File name:

winsvcs.exe.zip

Full analysis: https://app.any.run/tasks/9dc1ae6d-1594-4de5-be5d-ee9342052c53
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: July 14, 2019, 05:23:02
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
trojan
loader
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

89E28A4E440BA39C16A7220AA673AAD3

SHA1:

84BF529F733B7C2AC081926A3C8DCA1795B06A84

SHA256:

94D1BE1F35B2CE79251C520CBDB025596D4CDE4B536FA23E6567A3F84678DBFB

SSDEEP:

1536:PoHmuTtSKDrEnxNgu/gx4QyMhehJ4SH2ztlY8vXuFTrq:Umu1YnxNa/hehJl2ztlURG

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • winsvcs.exe (PID: 2044)
      • winsvcs.exe (PID: 3200)
      • 3519342454.exe (PID: 2996)
    • Changes the autorun value in the registry

      • winsvcs.exe (PID: 2044)
    • Disables Windows Defender

      • winsvcs.exe (PID: 3200)
    • Changes Security Center notification settings

      • winsvcs.exe (PID: 3200)
    • Disables Windows System Restore

      • winsvcs.exe (PID: 3200)
    • Downloads executable files from the Internet

      • winsvcs.exe (PID: 3200)
  • SUSPICIOUS

    • Starts itself from another location

      • winsvcs.exe (PID: 2044)
    • Executable content was dropped or overwritten

      • winsvcs.exe (PID: 2044)
      • winsvcs.exe (PID: 3200)
    • Creates files in the user directory

      • winsvcs.exe (PID: 3200)
    • Executes application which crashes

      • winsvcs.exe (PID: 3200)
  • INFO

    • Manual execution by user

      • winsvcs.exe (PID: 2044)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0009
ZipCompression: Unknown (99)
ZipModifyDate: 1980:00:00 00:00:00
ZipCRC: 0x00000000
ZipCompressedSize: 79299
ZipUncompressedSize: 89600
ZipFileName: 099ad82f3584a45432553e4f5f743e6e38d8fc4804809fc529fc9cac3e95ce32
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
46
Monitored processes
8
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start drop and start drop and start winrar.exe no specs winsvcs.exe winsvcs.exe 3519342454.exe no specs ntvdm.exe no specs ntvdm.exe no specs ntvdm.exe no specs ntvdm.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
184"C:\Windows\system32\ntvdm.exe" -i1 C:\Windows\system32\ntvdm.exewinsvcs.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
NTVDM.EXE
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ntvdm.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2044"C:\Users\admin\Desktop\winsvcs.exe" C:\Users\admin\Desktop\winsvcs.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\winsvcs.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\gdi32.dll
2180"C:\Windows\system32\ntvdm.exe" -i4 C:\Windows\system32\ntvdm.exewinsvcs.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
NTVDM.EXE
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ntvdm.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2628"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\winsvcs.exe.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2872"C:\Windows\system32\ntvdm.exe" -i3 C:\Windows\system32\ntvdm.exewinsvcs.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
NTVDM.EXE
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ntvdm.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2996C:\Users\admin\AppData\Local\Temp\3519342454.exeC:\Users\admin\AppData\Local\Temp\3519342454.exewinsvcs.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\3519342454.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msimg32.dll
3200C:\Users\admin\5080736074306080\winsvcs.exeC:\Users\admin\5080736074306080\winsvcs.exe
winsvcs.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\5080736074306080\winsvcs.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\gdi32.dll
3728"C:\Windows\system32\ntvdm.exe" -i2 C:\Windows\system32\ntvdm.exewinsvcs.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
NTVDM.EXE
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ntvdm.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
Total events
540
Read events
488
Write events
52
Delete events
0

Modification events

(PID) Process:(2628) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2628) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2628) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\70\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2628) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\winsvcs.exe.zip
(PID) Process:(2628) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2628) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2628) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2628) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2628) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
(PID) Process:(2628) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF790000002E0000003904000023020000
Executable files
3
Suspicious files
0
Text files
8
Unknown types
0

