File name:

Roblox-file-free-dow_324948361.zip

Full analysis: https://app.any.run/tasks/8b322d83-fb7b-403a-94a5-1ab40a45f90b
Verdict: Malicious activity
Threats:

Trojans are a group of malicious programs distinguished by their ability to masquerade as benign software. Depending on their type, trojans possess a variety of capabilities, ranging from maintaining full remote control over the victim’s machine to stealing data and files, as well as dropping other malware. At the same time, the main functionality of each trojan family can differ significantly depending on its type. The most common trojan infection chain starts with a phishing email.

Analysis date: September 19, 2021, 06:15:41
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
trojan
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

78A7CD9044C6F16A28FC75319F72BF8F

SHA1:

A113876EE05CAE2B71FF9669382557A1353DF487

SHA256:

A58F9A5A8C524C71B13366BFA84D19652CBC973241E116F2EF70489A578775E9

SSDEEP:

98304:n+ffbJwhuB+IYamV0cUq67yQ3OCga/oiXTL5yITK8BaImj3sRF4Z/mO1:n+fT+hul1jP+XxiXTLBTfBeLsQ/mO1

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Roblox-file-free-dow_324948361.exe (PID: 3280)
      • Roblox-file-free-dow_324948361.exe (PID: 1436)
      • Minima.exe (PID: 3876)
      • TrayStatus.exe (PID: 1600)
    • Drops executable file immediately after starts

      • Roblox-file-free-dow_324948361.exe (PID: 3280)
      • Roblox-file-free-dow_324948361.exe (PID: 1436)
      • Roblox-file-free-dow_324948361.tmp (PID: 1972)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3452)
      • Roblox-file-free-dow_324948361.exe (PID: 3280)
      • Roblox-file-free-dow_324948361.exe (PID: 1436)
      • Roblox-file-free-dow_324948361.tmp (PID: 1972)
    • Reads the computer name

      • WinRAR.exe (PID: 3452)
      • Roblox-file-free-dow_324948361.tmp (PID: 1968)
      • Roblox-file-free-dow_324948361.tmp (PID: 1972)
      • Minima.exe (PID: 3876)
      • TrayStatus.exe (PID: 1600)
    • Checks supported languages

      • Roblox-file-free-dow_324948361.exe (PID: 3280)
      • WinRAR.exe (PID: 3452)
      • Roblox-file-free-dow_324948361.tmp (PID: 1968)
      • Roblox-file-free-dow_324948361.exe (PID: 1436)
      • Roblox-file-free-dow_324948361.tmp (PID: 1972)
      • Minima.exe (PID: 3876)
      • TrayStatus.exe (PID: 1600)
    • Reads Windows owner or organization settings

      • Roblox-file-free-dow_324948361.tmp (PID: 1972)
    • Drops a file that was compiled in debug mode

      • Roblox-file-free-dow_324948361.tmp (PID: 1972)
    • Drops a file with too old compile date

      • Roblox-file-free-dow_324948361.tmp (PID: 1972)
    • Reads the Windows organization settings

      • Roblox-file-free-dow_324948361.tmp (PID: 1972)
    • Drops a file with a compile date too recent

      • Roblox-file-free-dow_324948361.tmp (PID: 1972)
    • Reads Microsoft Outlook installation path

      • Minima.exe (PID: 3876)
    • Creates a directory in Program Files

      • Roblox-file-free-dow_324948361.tmp (PID: 1972)
  • INFO

    • Manual execution by user

      • Roblox-file-free-dow_324948361.exe (PID: 3280)
      • TrayStatus.exe (PID: 1600)
    • Creates files in the program directory

      • Roblox-file-free-dow_324948361.tmp (PID: 1972)
    • Creates a software uninstall entry

      • Roblox-file-free-dow_324948361.tmp (PID: 1972)
    • Application was dropped or rewritten from another process

      • Roblox-file-free-dow_324948361.tmp (PID: 1972)
      • Roblox-file-free-dow_324948361.tmp (PID: 1968)
    • Loads dropped or rewritten executable

      • Roblox-file-free-dow_324948361.tmp (PID: 1972)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: TrayStatus.exe
ZipUncompressedSize: 3552696
ZipCompressedSize: 1777304
ZipCRC: 0x7df98dd6
ZipModifyDate: 2019:12:24 12:47:22
ZipCompression: Deflated
ZipBitFlag: -
ZipRequiredVersion: 20
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
49
Monitored processes
7
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start drop and start drop and start drop and start winrar.exe roblox-file-free-dow_324948361.exe roblox-file-free-dow_324948361.tmp no specs roblox-file-free-dow_324948361.exe roblox-file-free-dow_324948361.tmp minima.exe traystatus.exe

