File name:

NNYCDFOD02_2023-12-27_22_54_44.809.zip

Full analysis: https://app.any.run/tasks/efa2d7ef-21ad-4dcc-91fe-7dc627cad110
Verdict: Malicious activity
Analysis date: December 27, 2023, 22:55:26
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v4.5 to extract
MD5:

60E83DE4EDC5C9C7D328AD4E8BDC811B

SHA1:

016B7D9F92B9EC83950A8659942F44A2799007D3

SHA256:

A34E75ED380765EE8EACB882FBE0628DE65FB4B8CE3540DD853275EA5FAB7FA3

SSDEEP:

98304:e9sRZsRS2QfHUfr5xyMcAjcVQlFQHzTlXXPZ9c5QPlvAPmR+I1Lvj3/y/4qFxyf0:wNBgQl

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads the Internet Settings

      • msiexec.exe (PID: 2624)
      • MSID091.tmp (PID: 3112)
      • MSID100.tmp (PID: 3148)
      • QuickBooksDownloder.exe (PID: 3100)
    • Adds/modifies Windows certificates

      • msiexec.exe (PID: 2580)
    • Checks Windows Trust Settings

      • msiexec.exe (PID: 188)
    • Connects to the server without a host name

      • QuickBooksDownloder.exe (PID: 3100)
  • INFO

    • Checks supported languages

      • msiexec.exe (PID: 188)
      • msiexec.exe (PID: 2624)
      • msiexec.exe (PID: 1268)
      • msiexec.exe (PID: 2876)
      • msiexec.exe (PID: 3052)
      • QuickBooksDownloder.exe (PID: 3100)
      • MSID091.tmp (PID: 3112)
      • MSID100.tmp (PID: 3148)
      • QBMaker.exe (PID: 3124)
    • Reads the computer name

      • msiexec.exe (PID: 188)
      • msiexec.exe (PID: 2624)
      • msiexec.exe (PID: 1268)
      • msiexec.exe (PID: 3052)
      • MSID091.tmp (PID: 3112)
      • MSID100.tmp (PID: 3148)
      • QuickBooksDownloder.exe (PID: 3100)
      • msiexec.exe (PID: 2876)
      • QBMaker.exe (PID: 3124)
    • Reads security settings of Internet Explorer

      • msiexec.exe (PID: 2056)
      • msiexec.exe (PID: 2580)
    • Manual execution by a user

      • msiexec.exe (PID: 2056)
    • Application launched itself

      • msiexec.exe (PID: 2624)
      • msiexec.exe (PID: 188)
    • Reads the machine GUID from the registry

      • msiexec.exe (PID: 188)
      • msiexec.exe (PID: 2624)
      • msiexec.exe (PID: 1268)
      • msiexec.exe (PID: 2876)
      • msiexec.exe (PID: 3052)
      • QuickBooksDownloder.exe (PID: 3100)
      • QBMaker.exe (PID: 3124)
    • Drops the executable file immediately after the start

      • msiexec.exe (PID: 2056)
      • msiexec.exe (PID: 2580)
      • msiexec.exe (PID: 188)
    • Executes as Windows Service

      • VSSVC.exe (PID: 2596)
    • Create files in a temporary directory

      • msiexec.exe (PID: 188)
    • Starts application with an unusual extension

      • msiexec.exe (PID: 188)
    • Checks transactions between databases Windows and Oracle

