File name:

Roblox-file-free-dow_324948361.zip

Full analysis: https://app.any.run/tasks/8b322d83-fb7b-403a-94a5-1ab40a45f90b
Verdict: Malicious activity
Threats:

Trojans are a group of malicious programs distinguished by their ability to masquerade as benign software. Depending on their type, trojans possess a variety of capabilities, ranging from maintaining full remote control over the victim’s machine to stealing data and files, as well as dropping other malware. At the same time, the main functionality of each trojan family can differ significantly depending on its type. The most common trojan infection chain starts with a phishing email.

Analysis date: September 19, 2021, 06:15:41
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
trojan
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

78A7CD9044C6F16A28FC75319F72BF8F

SHA1:

A113876EE05CAE2B71FF9669382557A1353DF487

SHA256:

A58F9A5A8C524C71B13366BFA84D19652CBC973241E116F2EF70489A578775E9

SSDEEP:

98304:n+ffbJwhuB+IYamV0cUq67yQ3OCga/oiXTL5yITK8BaImj3sRF4Z/mO1:n+fT+hul1jP+XxiXTLBTfBeLsQ/mO1

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops executable file immediately after starts

      • Roblox-file-free-dow_324948361.exe (PID: 3280)
      • Roblox-file-free-dow_324948361.exe (PID: 1436)
      • Roblox-file-free-dow_324948361.tmp (PID: 1972)
    • Application was dropped or rewritten from another process

      • Roblox-file-free-dow_324948361.exe (PID: 3280)
      • Roblox-file-free-dow_324948361.exe (PID: 1436)
      • Minima.exe (PID: 3876)
      • TrayStatus.exe (PID: 1600)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3452)
      • Roblox-file-free-dow_324948361.exe (PID: 3280)
      • Roblox-file-free-dow_324948361.exe (PID: 1436)
      • Roblox-file-free-dow_324948361.tmp (PID: 1972)
    • Reads the computer name

      • WinRAR.exe (PID: 3452)
      • Roblox-file-free-dow_324948361.tmp (PID: 1968)
      • Roblox-file-free-dow_324948361.tmp (PID: 1972)
      • Minima.exe (PID: 3876)
      • TrayStatus.exe (PID: 1600)
    • Checks supported languages

      • WinRAR.exe (PID: 3452)
      • Roblox-file-free-dow_324948361.tmp (PID: 1968)
      • Roblox-file-free-dow_324948361.exe (PID: 3280)
      • Roblox-file-free-dow_324948361.exe (PID: 1436)
      • Roblox-file-free-dow_324948361.tmp (PID: 1972)
      • Minima.exe (PID: 3876)
      • TrayStatus.exe (PID: 1600)
    • Reads Windows owner or organization settings

      • Roblox-file-free-dow_324948361.tmp (PID: 1972)
    • Reads the Windows organization settings

      • Roblox-file-free-dow_324948361.tmp (PID: 1972)
    • Drops a file that was compiled in debug mode

      • Roblox-file-free-dow_324948361.tmp (PID: 1972)
    • Drops a file with too old compile date

      • Roblox-file-free-dow_324948361.tmp (PID: 1972)
    • Creates a directory in Program Files

      • Roblox-file-free-dow_324948361.tmp (PID: 1972)
    • Drops a file with a compile date too recent

      • Roblox-file-free-dow_324948361.tmp (PID: 1972)
    • Reads Microsoft Outlook installation path

      • Minima.exe (PID: 3876)
  • INFO

    • Manual execution by user

      • Roblox-file-free-dow_324948361.exe (PID: 3280)
      • TrayStatus.exe (PID: 1600)
    • Application was dropped or rewritten from another process

      • Roblox-file-free-dow_324948361.tmp (PID: 1968)
      • Roblox-file-free-dow_324948361.tmp (PID: 1972)
    • Creates a software uninstall entry

      • Roblox-file-free-dow_324948361.tmp (PID: 1972)
    • Loads dropped or rewritten executable

      • Roblox-file-free-dow_324948361.tmp (PID: 1972)
    • Creates files in the program directory

      • Roblox-file-free-dow_324948361.tmp (PID: 1972)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: TrayStatus.exe
ZipUncompressedSize: 3552696
ZipCompressedSize: 1777304
ZipCRC: 0x7df98dd6
ZipModifyDate: 2019:12:24 12:47:22
ZipCompression: Deflated
ZipBitFlag: -
ZipRequiredVersion: 20
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
49
Monitored processes
7
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start drop and start drop and start drop and start winrar.exe roblox-file-free-dow_324948361.exe roblox-file-free-dow_324948361.tmp no specs roblox-file-free-dow_324948361.exe roblox-file-free-dow_324948361.tmp minima.exe traystatus.exe

