File name:

TQ RFQ kk725242628826242,pdf.iso

Full analysis: https://app.any.run/tasks/044b917a-0c03-44dc-a065-b39b16f08222
Verdict: Malicious activity
Analysis date: March 30, 2020, 19:14:34
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-iso9660-image
File info: ISO 9660 CD-ROM filesystem data 'BO RFQ kk725242628826242,pdf'
MD5:

7DBECEF9F8C415578156E8AB6DD6C70A

SHA1:

715ADCEB44CAE3E43FF9B828A0A35CE87DC9B2BF

SHA256:

A308EEA438BAB5BCA5A584412E39B4217518CEB0CCBCB428222BC4814A457684

SSDEEP:

24576:c7VqsmW4vFw+u7qyMtMUALS13u+WGp0c4KxWj:cACMyMmrB5uW

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • BO RFQ kk725242628826242,pdf.exe (PID: 2560)
    • Changes settings of System certificates

      • BO RFQ kk725242628826242,pdf.exe (PID: 2560)
  • SUSPICIOUS

    • Reads Internet Cache Settings

      • BO RFQ kk725242628826242,pdf.exe (PID: 2560)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1812)
    • Adds / modifies Windows certificates

      • BO RFQ kk725242628826242,pdf.exe (PID: 2560)
  • INFO

    • Reads settings of System Certificates

      • BO RFQ kk725242628826242,pdf.exe (PID: 2560)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.iso | ISO 9660 CD image (27.6)
.atn | Photoshop Action (27.1)
.gmc | Game Music Creator Music (6.1)

EXIF

ISO

System: Win32
VolumeName: BO RFQ kk725242628826242,pdf
VolumeBlockCount: 496
VolumeBlockSize: 2048
RootDirectoryCreateDate: 2020:03:30 16:55:46+01:00
Software: PowerISO
VolumeCreateDate: 2020:03:30 16:55:46.00+01:00
VolumeModifyDate: 2020:03:30 16:55:46.00+01:00

Composite

VolumeSize: 992 kB
No data.
screenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
36
Monitored processes
2
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start winrar.exe bo rfq kk725242628826242,pdf.exe

Process information

PID
CMD
Path
Indicators
Parent process
1812"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\TQ RFQ kk725242628826242,pdf.iso"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2560"C:\Users\admin\AppData\Local\Temp\Rar$EXa1812.2655\BO RFQ kk725242628826242,pdf.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa1812.2655\BO RFQ kk725242628826242,pdf.exe
WinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa1812.2655\bo rfq kk725242628826242,pdf.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
Total events
2 040
Read events
444
Write events
1 068
Delete events
528

Modification events

(PID) Process:(1812) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1812) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1812) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1812) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\TQ RFQ kk725242628826242,pdf.iso
(PID) Process:(1812) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1812) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1812) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1812) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1812) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(1812) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
Executable files
1
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
1812WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1812.2655\BO RFQ kk725242628826242,pdf.exeexecutable
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
1
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2560
BO RFQ kk725242628826242,pdf.exe
216.58.210.14:443
drive.google.com
Google Inc.
US
whitelisted

DNS requests

Domain
IP
Reputation
drive.google.com
  • 216.58.210.14
shared

Threats

No threats detected
No debug info