File name:

Winlocker.VB6.Blacksod.zip

Full analysis: https://app.any.run/tasks/3cb56ce9-2051-4261-b31d-3ca63f848c63
Verdict: Malicious activity
Analysis date: April 29, 2021, 13:43:38
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

713F3673049A096EA23787A9BCB63329

SHA1:

B6DAD889F46DC19AE8A444B93B0A14248404C11D

SHA256:

A62C54FEFDE2762426208C6E6C7F01EF2066FC837F94F5F36D11A36B3ECDDD5F

SSDEEP:

49152:2OiR+zJsyziTwWQRtQWgpn8QbX1ncWFwUGVF6VpHk:2OVdzVW4tQWgp8QT1XFwUGKPk

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Endermanch@WinlockerVB6Blacksod.exe (PID: 4052)
      • Endermanch@WinlockerVB6Blacksod.exe (PID: 2400)
      • Endermanch@WinlockerVB6Blacksod.exe (PID: 2768)
    • Loads the Task Scheduler DLL interface

      • MsiExec.exe (PID: 564)
      • Endermanch@WinlockerVB6Blacksod.exe (PID: 4052)
      • MsiExec.exe (PID: 2972)
      • Endermanch@WinlockerVB6Blacksod.exe (PID: 2400)
      • MsiExec.exe (PID: 3496)
    • Loads dropped or rewritten executable

      • Endermanch@WinlockerVB6Blacksod.exe (PID: 4052)
      • Endermanch@WinlockerVB6Blacksod.exe (PID: 2400)
      • Endermanch@WinlockerVB6Blacksod.exe (PID: 2768)
    • Drops executable file immediately after starts

      • Endermanch@WinlockerVB6Blacksod.exe (PID: 4052)
      • Endermanch@WinlockerVB6Blacksod.exe (PID: 2768)
      • Endermanch@WinlockerVB6Blacksod.exe (PID: 2400)
  • SUSPICIOUS

    • Reads Environment values

      • Endermanch@WinlockerVB6Blacksod.exe (PID: 4052)
      • MsiExec.exe (PID: 3548)
      • Endermanch@WinlockerVB6Blacksod.exe (PID: 2400)
      • MsiExec.exe (PID: 2212)
      • Endermanch@WinlockerVB6Blacksod.exe (PID: 2768)
      • MsiExec.exe (PID: 3180)
    • Executable content was dropped or overwritten

      • Endermanch@WinlockerVB6Blacksod.exe (PID: 4052)
      • Endermanch@WinlockerVB6Blacksod.exe (PID: 2400)
      • Endermanch@WinlockerVB6Blacksod.exe (PID: 2768)
    • Creates files in the Windows directory

      • MsiExec.exe (PID: 564)
    • Creates files in the user directory

      • Endermanch@WinlockerVB6Blacksod.exe (PID: 4052)
      • MsiExec.exe (PID: 3548)
      • Endermanch@WinlockerVB6Blacksod.exe (PID: 2400)
      • MsiExec.exe (PID: 2212)
      • Endermanch@WinlockerVB6Blacksod.exe (PID: 2768)
      • MsiExec.exe (PID: 3180)
    • Starts Microsoft Installer

      • Endermanch@WinlockerVB6Blacksod.exe (PID: 4052)
      • Endermanch@WinlockerVB6Blacksod.exe (PID: 2400)
      • Endermanch@WinlockerVB6Blacksod.exe (PID: 2768)
    • Application launched itself

      • taskmgr.exe (PID: 2348)
  • INFO

    • Manual execution by user

      • Endermanch@WinlockerVB6Blacksod.exe (PID: 4052)
      • taskmgr.exe (PID: 2348)
      • Endermanch@WinlockerVB6Blacksod.exe (PID: 2400)
      • Endermanch@WinlockerVB6Blacksod.exe (PID: 2768)
    • Loads dropped or rewritten executable

