File name:

Sample1.zip

Full analysis: https://app.any.run/tasks/8348cc6b-ab16-49aa-a90f-5322bbac61c7
Verdict: Malicious activity
Analysis date: June 19, 2019, 05:34:27
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract
MD5:

3118D28F4443A48859D2C7217727469F

SHA1:

D21A90A5DD5893E894D9EAE4F85B636654BF4C88

SHA256:

A2CD7AF78EB987CC515284A26E11AD4DC59E68E6C428B1A8589E922914CE6371

SSDEEP:

196608:9nElW6eG9BtROqu7lI3OxBkxTyruntiPcZrHQFXN7zKAl:9daBtR7aI+mtiACXRJl

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • mscontrol.exe (PID: 1736)
      • VeritasQuickAssist.exe (PID: 2636)
      • SymDiag.exe (PID: 2308)
      • upxg.exe (PID: 324)
      • upx.exe (PID: 2976)
      • upxg.exe (PID: 3116)
      • VeritasQuickAssist.exe (PID: 2788)
      • SymDiag.exe (PID: 3444)
      • SymDiagUi3.exe (PID: 1380)
    • Loads dropped or rewritten executable

      • VeritasQuickAssist.exe (PID: 2788)
      • VeritasQuickAssist.exe (PID: 2820)
      • VeritasQuickAssist.exe (PID: 2636)
      • SymDiagUi3.exe (PID: 1380)
    • Runs PING.EXE for delay simulation

      • cmd.exe (PID: 864)
    • Loads the Task Scheduler COM API

      • SymDiagUi3.exe (PID: 1380)
    • Changes settings of System certificates

      • SymDiag.exe (PID: 3444)
  • SUSPICIOUS

    • Executes application which crashes

      • WinRAR.exe (PID: 2176)
    • Executable content was dropped or overwritten

      • VeritasQuickAssist.exe (PID: 2788)
      • VeritasQuickAssist.exe (PID: 2820)
      • upxg.exe (PID: 3116)
      • VeritasQuickAssist.exe (PID: 2636)
      • WinRAR.exe (PID: 2176)
    • Starts CMD.EXE for commands execution

      • VeritasQuickAssist.exe (PID: 2820)
    • Starts CMD.EXE for self-deleting

      • VeritasQuickAssist.exe (PID: 2820)
    • Adds / modifies Windows certificates

      • SymDiag.exe (PID: 3444)
    • Low-level read access rights to disk partition

      • SymDiagUi3.exe (PID: 1380)
    • Reads Environment values

      • SymDiagUi3.exe (PID: 1380)
    • Executed as Windows Service

      • WmiApSrv.exe (PID: 3804)
    • Reads CPU info

      • SymDiagUi3.exe (PID: 1380)
  • INFO

    • Reads settings of System Certificates

      • SymDiagUi3.exe (PID: 1380)
    • Reads Microsoft Office registry keys

      • SymDiagUi3.exe (PID: 1380)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2019:06:18 16:04:13
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: known malisious/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
57
Monitored processes
15
Malicious processes
6
Suspicious processes
1

