File name:

NetTraffic Portable 1.71.0.zip

Full analysis: https://app.any.run/tasks/c2c626c1-cac6-4676-987e-96d43a8e2dc6
Verdict: Malicious activity
Analysis date: July 11, 2024, 10:46:45
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=store
MD5:

1B0507946724DC9A3EBB989C8AE5919D

SHA1:

A58CA5293B9C0F1A6D96ED47D3D7977A39F07287

SHA256:

A7952414CB3CFDFF3921A21237927526AE12A2D5F932EA9E98BEB522831DBF49

SSDEEP:

24576:rQOzIfHQrmWm4KYutpBSziKqE7JMs5PgFOz43blAkB:rQeIfHQrmWm4KYutpBSziKqE7JMs5PgP

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 3344)
  • SUSPICIOUS

    • Uses ROUTE.EXE to obtain the routing table information

      • NetTraffic.exe (PID: 3532)
    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 3344)
    • Process uses ARP to discover network configuration

      • NetTraffic.exe (PID: 3532)
    • Get information on the list of running processes

      • NetTraffic.exe (PID: 3532)
    • Process uses IPCONFIG to discover network configuration

      • NetTraffic.exe (PID: 3532)
    • The process executes via Task Scheduler

      • sipnotify.exe (PID: 1580)
      • ctfmon.exe (PID: 1408)
    • Reads the Internet Settings

      • sipnotify.exe (PID: 1580)
    • Reads settings of System Certificates

      • sipnotify.exe (PID: 1580)
  • INFO

    • Create files in a temporary directory

      • NetTraffic.exe (PID: 3532)
    • Checks supported languages

      • NetTraffic.exe (PID: 3532)
      • IMEKLMG.EXE (PID: 2096)
      • IMEKLMG.EXE (PID: 2104)
      • wmpnscfg.exe (PID: 2404)
      • wmpnscfg.exe (PID: 2428)
    • Reads the computer name

      • NetTraffic.exe (PID: 3532)
      • IMEKLMG.EXE (PID: 2096)
      • IMEKLMG.EXE (PID: 2104)
      • wmpnscfg.exe (PID: 2428)
      • wmpnscfg.exe (PID: 2404)
    • Reads the machine GUID from the registry

      • NetTraffic.exe (PID: 3532)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3344)
    • Reads security settings of Internet Explorer

      • sipnotify.exe (PID: 1580)
    • Manual execution by a user

      • IMEKLMG.EXE (PID: 2104)
      • IMEKLMG.EXE (PID: 2096)
      • wmpnscfg.exe (PID: 2404)
      • wmpnscfg.exe (PID: 2428)
    • Process checks whether UAC notifications are on

      • IMEKLMG.EXE (PID: 2104)
      • IMEKLMG.EXE (PID: 2096)
    • Reads the software policy settings

      • sipnotify.exe (PID: 1580)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2023:09:25 23:44:42
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: NetTraffic/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
108
Monitored processes
15
Malicious processes
1
Suspicious processes
2

Behavior graph

Click at the process to see the details
start winrar.exe nettraffic.exe no specs hostname.exe no specs route.exe no specs tasklist.exe no specs arp.exe no specs netstat.exe no specs ipconfig.exe no specs tasklist.exe no specs ctfmon.exe no specs sipnotify.exe imeklmg.exe no specs imeklmg.exe no specs wmpnscfg.exe no specs wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
268"tasklist" /vC:\Windows\System32\tasklist.exeNetTraffic.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Lists the current running tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\tasklist.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
932"ipconfig" /allC:\Windows\System32\ipconfig.exeNetTraffic.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
IP Configuration Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ipconfig.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\ws2_32.dll
1408C:\Windows\System32\ctfmon.exe C:\Windows\System32\ctfmon.exetaskeng.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
CTF Loader
Exit code:
1073807364
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ctfmon.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msctfmonitor.dll
c:\windows\system32\msctf.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
1580C:\Windows\system32\sipnotify.exe -LogonOrUnlockC:\Windows\System32\sipnotify.exe
taskeng.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
sipnotify
Exit code:
0
Version:
6.1.7602.20480 (win7sp1_ldr_escrow.191010-1716)
Modules
Images
c:\windows\system32\sipnotify.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2096"C:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXE" /SetPreload /JPN /LogC:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Office IME 2010
Exit code:
1
Version:
14.0.4734.1000
Modules
Images
c:\program files\common files\microsoft shared\ime14\shared\imeklmg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\userenv.dll
2104"C:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXE" /SetPreload /KOR /LogC:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Office IME 2010
Exit code:
1
Version:
14.0.4734.1000
Modules
Images
c:\program files\common files\microsoft shared\ime14\shared\imeklmg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\userenv.dll
2404"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2428"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2852"tasklist"C:\Windows\System32\tasklist.exeNetTraffic.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Lists the current running tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\tasklist.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3176"route" printC:\Windows\System32\ROUTE.EXENetTraffic.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
TCP/IP Route Command
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\route.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
Total events
11 518
Read events
11 465
Write events
52
Delete events
1

