File name:

UserBenchMark.zip

Full analysis: https://app.any.run/tasks/b7f51be6-acff-4527-bfdb-3ec96a01aa47
Verdict: Malicious activity
Analysis date: February 07, 2025, 16:07:48
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
arch-exec
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

B5746C8087A4AAD562ED09986A885A74

SHA1:

9D9D96EFAD3BB787EE128ED46648B35DE3F65625

SHA256:

8CA4F87E4430027B9D8BB32F50FB76CC4AA4D4458F41E0F19FACAC27358D08DF

SSDEEP:

98304:bmIMEaNtswDgmZhNJ7f7DZBAFNsKTgUnZTO3PMZeVnur8qn+uqp72WYI1g/oR4iX:QyG6zNCu77/cO7n3La

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 1984)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 1984)
      • UserBenchMark.exe (PID: 2604)
    • The process creates files with name similar to system file names

      • UserBenchMark.exe (PID: 2604)
    • Executable content was dropped or overwritten

      • UserBenchMark.exe (PID: 2604)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • UserBenchMark.exe (PID: 2604)
    • There is functionality for taking screenshot (YARA)

      • UserBenchMark.exe (PID: 2604)
    • Process drops legitimate windows executable

      • UserBenchMark.exe (PID: 2604)
    • Reads the Internet Settings

      • UserBenchMark.exe (PID: 2604)
    • Reads settings of System Certificates

      • UserBenchMark.exe (PID: 2604)
    • Checks Windows Trust Settings

      • UserBenchMark.exe (PID: 2604)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1984)
    • Create files in a temporary directory

      • UserBenchMark.exe (PID: 2604)
    • Checks supported languages

      • UserBenchMark.exe (PID: 2604)
      • wmpnscfg.exe (PID: 120)
    • The sample compiled with english language support

      • UserBenchMark.exe (PID: 2604)
    • Checks proxy server information

      • UserBenchMark.exe (PID: 2604)
    • Reads the machine GUID from the registry

      • UserBenchMark.exe (PID: 2604)
    • Reads the software policy settings

      • UserBenchMark.exe (PID: 2604)
    • Creates files or folders in the user directory

      • UserBenchMark.exe (PID: 2604)
    • Reads the computer name

      • UserBenchMark.exe (PID: 2604)
      • wmpnscfg.exe (PID: 120)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 120)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2021:06:22 14:33:56
ZipCRC: 0x410b7c2f
ZipCompressedSize: 8450240
ZipUncompressedSize: 8474901
ZipFileName: UserBenchMark.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
41
Monitored processes
4
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe userbenchmark.exe no specs userbenchmark.exe wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
120"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1500"C:\Users\admin\AppData\Local\Temp\Rar$EXa1984.29843\UserBenchMark.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa1984.29843\UserBenchMark.exeWinRAR.exe
User:
admin
Company:
UserBenchmark.com
Integrity Level:
MEDIUM
Description:
Benchmark Software
Exit code:
3221226540
Version:
3.0.3.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa1984.29843\userbenchmark.exe
c:\windows\system32\ntdll.dll
1984"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\Desktop\UserBenchMark.zipC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2604"C:\Users\admin\AppData\Local\Temp\Rar$EXa1984.29843\UserBenchMark.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa1984.29843\UserBenchMark.exe
WinRAR.exe
User:
admin
Company:
UserBenchmark.com
Integrity Level:
HIGH
Description:
Benchmark Software
Exit code:
2
Version:
3.0.3.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa1984.29843\userbenchmark.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
Total events
6 437
Read events
6 378
Write events
53
Delete events
6

Modification events

(PID) Process:(1984) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1984) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1984) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1984) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(1984) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(1984) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(1984) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\UserBenchMark.zip
(PID) Process:(1984) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1984) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1984) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
19
Suspicious files
42
Text files
23
Unknown types
0

