File name: | ALCOR_U2_MP_v20.09.16.00.7z |
Full analysis: | https://app.any.run/tasks/d60b5aa5-fc78-43fb-872c-54c60846fc88 |
Verdict: | Malicious activity |
Analysis date: | December 13, 2023, 07:00:34 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/x-7z-compressed |
File info: | 7-zip archive data, version 0.4 |
MD5: | 9FBC9D40C2451418FA85082FDA5E36C0 |
SHA1: | 5E679B8AA57BF5177FE25E611D6F7F7C8DE9F40D |
SHA256: | 9A2E57E380D5CBEE33D6C3B00A521337D97C0F11FF712F2D516BCE1540AA10EA |
SSDEEP: | 98304:6MOt0flQfkn2mDExSMQvhzlgjA47CMkkxgDk6SKawPXW3psZ0k1R/AdXPI7oMhGl:mexgUgqQOWXenhu |
.7z | | | 7-Zip compressed archive (v0.4) (57.1) |
---|---|---|
.7z | | | 7-Zip compressed archive (gen) (42.8) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
944 | "C:\Users\admin\Desktop\ALCOR_U2_MP_v20.09.16.00\AutoMP.exe" | C:\Users\admin\Desktop\ALCOR_U2_MP_v20.09.16.00\AutoMP.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: AutoMP Microsoft 基础类应用程序 Exit code: 2 Version: 1, 0, 0, 1 Modules
| |||||||||||||||
968 | C:\Users\admin\Desktop\ALCOR_U2_MP_v20.09.16.00\drivers\LoadDrv.exe SetIgnoreHwID 058f6387 | C:\Users\admin\Desktop\ALCOR_U2_MP_v20.09.16.00\DRIVERS\LoadDrv.exe | — | AlcorMP.exe | |||||||||||
User: admin Company: ALCOR Integrity Level: HIGH Description: LoadDrv Exit code: 0 Version: 1, 2, 0, 0 Modules
| |||||||||||||||
984 | C:\Windows\system32\DrvCovEx.exe RegisterOnly DrvCovEx | C:\Windows\System32\DrvCovEx.exe | — | LoadDrv.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 1 Modules
| |||||||||||||||
1016 | "C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe" --type=renderer --log-file="C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log" --touch-events=enabled --field-trial-handle=1164,8243647319095041121,10362609712404587434,131072 --disable-features=NetworkService,VizDisplayCompositor --disable-gpu-compositing --lang=en-US --disable-pack-loading --log-file="C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\debug.log" --log-severity=disable --product-version="ReaderServices/20.13.20064 Chrome/80.0.0.0" --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=12328738564227501697 --renderer-client-id=2 --mojo-platform-channel-handle=1172 --allow-no-sandbox-job /prefetch:1 | C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe | — | RdrCEF.exe | |||||||||||
User: admin Company: Adobe Systems Incorporated Integrity Level: LOW Description: Adobe RdrCEF Exit code: 0 Version: 20.13.20064.405839 Modules
| |||||||||||||||
1116 | "C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe" "C:\Users\admin\AppData\Local\Temp\Rar$DIa2524.35889\AU698X MP user's manual_Chinese.pdf" | C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe | — | WinRAR.exe | |||||||||||
User: admin Company: Adobe Systems Incorporated Integrity Level: MEDIUM Description: Adobe Acrobat Reader DC Exit code: 1 Version: 20.13.20064.405839 Modules
| |||||||||||||||
1352 | "C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe" --type=renderer "C:\Users\admin\AppData\Local\Temp\Rar$DIa2524.35889\AU698X MP user's manual_Chinese.pdf" | C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe | — | AcroRd32.exe | |||||||||||
User: admin Company: Adobe Systems Incorporated Integrity Level: LOW Description: Adobe Acrobat Reader DC Exit code: 1 Version: 20.13.20064.405839 Modules
| |||||||||||||||
1888 | C:\Users\admin\Desktop\ALCOR_U2_MP_v20.09.16.00\drivers\LoadDrv.exe InstByIni | C:\Users\admin\Desktop\ALCOR_U2_MP_v20.09.16.00\DRIVERS\LoadDrv.exe | — | AlcorMP.exe | |||||||||||
User: admin Company: ALCOR Integrity Level: HIGH Description: LoadDrv Exit code: 0 Version: 1, 2, 0, 0 Modules
| |||||||||||||||
2028 | C:\Windows\System32\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {995C996E-D918-4a8c-A302-45719A6F4EA7} -Embedding | C:\Windows\System32\rundll32.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
2056 | C:\Users\admin\Desktop\ALCOR_U2_MP_v20.09.16.00\drivers\KillBaboon.exe Once | C:\Users\admin\Desktop\ALCOR_U2_MP_v20.09.16.00\DRIVERS\KillBaboon.exe | — | LoadDrv.exe | |||||||||||
User: admin Integrity Level: HIGH Description: KillBaboon Exit code: 0 Version: 1, 2, 0, 0 Modules
