analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

CVE-2018-4878_#PoC#.zip

Full analysis: https://app.any.run/tasks/2b0f6b57-2142-4c4a-993f-f5ae2fd89539
Verdict: Malicious activity
Analysis date: December 06, 2018, 09:33:54
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

ACFD127D82A01F89AFA94F3FFD836BEC

SHA1:

4710F1B2B8C8784B60C00DD65ECEC7DEE912B58E

SHA256:

9A5345FBE2991EA07F050ED5C5D086CF759E11E7C2ED2A2ACD90582238A50411

SSDEEP:

192:Vt4kQYLxoDsFVlJbm9p2stwhYManoCoLdkjJil08fGO+MNSeNLX2BZ7Ldxk:Vtm2UsFLJKPxManEwOvfG/MN3Ls6

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Starts CMD.EXE for commands execution

      • iexplore.exe (PID: 3124)
    • Runs app for hidden code execution

      • iexplore.exe (PID: 3124)
  • SUSPICIOUS

    • Starts Internet Explorer

      • rundll32.exe (PID: 3060)
  • INFO

    • Reads internet explorer settings

      • iexplore.exe (PID: 3124)
    • Creates files in the user directory

      • iexplore.exe (PID: 3124)
    • Reads Internet Cache Settings

      • iexplore.exe (PID: 3124)
    • Changes internet zones settings

      • iexplore.exe (PID: 2944)
    • Application launched itself

      • iexplore.exe (PID: 2944)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: CVE-2018-4878_#PoC#/
ZipUncompressedSize: -
ZipCompressedSize: -
ZipCRC: 0x00000000
ZipModifyDate: 2018:02:13 14:00:19
ZipCompression: None
ZipBitFlag: -
ZipRequiredVersion: 20
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
41
Monitored processes
6
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs rundll32.exe no specs iexplore.exe iexplore.exe cmd.exe no specs calc.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3536"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\CVE-2018-4878_#PoC#.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.60.0
3060"C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\Desktop\CVE-2018-4878_#PoC#\CVE-2018-4878_#PoC#\CVE-2018-4878_PoC.swfC:\Windows\system32\rundll32.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
2944"C:\Program Files\Internet Explorer\iexplore.exe" C:\Users\admin\Desktop\CVE-2018-4878_#PoC#\CVE-2018-4878_#PoC#\CVE-2018-4878_PoC.swfC:\Program Files\Internet Explorer\iexplore.exe
rundll32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
3124"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2944 CREDAT:79873C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
3392C:\Windows\System32\cmd.exeC:\Windows\System32\cmd.exeiexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1278912021
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
3856calcC:\Windows\System32\calc.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Calculator
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Total events
887
Read events
744
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
0
Text files
2
Unknown types
36

Dropped files

PID
Process
Filename
Type
2944iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RB73MZ6Y\favicon[1].ico
MD5:
SHA256:
2944iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
MD5:
SHA256:
3124iexplore.exeC:\Users\admin\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\settings.sxx
MD5:
SHA256:
3124iexplore.exeC:\Users\admin\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\settings.solsol
MD5:B997568AE38E73A24A5A1B1A7D2F074F
SHA256:76D8CB31013262D56C49410869B11983266E0F0A76952C6A111B81B89FF7938B
3536WinRAR.exeC:\Users\admin\Desktop\CVE-2018-4878_#PoC#\CVE-2018-4878_#PoC#\CVE-2018-4878_PoC.swfswf
MD5:462DFCF05B61CD39E4C1D158FD1FB725
SHA256:53FA83D02CC60765A75ABD0921F5084C03E0B7521A61C4260176E68B6A402834
2944iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RB73MZ6Y\favicon[3].pngimage
MD5:9FB559A691078558E77D6848202F6541
SHA256:6D8A01DC7647BC218D003B58FE04049E24A9359900B7E0CEBAE76EDF85B8B914
3124iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9ZEWH8D\crossdomain[1].xmlxml
MD5:D6857C0A71E33470BD1374FCB55321A2
SHA256:9D18E552EA3988EA9CBF9F34A69C969D2E1434E19D6BDC7DE8814E0FF6E1E308
3124iexplore.exeC:\Users\admin\AppData\Roaming\Adobe\Flash Player\APSPrivateData2\0\drm-ax-win-x86\CertStore.datcat
MD5:25E2F963E7A72DAACA46C4A46220391F
SHA256:7A4BF3A3E68A16F8601E59B7A8D11C6E4FAEA68C085162FD433D41D021BE2248
3124iexplore.exeC:\Users\admin\AppData\Roaming\Adobe\Flash Player\APSPrivateData2\0\drm-ax-win-x86\GlobalStateStore.gsder
MD5:A75B4F1271737A9CF3E2A38CB7CD34A2
SHA256:CFFB67238DD1699AFBAA8864A3CF60AFD5EDD6F3A088F8C4C899B6C01733B6EA
3124iexplore.exeC:\Users\admin\AppData\Roaming\Adobe\Flash Player\APSPrivateData2\0\drm-ax-win-x86\GlobalStateStore.gs.lkgder
MD5:A75B4F1271737A9CF3E2A38CB7CD34A2
SHA256:CFFB67238DD1699AFBAA8864A3CF60AFD5EDD6F3A088F8C4C899B6C01733B6EA
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
2
DNS requests
2
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3124
iexplore.exe
GET
200
52.4.148.166:80
http://individualization.adobe.com/crossdomain.xml
US
xml
286 b
whitelisted
3124
iexplore.exe
POST
200
52.4.148.166:80
http://individualization.adobe.com/flashaccess/i15n/v5
US
cat
9.54 Kb
whitelisted
2944
iexplore.exe
GET
200
204.79.197.200:80
http://www.bing.com/favicon.ico
US
image
237 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2944
iexplore.exe
204.79.197.200:80
www.bing.com
Microsoft Corporation
US
whitelisted
3124
iexplore.exe
52.4.148.166:80
individualization.adobe.com
Amazon.com, Inc.
US
suspicious

DNS requests

Domain
IP
Reputation
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
individualization.adobe.com
  • 52.4.148.166
  • 34.226.255.180
  • 54.145.157.179
whitelisted

Threats

PID
Process
Class
Message
3124
iexplore.exe
Potential Corporate Privacy Violation
ET POLICY Outdated Flash Version M1
No debug info