| File name: | Microsoft_Office_Starter_2010_italiano_gratis.zip |
| Full analysis: | https://app.any.run/tasks/3c5e3496-e41c-4088-8fca-e116df02d1d5 |
| Verdict: | Malicious activity |
| Threats: | A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection. |
| Analysis date: | October 29, 2020, 08:48:30 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | EB1C6A568D5A09FCEFE7E35A1AECA901 |
| SHA1: | D659A4CC16F2BECBA49EB78D0586026D942F8024 |
| SHA256: | 96D131BB40941476EBDDF354CA109B5A5C2EF79471C5AE55400B4457ABC67CD0 |
| SSDEEP: | 24576:MD9ib/I+986epSBffJA//Fl3ufH4F4vyVj2CIfySdSRP/Uk5:O9iLR2TpSlSXFMfYfh2Km4 |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2014:06:07 12:57:07 |
| ZipCRC: | 0xcc31d6fe |
| ZipCompressedSize: | 1003415 |
| ZipUncompressedSize: | 1632200 |
| ZipFileName: | OfficeStarter2010_online_installer.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 380 | "C:\Windows\system32\SearchFilterHost.exe" 0 516 520 528 65536 524 | C:\Windows\system32\SearchFilterHost.exe | — | SearchIndexer.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Windows Search Filter Host Exit code: 0 Version: 7.00.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1024 | "C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Word Exit code: 0 Version: 14.0.6024.1000 Modules
| |||||||||||||||
| 1164 | "C:\Program Files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE" | C:\Program Files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft Office Client Virtualization Service Exit code: 0 Version: 14.0.6117.5000 Modules
| |||||||||||||||
| 1324 | C:\Windows\system32\MsiExec.exe -Embedding 0EDF5AD04ED086968C15B615F48CADD0 | C:\Windows\system32\MsiExec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1596 | C:\Windows\system32\MsiExec.exe -Embedding A474C47154C1AA766E9151DC632710C0 | C:\Windows\system32\MsiExec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1748 | "C:\Windows\system32\SearchFilterHost.exe" 0 516 520 528 65536 524 | C:\Windows\system32\SearchFilterHost.exe | — | SearchIndexer.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Windows Search Filter Host Exit code: 0 Version: 7.00.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1912 | "C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe_S-1-5-21-1302019708-1500728564-335382590-10001_ Global\UsGthrCtrlFltPipeMssGthrPipe_S-1-5-21-1302019708-1500728564-335382590-10001 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" "1" | C:\Windows\system32\SearchProtocolHost.exe | — | SearchIndexer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Windows Search Protocol Host Exit code: 0 Version: 7.00.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1968 | "C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe" | C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft Application Virtualization Virtual Service Agent Exit code: 0 Version: 4.6.2.22610 Modules
| |||||||||||||||
| 2248 | C:\Windows\system32\msiexec.exe /V | C:\Windows\system32\msiexec.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2352 | C:\Windows\system32\SearchIndexer.exe /Embedding | C:\Windows\system32\SearchIndexer.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft Windows Search Indexer Exit code: 0 Version: 7.00.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (2604) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (2604) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (2604) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2604) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Microsoft_Office_Starter_2010_italiano_gratis.zip | |||
| (PID) Process: | (2604) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2604) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2604) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2604) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (2604) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin |
| Operation: | write | Name: | Placement |
Value: 2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000 | |||
