File name:

varfeys-chit-rav_131235212.zip

Full analysis: https://app.any.run/tasks/8c1452f3-0ae9-4c86-b75d-da7942805ddb
Verdict: Malicious activity
Analysis date: May 03, 2021, 12:52:00
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

3473971DD516CF46C80593E11CC85C17

SHA1:

DFEDC32389A2C806C17D8667B3DBAC9EF90D028E

SHA256:

9F5677D61D1E148F9BFE71242E95439554ACF7B8D3B6E7F6A5AF28BD8A724998

SSDEEP:

196608:i9IYlqq+uKFBIOAqp+MXd1WmKLo1NPKomsc2aFzyGUgZuTSs9yrlc7nmLrC:4jh+HFedM7WjLsKomsc2CbUg0OsE+Lmy

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • sya2w3os.ocg.exe (PID: 2976)
      • sya2w3os.ocg.exe (PID: 2764)
      • sya2w3os.ocg.exe (PID: 148)
      • sya2w3os.ocg.exe (PID: 2368)
      • varfeys-chit-rav_131235212.exe (PID: 4076)
      • varfeys-chit-rav_131235212.exe (PID: 3176)
      • wmfdist.exe (PID: 4048)
      • FilesInspector.exe (PID: 1064)
    • Drops executable file immediately after starts

      • sya2w3os.ocg.exe (PID: 2764)
      • sya2w3os.ocg.exe (PID: 2976)
      • sya2w3os.ocg.exe (PID: 148)
      • sya2w3os.ocg.exe (PID: 2368)
      • varfeys-chit-rav_131235212.exe (PID: 4076)
      • varfeys-chit-rav_131235212.exe (PID: 3176)
      • varfeys-chit-rav_131235212.tmp (PID: 1832)
    • Loads dropped or rewritten executable

      • WerFault.exe (PID: 2112)
      • FilesInspector.exe (PID: 1064)
  • SUSPICIOUS

    • Checks supported languages

      • sya2w3os.ocg.tmp (PID: 3464)
      • sya2w3os.ocg.exe (PID: 2976)
      • sya2w3os.ocg.tmp (PID: 3496)
      • sya2w3os.ocg.exe (PID: 2764)
      • WinRAR.exe (PID: 2448)
      • sya2w3os.ocg.exe (PID: 148)
      • sya2w3os.ocg.tmp (PID: 892)
      • sya2w3os.ocg.exe (PID: 2368)
      • varfeys-chit-rav_131235212.exe (PID: 4076)
      • sya2w3os.ocg.tmp (PID: 2584)
      • varfeys-chit-rav_131235212.tmp (PID: 2972)
      • varfeys-chit-rav_131235212.exe (PID: 3176)
      • varfeys-chit-rav_131235212.tmp (PID: 1832)
      • wmfdist.exe (PID: 4048)
      • FilesInspector.exe (PID: 1064)
    • Reads the computer name

      • sya2w3os.ocg.tmp (PID: 3464)
      • sya2w3os.ocg.tmp (PID: 3496)
      • WinRAR.exe (PID: 2448)
      • sya2w3os.ocg.tmp (PID: 892)
      • sya2w3os.ocg.tmp (PID: 2584)
      • varfeys-chit-rav_131235212.tmp (PID: 2972)
      • varfeys-chit-rav_131235212.tmp (PID: 1832)
      • FilesInspector.exe (PID: 1064)
    • Executable content was dropped or overwritten

      • sya2w3os.ocg.exe (PID: 2976)
      • WinRAR.exe (PID: 2448)
      • sya2w3os.ocg.exe (PID: 2764)
      • sya2w3os.ocg.exe (PID: 148)
      • sya2w3os.ocg.exe (PID: 2368)
      • varfeys-chit-rav_131235212.exe (PID: 4076)
      • varfeys-chit-rav_131235212.exe (PID: 3176)
      • varfeys-chit-rav_131235212.tmp (PID: 1832)
    • Reads the date of Windows installation

      • sya2w3os.ocg.tmp (PID: 3464)
      • sya2w3os.ocg.tmp (PID: 892)
    • Reads Windows owner or organization settings

      • varfeys-chit-rav_131235212.tmp (PID: 1832)
    • Drops a file with too old compile date

      • varfeys-chit-rav_131235212.tmp (PID: 1832)
    • Reads the Windows organization settings

      • varfeys-chit-rav_131235212.tmp (PID: 1832)
    • Creates a directory in Program Files

      • varfeys-chit-rav_131235212.tmp (PID: 1832)
    • Drops a file with a compile date too recent

      • varfeys-chit-rav_131235212.tmp (PID: 1832)
    • Reads Microsoft Outlook installation path

