File name:

假外挂+MEMZ,密码YT666.zip

Full analysis: https://app.any.run/tasks/de26c885-1029-477f-9555-a09117143d14
Verdict: Malicious activity
Analysis date: June 25, 2018, 09:27:14
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

3CA2CC5D298B4CA64F82573D8C4417A4

SHA1:

9EAA79425F9629145987D41D91CC320380C61E34

SHA256:

98096338058C4A16F462E0F8194A94B98894C219A1644DADBDD0579B7C8C14C2

SSDEEP:

1536:gMqTo2BwAu03+m2FdqPJ/x9SQeGvA5KgZSbZXxW3bmHE6eBAIceA0HajOZewgb:gMqT4O+m46eQe0o5SbZX42EQIcepwwK

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • geometry dash auto speedhack.exe (PID: 2584)
      • geometry dash auto speedhack.exe (PID: 1524)
      • geometry dash auto speedhack.exe (PID: 2924)
      • geometry dash auto speedhack.exe (PID: 1728)
      • geometry dash auto speedhack.exe (PID: 1488)
      • geometry dash auto speedhack.exe (PID: 2700)
      • geometry dash auto speedhack.exe (PID: 3452)
      • geometry dash auto speedhack.exe (PID: 3844)
    • Low-level write access rights to disk partition

      • geometry dash auto speedhack.exe (PID: 3452)
  • SUSPICIOUS

    • Low-level read access rights to disk partition

      • geometry dash auto speedhack.exe (PID: 3452)
    • Creates files in the user directory

      • geometry dash auto speedhack.exe (PID: 3452)
    • Executable content was dropped or overwritten

      • 7zFM.exe (PID: 1004)
    • Application launched itself

      • geometry dash auto speedhack.exe (PID: 1728)
    • Starts Internet Explorer

      • geometry dash auto speedhack.exe (PID: 3452)
    • Uses TASKKILL.EXE to kill process

      • cmd.exe (PID: 1656)
  • INFO

    • Creates files in the user directory

      • iexplore.exe (PID: 2176)
      • iexplore.exe (PID: 1828)
      • iexplore.exe (PID: 3256)
      • iexplore.exe (PID: 1136)
      • iexplore.exe (PID: 3632)
    • Dropped object may contain URL's

      • 7zFM.exe (PID: 1004)
      • iexplore.exe (PID: 2688)
      • iexplore.exe (PID: 2176)
      • iexplore.exe (PID: 2024)
      • iexplore.exe (PID: 3252)
      • iexplore.exe (PID: 3256)
      • iexplore.exe (PID: 1136)
      • iexplore.exe (PID: 3632)
    • Application launched itself

      • iexplore.exe (PID: 2688)
      • iexplore.exe (PID: 2024)
      • iexplore.exe (PID: 2152)
    • Changes internet zones settings

      • iexplore.exe (PID: 2688)
      • iexplore.exe (PID: 2024)
      • iexplore.exe (PID: 3252)
      • iexplore.exe (PID: 2152)
    • Changes settings of System certificates

      • iexplore.exe (PID: 2176)
    • Adds / modifies Windows certificates

      • iexplore.exe (PID: 2176)
    • Reads internet explorer settings

      • iexplore.exe (PID: 2176)
      • iexplore.exe (PID: 1828)
      • iexplore.exe (PID: 3256)
      • iexplore.exe (PID: 1136)
      • iexplore.exe (PID: 3632)
    • Reads Internet Cache Settings