Process information

PID
CMD
Path
Indicators
Parent process
1436"C:\Users\admin\Desktop\Roblox-file-free-dow_324948361\Roblox-file-free-dow_324948361.exe" /SPAWNWND=$101E8 /NOTIFYWND=$101D6 C:\Users\admin\Desktop\Roblox-file-free-dow_324948361\Roblox-file-free-dow_324948361.exe
Roblox-file-free-dow_324948361.tmp
User:
admin
Company:
Integrity Level:
HIGH
Description:
Et Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\desktop\roblox-file-free-dow_324948361\roblox-file-free-dow_324948361.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1600"C:\Users\admin\Desktop\Roblox-file-free-dow_324948361\TrayStatus.exe" C:\Users\admin\Desktop\Roblox-file-free-dow_324948361\TrayStatus.exe
Explorer.EXE
User:
admin
Company:
Binary Fortress Software
Integrity Level:
MEDIUM
Description:
TrayStatus
Exit code:
3221225477
Version:
4.1.0.0
Modules
Images
c:\users\admin\desktop\roblox-file-free-dow_324948361\traystatus.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1968"C:\Users\admin\AppData\Local\Temp\is-MNSFL.tmp\Roblox-file-free-dow_324948361.tmp" /SL5="$101D6,3487695,140800,C:\Users\admin\Desktop\Roblox-file-free-dow_324948361\Roblox-file-free-dow_324948361.exe" C:\Users\admin\AppData\Local\Temp\is-MNSFL.tmp\Roblox-file-free-dow_324948361.tmpRoblox-file-free-dow_324948361.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-mnsfl.tmp\roblox-file-free-dow_324948361.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1972"C:\Users\admin\AppData\Local\Temp\is-FBEPE.tmp\Roblox-file-free-dow_324948361.tmp" /SL5="$201EA,3487695,140800,C:\Users\admin\Desktop\Roblox-file-free-dow_324948361\Roblox-file-free-dow_324948361.exe" /SPAWNWND=$101E8 /NOTIFYWND=$101D6 C:\Users\admin\AppData\Local\Temp\is-FBEPE.tmp\Roblox-file-free-dow_324948361.tmp
Roblox-file-free-dow_324948361.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-fbepe.tmp\roblox-file-free-dow_324948361.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3280"C:\Users\admin\Desktop\Roblox-file-free-dow_324948361\Roblox-file-free-dow_324948361.exe" C:\Users\admin\Desktop\Roblox-file-free-dow_324948361\Roblox-file-free-dow_324948361.exe
Explorer.EXE
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Et Setup
Exit code:
0
Version:
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
3452"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\Roblox-file-free-dow_324948361.zip"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3876"C:\Program Files\Et/\et\Minima.exe" 9f5376b4e7e43ad7fa29fa6f4bef38bfC:\Program Files\Et\et\Minima.exe
Roblox-file-free-dow_324948361.tmp
User:
admin
Company:
Software Security System
Integrity Level:
HIGH
Description:
ElecKey Agent for NT-based Operating Systems
Exit code:
0
Version:
2.0.9.4
Modules
Images
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\et\et\minima.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\gdi32.dll
Total events
1 311
Read events
1 281
Write events
30
Delete events
0

Modification events

(PID) Process:(3452) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3452) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3452) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\171\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3452) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\Roblox-file-free-dow_324948361.zip
(PID) Process:(3452) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3452) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3452) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3452) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3452) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath
Operation:writeName:0
Value:
C:\Users\admin\Desktop\Roblox-file-free-dow_324948361
(PID) Process:(1972) Roblox-file-free-dow_324948361.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
B4070000FAB54DD61DADD701
Executable files
10
Suspicious files
0
Text files
26
Unknown types
1

Dropped files

PID
Process
Filename
Type
3452WinRAR.exeC:\Users\admin\Desktop\Roblox-file-free-dow_324948361\Roblox-file-free-dow_324948361.exeexecutable
MD5:
SHA256:
1972Roblox-file-free-dow_324948361.tmpC:\Program Files\Et\unins000.exeexecutable
MD5:
SHA256:
1972Roblox-file-free-dow_324948361.tmpC:\Program Files\Et\is-CE69S.tmptext
MD5:
SHA256:
1972Roblox-file-free-dow_324948361.tmpC:\Program Files\Et\is-8QNVO.tmpexecutable
MD5:
SHA256:
1972Roblox-file-free-dow_324948361.tmpC:\Program Files\Et\Enim.txttext
MD5:
SHA256:
1972Roblox-file-free-dow_324948361.tmpC:\Program Files\Et\is-E4JHQ.tmptext
MD5:
SHA256:
1436Roblox-file-free-dow_324948361.exeC:\Users\admin\AppData\Local\Temp\is-FBEPE.tmp\Roblox-file-free-dow_324948361.tmpexecutable
MD5:3E82D951014D6FA1F34B7EA9A6BAB125
SHA256:EC822C16B67F304645977E8B20A81B06EB9D577E890AEEC33155D3B19FE61854
1972Roblox-file-free-dow_324948361.tmpC:\Users\admin\AppData\Local\Temp\is-CGQ4V.tmp\_isetup\_shfoldr.dllexecutable
MD5:92DC6EF532FBB4A5C3201469A5B5EB63
SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87
1972Roblox-file-free-dow_324948361.tmpC:\Users\admin\AppData\Local\Temp\is-CGQ4V.tmp\_isetup\_iscrypt.dllexecutable
MD5:A69559718AB506675E907FE49DEB71E9
SHA256:2F6294F9AA09F59A574B5DCD33BE54E16B39377984F3D5658CDA44950FA0F8FC
1972Roblox-file-free-dow_324948361.tmpC:\Program Files\Et\is-L5OGO.tmptext
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
2
DNS requests
1
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3876
Minima.exe
POST
172.67.177.45:80
http://jorjifornk.live/v3/api
US
malicious
3876
Minima.exe
POST
172.67.177.45:80
http://jorjifornk.live/v3/api
US
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3876
Minima.exe
172.67.177.45:80
jorjifornk.live
US
malicious

DNS requests

Domain
IP
Reputation
jorjifornk.live
  • 172.67.177.45
  • 104.21.80.102
unknown

Threats

PID
Process
Class
Message
3876
Minima.exe
A Network Trojan was detected
ET TROJAN Win32/Malgent!MSR Dropper Requesting Payload
No debug info