File name:

SDI_R2408.zip

Full analysis: https://app.any.run/tasks/fbb5cd8e-9530-47a3-92ed-31ddf00d4f59
Verdict: Malicious activity
Analysis date: October 13, 2024, 14:44:01
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-doc
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=store
MD5:

BB2F5E549E66542B153D320D890B073E

SHA1:

328F4CDAA75AAB420DCDB92B0CC108E62BCB05EF

SHA256:

8DA63FBC0CE6A9DDEFE42B1A4BA91618958133D9351116A83FCAEFAB882E466A

SSDEEP:

98304:kcy3MGDUHw7g36Yik51tJlQiwm2rDR7snyiX4s3TPjauIAabGXYy7KEWxwk71a8A:8Ne8SH4i9Lxv

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Potential Corporate Privacy Violation

      • SDI_x64_R2408.exe (PID: 1576)
    • Connects to unusual port

      • SDI_x64_R2408.exe (PID: 1576)
  • INFO

    • The process uses the downloaded file

      • WinRAR.exe (PID: 6432)
    • Manual execution by a user

      • SDI_x64_R2408.exe (PID: 1576)
      • SDI_x64_R2408.exe (PID: 3852)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 6432)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0002
ZipCompression: None
ZipModifyDate: 2018:09:29 00:24:12
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: tools/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
140
Monitored processes
7
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe sdi_x64_r2408.exe no specs sdi_x64_r2408.exe conhost.exe no specs sppextcomobj.exe no specs slui.exe slui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1252"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
1576"C:\Users\admin\Desktop\SDI_x64_R2408.exe" C:\Users\admin\Desktop\SDI_x64_R2408.exe
explorer.exe
User:
admin
Company:
www.SamLab.ws
Integrity Level:
HIGH
Description:
Snappy Driver Installer
Version:
1.24 1.24.8
Modules
Images
c:\users\admin\desktop\sdi_x64_r2408.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
2056C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
3852"C:\Users\admin\Desktop\SDI_x64_R2408.exe" C:\Users\admin\Desktop\SDI_x64_R2408.exeexplorer.exe
User:
admin
Company:
www.SamLab.ws
Integrity Level:
MEDIUM
Description:
Snappy Driver Installer
Exit code:
3221226540
Version:
1.24 1.24.8
Modules
Images
c:\users\admin\desktop\sdi_x64_r2408.exe
c:\windows\system32\ntdll.dll
6432"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\SDI_R2408.zipC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
6696C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
6752\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeSDI_x64_R2408.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
5 522
Read events
5 500
Write events
9
Delete events
13

Modification events

(PID) Process:(6432) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\GoogleChromeEnterpriseBundle64.zip
(PID) Process:(6432) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\SDI_R2408.zip
(PID) Process:(6432) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(6432) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(6432) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(6432) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(6432) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:delete valueName:15
Value:
(PID) Process:(6432) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:delete valueName:14
Value:
(PID) Process:(6432) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:delete valueName:13
Value:
(PID) Process:(6432) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:delete valueName:12
Value:
Executable files
2
Suspicious files
9
Text files
239
Unknown types
0

Dropped files

PID
Process
Filename
Type
6432WinRAR.exeC:\Users\admin\Desktop\tools\SDI\langs\azerbaijan.txttext
MD5:505B0DE7B97212F78BA4266BB5A055E1
SHA256:4543E9820A0C7E0C807D18B423C0018FF8015BC8664E7F10673EF53282AFD9DA
6432WinRAR.exeC:\Users\admin\Desktop\tools\SDI\langs\belarusian.txttext
MD5:D3027F02B6B46F426891EBD063AB94CA
SHA256:B0917EF1C1C48FFCA4B2286DF41C5BF969767830D9F6F01285B5F7B3C3A9E9CB
6432WinRAR.exeC:\Users\admin\Desktop\tools\SDI\langs\chinese_tw.txttext
MD5:6B4485A8830B8E75A5D89514ACA3CDC3
SHA256:1D07EED3C3062803A3BF36E180372533B66212CB6A75EE9260C1B7A6EAB68B84
6432WinRAR.exeC:\Users\admin\Desktop\tools\SDI\langs\chinese_cn.txttext
MD5:1C0E58EFB136A5078E8D0B0A94B3B8D6
SHA256:5097B1FDE548223EE8B29A593B0F3BA7A4A1522C19A482C3DC2890048EA14844
6432WinRAR.exeC:\Users\admin\Desktop\tools\SDI\langs\catalan.txttext
MD5:76D31CEA7C4689EA1975E9F9F6776F91
SHA256:5006A1541C92CCB8AF1516677731FE97F0EADC25B5DCAD5E11DCC35E5D27792D
6432WinRAR.exeC:\Users\admin\Desktop\tools\SDI\langs\brazilian.txttext
MD5:B7840D1E918FE67A26A3657C7C2BD79C
SHA256:E882A08233547FA9BA20E24CDAF64E36206ECA8ABAF3672A6C52A85D6EFBFCED
6432WinRAR.exeC:\Users\admin\Desktop\tools\SDI\langs\arabic.txttext
MD5:59A306BD36D777E2C7EDCE73D5963825
SHA256:490C61DBDD6393A3FE7457EB3E5E5D1047DE2ED05D8DFD5EA7FFA36234BFFC37
6432WinRAR.exeC:\Users\admin\Desktop\tools\SDI\langs\armenian.txttext
MD5:8C12D4A4463BAF32E3714A5C58476022
SHA256:A5FC6D54254ECD4BF53E4495C58BD0564DEC89CE6D7462E989CD1F4E233652AC
6432WinRAR.exeC:\Users\admin\Desktop\tools\SDI\langs\estonian.txttext
MD5:724C5950CEB61C69CD8616600E5E8C18
SHA256:6F3B89F6EB5D303C5EA644026516E91EC427B9A896599BED4EB015C6A4301689
6432WinRAR.exeC:\Users\admin\Desktop\tools\SDI\langs\czech.txttext
MD5:898076B87800DEA4582E047AD919F128
SHA256:92E556B79C7A9AA1B8255FDAC3759375D0CF2BA9AA53FA64F53B323730A307EB
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
10
TCP/UDP connections
466
DNS requests
28
Threats
20