      • FilesInspector.exe (PID: 1064)
    • Creates files in the program directory

      • WerFault.exe (PID: 2112)
    • Drops a file that was compiled in debug mode

      • varfeys-chit-rav_131235212.tmp (PID: 1832)
  • INFO

    • Application was dropped or rewritten from another process

      • sya2w3os.ocg.tmp (PID: 3464)
      • sya2w3os.ocg.tmp (PID: 3496)
      • sya2w3os.ocg.tmp (PID: 892)
      • sya2w3os.ocg.tmp (PID: 2584)
      • varfeys-chit-rav_131235212.tmp (PID: 2972)
      • varfeys-chit-rav_131235212.tmp (PID: 1832)
    • Creates files in the program directory

      • varfeys-chit-rav_131235212.tmp (PID: 1832)
    • Loads dropped or rewritten executable

      • varfeys-chit-rav_131235212.tmp (PID: 1832)
    • Creates a software uninstall entry

      • varfeys-chit-rav_131235212.tmp (PID: 1832)
    • Reads the computer name

      • WerFault.exe (PID: 2112)
    • Checks supported languages

      • WerFault.exe (PID: 2112)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: sya2w3os.ocg.exe
ZipUncompressedSize: 4136792
ZipCompressedSize: 3661082
ZipCRC: 0xc2f14acd
ZipModifyDate: 2019:12:24 23:16:18
ZipCompression: Deflated
ZipBitFlag: -
ZipRequiredVersion: 20
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
60
Monitored processes
16
Malicious processes
8
Suspicious processes
5

Behavior graph

Click at the process to see the details
drop and start drop and start drop and start start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start winrar.exe sya2w3os.ocg.exe sya2w3os.ocg.tmp no specs sya2w3os.ocg.exe sya2w3os.ocg.tmp no specs sya2w3os.ocg.exe sya2w3os.ocg.tmp no specs sya2w3os.ocg.exe sya2w3os.ocg.tmp no specs varfeys-chit-rav_131235212.exe varfeys-chit-rav_131235212.tmp no specs varfeys-chit-rav_131235212.exe varfeys-chit-rav_131235212.tmp wmfdist.exe no specs filesinspector.exe werfault.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
148"C:\Users\admin\AppData\Local\Temp\Rar$EXa2448.20587\sya2w3os.ocg.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2448.20587\sya2w3os.ocg.exe
WinRAR.exe
User:
admin
Company:
KirySoft
Integrity Level:
MEDIUM
Description:
WSCC4 (x64)
Exit code:
1
Version:
4.0.1.7
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2448.20587\sya2w3os.ocg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
892"C:\Users\admin\AppData\Local\Temp\is-04LFT.tmp\sya2w3os.ocg.tmp" /SL5="$901AC,3403402,721408,C:\Users\admin\AppData\Local\Temp\Rar$EXa2448.20587\sya2w3os.ocg.exe" C:\Users\admin\AppData\Local\Temp\is-04LFT.tmp\sya2w3os.ocg.tmpsya2w3os.ocg.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
1
Version:
51.1052.0.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\appdata\local\temp\is-04lft.tmp\sya2w3os.ocg.tmp
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1064"C:\Program Files\Inmatrix\FilesInspector.exe" varfeys-chit-rav_131235212.exeC:\Program Files\Inmatrix\FilesInspector.exe
varfeys-chit-rav_131235212.tmp
User:
admin
Company:
Terra Informatica Software, Inc., British Columbia, Canada.
Integrity Level:
HIGH
Description:
HTMLayout - embeddable HTML rendering and layout component
Exit code:
3221225477
Version:
3, 3, 3, 12
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\program files\inmatrix\sqlite3.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\ole32.dll
1832"C:\Users\admin\AppData\Local\Temp\is-3K505.tmp\varfeys-chit-rav_131235212.tmp" /SL5="$D0134,10316625,1017344,C:\Users\admin\AppData\Local\Temp\Rar$EXa2448.21769\varfeys-chit-rav_131235212.exe" /SPAWNWND=$A0172 /NOTIFYWND=$B01AC C:\Users\admin\AppData\Local\Temp\is-3K505.tmp\varfeys-chit-rav_131235212.tmp
varfeys-chit-rav_131235212.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-3k505.tmp\varfeys-chit-rav_131235212.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2112C:\Windows\system32\WerFault.exe -u -p 1064 -s 544C:\Windows\system32\WerFault.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Problem Reporting
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2368"C:\Users\admin\AppData\Local\Temp\Rar$EXa2448.20587\sya2w3os.ocg.exe" /SPAWNWND=$B017E /NOTIFYWND=$901AC C:\Users\admin\AppData\Local\Temp\Rar$EXa2448.20587\sya2w3os.ocg.exe
sya2w3os.ocg.tmp
User:
admin
Company:
KirySoft
Integrity Level:
HIGH
Description:
WSCC4 (x64)
Exit code:
1
Version:
4.0.1.7
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2448.20587\sya2w3os.ocg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2448"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\varfeys-chit-rav_131235212.zip"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2584"C:\Users\admin\AppData\Local\Temp\is-PKG86.tmp\sya2w3os.ocg.tmp" /SL5="$60108,3403402,721408,C:\Users\admin\AppData\Local\Temp\Rar$EXa2448.20587\sya2w3os.ocg.exe" /SPAWNWND=$B017E /NOTIFYWND=$901AC C:\Users\admin\AppData\Local\Temp\is-PKG86.tmp\sya2w3os.ocg.tmpsya2w3os.ocg.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
1
Version:
51.1052.0.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\appdata\local\temp\is-pkg86.tmp\sya2w3os.ocg.tmp
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2764"C:\Users\admin\AppData\Local\Temp\Rar$EXa2448.17995\sya2w3os.ocg.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2448.17995\sya2w3os.ocg.exe
WinRAR.exe
User:
admin
Company:
KirySoft
Integrity Level:
MEDIUM
Description:
WSCC4 (x64)
Exit code:
1
Version:
4.0.1.7
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2448.17995\sya2w3os.ocg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2972"C:\Users\admin\AppData\Local\Temp\is-VK6AS.tmp\varfeys-chit-rav_131235212.tmp" /SL5="$B01AC,10316625,1017344,C:\Users\admin\AppData\Local\Temp\Rar$EXa2448.21769\varfeys-chit-rav_131235212.exe" C:\Users\admin\AppData\Local\Temp\is-VK6AS.tmp\varfeys-chit-rav_131235212.tmpvarfeys-chit-rav_131235212.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\appdata\local\temp\is-vk6as.tmp\varfeys-chit-rav_131235212.tmp
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\mpr.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\user32.dll
Total events
5 102
Read events
4 946
Write events
156
Delete events
0

