File name:

Sample1.zip

Full analysis: https://app.any.run/tasks/b7ff5b0d-4179-47c7-a3cc-ee41cbec3312
Verdict: Malicious activity
Analysis date: June 19, 2019, 06:49:27
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract
MD5:

3118D28F4443A48859D2C7217727469F

SHA1:

D21A90A5DD5893E894D9EAE4F85B636654BF4C88

SHA256:

A2CD7AF78EB987CC515284A26E11AD4DC59E68E6C428B1A8589E922914CE6371

SSDEEP:

196608:9nElW6eG9BtROqu7lI3OxBkxTyruntiPcZrHQFXN7zKAl:9daBtR7aI+mtiACXRJl

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • unins000.exe (PID: 3404)
      • unins000.exe (PID: 3400)
      • VeritasQuickAssist.exe (PID: 760)
      • VeritasQuickAssist.exe (PID: 968)
      • SymDiagUi3.exe (PID: 2324)
      • SymDiag.exe (PID: 2384)
      • SymDiag.exe (PID: 2268)
    • Loads dropped or rewritten executable

      • VeritasQuickAssist.exe (PID: 760)
      • VeritasQuickAssist.exe (PID: 968)
      • SymDiagUi3.exe (PID: 2324)
      • VeritasQuickAssist.exe (PID: 3556)
    • Changes settings of System certificates

      • SymDiag.exe (PID: 2384)
    • Loads the Task Scheduler COM API

      • SymDiagUi3.exe (PID: 2324)
    • Runs PING.EXE for delay simulation

      • cmd.exe (PID: 3800)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • VeritasQuickAssist.exe (PID: 760)
      • WinRAR.exe (PID: 3508)
      • VeritasQuickAssist.exe (PID: 3556)
      • VeritasQuickAssist.exe (PID: 968)
    • Starts CMD.EXE for self-deleting

      • VeritasQuickAssist.exe (PID: 3556)
    • Adds / modifies Windows certificates

      • SymDiag.exe (PID: 2384)
    • Reads Environment values

      • SymDiagUi3.exe (PID: 2324)
    • Low-level read access rights to disk partition

      • SymDiagUi3.exe (PID: 2324)
    • Reads CPU info

      • SymDiagUi3.exe (PID: 2324)
    • Executed as Windows Service

      • WmiApSrv.exe (PID: 2520)
    • Starts CMD.EXE for commands execution

      • VeritasQuickAssist.exe (PID: 3556)
  • INFO

    • Manual execution by user

      • wermgr.exe (PID: 2484)
      • unins000.exe (PID: 3400)
      • unins000.exe (PID: 3404)
    • Reads Microsoft Office registry keys

