File name:

Payment001.img

Full analysis: https://app.any.run/tasks/4dda758c-fae7-4d1c-95da-88b76fc26ed3
Verdict: Malicious activity
Analysis date: March 25, 2021, 07:17:12
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-iso9660-image
File info: UDF filesystem data (version 1.5) 'EMANN3C'
MD5:

9BAE75323C0D712F0B2032C863A1A57F

SHA1:

B925F2452888D024089F1B6DE07F7740E2C93F0E

SHA256:

9FE37E4063450C65DFE1E5FEF9ACE79892F9406333A4EEF9D5F7954D5F17A069

SSDEEP:

1536:1pqgE4P1TSKjP+CJVenp6nfl3fHTD4QCFXkDupE:3qC5jpoOPGXeu

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Payment001_png.scr (PID: 3352)
      • Payment001_png.scr (PID: 1468)
      • Payment001_png.scr (PID: 1016)
      • Payment001_png.scr (PID: 1528)
      • Payment001_png.scr (PID: 3992)
      • Payment001_png.scr (PID: 1400)
      • Payment001_png.scr (PID: 1476)
      • Payment001_png.scr (PID: 2196)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2180)
    • Drops a file with too old compile date

      • WinRAR.exe (PID: 2180)
  • INFO

    • Changes default file association

      • rundll32.exe (PID: 1956)
    • Manual execution by user

      • Payment001_png.scr (PID: 3992)
      • Payment001_png.scr (PID: 1476)
      • Payment001_png.scr (PID: 3352)
      • Payment001_png.scr (PID: 1528)
      • Payment001_png.scr (PID: 1468)
      • Payment001_png.scr (PID: 1016)
      • Payment001_png.scr (PID: 1400)
      • Payment001_png.scr (PID: 2196)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.iso | ISO 9660 CD image (27.6)
.atn | Photoshop Action (27.1)
.gmc | Game Music Creator Music (6.1)

EXIF

Composite

VolumeSize: 1198 kB

ISO

VolumeModifyDate: 2021:03:23 02:47:13.00+01:00
VolumeCreateDate: 2021:03:23 02:47:13.00+01:00
Software: IMGBURN V2.5.8.0 - THE ULTIMATE IMAGE BURNER!
VolumeSetName: UNDEFINED
RootDirectoryCreateDate: 2021:03:23 02:47:13+01:00
VolumeBlockSize: 2048
VolumeBlockCount: 599
VolumeName: EMANN3C
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
49
Monitored processes
10
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start rundll32.exe no specs winrar.exe payment001_png.scr no specs payment001_png.scr no specs payment001_png.scr no specs payment001_png.scr no specs payment001_png.scr no specs payment001_png.scr no specs payment001_png.scr no specs payment001_png.scr no specs

Process information

PID
CMD
Path
Indicators
Parent process
1016"C:\Users\admin\Desktop\Payment001_png.scr" /SC:\Users\admin\Desktop\Payment001_png.screxplorer.exe
User:
admin
Company:
Baidu
Integrity Level:
MEDIUM
Description:
Baidu
Exit code:
0
Version:
3.01
Modules
Images
c:\users\admin\desktop\payment001_png.scr
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
1400"C:\Users\admin\Desktop\Payment001_png.scr" /SC:\Users\admin\Desktop\Payment001_png.screxplorer.exe
User:
admin
Company:
Baidu
Integrity Level:
MEDIUM
Description:
Baidu
Exit code:
0
Version:
3.01
Modules
Images
c:\users\admin\desktop\payment001_png.scr
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
1468"C:\Users\admin\Desktop\Payment001_png.scr" /SC:\Users\admin\Desktop\Payment001_png.screxplorer.exe
User:
admin
Company:
Baidu
Integrity Level:
MEDIUM
Description:
Baidu
Exit code:
0
Version:
3.01
Modules
Images
c:\users\admin\desktop\payment001_png.scr
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
1476"C:\Users\admin\Desktop\Payment001_png.scr" /SC:\Users\admin\Desktop\Payment001_png.screxplorer.exe
User:
admin
Company:
Baidu
Integrity Level:
MEDIUM
Description:
Baidu
Exit code:
0
Version:
3.01
Modules
Images
c:\users\admin\desktop\payment001_png.scr
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
1528"C:\Users\admin\Desktop\Payment001_png.scr" /SC:\Users\admin\Desktop\Payment001_png.screxplorer.exe
User:
admin
Company:
Baidu
Integrity Level:
MEDIUM
Description:
Baidu
Exit code:
0
Version:
3.01
Modules
Images
c:\users\admin\desktop\payment001_png.scr
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
1956"C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\AppData\Local\Temp\Payment001.imgC:\Windows\system32\rundll32.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imagehlp.dll
2180"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Payment001.img"C:\Program Files\WinRAR\WinRAR.exe
rundll32.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
2196"C:\Users\admin\Desktop\Payment001_png.scr" /SC:\Users\admin\Desktop\Payment001_png.screxplorer.exe
User:
admin
Company:
Baidu
Integrity Level:
MEDIUM
Description:
Baidu
Exit code:
0
Version:
3.01
Modules
Images
c:\users\admin\desktop\payment001_png.scr
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
3352"C:\Users\admin\Desktop\Payment001_png.scr" /SC:\Users\admin\Desktop\Payment001_png.screxplorer.exe
User:
admin
Company:
Baidu
Integrity Level:
MEDIUM
Description:
Baidu
Exit code:
0
Version:
3.01
Modules
Images
c:\users\admin\desktop\payment001_png.scr
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
3992"C:\Users\admin\Desktop\Payment001_png.scr" /SC:\Users\admin\Desktop\Payment001_png.screxplorer.exe
User:
admin
Company:
Baidu
Integrity Level:
MEDIUM
Description:
Baidu
Exit code:
0
Version:
3.01
Modules
Images
c:\users\admin\desktop\payment001_png.scr
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
Total events
1 282
Read events
1 114
Write events
167
Delete events
1

Modification events

(PID) Process:(1956) rundll32.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1956) rundll32.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E
Operation:writeName:@C:\Windows\System32\isoburn.exe,-350
Value:
Disc Image File
(PID) Process:(1956) rundll32.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.img\OpenWithProgids
Operation:writeName:Windows.IsoFile
Value:
(PID) Process:(1956) rundll32.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E
Operation:writeName:@%SystemRoot%\System32\isoburn.exe,-352
Value:
Windows Disc Image Burner
(PID) Process:(1956) rundll32.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Operation:writeName:C:\Windows\System32\isoburn.exe
Value:
Windows Disc Image Burner
(PID) Process:(1956) rundll32.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Operation:writeName:C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe
Value:
Adobe Acrobat Reader DC
(PID) Process:(1956) rundll32.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Operation:writeName:C:\Windows\eHome\ehshell.exe
Value:
Windows Media Center
(PID) Process:(1956) rundll32.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Operation:writeName:C:\Windows\system32\mspaint.exe
Value:
Paint
(PID) Process:(1956) rundll32.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Operation:writeName:C:\Windows\system32\NOTEPAD.EXE
Value:
Notepad
(PID) Process:(1956) rundll32.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Operation:writeName:C:\PROGRA~1\MICROS~1\Office14\OIS.EXE
Value:
Microsoft Office 2010
Executable files
1
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
2180WinRAR.exeC:\Users\admin\Desktop\Payment001_png.screxecutable
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
1
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
192.168.100.70:137
malicious

DNS requests

No data

Threats

No threats detected
No debug info