| |||||||||||||||
2524 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\ALCOR_U2_MP_v20.09.16.00.7z" | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
|
(PID) Process: | (2524) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\17F\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (2524) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
(PID) Process: | (2524) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
(PID) Process: | (2524) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
(PID) Process: | (2524) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | name |
Value: 120 | |||
(PID) Process: | (2524) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | size |
Value: 80 | |||
(PID) Process: | (2524) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | type |
Value: 120 | |||
(PID) Process: | (2524) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | mtime |
Value: 100 | |||
(PID) Process: | (1352) AcroRd32.exe | Key: | HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\ExitSection |
Operation: | write | Name: | bLastExitNormal |
Value: 1 | |||
(PID) Process: | (1352) AcroRd32.exe | Key: | HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AVGeneral |
Operation: | write | Name: | uLastAppLaunchTimeStamp |
Value: 738908672 |
PID | Process | Filename | Type | |
---|---|---|---|---|
1352 | AcroRd32.exe | C:\Users\admin\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Reader\SOPHIA.json | binary | |
MD5:01F233C92A89C705229A0D63D09F846A | SHA256:62137C4381ACC2DE8BCA158AD9D9CE730BD7A96A39A2FB64CE7CFA5C861CF7B4 | |||
2524 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DIa2524.35889\AU698X MP user's manual_Chinese.pdf | ||
MD5:57FC8257D01A08CB974FF5A44F19B5E8 | SHA256:1BCE74E048ACDF8D6878D7613E59CCC97A3B5BE0C7E5E0059E3D5631F7CEB1D7 | |||
3940 | RdrCEF.exe | C:\Users\admin\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\4a0e94571d979b3c_0 | binary | |
MD5:2C1A2D0F3CD5744492C5754721767A6F | SHA256:D4E313DA7ED021FA87DBCD949E4E14DA7E015FA44B4260121223FF6B54DD35E1 | |||
1352 | AcroRd32.exe | C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\ES_session_storei | binary | |
MD5:C73BEC68085E957B08D29BED1AC299C3 | SHA256:135C01B699D9F78A13CA1590AB59CD01F2A508EFA799573827D8D6F1B7EC7349 | |||
3940 | RdrCEF.exe | C:\Users\admin\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\0786087c3c360803_0 | binary | |
MD5:9A454761AF910141B155CA94EE0B6ACC | SHA256:E88DECB2C9073FB5FDD42025B0CBB121BCE4B58AE1420EE01813B0F4E22000A8 | |||
1352 | AcroRd32.exe | C:\Users\admin\AppData\Local\Adobe\Acrobat\DC\IconCacheRdr65536.dat | binary | |
MD5:AEA4B7C4BD9A71FE68A3C05EA6C6B9DC | SHA256:77AF5BAF8568F3CCF91B1C21C6099A56A9E103DAA4490707E9184D227595E33B | |||
3940 | RdrCEF.exe | C:\Users\admin\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\983b7a3da8f39a46_0 | binary | |
MD5:42D7074974A53832BC5B55EDB8D6F508 | SHA256:2F7D2813AA6F43B4D8199D261328152DBE1BA70B572CDE3DD1BA998560625EC5 | |||
3940 | RdrCEF.exe | C:\Users\admin\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\bba29d2e6197e2f4_0 | binary | |
MD5:05F277B612230DA7A3036418A58A468A | SHA256:C9AE46F4B089E167D70334359C7157BB2421F43512FC81092559FFEDFCC92D4B | |||
3940 | RdrCEF.exe | C:\Users\admin\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\2a426f11fd8ebe18_0 | binary | |
MD5:90655600351A479AD1923E3D50672EDC | SHA256:672C1D1B5253E3830836DFE1CB4DD9EFCBD7BE74F83B5E13F3E90EBF974C76AC | |||
3940 | RdrCEF.exe | C:\Users\admin\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\8e417e79df3bf0e9_0 | binary | |
MD5:F79205D589E80D98DE390765C8C16F43 | SHA256:C45580524542136EC41703FC5176F48917C13974A03BF73D65ACE0EE9E783358 |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | unknown |
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | unknown |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
— | — | 192.168.100.162:49211 | — | — | — | unknown |
3716 | AlcorMP.exe | 10.5.100.215:34835 | — | — | — | unknown |
3716 | AlcorMP.exe | 16.1.64.254:34835 | — | — | US | unknown |
— | — | 192.168.100.162:49215 | — | — | — | unknown |
— | — | 192.168.100.162:49219 | — | — | — | unknown |