analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

Sample1.zip

Full analysis: https://app.any.run/tasks/b7ff5b0d-4179-47c7-a3cc-ee41cbec3312
Verdict: Malicious activity
Analysis date: June 19, 2019, 06:49:27
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract
MD5:

3118D28F4443A48859D2C7217727469F

SHA1:

D21A90A5DD5893E894D9EAE4F85B636654BF4C88

SHA256:

A2CD7AF78EB987CC515284A26E11AD4DC59E68E6C428B1A8589E922914CE6371

SSDEEP:

196608:9nElW6eG9BtROqu7lI3OxBkxTyruntiPcZrHQFXN7zKAl:9daBtR7aI+mtiACXRJl

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • unins000.exe (PID: 3404)
      • unins000.exe (PID: 3400)
      • VeritasQuickAssist.exe (PID: 968)
      • VeritasQuickAssist.exe (PID: 760)
      • SymDiag.exe (PID: 2268)
      • SymDiagUi3.exe (PID: 2324)
      • SymDiag.exe (PID: 2384)
    • Loads dropped or rewritten executable

      • VeritasQuickAssist.exe (PID: 760)
      • VeritasQuickAssist.exe (PID: 3556)
      • VeritasQuickAssist.exe (PID: 968)
      • SymDiagUi3.exe (PID: 2324)
    • Runs PING.EXE for delay simulation

      • cmd.exe (PID: 3800)
    • Loads the Task Scheduler COM API

      • SymDiagUi3.exe (PID: 2324)
    • Changes settings of System certificates

      • SymDiag.exe (PID: 2384)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • VeritasQuickAssist.exe (PID: 3556)
      • WinRAR.exe (PID: 3508)
      • VeritasQuickAssist.exe (PID: 760)
      • VeritasQuickAssist.exe (PID: 968)
    • Starts CMD.EXE for self-deleting

      • VeritasQuickAssist.exe (PID: 3556)
    • Starts CMD.EXE for commands execution

      • VeritasQuickAssist.exe (PID: 3556)
    • Low-level read access rights to disk partition

      • SymDiagUi3.exe (PID: 2324)
    • Adds / modifies Windows certificates

      • SymDiag.exe (PID: 2384)
    • Reads Environment values

      • SymDiagUi3.exe (PID: 2324)
    • Executed as Windows Service

      • WmiApSrv.exe (PID: 2520)
    • Reads CPU info

      • SymDiagUi3.exe (PID: 2324)
  • INFO

    • Manual execution by user

      • unins000.exe (PID: 3404)
      • wermgr.exe (PID: 2484)
      • unins000.exe (PID: 3400)
    • Reads Microsoft Office registry keys