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6944
svchost.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6944
svchost.exe
GET
200
23.48.23.156:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1576
SDI_x64_R2408.exe
GET
200
185.26.122.80:80
http://sdi.com.ru/SDI_Update.torrent
unknown
unknown
1576
SDI_x64_R2408.exe
GET
192.9.228.30:8080
http://share.camoe.cn:8080/announce?info_hash=%3e%c3%e9%d1%3ff%d2%24%8d%05%b90%b7%f3xt%b3%b90v&peer_id=-LT1000-i1GH_KO!5w*s&port=6881&uploaded=0&downloaded=0&left=45782449399&corrupt=0&key=9AFC205E&event=started&numwant=200&compact=1&no_peer_id=1&supportcrypto=1&redundant=0
unknown
unknown
4360
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
2364
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
1576
SDI_x64_R2408.exe
GET
192.9.228.30:8080
http://share.camoe.cn:8080/announce?info_hash=%3e%c3%e9%d1%3ff%d2%24%8d%05%b90%b7%f3xt%b3%b90v&peer_id=-LT1000-i1GH_KO!5w*s&port=6881&uploaded=0&downloaded=911413&left=45782449399&corrupt=0&key=9AFC205E&event=started&numwant=200&compact=1&no_peer_id=1&supportcrypto=1&redundant=0
unknown
unknown
6176
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6176
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
3156
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
6944
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6988
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5488
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4360
SearchApp.exe
104.126.37.186:443
www.bing.com
Akamai International B.V.
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
6944
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6944
svchost.exe
23.48.23.156:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
6944
svchost.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
1576
SDI_x64_R2408.exe
185.26.122.80:80
sdi.com.ru
Hostland LTD
RU
suspicious

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 4.231.128.59
whitelisted
www.bing.com
  • 104.126.37.186
  • 104.126.37.130
  • 104.126.37.170
  • 104.126.37.178
  • 104.126.37.129
  • 104.126.37.160
  • 104.126.37.155
  • 104.126.37.137
  • 104.126.37.153
  • 104.126.37.163
  • 104.126.37.136
  • 104.126.37.139
  • 104.126.37.179
whitelisted
google.com
  • 216.58.206.46
whitelisted
crl.microsoft.com
  • 23.48.23.156
  • 23.48.23.143
whitelisted
www.microsoft.com
  • 184.30.21.171
  • 88.221.169.152
whitelisted
router.bittorrent.com
  • 67.215.246.10
whitelisted
router.utorrent.com
  • 82.221.103.244
whitelisted
router.bitcomet.com
unknown
sdi.com.ru
  • 185.26.122.80
unknown
ocsp.digicert.com
  • 192.229.221.95
whitelisted

Threats

PID
Process
Class
Message
1576
SDI_x64_R2408.exe
Potential Corporate Privacy Violation
ET P2P Possible Torrent Download via HTTP Request
1576
SDI_x64_R2408.exe
Potential Corporate Privacy Violation
ET P2P BitTorrent - Torrent File Downloaded
1576
SDI_x64_R2408.exe
Potential Corporate Privacy Violation
ET P2P BitTorrent DHT ping request
1576
SDI_x64_R2408.exe
Potential Corporate Privacy Violation
ET P2P Vuze BT UDP Connection (5)
1576
SDI_x64_R2408.exe
Potential Corporate Privacy Violation
GPL P2P BitTorrent announce request
1576
SDI_x64_R2408.exe
Potential Corporate Privacy Violation
ET P2P BitTorrent peer sync
1576
SDI_x64_R2408.exe
Potential Corporate Privacy Violation
ET P2P BitTorrent peer sync
1576
SDI_x64_R2408.exe
Potential Corporate Privacy Violation
ET P2P BitTorrent peer sync
1576
SDI_x64_R2408.exe
Potential Corporate Privacy Violation
GPL P2P BitTorrent transfer
1576
SDI_x64_R2408.exe
Potential Corporate Privacy Violation
GPL P2P BitTorrent transfer
No debug info