| File name: | wemod.zip |
| Full analysis: | https://app.any.run/tasks/0160b258-bd8a-48d0-973e-5f092731a637 |
| Verdict: | Malicious activity |
| Analysis date: | August 29, 2024, 07:30:22 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract, compression method=deflate |
| MD5: | 13DBE11725C430282CBC03CE65BCCB83 |
| SHA1: | BD83E067FF65100CF6E419053BE08C593CE4C513 |
| SHA256: | 8C7F03D71490D213B45BC57CF9F5E4AD3B2C3A13031A1814A7342B99B3947425 |
| SSDEEP: | 24576:TFC8eC2VHULjYUh/zyVHoH2fuyAv/QSBQTWnZS:TFC8eC2VHULjYUh/zyVIH2fuyAnQSBQP |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | 0x0001 |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2024:08:29 14:18:06 |
| ZipCRC: | 0x3e53feb4 |
| ZipCompressedSize: | 509105 |
| ZipUncompressedSize: | 1517184 |
| ZipFileName: | FoxitPDFReader111_Setup.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1076 | "C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\wemod.zip | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Version: 5.91.0 Modules
| |||||||||||||||
| 1172 | "C:\WINDOWS\system32\regsvr32.exe" /s "C:\Program Files (x86)\Foxit Software\Foxit PDF Reader\plugins\FoxitPDFReaderBrowserAx64.dll" | C:\Windows\SysWOW64\regsvr32.exe | — | FoxitPDFReader.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft(C) Register Server Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1184 | "C:\Users\admin\Desktop\FoxitPDFReader111_Setup.exe" | C:\Users\admin\Desktop\FoxitPDFReader111_Setup.exe | explorer.exe | ||||||||||||
User: admin Company: Foxit Software Inc. Integrity Level: HIGH Description: Foxit PDF Reader Setup Exit code: 0 Version: 11.1.0.52543 Modules
| |||||||||||||||
| 1288 | "C:\Program Files (x86)\Foxit Software\Foxit PDF Reader\FoxitPDFReader.exe" | C:\Program Files (x86)\Foxit Software\Foxit PDF Reader\FoxitPDFReader.exe | FoxitPDFReader111_Setup.exe | ||||||||||||
User: admin Company: Foxit Software Inc. Integrity Level: HIGH Description: Foxit PDF Reader 11.1 Version: 11.1.0.52543 Modules
| |||||||||||||||
| 2028 | "C:\Users\admin\AppData\Roaming\Foxit Software\Addon\Foxit PDF Reader\FoxitPDFReaderUpdater.exe" -updater -type "Auto Updater" -hwnd 656192 -bnoshowtip -readerpath "C:\Program Files (x86)\Foxit Software\Foxit PDF Reader\" -regpath "HKEY_CURRENT_USER\Software\Foxit Software\Foxit PDF Reader 11.0" -version "11.1.0.52543" -readerlang "en-US" -UpdateMode "1" | C:\Users\admin\AppData\Roaming\Foxit Software\Addon\Foxit PDF Reader\FoxitPDFReaderUpdater.exe | FoxitPDFReader.exe | ||||||||||||
User: admin Company: Foxit Corporation Integrity Level: HIGH Description: Foxit Updater Version: 11.1.0.52532 Modules
| |||||||||||||||
| 2088 | "C:\Program Files (x86)\Foxit Software\Foxit PDF Reader\FoxitPDFReaderUpdateService.exe" -install | C:\Program Files (x86)\Foxit Software\Foxit PDF Reader\FoxitPDFReaderUpdateService.exe | — | FoxitPDFReader.tmp | |||||||||||
User: admin Company: Foxit Software Inc. Integrity Level: HIGH Description: Foxit PDF Reader Update Service Exit code: 0 Version: 1.0.0.1 Modules
| |||||||||||||||
| 2248 | "C:\Program Files (x86)\Foxit Software\Foxit PDF Reader\FoxitPDFReaderUpdateService.exe" | C:\Program Files (x86)\Foxit Software\Foxit PDF Reader\FoxitPDFReaderUpdateService.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Foxit Software Inc. Integrity Level: SYSTEM Description: Foxit PDF Reader Update Service Version: 1.0.0.1 Modules
