File name:

SDI_R2408.zip

Full analysis: https://app.any.run/tasks/fbb5cd8e-9530-47a3-92ed-31ddf00d4f59
Verdict: Malicious activity
Analysis date: October 13, 2024, 14:44:01
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-doc
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=store
MD5:

BB2F5E549E66542B153D320D890B073E

SHA1:

328F4CDAA75AAB420DCDB92B0CC108E62BCB05EF

SHA256:

8DA63FBC0CE6A9DDEFE42B1A4BA91618958133D9351116A83FCAEFAB882E466A

SSDEEP:

98304:kcy3MGDUHw7g36Yik51tJlQiwm2rDR7snyiX4s3TPjauIAabGXYy7KEWxwk71a8A:8Ne8SH4i9Lxv

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Potential Corporate Privacy Violation

      • SDI_x64_R2408.exe (PID: 1576)
    • Connects to unusual port

      • SDI_x64_R2408.exe (PID: 1576)
  • INFO

    • Manual execution by a user

      • SDI_x64_R2408.exe (PID: 1576)
      • SDI_x64_R2408.exe (PID: 3852)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 6432)
    • The process uses the downloaded file

      • WinRAR.exe (PID: 6432)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0002
ZipCompression: None
ZipModifyDate: 2018:09:29 00:24:12
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: tools/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
140
Monitored processes
7
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe sdi_x64_r2408.exe no specs sdi_x64_r2408.exe conhost.exe no specs sppextcomobj.exe no specs slui.exe slui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1252"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
1576"C:\Users\admin\Desktop\SDI_x64_R2408.exe" C:\Users\admin\Desktop\SDI_x64_R2408.exe
explorer.exe
User:
admin
Company:
www.SamLab.ws
Integrity Level:
HIGH
Description:
Snappy Driver Installer
Version:
1.24 1.24.8
Modules
Images
c:\users\admin\desktop\sdi_x64_r2408.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
2056C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
3852"C:\Users\admin\Desktop\SDI_x64_R2408.exe" C:\Users\admin\Desktop\SDI_x64_R2408.exeexplorer.exe
User:
admin
Company:
www.SamLab.ws
Integrity Level:
MEDIUM
Description:
Snappy Driver Installer
Exit code:
3221226540
Version:
1.24 1.24.8
Modules
Images
c:\users\admin\desktop\sdi_x64_r2408.exe
c:\windows\system32\ntdll.dll
6432"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\SDI_R2408.zipC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
6696C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
6752\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeSDI_x64_R2408.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
5 522
Read events
5 500
Write events
9
Delete events
13

Modification events

(PID) Process:(6432) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\GoogleChromeEnterpriseBundle64.zip
(PID) Process:(6432) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\SDI_R2408.zip
(PID) Process:(6432) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(6432) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(6432) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(6432) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(6432) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:delete valueName:15
Value:
(PID) Process:(6432) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:delete valueName:14
Value:
(PID) Process:(6432) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:delete valueName:13
Value:
(PID) Process:(6432) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:delete valueName:12
Value:
Executable files
2
Suspicious files
9
Text files
239
Unknown types
0

Dropped files

PID
Process
Filename
Type
6432WinRAR.exeC:\Users\admin\Desktop\tools\SDI\langs\azerbaijan.txttext
MD5:505B0DE7B97212F78BA4266BB5A055E1
SHA256:4543E9820A0C7E0C807D18B423C0018FF8015BC8664E7F10673EF53282AFD9DA
6432WinRAR.exeC:\Users\admin\Desktop\tools\SDI\langs\chinese.txttext
MD5:49040B8AC3F1047494418AC916C4F21D
SHA256:489C0CBFB84A40C2EF7B9015F550D0F53221588024BFCE00303D9F9FE9EFD553
6432WinRAR.exeC:\Users\admin\Desktop\tools\SDI\langs\brazilian.txttext
MD5:B7840D1E918FE67A26A3657C7C2BD79C
SHA256:E882A08233547FA9BA20E24CDAF64E36206ECA8ABAF3672A6C52A85D6EFBFCED
6432WinRAR.exeC:\Users\admin\Desktop\tools\SDI\langs\armenian.txttext
MD5:8C12D4A4463BAF32E3714A5C58476022
SHA256:A5FC6D54254ECD4BF53E4495C58BD0564DEC89CE6D7462E989CD1F4E233652AC
6432WinRAR.exeC:\Users\admin\Desktop\tools\SDI\langs\chinese_cn.txttext
MD5:1C0E58EFB136A5078E8D0B0A94B3B8D6
SHA256:5097B1FDE548223EE8B29A593B0F3BA7A4A1522C19A482C3DC2890048EA14844
6432WinRAR.exeC:\Users\admin\Desktop\tools\SDI\langs\belarusian.txttext
MD5:D3027F02B6B46F426891EBD063AB94CA
SHA256:B0917EF1C1C48FFCA4B2286DF41C5BF969767830D9F6F01285B5F7B3C3A9E9CB
6432WinRAR.exeC:\Users\admin\Desktop\tools\SDI\langs\english.txttext
MD5:3847CA6996306078F53B1BD3D1CDC4A0
SHA256:CE2E90B7488184CE71B463CBB5EF594BD96FFAEA1F81473ABCC4F28851352249
6432WinRAR.exeC:\Users\admin\Desktop\tools\SDI\langs\chinese_tw.txttext
MD5:6B4485A8830B8E75A5D89514ACA3CDC3
SHA256:1D07EED3C3062803A3BF36E180372533B66212CB6A75EE9260C1B7A6EAB68B84
6432WinRAR.exeC:\Users\admin\Desktop\tools\SDI\langs\chinese_zh.txttext
MD5:EAE8E356B8D4372902F6ACA9959985F2
SHA256:4206E23A077026C61B0F57B350803327F1B0A33D2BD7B06EA47375A6E82810CD
6432WinRAR.exeC:\Users\admin\Desktop\tools\SDI\langs\croatian.txttext
MD5:B4B3114DA6380F1566C577934EFD3272
SHA256:6710177EB1CF25611A1B0560A7ED1840769A97BE26D141F366E2BA87802802AD
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
10
TCP/UDP connections
466
DNS requests
28
Threats
20

