File name:

MDE_File_Sample_5ee1f280606b09b3fce092c9f48fba1e4bf1cad6.zip

Full analysis: https://app.any.run/tasks/e0dbb902-79b8-4c89-9d58-6c33a0e2f278
Verdict: Malicious activity
Analysis date: January 17, 2025, 13:15:15
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

97498E6EDB80D3F8DB4902EC597BDF3C

SHA1:

412CAD1DA4A281125C8A07937BAF4C2FB5CF94D3

SHA256:

A04C1979E5FE4A9C5E5CF0B2DADA055DCA5D21B9154401C87F40568CA72F3A6F

SSDEEP:

98304:CPZw76H3Pi5/+Nge7Mg1E7vAkTjHTvvjVFw8hDDHIKztd6TgIa8Tv+d4CBy4oHn/:Fw

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • New Agreement SoftGamings skype.com (PID: 5300)
      • feedback.exe (PID: 4136)
    • Process drops legitimate windows executable

      • New Agreement SoftGamings skype.com (PID: 5300)
    • The process executes via Task Scheduler

      • reg.exe (PID: 5788)
      • regsvr32.exe (PID: 4540)
    • Connects to unusual port

      • regsvr32.exe (PID: 1804)
    • There is functionality for taking screenshot (YARA)

      • regsvr32.exe (PID: 1804)
    • Creates a software uninstall entry

      • New Agreement SoftGamings skype.com (PID: 5300)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 6488)
    • Reads the computer name

      • feedback.exe (PID: 4136)
      • New Agreement SoftGamings skype.com (PID: 5300)
    • Creates files or folders in the user directory

      • feedback.exe (PID: 4136)
      • New Agreement SoftGamings skype.com (PID: 5300)
    • Manual execution by a user

      • New Agreement SoftGamings skype.com (PID: 5300)
      • feedback.exe (PID: 4136)
    • Checks supported languages

      • New Agreement SoftGamings skype.com (PID: 5300)
      • feedback.exe (PID: 4136)
    • Reads Environment values

      • New Agreement SoftGamings skype.com (PID: 5300)
    • Reads Microsoft Office registry keys

      • New Agreement SoftGamings skype.com (PID: 5300)
    • The process uses the downloaded file

      • WinRAR.exe (PID: 6488)
    • Create files in a temporary directory

      • New Agreement SoftGamings skype.com (PID: 5300)
      • feedback.exe (PID: 4136)
    • The sample compiled with chinese language support

      • New Agreement SoftGamings skype.com (PID: 5300)
    • The sample compiled with english language support

      • feedback.exe (PID: 4136)
      • New Agreement SoftGamings skype.com (PID: 5300)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0001
ZipCompression: Deflated
ZipModifyDate: 2025:01:17 13:09:12
ZipCRC: 0xf5871e27
ZipCompressedSize: 2067748
ZipUncompressedSize: 2280056
ZipFileName: New Agreement SoftGamings skype.com
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
135
Monitored processes
7
Malicious processes
0
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe new agreement softgamings                                                                                                                                        skype.com feedback.exe reg.exe no specs conhost.exe no specs regsvr32.exe no specs regsvr32.exe

Process information

PID
CMD
Path
Indicators
Parent process
1804 /u FeedbackSense.dllC:\Windows\SysWOW64\regsvr32.exe
regsvr32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft(C) Register Server
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
3792\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exereg.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4136"C:\Users\admin\AppData\Local\Temp\feedback.exe" C:\Users\admin\AppData\Local\Temp\feedback.exe
explorer.exe
User:
admin
Company:
TODO: <Company name>
Integrity Level:
MEDIUM
Description:
feedback
Exit code:
0
Version:
1.0.0.1
Modules
Images
c:\users\admin\appdata\local\temp\feedback.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
4540"regsvr32.exe" /u FeedbackSense.dllC:\Windows\System32\regsvr32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft(C) Register Server
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
5300"C:\Users\admin\Desktop\New Agreement SoftGamings skype.com" C:\Users\admin\Desktop\New Agreement SoftGamings skype.com
explorer.exe
User:
admin
Company:
OpenCloner
Integrity Level:
MEDIUM
Description:
Installer for FeedBack
Exit code:
0
Version:
2025.1.15.328
Modules
Images
c:\users\admin\desktop\new agreement softgamings skype.com
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
5788"C:\WINDOWS\system32\REG.EXE" ADD "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /V "FeedB" /t REG_SZ /F /D "schtasks /run /tn FeedB"C:\Windows\System32\reg.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Registry Console Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\reg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ws2_32.dll
6488"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\MDE_File_Sample_5ee1f280606b09b3fce092c9f48fba1e4bf1cad6.zipC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
Total events
2 953
Read events
2 913
Write events
26
Delete events
14

Modification events

(PID) Process:(6488) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(6488) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(6488) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(6488) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\MDE_File_Sample_5ee1f280606b09b3fce092c9f48fba1e4bf1cad6.zip
(PID) Process:(6488) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(6488) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(6488) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(6488) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(6488) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:delete valueName:15
Value:
(PID) Process:(6488) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:delete valueName:14
Value:
Executable files
14
Suspicious files
3
Text files
9
Unknown types
0

