File name:

Radmin3521.zip

Full analysis: https://app.any.run/tasks/d01dd349-3ea2-47c5-a49a-98c8475c76fa
Verdict: Malicious activity
Analysis date: November 13, 2018, 11:42:31
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

A253894476D58F4E63C58BFD4164668F

SHA1:

B54338F8C3CB8CE9435C9DD90BFAC7976DB6BB7A

SHA256:

8CB9E13026BEEED113590342D516013AA40749139A79F75F438F5DD661297AB5

SSDEEP:

49152:bdq+QE6k8HfZlg+vAXHLznGgO1kJHrbsw4w8VierCJSqMVjKyb4ytXIjBO/QOQ5j:bQT5BfgkAbbFOIzTer3KqIjTnOKOBZg

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 716)
      • RServer3.exe (PID: 3832)
    • Application was dropped or rewritten from another process

      • rsetup.exe (PID: 3648)
      • rsetup.exe (PID: 2628)
      • rsetup.exe (PID: 1552)
      • RServer3.exe (PID: 3832)
      • FamItrfc.Exe (PID: 2168)
      • rsl.exe (PID: 2916)
  • SUSPICIOUS

    • Starts Microsoft Installer

      • WinRAR.exe (PID: 2456)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2456)
      • msiexec.exe (PID: 3460)
      • MsiExec.exe (PID: 2056)
      • msiexec.exe (PID: 3880)
      • rsetup.exe (PID: 2628)
      • DrvInst.exe (PID: 3840)
      • DrvInst.exe (PID: 3724)
    • Creates files in the Windows directory

      • msiexec.exe (PID: 3880)
      • rsetup.exe (PID: 2628)
      • DrvInst.exe (PID: 3840)
      • DrvInst.exe (PID: 3724)
      • RServer3.exe (PID: 3832)
    • Creates files in the driver directory

      • DrvInst.exe (PID: 3840)
      • DrvInst.exe (PID: 3724)
    • Creates or modifies windows services

      • DrvInst.exe (PID: 3724)
    • Removes files from Windows directory

      • DrvInst.exe (PID: 3724)
      • DrvInst.exe (PID: 3840)
    • Uses NETSH.EXE for network configuration

      • MsiExec.exe (PID: 184)
  • INFO

    • Loads dropped or rewritten executable

      • MsiExec.exe (PID: 2056)
      • MsiExec.exe (PID: 2240)
      • MsiExec.exe (PID: 184)
    • Searches for installed software

      • msiexec.exe (PID: 3880)
    • Low-level read access rights to disk partition

      • vssvc.exe (PID: 3768)
    • Creates or modifies windows services

      • msiexec.exe (PID: 3880)
      • vssvc.exe (PID: 3768)
    • Application launched itself

      • msiexec.exe (PID: 3880)
    • Creates files in the program directory

      • msiexec.exe (PID: 3880)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 3880)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.xpi | Mozilla Firefox browser extension (66.6)
.zip | ZIP compressed archive (33.3)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2018:11:13 11:04:23
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: NewTrialStop.v2.3/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
59
Monitored processes
19
Malicious processes
5
Suspicious processes
2