      • SymDiagUi3.exe (PID: 2324)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2019:06:18 16:04:13
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: known malisious/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
59
Monitored processes
13
Malicious processes
7
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start drop and start drop and start drop and start winrar.exe wermgr.exe no specs unins000.exe no specs unins000.exe veritasquickassist.exe veritasquickassist.exe veritasquickassist.exe cmd.exe no specs ping.exe no specs symdiag.exe no specs symdiag.exe symdiagui3.exe wmiapsrv.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
760"C:\Users\admin\AppData\Local\Temp\Rar$EXb3508.21133\unknown\VeritasQuickAssist.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb3508.21133\unknown\VeritasQuickAssist.exe
WinRAR.exe
User:
admin
Company:
Veritas Technologies LLC
Integrity Level:
MEDIUM
Description:
Veritas Quick Assist self-extractor
Exit code:
0
Version:
2.2.141.81
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb3508.21133\unknown\veritasquickassist.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\comdlg32.dll
968"C:\Users\admin\AppData\Local\Temp\Rar$EXb3508.21133\unknown\VeritasQuickAssist.exe" isup C:\Users\admin\AppData\Local\Temp\Rar$EXb3508.21133\unknown\VeritasQuickAssist.exe
VeritasQuickAssist.exe
User:
admin
Company:
Veritas Technologies LLC
Integrity Level:
MEDIUM
Description:
Veritas Quick Assist self-extractor
Exit code:
0
Version:
2.3.152.211
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb3508.21133\unknown\veritasquickassist.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
1944ping 127.0.0.1 -n 3 C:\Windows\system32\PING.EXEcmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
TCP/IP Ping Command
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ping.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
2268"C:\Users\admin\AppData\Local\Temp\STSFX1B5B\SymDiag.exe" -iso en -vqapath "C:\Users\admin\AppData\Local\Temp\Rar$EXb3508.21133\unknown\VeritasQuickAssist.exe" isup C:\Users\admin\AppData\Local\Temp\STSFX1B5B\SymDiag.exeVeritasQuickAssist.exe
User:
admin
Company:
Veritas Technologies LLC
Integrity Level:
MEDIUM
Description:
Veritas Quick Assist
Exit code:
3221226540
Version:
2.3.152.211
Modules
Images
c:\users\admin\appdata\local\temp\stsfx1b5b\symdiag.exe
c:\systemroot\system32\ntdll.dll
2324"C:\Users\admin\AppData\Local\Temp\STSFX1B5B\SymDiagUi3.exe" "C:\Users\admin\AppData\Local\Temp\STSFX1B5B\SymDiag.exe" -iso en -vqapath "C:\Users\admin\AppData\Local\Temp\Rar$EXb3508.21133\unknown\VeritasQuickAssist.exe" isup C:\Users\admin\AppData\Local\Temp\STSFX1B5B\SymDiagUi3.exe
SymDiag.exe
User:
admin
Company:
Veritas Technologies LLC
Integrity Level:
HIGH
Description:
Veritas Quick Assist
Exit code:
0
Version:
2.3.152.211
Modules
Images
c:\users\admin\appdata\local\temp\stsfx1b5b\symdiagui3.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2384"C:\Users\admin\AppData\Local\Temp\STSFX1B5B\SymDiag.exe" -iso en -vqapath "C:\Users\admin\AppData\Local\Temp\Rar$EXb3508.21133\unknown\VeritasQuickAssist.exe" isup C:\Users\admin\AppData\Local\Temp\STSFX1B5B\SymDiag.exe
VeritasQuickAssist.exe
User:
admin
Company:
Veritas Technologies LLC
Integrity Level:
HIGH
Description:
Veritas Quick Assist
Exit code:
2324
Version:
2.3.152.211
Modules
Images
c:\users\admin\appdata\local\temp\stsfx1b5b\symdiag.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2484"C:\Windows\system32\wermgr.exe" "-outproc" "2036" "3192" C:\Windows\system32\wermgr.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\wermgr.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
2520C:\Windows\system32\wbem\WmiApSrv.exeC:\Windows\system32\wbem\WmiApSrv.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
WMI Performance Reverse Adapter
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\wbem\wmiapsrv.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3400"C:\Users\admin\Desktop\unins000.exe" C:\Users\admin\Desktop\unins000.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
Uninstaller
Exit code:
1
Version:
51.15.0.0
Modules
Images
c:\users\admin\desktop\unins000.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
3404"C:\Users\admin\Desktop\unins000.exe" C:\Users\admin\Desktop\unins000.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Uninstaller
Exit code:
3221226540
Version:
51.15.0.0
Modules
Images
c:\users\admin\desktop\unins000.exe
c:\systemroot\system32\ntdll.dll
Total events
1 900
Read events
1 778
Write events
122
Delete events
0

Modification events

(PID) Process:(3508) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3508) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3508) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3508) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Sample1.zip
(PID) Process:(3508) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3508) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3508) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3508) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3508) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
(PID) Process:(3508) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
Executable files
172
Suspicious files
38
Text files
51
Unknown types
31