Behavior graph

Click at the process to see the details
drop and start drop and start drop and start drop and start start drop and start drop and start drop and start drop and start winrar.exe mscontrol.exe no specs ntvdm.exe no specs upxg.exe no specs upxg.exe upx.exe no specs veritasquickassist.exe veritasquickassist.exe veritasquickassist.exe cmd.exe no specs ping.exe no specs symdiag.exe no specs symdiag.exe symdiagui3.exe wmiapsrv.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
284ping 127.0.0.1 -n 3 C:\Windows\system32\PING.EXEcmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
TCP/IP Ping Command
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ping.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
324"C:\Users\admin\AppData\Local\Temp\Rar$EXb2176.14541\known malisious\upxg.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb2176.14541\known malisious\upxg.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb2176.14541\known malisious\upxg.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\gdi32.dll
864"C:\Windows\system32\cmd.exe" /c ping 127.0.0.1 -n 3 & del C:\Users\admin\AppData\Local\Temp\STSFX6~2\VERITA~1.EXE & rmdir C:\Users\admin\AppData\Local\Temp\STSFX6~2C:\Windows\system32\cmd.exeVeritasQuickAssist.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1096"C:\Windows\system32\ntvdm.exe" -i1 C:\Windows\system32\ntvdm.exeWinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
NTVDM.EXE
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ntvdm.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1380"C:\Users\admin\AppData\Local\Temp\STSFX6249\SymDiagUi3.exe" "C:\Users\admin\AppData\Local\Temp\STSFX6249\SymDiag.exe" -iso en -vqapath "C:\Users\admin\AppData\Local\Temp\Rar$EXb2176.23483\unknown\VeritasQuickAssist.exe" isup C:\Users\admin\AppData\Local\Temp\STSFX6249\SymDiagUi3.exe
SymDiag.exe
User:
admin
Company:
Veritas Technologies LLC
Integrity Level:
HIGH
Description:
Veritas Quick Assist
Exit code:
0
Version:
2.3.152.211
Modules
Images
c:\users\admin\appdata\local\temp\stsfx6249\symdiagui3.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1736"C:\Users\admin\AppData\Local\Temp\Rar$EXb2176.2005\known malisious\mscontrol.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb2176.2005\known malisious\mscontrol.exeWinRAR.exe
User:
admin
Company:
SCHM-Soft
Integrity Level:
MEDIUM
Exit code:
0
Version:
0.1.1.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb2176.2005\known malisious\mscontrol.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2176"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Sample1.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2308"C:\Users\admin\AppData\Local\Temp\STSFX6249\SymDiag.exe" -iso en -vqapath "C:\Users\admin\AppData\Local\Temp\Rar$EXb2176.23483\unknown\VeritasQuickAssist.exe" isup C:\Users\admin\AppData\Local\Temp\STSFX6249\SymDiag.exeVeritasQuickAssist.exe
User:
admin
Company:
Veritas Technologies LLC
Integrity Level:
MEDIUM
Description:
Veritas Quick Assist
Exit code:
3221226540
Version:
2.3.152.211
Modules
Images
c:\users\admin\appdata\local\temp\stsfx6249\symdiag.exe
c:\systemroot\system32\ntdll.dll
2636"C:\Users\admin\AppData\Local\Temp\Rar$EXb2176.23483\unknown\VeritasQuickAssist.exe" isup C:\Users\admin\AppData\Local\Temp\Rar$EXb2176.23483\unknown\VeritasQuickAssist.exe
VeritasQuickAssist.exe
User:
admin
Company:
Veritas Technologies LLC
Integrity Level:
MEDIUM
Description:
Veritas Quick Assist self-extractor
Exit code:
0
Version:
2.3.152.211
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb2176.23483\unknown\veritasquickassist.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2788"C:\Users\admin\AppData\Local\Temp\Rar$EXb2176.23483\unknown\VeritasQuickAssist.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb2176.23483\unknown\VeritasQuickAssist.exe
WinRAR.exe
User:
admin
Company:
Veritas Technologies LLC
Integrity Level:
MEDIUM
Description:
Veritas Quick Assist self-extractor
Exit code:
0
Version:
2.2.141.81
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb2176.23483\unknown\veritasquickassist.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
2 487
Read events
2 302
Write events
184
Delete events
1

Modification events

(PID) Process:(2176) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2176) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2176) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2176) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Sample1.zip
(PID) Process:(2176) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2176) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2176) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2176) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2176) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
(PID) Process:(2176) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
Executable files
270
Suspicious files
35
Text files
50
Unknown types
39

