File name:

OTool.zip

Full analysis: https://app.any.run/tasks/015c4e5f-9db5-42be-8b3b-e9b70b764a68
Verdict: Malicious activity
Analysis date: November 14, 2018, 13:35:30
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract
MD5:

F5572E58DC156287BD479E885A7BE1F6

SHA1:

B85F4453507642AC99B6680AA24C85B2E3D15AEC

SHA256:

9DFB663B8C961752B8F9201DC6AB8D380742325E95F273248127D90E6EC49120

SSDEEP:

196608:FplogZ5QkZ4fCeQfgd7hej2mG/J47LNaPoFdZw73/HaDa:FplogZ4bQfg6j23OaGdCj/aDa

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • 7za.exe (PID: 3140)
      • Office Tool Plus.exe (PID: 3952)
      • 7za.exe (PID: 2528)
      • 7za.exe (PID: 3708)
      • Office Tool Plus.exe (PID: 1404)
      • 7za.exe (PID: 3032)
      • 7za.exe (PID: 2060)
      • 7za.exe (PID: 3268)
      • 7za.exe (PID: 3516)
      • setup.exe (PID: 1696)
      • aria2c.exe (PID: 1016)
      • check.exe (PID: 772)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3692)
    • Creates files in the program directory

      • Office Tool Plus.exe (PID: 1404)
      • 7za.exe (PID: 2528)
      • 7za.exe (PID: 3516)
      • 7za.exe (PID: 3708)
      • 7za.exe (PID: 3032)
      • 7za.exe (PID: 3140)
      • 7za.exe (PID: 3268)
      • 7za.exe (PID: 2060)
    • Reads Internet Cache Settings

      • Office Tool Plus.exe (PID: 1404)
    • Reads Environment values

      • Office Tool Plus.exe (PID: 1404)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2018:06:30 17:00:15
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: OTool/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
58
Monitored processes
14
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start drop and start drop and start drop and start drop and start start winrar.exe office tool plus.exe no specs office tool plus.exe notepad.exe no specs 7za.exe no specs 7za.exe no specs 7za.exe no specs 7za.exe no specs 7za.exe no specs 7za.exe no specs 7za.exe no specs setup.exe aria2c.exe no specs check.exe