Dropped files

PID
Process
Filename
Type
2628WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb2628.30900\099ad82f3584a45432553e4f5f743e6e38d8fc4804809fc529fc9cac3e95ce32
MD5:
SHA256:
184ntvdm.exeC:\Users\admin\AppData\Local\Temp\scs840F.tmp
MD5:
SHA256:
184ntvdm.exeC:\Users\admin\AppData\Local\Temp\scs8410.tmp
MD5:
SHA256:
3728ntvdm.exeC:\Users\admin\AppData\Local\Temp\scs85B5.tmp
MD5:
SHA256:
3728ntvdm.exeC:\Users\admin\AppData\Local\Temp\scs85C6.tmp
MD5:
SHA256:
2872ntvdm.exeC:\Users\admin\AppData\Local\Temp\scs8826.tmp
MD5:
SHA256:
2872ntvdm.exeC:\Users\admin\AppData\Local\Temp\scs8827.tmp
MD5:
SHA256:
2180ntvdm.exeC:\Users\admin\AppData\Local\Temp\scs8AC6.tmp
MD5:
SHA256:
2180ntvdm.exeC:\Users\admin\AppData\Local\Temp\scs8AC7.tmp
MD5:
SHA256:
3200winsvcs.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGRR2OYX\1[1].exeexecutable
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
29
TCP/UDP connections
24
DNS requests
54
Threats
100

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3200
winsvcs.exe
GET
92.63.197.59:80
http://92.63.197.59/1.exe
RU
malicious
3200
winsvcs.exe
GET
92.63.197.59:80
http://92.63.197.59/2.exe
RU
malicious
3200
winsvcs.exe
GET
92.63.197.59:80
http://92.63.197.59/1.exe
RU
malicious
3200
winsvcs.exe
GET
92.63.197.59:80
http://92.63.197.59/3.exe
RU
malicious
3200
winsvcs.exe
GET
92.63.197.59:80
http://92.63.197.59/4.exe
RU
malicious
3200
winsvcs.exe
GET
92.63.197.59:80
http://92.63.197.59/2.exe
RU
malicious
3200
winsvcs.exe
GET
92.63.197.59:80
http://92.63.197.59/3.exe
RU
malicious
3200
winsvcs.exe
GET
92.63.197.59:80
http://92.63.197.59/5.exe
RU
malicious
3200
winsvcs.exe
GET
92.63.197.59:80
http://92.63.197.59/4.exe
RU
malicious
3200
winsvcs.exe
GET
92.63.197.59:80
http://92.63.197.59/5.exe
RU
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3200
winsvcs.exe
92.63.197.59:80
RU
malicious
92.63.197.59:80
RU
malicious
3200
winsvcs.exe
193.32.161.77:80
ouhfuosuoosrhfzr.su
malicious
3200
winsvcs.exe
92.63.197.153:80
RU
malicious

DNS requests

Domain
IP
Reputation
ouhfuosuoosrhfzr.su
  • 193.32.161.77
malicious
eouhoeufhhghufzr.su
unknown
ehaofehofhuhffzr.su
unknown
euaoufhaheghffzr.su
unknown
ouaoueouefnuffzr.su
unknown
uohouefhoahfufzr.su
unknown
oanfoenuoanfufzr.su
unknown
ionfneonoigidfzr.su
unknown
uandnuaoegognfzr.su
unknown
ouhfuosuoosrhfzo.su
unknown

Threats

PID
Process
Class
Message
1064
svchost.exe
Potentially Bad Traffic
ET DNS Query for .su TLD (Soviet Union) Often Malware Related
3200
winsvcs.exe
Misc Attack
ET DROP Dshield Block Listed Source group 1
3200
winsvcs.exe
A Network Trojan was detected
ET TROJAN Single char EXE direct download likely trojan (multiple families)
3200
winsvcs.exe
Potentially Bad Traffic
ET POLICY HTTP Request to .su TLD (Soviet Union) Often Malware Related
3200
winsvcs.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
3200
winsvcs.exe
A Network Trojan was detected
ET TROJAN HTTP Executable Download from suspicious domain with direct request/fake browser (multiple families)
3200
winsvcs.exe
A Network Trojan was detected
ET TROJAN Single char EXE direct download likely trojan (multiple families)
3200
winsvcs.exe
Potentially Bad Traffic
ET POLICY HTTP Request to .su TLD (Soviet Union) Often Malware Related
3200
winsvcs.exe
A Network Trojan was detected
ET TROJAN Single char EXE direct download likely trojan (multiple families)
3200
winsvcs.exe
Potentially Bad Traffic
ET POLICY HTTP Request to .su TLD (Soviet Union) Often Malware Related
No debug info