      • iexplore.exe (PID: 2176)
      • iexplore.exe (PID: 3256)
      • iexplore.exe (PID: 1828)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0001
ZipCompression: Deflated
ZipModifyDate: 2018:05:20 12:28:09
ZipCRC: 0xecbd9ea7
ZipCompressedSize: 73309
ZipUncompressedSize: 140111
ZipFileName: ????.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
64
Monitored processes
24
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start drop and start start 7zfm.exe geometry dash auto speedhack.exe no specs geometry dash auto speedhack.exe geometry dash auto speedhack.exe no specs geometry dash auto speedhack.exe no specs geometry dash auto speedhack.exe no specs geometry dash auto speedhack.exe no specs geometry dash auto speedhack.exe no specs geometry dash auto speedhack.exe notepad.exe no specs taskmgr.exe no specs iexplore.exe iexplore.exe cmd.exe no specs iexplore.exe iexplore.exe iexplore.exe iexplore.exe iexplore.exe iexplore.exe taskkill.exe no specs calc.exe no specs iexplore.exe taskkill.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
980"C:\Windows\system32\taskmgr.exe" /4C:\Windows\system32\taskmgr.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Task Manager
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskmgr.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1004"C:\Program Files\7-Zip\7zFM.exe" "C:\Users\admin\Desktop\假外挂+MEMZ,密码YT666.zip"C:\Program Files\7-Zip\7zFM.exe
explorer.exe
User:
admin
Company:
Igor Pavlov
Integrity Level:
MEDIUM
Description:
7-Zip File Manager
Exit code:
0
Version:
16.04
Modules
Images
c:\program files\7-zip\7zfm.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1136"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2152 CREDAT:79873C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Internet Explorer
Exit code:
0
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1488"C:\Users\admin\AppData\Local\Temp\7zOCE3A5ECA\geometry dash auto speedhack.exe" /watchdogC:\Users\admin\AppData\Local\Temp\7zOCE3A5ECA\geometry dash auto speedhack.exegeometry dash auto speedhack.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\7zoce3a5eca\geometry dash auto speedhack.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1524"C:\Users\admin\AppData\Local\Temp\7zOCE3A5ECA\geometry dash auto speedhack.exe" /watchdogC:\Users\admin\AppData\Local\Temp\7zOCE3A5ECA\geometry dash auto speedhack.exegeometry dash auto speedhack.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\7zoce3a5eca\geometry dash auto speedhack.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1540"C:\Windows\System32\calc.exe" C:\Windows\System32\calc.exegeometry dash auto speedhack.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Calculator
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\calc.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1656"C:\Windows\system32\cmd.exe" C:\Windows\system32\cmd.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1728"C:\Users\admin\AppData\Local\Temp\7zOCE3A5ECA\geometry dash auto speedhack.exe" C:\Users\admin\AppData\Local\Temp\7zOCE3A5ECA\geometry dash auto speedhack.exe
7zFM.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\7zoce3a5eca\geometry dash auto speedhack.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1828"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2024 CREDAT:79873C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Internet Explorer
Exit code:
0
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2024"C:\Program Files\Internet Explorer\iexplore.exe" -nohomeC:\Program Files\Internet Explorer\iexplore.exe
geometry dash auto speedhack.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Internet Explorer
Exit code:
1
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
2 488
Read events
2 165
Write events
320
Delete events
3

Modification events

(PID) Process:(1004) 7zFM.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(1004) 7zFM.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(1728) geometry dash auto speedhack.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(1728) geometry dash auto speedhack.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(3452) geometry dash auto speedhack.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(3452) geometry dash auto speedhack.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(1004) 7zFM.exeKey:HKEY_CURRENT_USER\Software\7-Zip\FM
Operation:writeName:FolderShortcuts
Value:
(PID) Process:(1004) 7zFM.exeKey:HKEY_CURRENT_USER\Software\7-Zip\FM
Operation:writeName:FolderHistory
Value:
43003A005C00550073006500720073005C00610064006D0069006E005C004400650073006B0074006F0070005C004750165902632B004D0045004D005A000CFFC65B0178590054003600360036002E007A00690070005C004D0045004D005A002E007A00690070005C004D0045004D005A005C00000043003A005C00550073006500720073005C00610064006D0069006E005C004400650073006B0074006F0070005C004750165902632B004D0045004D005A000CFFC65B0178590054003600360036002E007A00690070005C004D0045004D005A002E007A00690070005C00000043003A005C00550073006500720073005C00610064006D0069006E005C004400650073006B0074006F0070005C004750165902632B004D0045004D005A000CFFC65B0178590054003600360036002E007A00690070005C000000
(PID) Process:(1004) 7zFM.exeKey:HKEY_CURRENT_USER\Software\7-Zip\FM
Operation:writeName:PanelPath0
Value:
C:\Users\admin\Desktop\
(PID) Process:(1004) 7zFM.exeKey:HKEY_CURRENT_USER\Software\7-Zip\FM
Operation:writeName:FlatViewArc0
Value:
0
Executable files
1
Suspicious files
7
Text files
60
Unknown types
2

