File name:

My MP4Box GUI v0.6.0.6.7z

Full analysis: https://app.any.run/tasks/2acee2bc-dd19-435a-b47f-b1f8e091dcd0
Verdict: Malicious activity
Analysis date: March 05, 2024, 11:20:43
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-7z-compressed
File info: 7-zip archive data, version 0.4
MD5:

6D87471B22D601459611FC7D712F0621

SHA1:

932404CE6C2FF4B11C4F4831358037E8E7DDF4B8

SHA256:

A3A1DCED46E95CBD454F606DFB6F601C21D95B15869D0B90D790B4261C6A40F4

SSDEEP:

98304:Pxcf7x/2YS2O1FF9XTQ1QUsPEcDQ3VeDPdaQ2PdLv28bUypKtHprj0Zo3CMtDqEd:oIR/5YahtW7w2anR

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 3672)
      • Setup0600.exe (PID: 1836)
      • Setup0600.exe (PID: 956)
      • Setup0600.tmp (PID: 1348)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Setup0600.exe (PID: 1836)
      • Setup0600.exe (PID: 956)
      • Setup0600.tmp (PID: 1348)
    • Process drops legitimate windows executable

      • Setup0600.tmp (PID: 1348)
    • Reads the Windows owner or organization settings

      • Setup0600.tmp (PID: 1348)
    • Reads the Internet Settings

      • My MP4Box GUI.exe (PID: 3516)
  • INFO

    • Manual execution by a user

      • Setup0600.exe (PID: 1836)
      • explorer.exe (PID: 3692)
    • Checks supported languages

      • Setup0600.tmp (PID: 1692)
      • Setup0600.exe (PID: 1836)
      • Setup0600.exe (PID: 956)
      • Setup0600.tmp (PID: 1348)
      • My MP4Box GUI.exe (PID: 3516)
    • Reads the computer name

      • Setup0600.tmp (PID: 1692)
      • Setup0600.tmp (PID: 1348)
      • My MP4Box GUI.exe (PID: 3516)
    • Create files in a temporary directory

      • Setup0600.exe (PID: 1836)
      • Setup0600.exe (PID: 956)
      • Setup0600.tmp (PID: 1348)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3672)
    • Creates files in the program directory

      • Setup0600.tmp (PID: 1348)
    • Creates a software uninstall entry

      • Setup0600.tmp (PID: 1348)
    • Reads Environment values

      • My MP4Box GUI.exe (PID: 3516)
    • Reads the machine GUID from the registry

      • My MP4Box GUI.exe (PID: 3516)
    • Application launched itself

      • msedge.exe (PID: 2000)
      • msedge.exe (PID: 1560)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.7z | 7-Zip compressed archive (v0.4) (57.1)
.7z | 7-Zip compressed archive (gen) (42.8)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
64
Monitored processes
26
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe explorer.exe no specs setup0600.exe setup0600.tmp no specs setup0600.exe setup0600.tmp my mp4box gui.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
296"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2212 --field-trial-handle=1268,i,11630928235862337298,1501092702120698903,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
908"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3788 --field-trial-handle=1268,i,11630928235862337298,1501092702120698903,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
956"C:\Users\admin\AppData\Local\Temp\My MP4Box GUI v0.6.0.6\My MP4Box GUI v0.6.0.6\Setup0600.exe" /SPAWNWND=$50218 /NOTIFYWND=$50266 C:\Users\admin\AppData\Local\Temp\My MP4Box GUI v0.6.0.6\My MP4Box GUI v0.6.0.6\Setup0600.exe
Setup0600.tmp
User:
admin
Company:
Matt Bodin
Integrity Level:
HIGH
Description:
My MP4Box GUI Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\my mp4box gui v0.6.0.6\my mp4box gui v0.6.0.6\setup0600.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
1020"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=7 --mojo-platform-channel-handle=2868 --field-trial-handle=1268,i,11630928235862337298,1501092702120698903,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1172"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --use-gl=angle --use-angle=swiftshader-webgl --mojo-platform-channel-handle=1556 --field-trial-handle=1268,i,11630928235862337298,1501092702120698903,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1348"C:\Users\admin\AppData\Local\Temp\is-IM45D.tmp\Setup0600.tmp" /SL5="$60236,3493358,54272,C:\Users\admin\AppData\Local\Temp\My MP4Box GUI v0.6.0.6\My MP4Box GUI v0.6.0.6\Setup0600.exe" /SPAWNWND=$50218 /NOTIFYWND=$50266 C:\Users\admin\AppData\Local\Temp\is-IM45D.tmp\Setup0600.tmp
Setup0600.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-im45d.tmp\setup0600.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
1544"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1480 --field-trial-handle=1360,i,16495928362903297448,1787053118219566280,131072 /prefetch:3C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1560"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --single-argument http://my-mp4box-gui.zymichost.com/download.htmlC:\Program Files\Microsoft\Edge\Application\msedge.exe
My MP4Box GUI.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1692"C:\Users\admin\AppData\Local\Temp\is-RNN7I.tmp\Setup0600.tmp" /SL5="$50266,3493358,54272,C:\Users\admin\AppData\Local\Temp\My MP4Box GUI v0.6.0.6\My MP4Box GUI v0.6.0.6\Setup0600.exe" C:\Users\admin\AppData\Local\Temp\is-RNN7I.tmp\Setup0600.tmpSetup0600.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-rnn7i.tmp\setup0600.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
1792"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1300 --field-trial-handle=1360,i,16495928362903297448,1787053118219566280,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
11 801
Read events
11 713
Write events
77
Delete events
11