| (PID) Process: | (2604) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\General |
| Operation: | write | Name: | LastFolder |
Value: C:\Users\admin\AppData\Local\Temp | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2604 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2604.17123\OfficeStarter2010_online_installer.exe | — | |
MD5:— | SHA256:— | |||
| 3064 | OfficeStarter2010_online_installer.exe | C:\Users\admin\AppData\Roaming\TP\{BFC5F7B9-7D85-46C7-8113-9F7229013DAD}\click2run.msi | — | |
MD5:— | SHA256:— | |||
| 2248 | msiexec.exe | C:\Windows\Installer\1586be.msi | — | |
MD5:— | SHA256:— | |||
| 2248 | msiexec.exe | C:\Windows\Installer\MSI8863.tmp | — | |
MD5:— | SHA256:— | |||
| 2248 | msiexec.exe | C:\Windows\Installer\MSI88E1.tmp | — | |
MD5:— | SHA256:— | |||
| 2248 | msiexec.exe | C:\Windows\Installer\MSI8940.tmp | — | |
MD5:— | SHA256:— | |||
| 2248 | msiexec.exe | C:\Windows\Installer\MSI8951.tmp | — | |
MD5:— | SHA256:— | |||
| 2248 | msiexec.exe | C:\Windows\Installer\MSI8961.tmp | — | |
MD5:— | SHA256:— | |||
| 2248 | msiexec.exe | C:\Windows\Installer\MSI8B29.tmp | — | |
MD5:— | SHA256:— | |||
| 3064 | OfficeStarter2010_online_installer.exe | C:\Users\admin\AppData\Roaming\TP\{BFC5F7B9-7D85-46C7-8113-9F7229013DAD}\descriptor.xml | text | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3476 | sftlist.exe | GET | 206 | 2.16.106.187:80 | http://c2r.microsoft.com/ConsumerC2R/it-it/14.0.4763.1000/ConsumerC2R.it-it_14.0.7261.5000.sft | unknown | binary | 370 Kb | whitelisted |
3476 | sftlist.exe | GET | 206 | 2.16.106.187:80 | http://c2r.microsoft.com/ConsumerC2R/it-it/14.0.4763.1000/ConsumerC2R.it-it_14.0.7261.5000.sft | unknown | sft | 167 b | whitelisted |
3064 | OfficeStarter2010_online_installer.exe | GET | 200 | 2.16.106.147:80 | http://c2r.microsoft.com/ConsumerC2R/it-it/14.0.4763.1000/descriptor.xml | unknown | text | 28.6 Kb | whitelisted |
3064 | OfficeStarter2010_online_installer.exe | GET | 200 | 2.16.106.147:80 | http://c2r.microsoft.com/ConsumerC2R/it-it/14.0.4763.1000/click2run.msi | unknown | executable | 25.4 Mb | whitelisted |
3064 | OfficeStarter2010_online_installer.exe | GET | 200 | 2.16.106.147:80 | http://c2r.microsoft.com/ConsumerC2R/it-it/14.0.4763.1000/72615000.cab | unknown | compressed | 2.64 Mb | whitelisted |
3064 | OfficeStarter2010_online_installer.exe | GET | 206 | 2.16.106.147:80 | http://c2r.microsoft.com/ConsumerC2R/it-it/14.0.4763.1000/ConsumerC2R.it-it_14.0.7261.5000.sft | unknown | binary | 370 Kb | whitelisted |
3064 | OfficeStarter2010_online_installer.exe | GET | 206 | 2.16.106.147:80 | http://c2r.microsoft.com/ConsumerC2R/it-it/14.0.4763.1000/ConsumerC2R.it-it_14.0.7261.5000.sft | unknown | sft | 227 Kb | whitelisted |
1164 | CVHSVC.EXE | GET | 200 | 2.16.106.147:80 | http://c2r.microsoft.com/ConsumerC2R/it-it/14.0.4763.1000/descriptor.xml | unknown | text | 28.6 Kb | whitelisted |
3064 | OfficeStarter2010_online_installer.exe | GET | 206 | 2.16.106.147:80 | http://c2r.microsoft.com/ConsumerC2R/it-it/14.0.4763.1000/ConsumerC2R.it-it_14.0.7261.5000.sft | unknown | binary | 1019 Kb | whitelisted |
3476 | sftlist.exe | GET | 200 | 2.16.186.120:80 | http://crl.microsoft.com/pki/crl/products/Microsoft%20Code%20Signing%20PCA(2).crl | unknown | der | 555 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3064 | OfficeStarter2010_online_installer.exe | 2.16.106.147:80 | c2r.microsoft.com | Akamai International B.V. | — | whitelisted |
1164 | CVHSVC.EXE | 2.16.106.147:80 | c2r.microsoft.com | Akamai International B.V. | — | whitelisted |
3476 | sftlist.exe | 2.16.186.120:80 | crl.microsoft.com | Akamai International B.V. | — | whitelisted |
3476 | sftlist.exe | 2.16.106.187:80 | c2r.microsoft.com | Akamai International B.V. | — | whitelisted |
1164 | CVHSVC.EXE | 2.22.119.33:80 | crl.microsoft.com | Akamai International B.V. | GB | whitelisted |
Domain | IP | Reputation |
|---|---|---|
c2r.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
Process | Message |
|---|---|
sftlist.exe | ReadOnly == false |