Behavior graph

Click at the process to see the details
start winrar.exe msiexec.exe msiexec.exe msiexec.exe vssvc.exe no specs searchprotocolhost.exe no specs drvinst.exe no specs cmd.exe msiexec.exe no specs msiexec.exe no specs rsetup.exe no specs rsetup.exe drvinst.exe drvinst.exe netsh.exe no specs rsetup.exe no specs rserver3.exe famitrfc.exe no specs rsl.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
184C:\Windows\system32\MsiExec.exe -Embedding DD5191335708A0DC036AF585891CA5CF M Global\MSI0000C:\Windows\system32\MsiExec.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
716"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe14_ Global\UsGthrCtrlFltPipeMssGthrPipe14 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1552"C:\Windows\system32\rserver30\rsetup.exe" /startC:\Windows\system32\rserver30\rsetup.exeMsiExec.exe
User:
SYSTEM
Company:
Famatech Corp.
Integrity Level:
SYSTEM
Description:
Radmin Setup Helper
Exit code:
1
Version:
3, 5, 2, 0
Modules
Images
c:\windows\system32\rserver30\rsetup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\gdi32.dll
2056C:\Windows\system32\MsiExec.exe -Embedding 43D0990024B686BBD9C9DC17B7183827 CC:\Windows\system32\MsiExec.exe
msiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2168"C:\Windows\system32\rserver30\FamItrfc.Exe"C:\Windows\system32\rserver30\FamItrfc.ExeRServer3.exe
User:
SYSTEM
Company:
Famatech Corp.
Integrity Level:
SYSTEM
Description:
Radmin component
Exit code:
0
Version:
3,5,2,1205
2240C:\Windows\system32\MsiExec.exe -Embedding 14053C0E03155427FCBA4947DFF86E7DC:\Windows\system32\MsiExec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2456"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Radmin3521.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2628"C:\Windows\system32\rserver30\rsetup.exe" /intsetupC:\Windows\system32\rserver30\rsetup.exe
MsiExec.exe
User:
SYSTEM
Company:
Famatech Corp.
Integrity Level:
SYSTEM
Description:
Radmin Setup Helper
Exit code:
1
Version:
3, 5, 2, 0
Modules
Images
c:\windows\system32\rserver30\rsetup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
2916C:\Windows\system32\rserver30\rsl.exe /setupC:\Windows\system32\rserver30\rsl.exemsiexec.exe
User:
admin
Company:
Famatech Corp.
Integrity Level:
MEDIUM
Description:
Radmin Server component
Exit code:
0
Version:
3, 5, 2, 0
3008"C:\Windows\System32\cmd.exe" /C "C:\Users\admin\Desktop\NewTrialStop.v2.3\NewTrialStop.v2.3\install.bat" C:\Windows\System32\cmd.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
1 829
Read events
1 336
Write events
480
Delete events
13

Modification events

(PID) Process:(2456) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2456) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2456) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2456) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Radmin3521.zip
(PID) Process:(2456) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2456) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2456) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2456) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2456) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
Operation:writeName:@C:\Windows\System32\msimsg.dll,-34
Value:
Windows Installer Package
(PID) Process:(2456) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
Executable files
43
Suspicious files
24
Text files
476
Unknown types
12

Dropped files

PID
Process
Filename
Type
2456WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2456.38839\Radmin_Server_3.5.2.1_EN.msi
MD5:
SHA256:
3460msiexec.exeC:\Users\admin\AppData\Local\Temp\MSICACE.tmp
MD5:
SHA256:
3880msiexec.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
2456WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2456.38839\NewTrialStop.v2.3\NewTrialStop.v2.3\READ ME - FIRST.txttext
MD5:
SHA256:
2456WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2456.38839\NewTrialStop.v2.3\NewTrialStop.v2.3\install.battext
MD5:
SHA256:
3460msiexec.exeC:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\E02357FC7708441D4B0BE5F371F4B28961870F70binary
MD5:
SHA256:
2456WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2456.38839\NewTrialStop.v2.3\NewTrialStop.v2.3\uninstall.battext
MD5:B2C688D4C753D4FFFB710B89B216316D
SHA256:A7E2A3DC19B245B55C27F60353BAC58703BF42D927A341B07677AE4731A57D23
2456WinRAR.exeC:\Users\admin\Desktop\NewTrialStop.v2.3\NewTrialStop.v2.3\install.battext
MD5:
SHA256:
2456WinRAR.exeC:\Users\admin\Desktop\NewTrialStop.v2.3\NewTrialStop.v2.3\READ ME - FIRST.txttext
MD5:
SHA256:
3300DrvInst.exeC:\Windows\INF\setupapi.dev.logini
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
Process
Message
RServer3.exe
%n%n%n%n%n%n%n%n%n