      • MsiExec.exe (PID: 3548)
      • MsiExec.exe (PID: 564)
      • MsiExec.exe (PID: 2972)
      • MsiExec.exe (PID: 2212)
      • MsiExec.exe (PID: 3180)
      • MsiExec.exe (PID: 3496)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: Endermanch@WinlockerVB6Blacksod.exe
ZipUncompressedSize: 2511528
ZipCompressedSize: 1654624
ZipCRC: 0xa5044670
ZipModifyDate: 2016:07:17 23:55:19
ZipCompression: Deflated
ZipBitFlag: 0x0001
ZipRequiredVersion: 20
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
63
Monitored processes
15
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs endermanch@winlockervb6blacksod.exe msiexec.exe no specs msiexec.exe no specs msiexec.exe taskmgr.exe no specs taskmgr.exe endermanch@winlockervb6blacksod.exe msiexec.exe no specs msiexec.exe msiexec.exe no specs endermanch@winlockervb6blacksod.exe msiexec.exe no specs msiexec.exe msiexec.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
564C:\Windows\system32\MsiExec.exe -Embedding 81E9DE4DB68C5315C146595F62572700 M Global\MSI0000C:\Windows\system32\MsiExec.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1568"C:\Windows\system32\msiexec.exe" /i "C:\Users\admin\AppData\Roaming\Windows\Error file remover 1.0.0.0\install\0A01606\Error file remover.msi" AI_SETUPEXEPATH=C:\Users\admin\Desktop\Endermanch@WinlockerVB6Blacksod.exe SETUPEXEDIR=C:\Users\admin\Desktop\ EXE_CMD_LINE="/exenoupdates /exelang 0 /noprereqs "C:\Windows\system32\msiexec.exeEndermanch@WinlockerVB6Blacksod.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1704"C:\Windows\system32\taskmgr.exe" /1C:\Windows\system32\taskmgr.exe
taskmgr.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Task Manager
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskmgr.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1908"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Winlocker.VB6.Blacksod.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2212C:\Windows\system32\MsiExec.exe -Embedding 5EC76815203CA8F52D91C64CAD43AC38C:\Windows\system32\MsiExec.exe
msiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2292"C:\Windows\system32\msiexec.exe" /i "C:\Users\admin\AppData\Roaming\Windows\Error file remover 1.0.0.0\install\0A01606\Error file remover.msi" AI_SETUPEXEPATH=C:\Users\admin\Desktop\Endermanch@WinlockerVB6Blacksod.exe SETUPEXEDIR=C:\Users\admin\Desktop\ EXE_CMD_LINE="/exenoupdates /exelang 0 /noprereqs "C:\Windows\system32\msiexec.exeEndermanch@WinlockerVB6Blacksod.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2348"C:\Windows\system32\taskmgr.exe" /4C:\Windows\system32\taskmgr.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Task Manager
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskmgr.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2400"C:\Users\admin\Desktop\Endermanch@WinlockerVB6Blacksod.exe" C:\Users\admin\Desktop\Endermanch@WinlockerVB6Blacksod.exe
explorer.exe
User:
admin
Company:
Windows
Integrity Level:
HIGH
Description:
This installer database contains the logic and data required to install Error file remover.
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\endermanch@winlockervb6blacksod.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2768"C:\Users\admin\Desktop\Endermanch@WinlockerVB6Blacksod.exe" C:\Users\admin\Desktop\Endermanch@WinlockerVB6Blacksod.exe
explorer.exe
User:
admin
Company:
Windows
Integrity Level:
HIGH
Description:
This installer database contains the logic and data required to install Error file remover.
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\endermanch@winlockervb6blacksod.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2972C:\Windows\system32\MsiExec.exe -Embedding 52A703E9BA9A8C62BF51D093B681645B M Global\MSI0000C:\Windows\system32\MsiExec.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
1 323
Read events
1 272
Write events
51
Delete events
0

Modification events

(PID) Process:(1908) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1908) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1908) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1908) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Winlocker.VB6.Blacksod.zip
(PID) Process:(1908) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1908) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1908) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1908) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1908) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
1
(PID) Process:(564) MsiExec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Caphyon\Advanced Installer\Scheduled Tasks\{2121A69D-A1B9-403A-97F4-2B777DD24939}
Operation:writeName:sys
Value:
1
Executable files
9
Suspicious files
3
Text files
68
Unknown types
6

Dropped files

PID
Process
Filename
Type
1908WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb1908.19498\Endermanch@WinlockerVB6Blacksod.exe
MD5:
SHA256:
3548MsiExec.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\H6UCGMQW.txt
MD5:
SHA256:
3548MsiExec.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\9XKMM0KV.txt
MD5:
SHA256:
3548MsiExec.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\0LVWVKTC.txt
MD5:
SHA256:
3548MsiExec.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\8CD1AB4J.txt
MD5:
SHA256:
3548MsiExec.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\5VPSREHZ.txt
MD5:
SHA256:
3548MsiExec.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\9231RHAW.txt
MD5:
SHA256:
3548MsiExec.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\G7Z1P469.txt
MD5:
SHA256:
3548MsiExec.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\IKVXD813.txt
MD5:
SHA256:
3548MsiExec.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\X29AVTRF.txt
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
32
TCP/UDP connections
3
DNS requests
3
Threats
31

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3548
MsiExec.exe
POST
402
54.226.29.2:80
http://collect.installeranalytics.com/
US
text
2 b
malicious
3548
MsiExec.exe
POST
402
54.226.29.2:80
http://collect.installeranalytics.com/
US
text
2 b
malicious
3548
MsiExec.exe
POST
402
54.226.29.2:80
http://collect.installeranalytics.com/
US
text
2 b
malicious
3548
MsiExec.exe
POST
402
54.226.29.2:80
http://collect.installeranalytics.com/
US
text
2 b
malicious
3548
MsiExec.exe
POST
402
54.226.29.2:80
http://collect.installeranalytics.com/
US
text
2 b
malicious
3548
MsiExec.exe
POST
402
54.226.29.2:80
http://collect.installeranalytics.com/
US
text
2 b
malicious
2212
MsiExec.exe
POST
402
52.23.109.145:80
http://collect.installeranalytics.com/
US
text
2 b
malicious
2212
MsiExec.exe
POST
402
52.23.109.145:80
http://collect.installeranalytics.com/
US
text
2 b
malicious
2212
MsiExec.exe
POST
402
52.23.109.145:80
http://collect.installeranalytics.com/
US
text
2 b
malicious
3548
MsiExec.exe
POST
402
54.226.29.2:80
http://collect.installeranalytics.com/
US
text
2 b
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3548
MsiExec.exe
54.226.29.2:80
collect.installeranalytics.com
Amazon.com, Inc.
US
malicious
3180
MsiExec.exe
54.226.29.2:80
collect.installeranalytics.com
Amazon.com, Inc.
US
malicious
2212
MsiExec.exe
52.23.109.145:80
collect.installeranalytics.com
Amazon.com, Inc.
US
suspicious

DNS requests

Domain
IP
Reputation
collect.installeranalytics.com
  • 54.226.29.2
  • 52.23.109.145
malicious

Threats

Found threats are available for the paid subscriptions
31 ETPRO signatures available at the full report
No debug info