Dropped files

PID
Process
Filename
Type
2604UserBenchMark.exeC:\Users\admin\AppData\Local\Temp\UserBenchMarkTemp\UserBenchMarkRunEngine.exeexecutable
MD5:2D15813586095BB58BA07E509421C8FD
SHA256:B82E4EAB9DD2FB9B03C52367DEE342AA364163AA60E49D232A4EBEE7059D12B1
2604UserBenchMark.exeC:\Users\admin\AppData\Local\Temp\UserBenchMarkTemp\SHADOW.exeexecutable
MD5:43E30AFBAF2C69FB118C52B93C4E2BA0
SHA256:5580FED075B38123B83B7CD9FB93F5BFA5038CD49B729E79A7650AAFC61187F2
2604UserBenchMark.exeC:\Users\admin\AppData\Local\Temp\nsuC24A.tmp\System.dllexecutable
MD5:C17103AE9072A06DA581DEC998343FC1
SHA256:DC58D8AD81CACB0C1ED72E33BFF8F23EA40B5252B5BB55D393A0903E6819AE2F
2604UserBenchMark.exeC:\Users\admin\AppData\Local\Temp\UserBenchMarkTemp\UBMRAMBench.exeexecutable
MD5:7D8AC338C0C2B7D7E56B799A57D2E77F
SHA256:FF98D07A16D0F1946B857C04320FAE97E6C8AEEEFC973D012E77E39E540B392F
1984WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1984.29843\UserBenchMark.exeexecutable
MD5:D35F8246F25DC9C303B09D35E8563500
SHA256:77C3771475C31F79A4FE4B7BBEE7FD37D5516D9FD794CB4D8322F3CFEA3A106A
2604UserBenchMark.exeC:\Users\admin\AppData\Local\Temp\UserBenchMarkTemp\UBMCPUBench.exeexecutable
MD5:03BB0E9F5811ED3910C9F1891E0398DE
SHA256:E60C5CEB11D7046F32068C8132AD00B54EC046B7BE15F14A4212237E87F37A54
2604UserBenchMark.exeC:\Users\admin\AppData\Local\Temp\UserBenchMarkTemp\UBMDriveBench.exeexecutable
MD5:5F352667474D245DE59E25AB4328F839
SHA256:D752F049E8919C2C4884E4BC97A1016F8265D8FFD6957ABA4A0B6A830DB689AB
2604UserBenchMark.exeC:\Users\admin\AppData\Local\Temp\UserBenchMarkTemp\UBMGPUStats.exeexecutable
MD5:B6D5545C1D746745F66E4B01EC501345
SHA256:A664B4C84939975B2DD6ED419981197CA995DD34A76C83EE93D63D58D3832C78
2604UserBenchMark.exeC:\Users\admin\AppData\Local\Temp\UserBenchMarkTemp\Media\room.xtext
MD5:BF875FF38274997EE6D79DC7A576266B
SHA256:2558BE7FAE5778A8E05C5677F53B113B41F0E93711892EDC01A9556A00C3ACB3
2604UserBenchMark.exeC:\Users\admin\AppData\Local\Temp\UserBenchMarkTemp\Media\ring.xtext
MD5:6E6CC828BE6740F61339600F69DD6B1B
SHA256:7E9519C38EE1D48210C0EC794208EF70F483C34980788A8ED45511C09C511BEF
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
7
DNS requests
3
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2604
UserBenchMark.exe
GET
200
192.124.249.22:80
http://ocsp.godaddy.com//MEowSDBGMEQwQjAJBgUrDgMCGgUABBS2CA1fbGt26xPkOKX4ZguoUjM0TgQUQMK9J47MNIMwojPX%2B2yz8LQsgM4CCQC%2BjNaYdRjfIw%3D%3D
unknown
whitelisted
2604
UserBenchMark.exe
GET
200
192.124.249.22:80
http://ocsp.godaddy.com//MEIwQDA%2BMDwwOjAJBgUrDgMCGgUABBQdI2%2BOBkuXH93foRUj4a7lAr4rGwQUOpqFBxBnKLbv9r0FQW4gwZTaD94CAQc%3D
unknown
whitelisted
2604
UserBenchMark.exe
GET
200
192.124.249.22:80
http://ocsp.godaddy.com//MEQwQjBAMD4wPDAJBgUrDgMCGgUABBTkIInKBAzXkF0Qh0pel3lfHJ9GPAQU0sSw0pHUTBFxs2HLPaH%2B3ahq1OMCAxvnFQ%3D%3D
unknown
whitelisted
2604
UserBenchMark.exe
GET
200
84.201.210.23:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?ae3e628236565b40
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1108
svchost.exe
224.0.0.252:5355
whitelisted
2604
UserBenchMark.exe
51.161.86.168:443
www.userbenchmark.com
OVH SAS
CA
whitelisted
2604
UserBenchMark.exe
84.201.210.23:80
ctldl.windowsupdate.com
IP4NET Sp. z o.o.
PL
whitelisted
2604
UserBenchMark.exe
192.124.249.22:80
ocsp.godaddy.com
SUCURI-SEC
US
whitelisted

DNS requests

Domain
IP
Reputation
www.userbenchmark.com
  • 51.161.86.168
whitelisted
ctldl.windowsupdate.com
  • 84.201.210.23
  • 84.201.210.39
  • 217.20.57.36
  • 217.20.57.34
  • 217.20.57.18
  • 217.20.57.35
  • 217.20.57.20
  • 217.20.57.19
whitelisted
ocsp.godaddy.com
  • 192.124.249.22
  • 192.124.249.23
  • 192.124.249.41
  • 192.124.249.36
  • 192.124.249.24
whitelisted

Threats

No threats detected
No debug info