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6944
svchost.exe
GET
200
23.48.23.156:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6944
svchost.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1576
SDI_x64_R2408.exe
GET
200
185.26.122.80:80
http://sdi.com.ru/SDI_Update.torrent
unknown
4360
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
1576
SDI_x64_R2408.exe
GET
192.9.228.30:8080
http://share.camoe.cn:8080/announce?info_hash=%3e%c3%e9%d1%3ff%d2%24%8d%05%b90%b7%f3xt%b3%b90v&peer_id=-LT1000-i1GH_KO!5w*s&port=6881&uploaded=0&downloaded=0&left=45782449399&corrupt=0&key=9AFC205E&event=started&numwant=200&compact=1&no_peer_id=1&supportcrypto=1&redundant=0
unknown
2364
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
1576
SDI_x64_R2408.exe
GET
192.9.228.30:8080
http://share.camoe.cn:8080/announce?info_hash=%3e%c3%e9%d1%3ff%d2%24%8d%05%b90%b7%f3xt%b3%b90v&peer_id=-LT1000-i1GH_KO!5w*s&port=6881&uploaded=0&downloaded=911413&left=45782449399&corrupt=0&key=9AFC205E&event=started&numwant=200&compact=1&no_peer_id=1&supportcrypto=1&redundant=0
unknown
6176
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6176
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
3156
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
6944
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6988
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5488
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4360
SearchApp.exe
104.126.37.186:443
www.bing.com
Akamai International B.V.
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
6944
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6944
svchost.exe
23.48.23.156:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
6944
svchost.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
1576
SDI_x64_R2408.exe
185.26.122.80:80
sdi.com.ru
Hostland LTD
RU
suspicious

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 4.231.128.59
whitelisted
www.bing.com
  • 104.126.37.186
  • 104.126.37.130
  • 104.126.37.170
  • 104.126.37.178
  • 104.126.37.129
  • 104.126.37.160
  • 104.126.37.155
  • 104.126.37.137
  • 104.126.37.153
  • 104.126.37.163
  • 104.126.37.136
  • 104.126.37.139
  • 104.126.37.179
whitelisted
google.com
  • 216.58.206.46
whitelisted
crl.microsoft.com
  • 23.48.23.156
  • 23.48.23.143
whitelisted
www.microsoft.com
  • 184.30.21.171
  • 88.221.169.152
whitelisted
router.bittorrent.com
  • 67.215.246.10
whitelisted
router.utorrent.com
  • 82.221.103.244
whitelisted
router.bitcomet.com
unknown
sdi.com.ru
  • 185.26.122.80
unknown
ocsp.digicert.com
  • 192.229.221.95
whitelisted

Threats

PID
Process
Class
Message
Potential Corporate Privacy Violation
ET P2P Possible Torrent Download via HTTP Request
Potential Corporate Privacy Violation
ET P2P BitTorrent - Torrent File Downloaded
Potential Corporate Privacy Violation
ET P2P BitTorrent DHT ping request
Potential Corporate Privacy Violation
ET P2P Vuze BT UDP Connection (5)
Potential Corporate Privacy Violation
GPL P2P BitTorrent announce request
Potential Corporate Privacy Violation
ET P2P BitTorrent peer sync
Potential Corporate Privacy Violation
ET P2P BitTorrent peer sync
Potential Corporate Privacy Violation
ET P2P BitTorrent peer sync
Potential Corporate Privacy Violation
GPL P2P BitTorrent transfer
Potential Corporate Privacy Violation
GPL P2P BitTorrent transfer
No debug info