Dropped files

PID
Process
Filename
Type
3508WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3508.5899\unknown\blat.exe
MD5:
SHA256:
3508WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3508.14495\unknown\unins000.exe
MD5:
SHA256:
2484wermgr.exeC:\Users\admin\AppData\Local\Microsoft\Windows\WER\ReportQueue\NonCritical_blat.exe_e180c86c7bb8cbbe20c64097ca9f5b38892d2b5_cab_09a7ab95\Report.werbinary
MD5:
SHA256:
3508WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb3508.21133\known malisious\ps2htm.exeexecutable
MD5:
SHA256:
2484wermgr.exeC:\Users\admin\AppData\Local\Microsoft\Windows\WER\ReportQueue\NonCritical_blat.exe_e180c86c7bb8cbbe20c64097ca9f5b38892d2b5_cab_09a7ab95\appcompat.txtxml
MD5:
SHA256:
3508WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb3508.21133\known malisious\module.sfxexecutable
MD5:
SHA256:
3508WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb3508.21133\known malisious\upxg.exeexecutable
MD5:
SHA256:
2484wermgr.exeC:\Users\admin\AppData\Local\Microsoft\Windows\WER\ReportQueue\NonCritical_blat.exe_e180c86c7bb8cbbe20c64097ca9f5b38892d2b5_cab_09a7ab95\TabAB37.tmptext
MD5:6D3B14447ECC617DA3029FBD5F66D16E
SHA256:BCE59783C3775964831C5B32EF99BDD9585838F9966F6C2CF06F9A59B0985AB7
3508WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb3508.21133\unknown\3dm.wlxexecutable
MD5:
SHA256:
3508WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb3508.21133\unknown\amlview.wlxexecutable
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
14
TCP/UDP connections
15
DNS requests
7
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
760
VeritasQuickAssist.exe
GET
301
2.19.45.226:80
http://www.veritas.com/content/dam/VQA/QuickAssistVer.txt
unknown
whitelisted
760
VeritasQuickAssist.exe
GET
301
2.19.45.226:80
http://www.veritas.com/content/dam/VQA/VeritasQuickAssist.exe
unknown
whitelisted
760
VeritasQuickAssist.exe
GET
200
23.37.43.27:80
http://s2.symcb.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS56bKHAoUD%2BOyl%2B0LhPg9JxyQm4gQUf9Nlp8Ld7LvwMAnzQzn6Aq8zMTMCED141%2Fl2SWCyYX308B7Khio%3D
NL
der
1.71 Kb
whitelisted
760
VeritasQuickAssist.exe
GET
200
23.37.43.27:80
http://sv.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQe6LNDJdqx%2BJOp7hVgTeaGFJ%2FCQgQUljtT8Hkzl699g%2B8uK8zKt4YecmYCEGaUcG%2FGFesgVls9jILcdXA%3D
NL
der
1.57 Kb
shared
760
VeritasQuickAssist.exe
GET
200
23.37.43.27:80
http://s.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ%2FYHKj6JjF6UBieQioTYpFsuEriQQUtnf6aUhHn1MS1cLqBzJ2B9GXBxkCEHsFsdRJaFFE98mJ0pwZnRI%3D
NL
der
1.68 Kb
shared
760
VeritasQuickAssist.exe
GET
200
23.37.43.27:80
http://ts-ocsp.ws.symantec.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQd11mpyHEqFCSocj4SCu93CBydHAQUr2PWyqNOhXLgp7xB8ymiOH%2BAdWICEHvU5a%2B6zAc%2FoQEjBCJBTRI%3D
NL
der
1.55 Kb
whitelisted
2324
SymDiagUi3.exe
POST
200
52.5.213.152:80
http://telemetry.community.veritas.com/entt
US
text
3 b
unknown
2324
SymDiagUi3.exe
POST
200
52.5.213.152:80
http://telemetry.community.veritas.com/entt
US
text
3 b
unknown
2324
SymDiagUi3.exe
POST
200
52.5.213.152:80
http://telemetry.community.veritas.com/entt
US
text
3 b
unknown
2324
SymDiagUi3.exe
POST
200
52.5.213.152:80
http://telemetry.community.veritas.com/entt
US
text
3 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
760
VeritasQuickAssist.exe
2.19.45.226:80
www.veritas.com
Akamai International B.V.
whitelisted
23.37.43.27:80
s2.symcb.com
Akamai Technologies, Inc.
NL
whitelisted
760
VeritasQuickAssist.exe
2.19.45.226:443
www.veritas.com
Akamai International B.V.
whitelisted
760
VeritasQuickAssist.exe
23.37.43.27:80
s2.symcb.com
Akamai Technologies, Inc.
NL
whitelisted
3556
VeritasQuickAssist.exe
52.5.213.152:80
telemetry.community.veritas.com
Amazon.com, Inc.
US
unknown
968
VeritasQuickAssist.exe
2.19.45.226:80
www.veritas.com
Akamai International B.V.
whitelisted
968
VeritasQuickAssist.exe
2.19.45.226:443
www.veritas.com
Akamai International B.V.
whitelisted
52.5.213.152:80
telemetry.community.veritas.com
Amazon.com, Inc.
US
unknown
2324
SymDiagUi3.exe
52.5.213.152:80
telemetry.community.veritas.com
Amazon.com, Inc.
US
unknown

DNS requests

Domain
IP
Reputation
www.veritas.com
  • 2.19.45.226
unknown
aemqa.veritas.com
unknown
s2.symcb.com
  • 23.37.43.27
whitelisted
sv.symcd.com
  • 23.37.43.27
shared
s.symcd.com
  • 23.37.43.27
shared
ts-ocsp.ws.symantec.com
  • 23.37.43.27
whitelisted
telemetry.community.veritas.com
  • 52.5.213.152
  • 18.211.239.170
  • 52.44.147.153
unknown

Threats

No threats detected
No debug info