      • SymDiagUi3.exe (PID: 2324)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2019:06:18 16:04:13
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: known malisious/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
59
Monitored processes
13
Malicious processes
7
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start drop and start drop and start drop and start winrar.exe wermgr.exe no specs unins000.exe no specs unins000.exe veritasquickassist.exe veritasquickassist.exe veritasquickassist.exe cmd.exe no specs ping.exe no specs symdiag.exe no specs symdiag.exe symdiagui3.exe wmiapsrv.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3508"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Sample1.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.60.0
2484"C:\Windows\system32\wermgr.exe" "-outproc" "2036" "3192" C:\Windows\system32\wermgr.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
3404"C:\Users\admin\Desktop\unins000.exe" C:\Users\admin\Desktop\unins000.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Uninstaller
Exit code:
3221226540
Version:
51.15.0.0
3400"C:\Users\admin\Desktop\unins000.exe" C:\Users\admin\Desktop\unins000.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
Uninstaller
Exit code:
1
Version:
51.15.0.0
760"C:\Users\admin\AppData\Local\Temp\Rar$EXb3508.21133\unknown\VeritasQuickAssist.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb3508.21133\unknown\VeritasQuickAssist.exe
WinRAR.exe
User:
admin
Company:
Veritas Technologies LLC
Integrity Level:
MEDIUM
Description:
Veritas Quick Assist self-extractor
Exit code:
0
Version:
2.2.141.81
3556"C:\Users\admin\AppData\Local\Temp\STSFX1B3E\VeritasQuickAssist.exe" C:\Users\admin\AppData\Local\Temp\STSFX1B3E\VeritasQuickAssist.exe
VeritasQuickAssist.exe
User:
admin
Company:
Veritas Technologies LLC
Integrity Level:
MEDIUM
Description:
Veritas Quick Assist self-extractor
Exit code:
0
Version:
2.3.152.211
968"C:\Users\admin\AppData\Local\Temp\Rar$EXb3508.21133\unknown\VeritasQuickAssist.exe" isup C:\Users\admin\AppData\Local\Temp\Rar$EXb3508.21133\unknown\VeritasQuickAssist.exe
VeritasQuickAssist.exe
User:
admin
Company:
Veritas Technologies LLC
Integrity Level:
MEDIUM
Description:
Veritas Quick Assist self-extractor
Version:
2.3.152.211
3800"C:\Windows\system32\cmd.exe" /c ping 127.0.0.1 -n 3 & del C:\Users\admin\AppData\Local\Temp\STSFX1~2\VERITA~1.EXE & rmdir C:\Users\admin\AppData\Local\Temp\STSFX1~2C:\Windows\system32\cmd.exeVeritasQuickAssist.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
1944ping 127.0.0.1 -n 3 C:\Windows\system32\PING.EXEcmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
TCP/IP Ping Command
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
2268"C:\Users\admin\AppData\Local\Temp\STSFX1B5B\SymDiag.exe" -iso en -vqapath "C:\Users\admin\AppData\Local\Temp\Rar$EXb3508.21133\unknown\VeritasQuickAssist.exe" isup C:\Users\admin\AppData\Local\Temp\STSFX1B5B\SymDiag.exeVeritasQuickAssist.exe
User:
admin
Company:
Veritas Technologies LLC
Integrity Level:
MEDIUM
Description:
Veritas Quick Assist
Exit code:
3221226540
Version:
2.3.152.211
Total events
1 900
Read events
1 778
Write events
0
Delete events
0