      • msiexec.exe (PID: 3052)
    • Process drops legitimate windows executable

      • msiexec.exe (PID: 188)
    • Reads Environment values

      • QBMaker.exe (PID: 3124)
      • QuickBooksDownloder.exe (PID: 3100)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0801
ZipCompression: Deflated
ZipModifyDate: 1980:00:00 00:00:00
ZipCRC: 0x1228448c
ZipCompressedSize: 4412568
ZipUncompressedSize: 5285376
ZipFileName: Device/HarddiskVolume3/Users/dgamaralalage/Downloads/QuickBooks Desktop Setup (1).msi
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
53
Monitored processes
14
Malicious processes
0
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe msiexec.exe no specs vssvc.exe no specs msiexec.exe no specs msiexec.exe no specs HNetCfg.FwPolicy2 no specs msid091.tmp no specs msid100.tmp no specs quickbooksdownloder.exe qbmaker.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
116"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\NNYCDFOD02_2023-12-27_22_54_44.809.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
188C:\Windows\system32\msiexec.exe /VC:\Windows\System32\msiexec.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1268C:\Windows\system32\MsiExec.exe -Embedding DDDBA7538CD703BBDC7D1BDB25DFB391 CC:\Windows\System32\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2056"C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\Desktop\Device\HarddiskVolume3\Users\dgamaralalage\Downloads\QuickBooks Desktop Setup (1).msi" C:\Windows\System32\msiexec.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
1602
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2580"C:\Windows\system32\msiexec.exe" /i "C:\Users\admin\Desktop\Device\HarddiskVolume3\Users\dgamaralalage\Downloads\QuickBooks Desktop Setup (1).msi"C:\Windows\System32\msiexec.exe
msiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2596C:\Windows\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2624C:\Windows\system32\MsiExec.exe -Embedding D08551B624C015E1243DC286FCBAB7C7 CC:\Windows\System32\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2876C:\Windows\system32\MsiExec.exe -Embedding 74F317B11B3CC0A444714DA7A5187F4FC:\Windows\System32\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3052C:\Windows\system32\MsiExec.exe -Embedding B6638127DC0F8651CE53FCF1F50ECFEF E Global\MSI0000C:\Windows\System32\msiexec.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3092C:\Windows\system32\DllHost.exe /Processid:{E2B3C97F-6AE1-41AC-817A-F6F92166D7DD}C:\Windows\System32\dllhost.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
COM Surrogate
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\dllhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
16 135
Read events
16 006
Write events
119
Delete events
10

Modification events

(PID) Process:(116) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(116) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(116) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(116) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(116) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(116) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(116) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(116) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(116) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2056) msiexec.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
Executable files
22
Suspicious files
11
Text files
4
Unknown types
0

Dropped files

PID
Process
Filename
Type
116WinRAR.exeC:\Users\admin\Desktop\Device\HarddiskVolume3\Users\dgamaralalage\Downloads\QuickBooks Desktop Setup (1).msi
MD5:
SHA256:
188msiexec.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
188msiexec.exeC:\Windows\Installer\ec782.msi
MD5:
SHA256:
2056msiexec.exeC:\Users\admin\AppData\Local\Temp\MSI946C.tmpexecutable
MD5:CFAB78AC0D042A1D8AD7085A94328EF6
SHA256:17B10DF05B4B92735B673914FE2BF0C0D7BBDA5B4A8F9A7FC81A0EFAA4380168
2580msiexec.exeC:\Users\admin\AppData\Local\Temp\MSI997F.tmpexecutable
MD5:CFAB78AC0D042A1D8AD7085A94328EF6
SHA256:17B10DF05B4B92735B673914FE2BF0C0D7BBDA5B4A8F9A7FC81A0EFAA4380168
2580msiexec.exeC:\Users\admin\AppData\Local\Temp\MSI994F.tmpexecutable
MD5:CFAB78AC0D042A1D8AD7085A94328EF6
SHA256:17B10DF05B4B92735B673914FE2BF0C0D7BBDA5B4A8F9A7FC81A0EFAA4380168
2580msiexec.exeC:\Users\admin\AppData\Local\Temp\MSI98FF.tmpexecutable
MD5:CFAB78AC0D042A1D8AD7085A94328EF6
SHA256:17B10DF05B4B92735B673914FE2BF0C0D7BBDA5B4A8F9A7FC81A0EFAA4380168
188msiexec.exeC:\System Volume Information\SPP\OnlineMetadataCache\{6d09e296-bd77-42d8-9def-70938e8c0d9f}_OnDiskSnapshotPropbinary
MD5:BC375B962F3CEC38E5CB1F52A6F62276
SHA256:B4B4B47E343083AC88B1099405EC9EB8A6B38D11AFD1D3E2D65BDBB3A15C24CD
188msiexec.exeC:\Windows\Installer\ec783.ipibinary
MD5:6A337AED7174E3352BEE8231D1CA84E5
SHA256:BA0EFBF0E76DB64D71EF4AEB2BF7E2C898960E034018AD0C3771F7CF34DF0C4C
188msiexec.exeC:\Windows\Installer\MSIC8D9.tmpexecutable
MD5:CFAB78AC0D042A1D8AD7085A94328EF6
SHA256:17B10DF05B4B92735B673914FE2BF0C0D7BBDA5B4A8F9A7FC81A0EFAA4380168
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
6
DNS requests
0
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3100
QuickBooksDownloder.exe
POST
200
185.161.211.237:80
http://185.161.211.237/api/get-software
unknown
binary
18.3 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
3100
QuickBooksDownloder.exe
185.161.211.237:80
Zemlyaniy Dmitro Leonidovich
NL
unknown

DNS requests

No data

Threats

PID
Process
Class
Message
3100
QuickBooksDownloder.exe
Malware Command and Control Activity Detected
ET MALWARE QuickBooks Pop-Up Scam - Request for QB Download Locations
No debug info