900)
      • EcMenu.exe (PID: 3544)
      • nircmd_X86.exe (PID: 3036)
      • EcMenu.exe (PID: 2128)
    • Create files in a temporary directory

      • EcMenu.exe (PID: 2852)
      • EcMenu.exe (PID: 3992)
      • EcMenu.exe (PID: 3684)
      • EcMenu.exe (PID: 1900)
      • EcMenu.exe (PID: 3544)
      • EcMenu.exe (PID: 2128)
    • Creates files in the program directory

      • EcMenu.exe (PID: 3992)
    • Reads the machine GUID from the registry

      • EcMenu.exe (PID: 3992)
      • EcMenu.exe (PID: 2128)
    • NirSoft software is detected

      • nircmd_X86.exe (PID: 3036)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2023:08:14 12:27:08
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: EcMenu_v1.6/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
53
Monitored processes
8
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe ecmenu.exe no specs ecmenu.exe ecmenu.exe no specs ecmenu.exe no specs ecmenu.exe ecmenu.exe no specs nircmd_x86.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1900"C:\Users\admin\Desktop\EcMenu_v1.6\EcMenu.exe" C:\Users\admin\Desktop\EcMenu_v1.6\EcMenu.exeexplorer.exe
User:
admin
Company:
www.sordum.org
Integrity Level:
MEDIUM
Description:
Easy Context Menu
Exit code:
0
Version:
1.6.0.0
Modules
Images
c:\users\admin\desktop\ecmenu_v1.6\ecmenu.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\version.dll
2128"C:\Program Files\Easy Context Menu\EcMenu.exe" /TempCleanC:\program files\easy context menu\EcMenu.exeexplorer.exe
User:
admin
Company:
www.sordum.org
Integrity Level:
MEDIUM
Description:
Easy Context Menu
Exit code:
0
Version:
1.6.0.0
Modules
Images
c:\program files\easy context menu\ecmenu.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\version.dll
2852"C:\Users\admin\Desktop\EcMenu_v1.6\EcMenu.exe" C:\Users\admin\Desktop\EcMenu_v1.6\EcMenu.exeexplorer.exe
User:
admin
Company:
www.sordum.org
Integrity Level:
MEDIUM
Description:
Easy Context Menu
Exit code:
0
Version:
1.6.0.0
Modules
Images
c:\users\admin\desktop\ecmenu_v1.6\ecmenu.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\version.dll
3036"C:\Program Files\Easy Context Menu\Files\nircmd\nircmd_X86.exe" emptybinC:\Program Files\Easy Context Menu\Files\nircmd\nircmd_X86.exeexplorer.exe
User:
admin
Company:
NirSoft
Integrity Level:
MEDIUM
Description:
NirCmd
Exit code:
0
Version:
2.75
Modules
Images
c:\program files\easy context menu\files\nircmd\nircmd_x86.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3544"C:\Users\admin\Desktop\EcMenu_v1.6\EcMenu.exe" /IsAdmin C:\Users\admin\Desktop\EcMenu_v1.6\EcMenu.exe
EcMenu.exe
User:
admin
Company:
www.sordum.org
Integrity Level:
HIGH
Description:
Easy Context Menu
Exit code:
0
Version:
1.6.0.0
Modules
Images
c:\users\admin\desktop\ecmenu_v1.6\ecmenu.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\version.dll
3672"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\ec_menu.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3684"C:\Program Files\Easy Context Menu\EcMenu.exe" /ChangeAttributes "C:\Users\admin\Desktop\EcMenu_v1.6\EcMenu.exe"C:\program files\easy context menu\EcMenu.exeexplorer.exe
User:
admin
Company:
www.sordum.org
Integrity Level:
MEDIUM
Description:
Easy Context Menu
Exit code:
0
Version:
1.6.0.0
Modules
Images
c:\program files\easy context menu\ecmenu.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\version.dll
3992"C:\Users\admin\Desktop\EcMenu_v1.6\EcMenu.exe" /IsAdmin C:\Users\admin\Desktop\EcMenu_v1.6\EcMenu.exe
EcMenu.exe
User:
admin
Company:
www.sordum.org
Integrity Level:
HIGH
Description:
Easy Context Menu
Exit code:
0
Version:
1.6.0.0
Modules
Images
c:\users\admin\desktop\ecmenu_v1.6\ecmenu.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\version.dll
Total events
7 232
Read events
7 137
Write events
89
Delete events
6

Modification events

(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3672) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\ec_menu.zip
(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
7
Suspicious files
5
Text files
23
Unknown types
3

Dropped files

PID
Process
Filename
Type
3672WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3672.2832\EcMenu_v1.6\EcMenu_x64.exeexecutable
MD5:D4CAE9981946B6E2FB1CF52EEDD10261
SHA256:4FC2CCF80F1DA2B3DB3F1E03A343865E255A176637FBB39B4DFE790692C7E250
3672WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3672.2832\EcMenu_v1.6\Files\EcMenu.initext
MD5:F420A0C948D6A7A3BAA1435EC4361877
SHA256:020C5B1E96E9284B381C110DF01BCF87B59B0A36D202CF3834F5C55435BD7A06
3672WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3672.2832\EcMenu_v1.6\Files\nircmd\nircmd_x64.exeexecutable
MD5:80CCE4AFC880CDE9F75DC4E8B497DA80
SHA256:14801FF8D189DCD12374101754D0212BE499FCEA3CD2B967D1AE21E8BD6201E0
3672WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3672.2832\EcMenu_v1.6\Files\nircmd\nircmd_x86.exeexecutable
MD5:BA2CF7D2D09AE9A29445704BD1B4F67B
SHA256:11F02159CD9E001E9C8EB6AB3875132F77B9E9E8AF981D45D182EC71CE68C5AD
3672WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3672.2832\EcMenu_v1.6\Files\nircmd\NirCmd.chmchm
MD5:66729EFE2819E71C060AF7FD49732C28
SHA256:E050308C4A297F637A848109D719C65A62F6AB6ED0D854D026CC2DF257515D32
3672WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3672.2832\EcMenu_v1.6\Files\SnippingTool\SnippingTool.icoimage
MD5:DBCF83361A0C5F09FA8B3014BBAAE632
SHA256:08EFD54155921539E1EF66EC2D621224E0AEEFD35FFC1D71E2E51BF9CC86F9E7
2852EcMenu.exeC:\Users\admin\AppData\Local\Temp\cglhvygtext
MD5:7C319183153F20EDF870A4AE7EBACAD0
SHA256:C1013C892F31771B01743274FDFA54629D201D9594E0574093F4F11CD8A7D8F2
3672WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3672.2832\EcMenu_v1.6\Files\SnippingTool\SnippingTool.vbstext
MD5:198E2203276744B37ED3327009580034
SHA256:5922D78FA3E417E7C6287E88A2A50D2CB5F51C3CB22C5DEABF854F2A8B90867D
3672WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3672.2832\EcMenu_v1.6\Files\StickyNotes\StickyNotes.vbstext
MD5:6036AF57C7A434A72C39D0E35BE4C02C
SHA256:8266312E9C7249E8D840F8B4E587DE90BCFD433B00E08CA81EBF092BD8FD5C57
3672WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3672.2832\EcMenu_v1.6\Files\StickyNotes\StickyNotes.icoimage
MD5:0B1299C03D6105C6CEA70E1EA9856825
SHA256:08533F5CC9FBC267F212F0619411F67BB4C2960042BCD2EC869ED7CD7663C0F9
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
224.0.0.252:5355
unknown
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info