Dropped files

PID
Process
Filename
Type
2176WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2176.2005\unknown\decthumbsdbviewer.wlxwlx
MD5:
SHA256:
2176WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2176.2005\known malisious\1module.sfxexecutable
MD5:
SHA256:
2176WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2176.2005\unknown\lameacm.acmexecutable
MD5:
SHA256:
2176WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2176.2005\unknown\swfll.wlxexecutable
MD5:
SHA256:
2176WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2176.2005\unknown\3dm.wlxexecutable
MD5:
SHA256:
2176WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2176.2005\unknown\amlview.wlxexecutable
MD5:
SHA256:
2176WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2176.2005\unknown\dfplay.ocxexecutable
MD5:
SHA256:
2176WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2176.2005\known malisious\upxg.exeexecutable
MD5:
SHA256:
2176WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2176.2005\unknown\eventlog.wlxexecutable
MD5:
SHA256:
2176WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2176.2005\unknown\dmflst.wlxexecutable
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
15
TCP/UDP connections
16
DNS requests
7
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2636
VeritasQuickAssist.exe
GET
301
2.19.45.226:80
http://www.veritas.com/content/dam/VQA/sdupdate.dat
unknown
whitelisted
2788
VeritasQuickAssist.exe
GET
200
23.37.43.27:80
http://s2.symcb.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS56bKHAoUD%2BOyl%2B0LhPg9JxyQm4gQUf9Nlp8Ld7LvwMAnzQzn6Aq8zMTMCED141%2Fl2SWCyYX308B7Khio%3D
NL
der
1.71 Kb
whitelisted
2788
VeritasQuickAssist.exe
GET
200
23.37.43.27:80
http://s.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ%2FYHKj6JjF6UBieQioTYpFsuEriQQUtnf6aUhHn1MS1cLqBzJ2B9GXBxkCEHsFsdRJaFFE98mJ0pwZnRI%3D
NL
der
1.68 Kb
shared
1380
SymDiagUi3.exe
POST
200
52.5.213.152:80
http://telemetry.community.veritas.com/entt
US
text
3 b
unknown
2788
VeritasQuickAssist.exe
GET
200
23.37.43.27:80
http://ts-ocsp.ws.symantec.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQd11mpyHEqFCSocj4SCu93CBydHAQUr2PWyqNOhXLgp7xB8ymiOH%2BAdWICEHvU5a%2B6zAc%2FoQEjBCJBTRI%3D
NL
der
1.55 Kb
whitelisted
2788
VeritasQuickAssist.exe
GET
200
23.37.43.27:80
http://sv.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQe6LNDJdqx%2BJOp7hVgTeaGFJ%2FCQgQUljtT8Hkzl699g%2B8uK8zKt4YecmYCEGaUcG%2FGFesgVls9jILcdXA%3D
NL
der
1.57 Kb
shared
2820
VeritasQuickAssist.exe
POST
200
52.5.213.152:80
http://telemetry.community.veritas.com/entt
US
text
3 b
unknown
1380
SymDiagUi3.exe
POST
200
52.5.213.152:80
http://telemetry.community.veritas.com/entt
US
text
3 b
unknown
1380
SymDiagUi3.exe
POST
200
52.5.213.152:80
http://telemetry.community.veritas.com/entt
US
text
3 b
unknown
1380
SymDiagUi3.exe
POST
200
52.5.213.152:80
http://telemetry.community.veritas.com/entt
US
text
3 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2788
VeritasQuickAssist.exe
2.19.45.226:443
www.veritas.com
Akamai International B.V.
whitelisted
2788
VeritasQuickAssist.exe
2.19.45.226:80
www.veritas.com
Akamai International B.V.
whitelisted
2788
VeritasQuickAssist.exe
23.37.43.27:80
s2.symcb.com
Akamai Technologies, Inc.
NL
whitelisted
2820
VeritasQuickAssist.exe
52.5.213.152:80
telemetry.community.veritas.com
Amazon.com, Inc.
US
unknown
2636
VeritasQuickAssist.exe
2.19.45.226:80
www.veritas.com
Akamai International B.V.
whitelisted
1380
SymDiagUi3.exe
52.5.213.152:80
telemetry.community.veritas.com
Amazon.com, Inc.
US
unknown
2636
VeritasQuickAssist.exe
2.19.45.226:443
www.veritas.com
Akamai International B.V.
whitelisted
52.5.213.152:80
telemetry.community.veritas.com
Amazon.com, Inc.
US
unknown

DNS requests

Domain
IP
Reputation
www.veritas.com
  • 2.19.45.226
unknown
aemqa.veritas.com
unknown
s2.symcb.com
  • 23.37.43.27
whitelisted
sv.symcd.com
  • 23.37.43.27
shared
s.symcd.com
  • 23.37.43.27
shared
ts-ocsp.ws.symantec.com
  • 23.37.43.27
whitelisted
telemetry.community.veritas.com
  • 52.5.213.152
  • 18.211.239.170
  • 52.44.147.153
unknown

Threats

No threats detected
No debug info