Process information

PID
CMD
Path
Indicators
Parent process
772"C:\Users\admin\AppData\Local\Temp\Rar$EXa3692.12704\OTool\files\activate\check.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3692.12704\OTool\files\activate\check.exe
WinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3692.12704\otool\files\activate\check.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\ws2_32.dll
1016"C:\Users\admin\AppData\Local\Temp\Rar$EXa3692.12373\OTool\files\Thunder\aria2c.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3692.12373\OTool\files\Thunder\aria2c.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3692.12373\otool\files\thunder\aria2c.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
1404"C:\Users\admin\AppData\Local\Temp\Rar$EXa3692.9868\OTool\Office Tool Plus.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3692.9868\OTool\Office Tool Plus.exe
WinRAR.exe
User:
admin
Company:
Landian Office 365
Integrity Level:
HIGH
Description:
Office Tool Plus
Exit code:
0
Version:
5.0.1.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3692.9868\otool\office tool plus.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1696"C:\Users\admin\AppData\Local\Temp\Rar$EXa3692.11928\OTool\files\setup.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3692.11928\OTool\files\setup.exe
WinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Office
Exit code:
0
Version:
16.0.10306.33602
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3692.11928\otool\files\setup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
2060"C:\Users\admin\AppData\Local\Temp\Rar$EXa3692.9868\OTool\files\7-zip\7za.exe" e C:\ProgramData\OTP\MRO.cab -oC:\ProgramData\OTP\ -aoaC:\Users\admin\AppData\Local\Temp\Rar$EXa3692.9868\OTool\files\7-zip\7za.exeOffice Tool Plus.exe
User:
admin
Company:
Igor Pavlov
Integrity Level:
HIGH
Description:
7-Zip Standalone Console
Exit code:
0
Version:
16.04
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3692.9868\otool\files\7-zip\7za.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2528"C:\Users\admin\AppData\Local\Temp\Rar$EXa3692.9868\OTool\files\7-zip\7za.exe" e C:\ProgramData\OTP\MRO.cab -oC:\ProgramData\OTP\ -aoaC:\Users\admin\AppData\Local\Temp\Rar$EXa3692.9868\OTool\files\7-zip\7za.exeOffice Tool Plus.exe
User:
admin
Company:
Igor Pavlov
Integrity Level:
HIGH
Description:
7-Zip Standalone Console
Exit code:
0
Version:
16.04
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3692.9868\otool\files\7-zip\7za.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2564"C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\AppData\Local\Temp\Rar$DIa3692.10423\Office GVLK Key.txtC:\Windows\system32\NOTEPAD.EXEWinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3032"C:\Users\admin\AppData\Local\Temp\Rar$EXa3692.9868\OTool\files\7-zip\7za.exe" e C:\ProgramData\OTP\MRO.cab -oC:\ProgramData\OTP\ -aoaC:\Users\admin\AppData\Local\Temp\Rar$EXa3692.9868\OTool\files\7-zip\7za.exeOffice Tool Plus.exe
User:
admin
Company:
Igor Pavlov
Integrity Level:
HIGH
Description:
7-Zip Standalone Console
Exit code:
0
Version:
16.04
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3692.9868\otool\files\7-zip\7za.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3140"C:\Users\admin\AppData\Local\Temp\Rar$EXa3692.9868\OTool\files\7-zip\7za.exe" e C:\ProgramData\OTP\MRO.cab -oC:\ProgramData\OTP\ -aoaC:\Users\admin\AppData\Local\Temp\Rar$EXa3692.9868\OTool\files\7-zip\7za.exeOffice Tool Plus.exe
User:
admin
Company:
Igor Pavlov
Integrity Level:
HIGH
Description:
7-Zip Standalone Console
Exit code:
0
Version:
16.04
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3692.9868\otool\files\7-zip\7za.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3268"C:\Users\admin\AppData\Local\Temp\Rar$EXa3692.9868\OTool\files\7-zip\7za.exe" e C:\ProgramData\OTP\MRO.cab -oC:\ProgramData\OTP\ -aoaC:\Users\admin\AppData\Local\Temp\Rar$EXa3692.9868\OTool\files\7-zip\7za.exeOffice Tool Plus.exe
User:
admin
Company:
Igor Pavlov
Integrity Level:
HIGH
Description:
7-Zip Standalone Console
Exit code:
0
Version:
16.04
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3692.9868\otool\files\7-zip\7za.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
Total events
1 059
Read events
915
Write events
139
Delete events
5

Modification events

(PID) Process:(3692) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3692) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3692) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3692) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Downloads\OTool.zip
(PID) Process:(3692) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3692) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3692) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3692) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3692) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(3692) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
Executable files
62
Suspicious files
17
Text files
33
Unknown types
0