Modification events

No data
Executable files
172
Suspicious files
38
Text files
51
Unknown types
31

Dropped files

PID
Process
Filename
Type
3508WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3508.5899\unknown\blat.exe
MD5:
SHA256:
3508WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3508.14495\unknown\unins000.exe
MD5:
SHA256:
3508WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb3508.21133\known malisious\ps2htm.exeexecutable
MD5:37147CD5F4B2752A7A9DD028A739F681
SHA256:67A02B4EFA2CBFDA45C9662D9C105183B862401CB8FBD846EE52D29BABBDBD04
2484wermgr.exeC:\Users\admin\AppData\Local\Microsoft\Windows\WER\ReportQueue\NonCritical_blat.exe_e180c86c7bb8cbbe20c64097ca9f5b38892d2b5_cab_09a7ab95\appcompat.txtxml
MD5:F2F5873A0B395DB9468CF9D1F8A771BE
SHA256:437774D68CAC028B4CBA8BC12C8E5993591E419E7990CEE6D81A435AB0364000
3508WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb3508.21133\unknown\blat.exeexecutable
MD5:5C189B05A0E803FA0B771281D9D9E1FD
SHA256:6397D4670119B287338AD617BA2238BD7FA3F5CD5C5510849A13CBBF5731AC99
3508WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb3508.21133\known malisious\module.sfxexecutable
MD5:B30EB8F5FDFDE64C3BF087502E96DD96
SHA256:4F74A25BE621038FA20CA0BBC18A060A180E10936682D0155D3D818925772360
3508WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb3508.21133\unknown\eventlog.wlxexecutable
MD5:EB9096E1C5396F27450A027A0DEC76AD
SHA256:1614D002A13792508C6B680FB52C2104273E2C081AA43883F68D3FCB14BCCB3A
3508WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb3508.21133\known malisious\1module.sfxexecutable
MD5:A6B126B3BEB03F813F4F7AA2D52C8D52
SHA256:CF812D72058870884D53F7D7A6D0D2B1A633D2F73B7148245A985632B56A2CC1
3508WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb3508.21133\unknown\3dm.wlxexecutable
MD5:AC2BE5E17FA26DEDF260C9E6776E7B5E
SHA256:8CD6760CC9C3E5C02056D3DA2A832B5FE8627BA14C04BBDB7499521529577837
3508WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb3508.21133\unknown\dfctrl.ocxexecutable
MD5:1EBCEBA9F9A19232B9F1BFF2402C673B
SHA256:40BA4D96EE4428BB758DF37B2A82BCF0761B31BC1982735EECCDEAE8C0546513
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
14
TCP/UDP connections
15
DNS requests
7
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
760
VeritasQuickAssist.exe
GET
301
2.19.45.226:80
http://www.veritas.com/content/dam/VQA/VeritasQuickAssist.exe
unknown
whitelisted
760
VeritasQuickAssist.exe
GET
301
2.19.45.226:80
http://www.veritas.com/content/dam/VQA/QuickAssistVer.txt
unknown
whitelisted
760
VeritasQuickAssist.exe
GET
200
23.37.43.27:80
http://ts-ocsp.ws.symantec.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQd11mpyHEqFCSocj4SCu93CBydHAQUr2PWyqNOhXLgp7xB8ymiOH%2BAdWICEHvU5a%2B6zAc%2FoQEjBCJBTRI%3D
NL
der
1.55 Kb
whitelisted
2324
SymDiagUi3.exe
POST
200
52.5.213.152:80
http://telemetry.community.veritas.com/entt
US
text
3 b
unknown
760
VeritasQuickAssist.exe
GET
200
23.37.43.27:80
http://s2.symcb.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS56bKHAoUD%2BOyl%2B0LhPg9JxyQm4gQUf9Nlp8Ld7LvwMAnzQzn6Aq8zMTMCED141%2Fl2SWCyYX308B7Khio%3D
NL
der
1.71 Kb
whitelisted
968
VeritasQuickAssist.exe
GET
301
2.19.45.226:80
http://www.veritas.com/content/dam/VQA/sdupdate.dat
unknown
whitelisted
760
VeritasQuickAssist.exe
GET
200
23.37.43.27:80
http://s.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ%2FYHKj6JjF6UBieQioTYpFsuEriQQUtnf6aUhHn1MS1cLqBzJ2B9GXBxkCEHsFsdRJaFFE98mJ0pwZnRI%3D
NL
der
1.68 Kb
shared
760
VeritasQuickAssist.exe
GET
200
23.37.43.27:80
http://sv.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQe6LNDJdqx%2BJOp7hVgTeaGFJ%2FCQgQUljtT8Hkzl699g%2B8uK8zKt4YecmYCEGaUcG%2FGFesgVls9jILcdXA%3D
NL
der
1.57 Kb
shared
3556
VeritasQuickAssist.exe
POST
200
52.5.213.152:80
http://telemetry.community.veritas.com/entt
US
text
3 b
unknown
2324
SymDiagUi3.exe
POST
200
52.5.213.152:80
http://telemetry.community.veritas.com/entt
US
text
3 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3556
VeritasQuickAssist.exe
52.5.213.152:80
telemetry.community.veritas.com
Amazon.com, Inc.
US
unknown
760
VeritasQuickAssist.exe
23.37.43.27:80
s2.symcb.com
Akamai Technologies, Inc.
NL
whitelisted
760
VeritasQuickAssist.exe
2.19.45.226:80
www.veritas.com
Akamai International B.V.
whitelisted
23.37.43.27:80
s2.symcb.com
Akamai Technologies, Inc.
NL
whitelisted
760
VeritasQuickAssist.exe
2.19.45.226:443
www.veritas.com
Akamai International B.V.
whitelisted
968
VeritasQuickAssist.exe
2.19.45.226:80
www.veritas.com
Akamai International B.V.
whitelisted
2324
SymDiagUi3.exe
52.5.213.152:80
telemetry.community.veritas.com
Amazon.com, Inc.
US
unknown
968
VeritasQuickAssist.exe
2.19.45.226:443
www.veritas.com
Akamai International B.V.
whitelisted
52.5.213.152:80
telemetry.community.veritas.com
Amazon.com, Inc.
US
unknown

DNS requests

Domain
IP
Reputation
www.veritas.com
  • 2.19.45.226
unknown
aemqa.veritas.com
unknown
s2.symcb.com
  • 23.37.43.27
whitelisted
sv.symcd.com
  • 23.37.43.27
shared
s.symcd.com
  • 23.37.43.27
shared
ts-ocsp.ws.symantec.com
  • 23.37.43.27
whitelisted
telemetry.community.veritas.com
  • 52.5.213.152
  • 18.211.239.170
  • 52.44.147.153
unknown

Threats

No threats detected
No debug info