Modification events

(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3672) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\My MP4Box GUI v0.6.0.6.7z
(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
21
Suspicious files
10
Text files
36
Unknown types
14

Dropped files

PID
Process
Filename
Type
3672WinRAR.exeC:\Users\admin\AppData\Local\Temp\My MP4Box GUI v0.6.0.6\My MP4Box GUI v0.6.0.6\Setup0606.exeexecutable
MD5:73E9E64850245948A331F169A49F1C47
SHA256:ADFFA1C6B662C0C49BFB05CA9468E182A6E37DC82090B7BEC30818FB3E3E7FD9
1836Setup0600.exeC:\Users\admin\AppData\Local\Temp\is-RNN7I.tmp\Setup0600.tmpexecutable
MD5:15430669556C2062CEADD5B125E8CEA7
SHA256:64DB719C67988B106BF2D1A5B842445E8FF9B6436BE28BCAA0B8876D330F8168
1348Setup0600.tmpC:\Program Files\My MP4Box GUI\is-I1FTR.tmpexecutable
MD5:2859A0640F96E1D29A627BED18C32190
SHA256:8736FCCB802404A95FBADD835EEA8A9FBDB0CC2FAF9B65413890F861AE352BE0
1348Setup0600.tmpC:\Users\admin\AppData\Local\Temp\is-04K8P.tmp\_isetup\_shfoldr.dllexecutable
MD5:92DC6EF532FBB4A5C3201469A5B5EB63
SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87
1348Setup0600.tmpC:\Program Files\My MP4Box GUI\unins000.exeexecutable
MD5:2859A0640F96E1D29A627BED18C32190
SHA256:8736FCCB802404A95FBADD835EEA8A9FBDB0CC2FAF9B65413890F861AE352BE0
3672WinRAR.exeC:\Users\admin\AppData\Local\Temp\My MP4Box GUI v0.6.0.6\My MP4Box GUI v0.6.0.6\Setup0600.exeexecutable
MD5:8522A3D299DD84E9147A9E92989D6E3E
SHA256:D198891ECEFB888AC1B93801BF59EB45124CD38F35FCB99DBEAFF1FD05B4D479
956Setup0600.exeC:\Users\admin\AppData\Local\Temp\is-IM45D.tmp\Setup0600.tmpexecutable
MD5:15430669556C2062CEADD5B125E8CEA7
SHA256:64DB719C67988B106BF2D1A5B842445E8FF9B6436BE28BCAA0B8876D330F8168
1348Setup0600.tmpC:\Program Files\My MP4Box GUI\Tools\js32.dllexecutable
MD5:E2498952567392698146764833D74459
SHA256:922B6FD6E416484BE36613AC0F6567B830C56EE6358E3C72AA45B01DAEBBBD0D
1348Setup0600.tmpC:\Program Files\My MP4Box GUI\Tools\is-IOEL9.tmpexecutable
MD5:FE7C36F4253D682599308E693B7F0413
SHA256:50952CD40FB10AFB49BFB4B8BF6A4247547D6A20C3756F26BB8305ABAA995A0C
1348Setup0600.tmpC:\Program Files\My MP4Box GUI\Tools\is-3HLH2.tmptext
MD5:B52F2D57D10C4F7EE67A7EB9615D5D24
SHA256:9CCF26CFE845E0EB8BB58053E47366E7AB6B697AE010F7650978D4B71B7D1FC1
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
9
DNS requests
16
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
3496
msedge.exe
204.79.197.239:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
1560
msedge.exe
239.255.255.250:1900
unknown
3496
msedge.exe
2.23.209.183:443
www.bing.com
Akamai International B.V.
GB
unknown
1560
msedge.exe
224.0.0.251:5353
unknown
3496
msedge.exe
13.107.21.239:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
3496
msedge.exe
152.199.21.175:443
msedgeextensions.sf.tlu.dl.delivery.mp.microsoft.com
EDGECAST
DE
whitelisted

DNS requests

Domain
IP
Reputation
config.edge.skype.com
unknown
my-mp4box-gui.zymichost.com
unknown
edge.microsoft.com
  • 204.79.197.239
  • 13.107.21.239
whitelisted
www.bing.com
  • 2.23.209.183
  • 2.23.209.185
  • 2.23.209.141
  • 2.23.209.189
  • 2.23.209.181
  • 2.23.209.140
  • 2.23.209.179
  • 2.23.209.135
  • 2.23.209.187
whitelisted
msedgeextensions.sf.tlu.dl.delivery.mp.microsoft.com
  • 152.199.21.175
whitelisted

Threats

No threats detected
No debug info