Dropped files

PID
Process
Filename
Type
3692WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3692.9868\OTool\files\activate\licenses.datacompressed
MD5:
SHA256:
3692WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3692.9868\OTool\files\activate\OSPP.VBStext
MD5:
SHA256:
3692WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3692.9868\OTool\files\clean\script.datacompressed
MD5:
SHA256:
3692WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3692.9868\OTool\files\setup.exeexecutable
MD5:
SHA256:
3692WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3692.9868\OTool\files\7-zip\7za.dllexecutable
MD5:8F8C8662D50A727EB783B4B6101B1FAB
SHA256:7CAE87154C752DEB52CD7A83FBFF4BE5064A424916D89CFFE3BF3712FA74FC92
3692WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3692.9868\OTool\files\7-zip\7za.exeexecutable
MD5:E3C061FA0450056E30285FD44A74CD2A
SHA256:E0E2C7D0F740FE2A4E8658CE54DFB6EB3C47C37FE90A44A839E560C685F1F1FA
3692WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3692.9868\OTool\files\clean\x64\cleanospp.exeexecutable
MD5:162AB955CB2F002A73C1530AA796477F
SHA256:5CE462E5F34065FC878362BA58617FAB28C22D631B9D836DDDCF43FB1AD4DE6E
3692WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3692.9868\OTool\files\7-zip\7zxa.dllexecutable
MD5:AE27DB1A0E1E2B338C79AF9D74967B7D
SHA256:DBE966226D1DF41C9AB854DA3897C0FA99858D8848DD23470EDB4974F256C2FA
3692WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3692.9868\OTool\files\activate\check.exeexecutable
MD5:BB4796A5F1AEE873CA1B0A4F06CB063A
SHA256:DE65F4506AD84C085A68A3FAE111D21A085F222C21EB58D62ECA377F7D52BA85
3692WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3692.9868\OTool\files\Thunder\atl71.dllexecutable
MD5:79CB6457C81ADA9EB7F2087CE799AAA7
SHA256:A68E1297FAE2BCF854B47FFA444F490353028DE1FA2CA713B6CF6CC5AA22B88A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
14
TCP/UDP connections
10
DNS requests
8
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1404
Office Tool Plus.exe
GET
301
2.18.232.120:80
http://officecdn.microsoft.com/pr/7ffbc6bf-bc32-4f92-8982-f9dd17fd3114/office/data/MRO.cab
unknown
whitelisted
1404
Office Tool Plus.exe
GET
301
2.18.232.120:80
http://officecdn.microsoft.com/pr/b8f9b850-328d-4355-9145-c59439a0c4cf/office/data/MRO.cab
unknown
whitelisted
1404
Office Tool Plus.exe
GET
301
2.18.232.120:80
http://officecdn.microsoft.com/pr/64256afe-f5d9-4f86-8936-8840a6a4f5be/office/data/MRO.cab
unknown
whitelisted
1404
Office Tool Plus.exe
GET
301
2.18.232.120:80
http://officecdn.microsoft.com/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60/office/data/MRO.cab
unknown
whitelisted
1404
Office Tool Plus.exe
GET
301
2.18.232.120:80
http://officecdn.microsoft.com/pr/f2e724c1-748f-4b47-8fb8-8e0d210e9208/office/data/MRO.cab
unknown
whitelisted
1404
Office Tool Plus.exe
GET
301
2.18.232.120:80
http://officecdn.microsoft.com/pr/ea4a4090-de26-49d7-93c1-91bff9e53fc3/office/data/MRO.cab
unknown
whitelisted
1404
Office Tool Plus.exe
GET
301
2.18.232.120:80
http://officecdn.microsoft.com/pr/5440fd1f-7ecb-4221-8110-145efaa6372f/office/data/MRO.cab
unknown
whitelisted
1404
Office Tool Plus.exe
GET
200
2.16.186.90:80
http://officecdn.microsoft.com.edgesuite.net/pr/7ffbc6bf-bc32-4f92-8982-f9dd17fd3114/office/data/MRO.cab
unknown
compressed
16.2 Kb
whitelisted
1404
Office Tool Plus.exe
GET
200
2.16.186.90:80
http://officecdn.microsoft.com.edgesuite.net/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60/office/data/MRO.cab
unknown
compressed
16.2 Kb
whitelisted
1404
Office Tool Plus.exe
GET
200
2.16.186.90:80
http://officecdn.microsoft.com.edgesuite.net/pr/b8f9b850-328d-4355-9145-c59439a0c4cf/office/data/MRO.cab
unknown
compressed
16.0 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1404
Office Tool Plus.exe
222.186.170.7:443
server.lancdn.com
No.31,Jin-rong Street
CN
unknown
1404
Office Tool Plus.exe
2.18.232.120:80
officecdn.microsoft.com
Akamai International B.V.
whitelisted
1404
Office Tool Plus.exe
2.16.186.90:80
officecdn.microsoft.com.edgesuite.net
Akamai International B.V.
whitelisted
1696
setup.exe
13.107.3.128:443
config.edge.skype.com
Microsoft Corporation
US
whitelisted
1696
setup.exe
52.109.120.18:443
nexusrules.officeapps.live.com
Microsoft Corporation
HK
whitelisted
1696
setup.exe
40.121.213.159:443
client-office365-tas.msedge.net
Microsoft Corporation
US
whitelisted
1696
setup.exe
52.109.76.34:443
nexus.officeapps.live.com
Microsoft Corporation
IE
whitelisted

DNS requests

Domain
IP
Reputation
server.lancdn.com
  • 222.186.170.7
malicious
officecdn.microsoft.com
  • 2.18.232.120
whitelisted
officecdn.microsoft.com.edgesuite.net
  • 2.16.186.90
  • 2.16.186.83
whitelisted
nexusrules.officeapps.live.com
  • 52.109.120.18
whitelisted
config.edge.skype.com
  • 13.107.3.128
malicious
client-office365-tas.msedge.net
  • 40.121.213.159
whitelisted
nexus.officeapps.live.com
  • 52.109.76.34
whitelisted

Threats

No threats detected
No debug info