| File name: | NNYCDFOD02_2023-12-27_22_54_44.809.zip |
| Full analysis: | https://app.any.run/tasks/efa2d7ef-21ad-4dcc-91fe-7dc627cad110 |
| Verdict: | Malicious activity |
| Analysis date: | December 27, 2023, 22:55:26 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v4.5 to extract |
| MD5: | 60E83DE4EDC5C9C7D328AD4E8BDC811B |
| SHA1: | 016B7D9F92B9EC83950A8659942F44A2799007D3 |
| SHA256: | A34E75ED380765EE8EACB882FBE0628DE65FB4B8CE3540DD853275EA5FAB7FA3 |
| SSDEEP: | 98304:e9sRZsRS2QfHUfr5xyMcAjcVQlFQHzTlXXPZ9c5QPlvAPmR+I1Lvj3/y/4qFxyf0:wNBgQl |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | 0x0801 |
| ZipCompression: | Deflated |
| ZipModifyDate: | 1980:00:00 00:00:00 |
| ZipCRC: | 0x1228448c |
| ZipCompressedSize: | 4412568 |
| ZipUncompressedSize: | 5285376 |
| ZipFileName: | Device/HarddiskVolume3/Users/dgamaralalage/Downloads/QuickBooks Desktop Setup (1).msi |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 116 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\NNYCDFOD02_2023-12-27_22_54_44.809.zip" | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 188 | C:\Windows\system32\msiexec.exe /V | C:\Windows\System32\msiexec.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1268 | C:\Windows\system32\MsiExec.exe -Embedding DDDBA7538CD703BBDC7D1BDB25DFB391 C | C:\Windows\System32\msiexec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2056 | "C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\Desktop\Device\HarddiskVolume3\Users\dgamaralalage\Downloads\QuickBooks Desktop Setup (1).msi" | C:\Windows\System32\msiexec.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 1602 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2580 | "C:\Windows\system32\msiexec.exe" /i "C:\Users\admin\Desktop\Device\HarddiskVolume3\Users\dgamaralalage\Downloads\QuickBooks Desktop Setup (1).msi" | C:\Windows\System32\msiexec.exe | msiexec.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2596 | C:\Windows\system32\vssvc.exe | C:\Windows\System32\VSSVC.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2624 | C:\Windows\system32\MsiExec.exe -Embedding D08551B624C015E1243DC286FCBAB7C7 C | C:\Windows\System32\msiexec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2876 | C:\Windows\system32\MsiExec.exe -Embedding 74F317B11B3CC0A444714DA7A5187F4F | C:\Windows\System32\msiexec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3052 | C:\Windows\system32\MsiExec.exe -Embedding B6638127DC0F8651CE53FCF1F50ECFEF E Global\MSI0000 | C:\Windows\System32\msiexec.exe | — | msiexec.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3092 | C:\Windows\system32\DllHost.exe /Processid:{E2B3C97F-6AE1-41AC-817A-F6F92166D7DD} | C:\Windows\System32\dllhost.exe | — | svchost.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: COM Surrogate Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (116) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (116) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (116) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (116) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (116) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
| (PID) Process: | (116) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (116) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (116) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (116) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (2056) msiexec.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 116 | WinRAR.exe | C:\Users\admin\Desktop\Device\HarddiskVolume3\Users\dgamaralalage\Downloads\QuickBooks Desktop Setup (1).msi | — | |
MD5:— | SHA256:— | |||
| 188 | msiexec.exe | C:\System Volume Information\SPP\metadata-2 | — | |
MD5:— | SHA256:— | |||
| 188 | msiexec.exe | C:\Windows\Installer\ec782.msi | — | |
MD5:— | SHA256:— | |||
| 2056 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\MSI946C.tmp | executable | |
MD5:CFAB78AC0D042A1D8AD7085A94328EF6 | SHA256:17B10DF05B4B92735B673914FE2BF0C0D7BBDA5B4A8F9A7FC81A0EFAA4380168 | |||
| 2580 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\MSI997F.tmp | executable | |
MD5:CFAB78AC0D042A1D8AD7085A94328EF6 | SHA256:17B10DF05B4B92735B673914FE2BF0C0D7BBDA5B4A8F9A7FC81A0EFAA4380168 | |||
| 2580 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\MSI994F.tmp | executable | |
MD5:CFAB78AC0D042A1D8AD7085A94328EF6 | SHA256:17B10DF05B4B92735B673914FE2BF0C0D7BBDA5B4A8F9A7FC81A0EFAA4380168 | |||
| 2580 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\MSI98FF.tmp | executable | |
MD5:CFAB78AC0D042A1D8AD7085A94328EF6 | SHA256:17B10DF05B4B92735B673914FE2BF0C0D7BBDA5B4A8F9A7FC81A0EFAA4380168 | |||
| 188 | msiexec.exe | C:\System Volume Information\SPP\OnlineMetadataCache\{6d09e296-bd77-42d8-9def-70938e8c0d9f}_OnDiskSnapshotProp | binary | |
MD5:BC375B962F3CEC38E5CB1F52A6F62276 | SHA256:B4B4B47E343083AC88B1099405EC9EB8A6B38D11AFD1D3E2D65BDBB3A15C24CD | |||
| 188 | msiexec.exe | C:\Windows\Installer\ec783.ipi | binary | |
MD5:6A337AED7174E3352BEE8231D1CA84E5 | SHA256:BA0EFBF0E76DB64D71EF4AEB2BF7E2C898960E034018AD0C3771F7CF34DF0C4C | |||
| 188 | msiexec.exe | C:\Windows\Installer\MSIC8D9.tmp | executable | |
MD5:CFAB78AC0D042A1D8AD7085A94328EF6 | SHA256:17B10DF05B4B92735B673914FE2BF0C0D7BBDA5B4A8F9A7FC81A0EFAA4380168 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3100 | QuickBooksDownloder.exe | POST | 200 | 185.161.211.237:80 | http://185.161.211.237/api/get-software | unknown | binary | 18.3 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
3100 | QuickBooksDownloder.exe | 185.161.211.237:80 | — | Zemlyaniy Dmitro Leonidovich | NL | unknown |
PID | Process | Class | Message |
|---|---|---|---|
3100 | QuickBooksDownloder.exe | Malware Command and Control Activity Detected | ET MALWARE QuickBooks Pop-Up Scam - Request for QB Download Locations |