| |||||||||||||||
| 4076 | "C:\Program Files (x86)\Foxit Software\Foxit PDF Reader\FoxitPDFReader.exe" /register | C:\Program Files (x86)\Foxit Software\Foxit PDF Reader\FoxitPDFReader.exe | — | FoxitPDFReader.tmp | |||||||||||
User: admin Company: Foxit Software Inc. Integrity Level: HIGH Description: Foxit PDF Reader 11.1 Exit code: 0 Version: 11.1.0.52543 Modules
| |||||||||||||||
| 4528 | "C:\Program Files (x86)\Foxit Software\Foxit PDF Reader\FoxitUpdater.exe" /version 11.1.0.52543 /green 0 /appname "Foxit PDF Reader" /productid 1 /ReaderLang en_us /AgentName "Foxit Reader(bundle PhantomStd)" /AgencyID 90 /isPhantom 0 /newuser 1 /IsWin10 1 /updaterinstall Website /uninstall 0 | C:\Program Files (x86)\Foxit Software\Foxit PDF Reader\FoxitUpdater.exe | FoxitPDFReader.tmp | ||||||||||||
User: admin Company: Foxit Corporation Integrity Level: HIGH Description: Foxit Updater Exit code: 0 Version: 11.1.0.52532 Modules
| |||||||||||||||
| 4680 | "C:\WINDOWS\system32\regsvr32.exe" /s "C:\Program Files (x86)\Foxit Software\Foxit PDF Reader\Shell Extensions\FoxitPrevHndlr.dll" | C:\Windows\SysWOW64\regsvr32.exe | — | FoxitPDFReader.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft(C) Register Server Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (1076) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (1076) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (1076) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\GoogleChromeEnterpriseBundle64.zip | |||
| (PID) Process: | (1076) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\wemod.zip | |||
| (PID) Process: | (1076) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (1076) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (1076) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (1076) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (1076) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop | |||
| (PID) Process: | (1076) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface |
| Operation: | write | Name: | ShowPassword |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 4528 | FoxitUpdater.exe | C:\ProgramData\Foxit Software\Foxit PDF Reader\FoxitSensor\Sensor.db-journal | binary | |
MD5:4B75F06C8C8EC3D8F3745A64981A1A61 | SHA256:EAE7F85A6985B77CC7EC2BFEA7367BA88537E86C40F065077358F31DA1F7FAA2 | |||
| 6224 | CountInstallation.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\CCF27F457097C0D5906D923640DE6E9C | binary | |
MD5:4AB24CADB0B5905F86879BAE896A035D | SHA256:9E7D2142AF41936F2CC0BEC5A5555AFF65026161C28F79FC29636671A37E0133 | |||
| 1076 | WinRAR.exe | C:\Users\admin\Desktop\FoxitPDFReader111_Setup.exe | executable | |
MD5:D7FA5852C659DDD17D78EC93F53D9908 | SHA256:77283E0EEB8569B80BDD2EF2E5ADEE98A1F414F1AE2E19D8EF32BB159E3978C6 | |||
| 6224 | CountInstallation.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B398B80134F72209547439DB21AB308D_D14B79B440CDC26D7D21C81855E2C04D | binary | |
MD5:4D27D36E73E235278E1D51BE70DE8275 | SHA256:DE68948AF2396C818F5B0DFB82DFA9461B3DF060587328A1E77AEAA6D5577A4C | |||
| 1288 | FoxitPDFReader.exe | C:\Users\admin\AppData\Roaming\Foxit Software\Addon\Foxit PDF Reader\FoxitPDFReaderUpdater.exe | executable | |