Modification events

(PID) Process:(2448) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2448) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2448) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2448) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(2448) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\varfeys-chit-rav_131235212.zip
(PID) Process:(2448) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2448) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2448) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2448) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2448) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
29
Suspicious files
4
Text files
12
Unknown types
2

Dropped files

PID
Process
Filename
Type
2448WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2448.17995\varfeys-chit-rav_131235212.exeexecutable
MD5:
SHA256:
2448WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2448.21769\varfeys-chit-rav_131235212.exeexecutable
MD5:
SHA256:
1832varfeys-chit-rav_131235212.tmpC:\Program Files\Inmatrix\is-RVP8N.tmpexecutable
MD5:
SHA256:
3176varfeys-chit-rav_131235212.exeC:\Users\admin\AppData\Local\Temp\is-3K505.tmp\varfeys-chit-rav_131235212.tmpexecutable
MD5:
SHA256:
2448WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2448.20587\varfeys-chit-rav_131235212.exeexecutable
MD5:
SHA256:
1832varfeys-chit-rav_131235212.tmpC:\Program Files\Inmatrix\unins000.exeexecutable
MD5:
SHA256:
2764sya2w3os.ocg.exeC:\Users\admin\AppData\Local\Temp\is-R92MJ.tmp\sya2w3os.ocg.tmpexecutable
MD5:84DB4B4205F705DA71471DC6ECC061F5
SHA256:647983EBDE53E0501FF1AF8EF6190DFEEA5CCC64CAF7DCE808F1E3D98FB66A3C
2368sya2w3os.ocg.exeC:\Users\admin\AppData\Local\Temp\is-PKG86.tmp\sya2w3os.ocg.tmpexecutable
MD5:84DB4B4205F705DA71471DC6ECC061F5
SHA256:647983EBDE53E0501FF1AF8EF6190DFEEA5CCC64CAF7DCE808F1E3D98FB66A3C
2448WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2448.17995\sya2w3os.ocg.exeexecutable
MD5:5641643229D30BDAE27DD0AF05F768EC
SHA256:17F59E0A4D95B18628ED3E0537E54ED16448DFE51594E3186FA96C1D87C16F0C
2448WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2448.21769\sya2w3os.ocg.exeexecutable
MD5:5641643229D30BDAE27DD0AF05F768EC
SHA256:17F59E0A4D95B18628ED3E0537E54ED16448DFE51594E3186FA96C1D87C16F0C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
1
DNS requests
1
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1064
FilesInspector.exe
POST
104.21.84.93:80
http://grigblog.club/v2/events
US
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1064
FilesInspector.exe
104.21.84.93:80
grigblog.club
Cloudflare Inc
US
malicious

DNS requests

Domain
IP
Reputation
grigblog.club
  • 104.21.84.93
  • 172.67.190.230
malicious

Threats

PID
Process
Class
Message
1064
FilesInspector.exe
A Network Trojan was detected
ET MALWARE DownloadAssistant Activity
No debug info