Process information

PID
CMD
Path
Indicators
Parent process
1436"C:\Users\admin\Desktop\Roblox-file-free-dow_324948361\Roblox-file-free-dow_324948361.exe" /SPAWNWND=$101E8 /NOTIFYWND=$101D6 C:\Users\admin\Desktop\Roblox-file-free-dow_324948361\Roblox-file-free-dow_324948361.exe
Roblox-file-free-dow_324948361.tmp
User:
admin
Company:
Integrity Level:
HIGH
Description:
Et Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\desktop\roblox-file-free-dow_324948361\roblox-file-free-dow_324948361.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1600"C:\Users\admin\Desktop\Roblox-file-free-dow_324948361\TrayStatus.exe" C:\Users\admin\Desktop\Roblox-file-free-dow_324948361\TrayStatus.exe
Explorer.EXE
User:
admin
Company:
Binary Fortress Software
Integrity Level:
MEDIUM
Description:
TrayStatus
Exit code:
3221225477
Version:
4.1.0.0
Modules
Images
c:\users\admin\desktop\roblox-file-free-dow_324948361\traystatus.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1968"C:\Users\admin\AppData\Local\Temp\is-MNSFL.tmp\Roblox-file-free-dow_324948361.tmp" /SL5="$101D6,3487695,140800,C:\Users\admin\Desktop\Roblox-file-free-dow_324948361\Roblox-file-free-dow_324948361.exe" C:\Users\admin\AppData\Local\Temp\is-MNSFL.tmp\Roblox-file-free-dow_324948361.tmpRoblox-file-free-dow_324948361.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-mnsfl.tmp\roblox-file-free-dow_324948361.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1972"C:\Users\admin\AppData\Local\Temp\is-FBEPE.tmp\Roblox-file-free-dow_324948361.tmp" /SL5="$201EA,3487695,140800,C:\Users\admin\Desktop\Roblox-file-free-dow_324948361\Roblox-file-free-dow_324948361.exe" /SPAWNWND=$101E8 /NOTIFYWND=$101D6 C:\Users\admin\AppData\Local\Temp\is-FBEPE.tmp\Roblox-file-free-dow_324948361.tmp
Roblox-file-free-dow_324948361.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-fbepe.tmp\roblox-file-free-dow_324948361.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3280"C:\Users\admin\Desktop\Roblox-file-free-dow_324948361\Roblox-file-free-dow_324948361.exe" C:\Users\admin\Desktop\Roblox-file-free-dow_324948361\Roblox-file-free-dow_324948361.exe
Explorer.EXE
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Et Setup
Exit code:
0
Version:
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
3452"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\Roblox-file-free-dow_324948361.zip"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3876"C:\Program Files\Et/\et\Minima.exe" 9f5376b4e7e43ad7fa29fa6f4bef38bfC:\Program Files\Et\et\Minima.exe
Roblox-file-free-dow_324948361.tmp
User:
admin
Company:
Software Security System
Integrity Level:
HIGH
Description:
ElecKey Agent for NT-based Operating Systems
Exit code:
0
Version:
2.0.9.4
Modules
Images
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\et\et\minima.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\gdi32.dll
Total events
1 311
Read events
1 281
Write events
30
Delete events
0

Modification events

(PID) Process:(3452) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3452) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3452) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\171\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3452) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\Roblox-file-free-dow_324948361.zip
(PID) Process:(3452) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3452) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3452) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3452) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3452) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath
Operation:writeName:0
Value:
C:\Users\admin\Desktop\Roblox-file-free-dow_324948361
(PID) Process:(1972) Roblox-file-free-dow_324948361.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
B4070000FAB54DD61DADD701
Executable files
10
Suspicious files
0
Text files
26
Unknown types
1

Dropped files

PID
Process
Filename
Type
3452WinRAR.exeC:\Users\admin\Desktop\Roblox-file-free-dow_324948361\Roblox-file-free-dow_324948361.exeexecutable
MD5:
SHA256:
3452WinRAR.exeC:\Users\admin\Desktop\Roblox-file-free-dow_324948361\TrayStatus.exeexecutable
MD5:659DDD8E403CDE0E6403D605829D0F3B
SHA256:BF5D0E8F30D74F2B00FCD1C5EE90C800B81C9B371E162B884278518925DAAB84
1972Roblox-file-free-dow_324948361.tmpC:\Program Files\Et\is-8QNVO.tmpexecutable
MD5:
SHA256:
1972Roblox-file-free-dow_324948361.tmpC:\Program Files\Et\is-CE69S.tmptext
MD5:
SHA256:
1972Roblox-file-free-dow_324948361.tmpC:\Program Files\Et\is-E4JHQ.tmptext
MD5:
SHA256:
1972Roblox-file-free-dow_324948361.tmpC:\Program Files\Et\unins000.exeexecutable
MD5:
SHA256:
1972Roblox-file-free-dow_324948361.tmpC:\Program Files\Et\Enim.txttext
MD5:
SHA256:
1972Roblox-file-free-dow_324948361.tmpC:\Program Files\Et\Molestiae.txttext
MD5:
SHA256:
1972Roblox-file-free-dow_324948361.tmpC:\Program Files\Et\is-L5OGO.tmptext
MD5:
SHA256:
1972Roblox-file-free-dow_324948361.tmpC:\Program Files\Et\is-JRQ3O.tmptext
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
2
DNS requests
1
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3876
Minima.exe
POST
172.67.177.45:80
http://jorjifornk.live/v3/api
US
malicious
3876
Minima.exe
POST
172.67.177.45:80
http://jorjifornk.live/v3/api
US
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3876
Minima.exe
172.67.177.45:80
jorjifornk.live
US
malicious

DNS requests

Domain
IP
Reputation
jorjifornk.live
  • 172.67.177.45
  • 104.21.80.102
unknown

Threats

PID
Process
Class
Message
3876
Minima.exe
A Network Trojan was detected
ET TROJAN Win32/Malgent!MSR Dropper Requesting Payload
No debug info