Dropped files

PID
Process
Filename
Type
5300New Agreement SoftGamings skype.comC:\Users\admin\AppData\Local\OpenCloner\Uninstall\{C01CBD08-5A79-4E31-8F23-48FAE72B522F}\Tsu.dllexecutable
MD5:DD804E04C89BB795545152159F8F5BCB
SHA256:AA7D394C0245D95B7D65B7B04CF45966F145186655A1E01BBE02B6F33B0D7E6C
5300New Agreement SoftGamings skype.comC:\Users\admin\AppData\Local\Temp\5B9E4C5A.datbinary
MD5:9B39F6DFD4AD47E00ECFCD57B9A9E989
SHA256:C4DC0EBEBBA34F61A6D2655347DC2D0B54B4DD66DD401B0D1B905C0A81922260
5300New Agreement SoftGamings skype.comC:\Users\admin\AppData\Local\Temp\5B9E4C5A\Setup.icoimage
MD5:23B7EEA3863B9DAC06B58794D16FD1F4
SHA256:211E2C9510C47A07F7E9D492199023796104B9BFF16434408577C48114BA24B8
5300New Agreement SoftGamings skype.comC:\Users\admin\AppData\Local\Temp\5B9E4C5A\Readme.txttext
MD5:A78F345BF58C4FE23D21B6C122468AD0
SHA256:CC521A115E9CFAE4E24C43855D5111BEC19E8C371C84A78EBC7B4F484E659F34
5300New Agreement SoftGamings skype.comC:\Users\admin\AppData\Local\Temp\Tsu131E9D55.dllexecutable
MD5:DD804E04C89BB795545152159F8F5BCB
SHA256:AA7D394C0245D95B7D65B7B04CF45966F145186655A1E01BBE02B6F33B0D7E6C
5300New Agreement SoftGamings skype.comC:\Users\admin\AppData\Local\OpenCloner\Uninstall\{C01CBD08-5A79-4E31-8F23-48FAE72B522F}\_Setup.dllexecutable
MD5:382D2F5D39D3AE742B15ABB41D019864
SHA256:0972766D1F72BBB290D0365857EC0A55028C1EC3C9D03D25D6BA882EC69E01D2
5300New Agreement SoftGamings skype.comC:\Users\admin\AppData\Local\Temp\5B9E4C5A\_Setup.dllexecutable
MD5:382D2F5D39D3AE742B15ABB41D019864
SHA256:0972766D1F72BBB290D0365857EC0A55028C1EC3C9D03D25D6BA882EC69E01D2
5300New Agreement SoftGamings skype.comC:\Users\admin\AppData\Local\OpenCloner\Uninstall\{C01CBD08-5A79-4E31-8F23-48FAE72B522F}\Setup.exeexecutable
MD5:591E0BD043FE8CD53BFE1DCE966D571F
SHA256:2EDAF3DA625EF50D486DADB7BA70185FEE6B40BF2FD96F98ABAE524A6E679C01
5300New Agreement SoftGamings skype.comC:\Users\admin\AppData\Local\Temp\5B9E4C5A\Setup.exeexecutable
MD5:591E0BD043FE8CD53BFE1DCE966D571F
SHA256:2EDAF3DA625EF50D486DADB7BA70185FEE6B40BF2FD96F98ABAE524A6E679C01
5300New Agreement SoftGamings skype.comC:\Users\admin\AppData\Local\OpenCloner\Uninstall\{C01CBD08-5A79-4E31-8F23-48FAE72B522F}\Setup.icoimage
MD5:23B7EEA3863B9DAC06B58794D16FD1F4
SHA256:211E2C9510C47A07F7E9D492199023796104B9BFF16434408577C48114BA24B8
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
27
DNS requests
16
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6388
backgroundTaskHost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
DE
binary
471 b
whitelisted
1176
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
DE
binary
471 b
whitelisted
4824
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
QA
binary
408 b
whitelisted
4824
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
QA
binary
419 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4712
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1076
svchost.exe
2.23.242.9:443
go.microsoft.com
Ooredoo Q.S.C.
QA
whitelisted
1176
svchost.exe
20.190.160.20:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1176
svchost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
4712
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4712
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2380
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6388
backgroundTaskHost.exe
20.223.35.26:443
arc.msn.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
go.microsoft.com
  • 2.23.242.9
whitelisted
login.live.com
  • 20.190.160.20
  • 40.126.32.133
  • 20.190.160.14
  • 40.126.32.134
  • 40.126.32.138
  • 40.126.32.72
  • 40.126.32.76
  • 20.190.160.22
whitelisted
settings-win.data.microsoft.com
  • 51.124.78.146
  • 40.127.240.158
  • 4.231.128.59
whitelisted
arc.msn.com
  • 20.223.35.26
whitelisted
ocsp.digicert.com
  • 2.23.77.188
whitelisted
fd.api.iris.microsoft.com
  • 20.223.35.26
whitelisted
slscr.update.microsoft.com
  • 4.175.87.197
whitelisted
www.microsoft.com
  • 2.23.246.101
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.95.31.18
whitelisted
0542j.com
  • 85.206.168.238
unknown

Threats

No threats detected
No debug info