Dropped files

PID
Process
Filename
Type
2688iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2LKO8ICX\favicon[1].ico
MD5:
SHA256:
2688iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
MD5:
SHA256:
2176iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@google.co[1].txt
MD5:
SHA256:
2176iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LM4BD81N\search[1].txt
MD5:
SHA256:
2688iexplore.exeC:\Users\admin\AppData\Local\Temp\~DF600733749FC9DEF4.TMP
MD5:
SHA256:
2176iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@google.co[2].txttext
MD5:
SHA256:
2688iexplore.exeC:\Users\admin\AppData\Local\Temp\~DF83A59BD26EF598A0.TMP
MD5:
SHA256:
2176iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@google.co[3].txttext
MD5:
SHA256:
2688iexplore.exeC:\Users\admin\AppData\Local\Temp\~DF33366A1F17C62AC1.TMP
MD5:
SHA256:
2176iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BCPS3ZPQ\images[1].jpgimage
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
14
TCP/UDP connections
54
DNS requests
8
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2176
iexplore.exe
GET
301
216.58.206.4:80
http://google.co.ck/search?q=montage+parody+making+program+2016
US
html
264 b
whitelisted
2176
iexplore.exe
GET
302
216.58.206.3:80
http://www.google.co.ck/search?q=montage+parody+making+program+2016
US
html
280 b
whitelisted
3632
iexplore.exe
GET
302
216.58.206.3:80
http://www.google.co.ck/search?q=g3t+r3kt
US
html
254 b
whitelisted
3256
iexplore.exe
GET
302
216.58.206.3:80
http://www.google.co.ck/search?q=is+illuminati+real
US
html
264 b
whitelisted
1828
iexplore.exe
GET
301
216.58.206.4:80
http://google.co.ck/search?q=how+2+remove+a+virus
US
html
250 b
whitelisted
1828
iexplore.exe
GET
302
216.58.206.3:80
http://www.google.co.ck/search?q=how+2+remove+a+virus
US
html
266 b
whitelisted
2024
iexplore.exe
GET
200
204.79.197.229:80
http://www.bing.com/favicon.ico
US
image
237 b
whitelisted
3256
iexplore.exe
GET
301
216.58.206.4:80
http://google.co.ck/search?q=is+illuminati+real
US
html
248 b
whitelisted
3632
iexplore.exe
GET
301
216.58.206.4:80
http://google.co.ck/search?q=g3t+r3kt
US
html
238 b
whitelisted
1136
iexplore.exe
GET
302
216.58.206.3:80
http://www.google.co.ck/search?q=vinesauce+meme+collection
US
html
271 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2688
iexplore.exe
204.79.197.200:80
www.bing.com
Microsoft Corporation
US
whitelisted
2176
iexplore.exe
216.58.206.4:80
google.co.ck
Google Inc.
US
whitelisted
2176
iexplore.exe
216.58.206.3:443
www.google.co.ck
Google Inc.
US
whitelisted
1828
iexplore.exe
216.58.206.4:80
google.co.ck
Google Inc.
US
whitelisted
2024
iexplore.exe
204.79.197.229:80
www.bing.com
Microsoft Corporation
US
whitelisted
1828
iexplore.exe
216.58.206.3:80
www.google.co.ck
Google Inc.
US
whitelisted
3256
iexplore.exe
216.58.206.4:80
google.co.ck
Google Inc.
US
whitelisted
3252
iexplore.exe
204.79.197.229:80
www.bing.com
Microsoft Corporation
US
whitelisted
3256
iexplore.exe
216.58.206.3:80
www.google.co.ck
Google Inc.
US
whitelisted
3256
iexplore.exe
172.217.23.142:443
img.youtube.com
Google Inc.
US
whitelisted

DNS requests

Domain
IP
Reputation
google.co.ck
  • 216.58.206.4
whitelisted
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
  • 204.79.197.229
whitelisted
www.google.co.ck
  • 216.58.206.3
whitelisted
img.youtube.com
  • 172.217.23.142
  • 216.58.206.14
  • 216.58.207.46
  • 172.217.16.174
  • 172.217.22.46
  • 216.58.210.14
  • 216.58.214.110
  • 172.217.23.174
  • 216.58.205.238
  • 172.217.21.238
  • 172.217.22.14
  • 172.217.18.14
whitelisted
encrypted-tbn0.gstatic.com
  • 172.217.22.14
whitelisted
clients1.google.co.ck
  • 216.58.206.3
whitelisted

Threats

No threats detected
No debug info