MD5:C60F09DC035E5360846EDA1BDB295D6C | SHA256:42AC76B300A170E49657E5C68E2F0CFECDB8CD89DD1098D19BFAB3528884F3A0 | |||
| 1288 | FoxitPDFReader.exe | C:\Users\admin\AppData\Roaming\Foxit Software\Addon\Foxit PDF Reader\lang\en-US\LoupeTool_strings_en-US.xml.fx | binary | |
MD5:C3FDCB6405A8B53D274608C94D0D09F3 | SHA256:A2CF7861B8A9BF19C72694D80547A3838ED2ADAB8D22769187C0FF3FEC7C7046 | |||
| 1288 | FoxitPDFReader.exe | C:\Users\admin\AppData\Roaming\Foxit Software\Addon\Foxit PDF Reader\lang\en-US\LayerPanelToolPlugin_strings_en-US.xml.fx | binary | |
MD5:9B9E8D3AD5844B7222E13949483D3D1B | SHA256:0AEBF3DF811EA9803A6C7FE54FE945954C317F0BFC98B1F1F50964EF2AC820D3 | |||
| 1288 | FoxitPDFReader.exe | C:\Users\admin\AppData\Roaming\Foxit Software\Addon\Foxit PDF Reader\lang\en-US\Email_strings_en-US.xml.fx | binary | |
MD5:D764F15D2813154E9493F41A5672CA1F | SHA256:C53332DB06218C58B52C47EC10FDF82F0CAAD4EA4D3D811B1F9EDB904FF97DC2 | |||
| 1288 | FoxitPDFReader.exe | C:\Users\admin\AppData\Roaming\Foxit Software\Addon\Foxit PDF Reader\lang\en-US\strings_en-US.xml.fx | binary | |
MD5:C183AE169FDE46B8E3F35D20092975FE | SHA256:6EFE319CACE4063F8D8F4432469F0D89998A8468C4335A054F4503C2FBA675B8 | |||
| 1288 | FoxitPDFReader.exe | C:\Users\admin\AppData\Roaming\Foxit Software\Addon\Foxit PDF Reader\lang\en-US\touchup_strings_en-US.xml.fx | binary | |
MD5:9850047DB0024DE3F325AF57E82DFFDC | SHA256:333D634FC0FCB051635E4949AD29FFA2297BACE237DCF895FB4C9849C2620421 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1404 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
6140 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
6140 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
7048 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
6224 | CountInstallation.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ5rEWLwbJFq%2FmAU80sm7E%3D | unknown | — | — | whitelisted |
6224 | CountInstallation.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSXi0cW5bD2WLrmnasWibg2OuPDpgQUVXRPsnJP9WC6UNHX5lFcmgGHGtcCEAoYUcrWzNNkWVgs7ELR7%2FU%3D | unknown | — | — | whitelisted |
1288 | FoxitPDFReader.exe | GET | 200 | 3.160.150.80:80 | http://ad.foxitsoftware.com/banners_de.a8199fee680a835057c132348f64e573-F06BD22D1756B4CE87C5A4BD15294E7C979300DB.zip | unknown | — | — | unknown |
1288 | FoxitPDFReader.exe | POST | 200 | 3.160.150.80:80 | http://ad.foxitsoftware.com/adserve.php | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 52.167.17.97:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2120 | MoUsoCoreWorker.exe | 52.167.17.97:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
3888 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
— | — | 40.115.3.253:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
1404 | svchost.exe | 40.126.31.69:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
1404 | svchost.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
6612 | svchost.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
1184 | FoxitPDFReader111_Setup.exe | 13.32.23.200:443 | d1qafa5kon3d4s.cloudfront.net | AMAZON-02 | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
d1qafa5kon3d4s.cloudfront.net |
| whitelisted |
d1c7htz94ypv8y.cloudfront.net |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |
Process | Message |
|---|---|
FoxitUpdater.exe | StopRequest |
FoxitPDFReader.exe | StopRequest |