Modification events

(PID) Process:(3344) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3344) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3344) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3344) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3344) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3344) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(3344) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\NetTraffic Portable 1.71.0.zip
(PID) Process:(3344) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3344) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3344) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
1
Suspicious files
10
Text files
37
Unknown types
4

Dropped files

PID
Process
Filename
Type
3344WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3344.12443\NetTraffic\Lang\Lang_AR.xmlxml
MD5:C6FA963C3303FD1372ED41A7680F642A
SHA256:42106F63602AA6E18A43FB117D163CBA26A1194B3F3BC2DE3ED04E439983DDD9
3344WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3344.12443\NetTraffic\Lang\Lang_ES.xmlxml
MD5:96B83905F455FC5C55C8ED476E0E1408
SHA256:36B2A91950FD12E58917F848AB5ABA6C577866121BBB77E261F858B60D8860CF
3344WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3344.12443\NetTraffic\Lang\Lang_EL.xmlxml
MD5:1F1288F224BBFAE9DCEBAB8C07E209E6
SHA256:B84A484F963C6D9C3BD705E83489F6976D218D8EC728D4FBAA35EF00DA9D3EA3
3344WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3344.12443\NetTraffic\Lang\Lang_EN.xmlxml
MD5:15560CB43BD4D4248D89BB8DC6DD88F6
SHA256:BCA03898347190CAC66E2871659DA57F5D13FA624B48F3EFF0A93D5C24916B12
3344WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3344.12443\NetTraffic\Lang\Lang_DE.xmlxml
MD5:122BF12295951BE432A0A1E2A2DDF610
SHA256:FDBE03AF199BB4AA43EB0752D2DFEAE4FBC619BC2ABFC0F44C57F7FBEF9F7FCC
3344WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3344.12443\NetTraffic\Lang\Lang_CN.xmlxml
MD5:8F633BF479D4BDEDAADBD9512CED62CF
SHA256:256FABF6DBE8BFA1EBE6592EA6D32C1D6FD7637B884B15FDE4FFBEED8CD8507C
3344WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3344.12443\NetTraffic\Lang\Lang_FA.xmlxml
MD5:2953415DB8C6CA5EAEBC32707CB38761
SHA256:D740C80C8794C68C3BA86870E1F8B7B2F85FBA514CA05D812D33A00E010D4C3D
3344WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3344.12443\NetTraffic\Lang\Lang_IT.xmlxml
MD5:021A8EEA3A57541F581BC84F5A43B1F3
SHA256:9D9E08CD9EE9E1F845E4E42C31DDFBAEBC7D81EA2AE8684182F7AA1C4FCC51E9
3344WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3344.12443\NetTraffic\Lang\Lang_NL.xmlxml
MD5:7D1F9F9F0678230ED92C933D37D66AED
SHA256:F366C5CBA2B3167A8245AD85611A8E68CE3DDE448C2CDA02FDCC6193F3DF9808
3344WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3344.12443\NetTraffic\Lang\Lang_PL.xmlxml
MD5:62A5AA97D18F0303D9398EA1BDEDA2E1
SHA256:AFE960C267C2FE5071AD88A6ADEC2F36BA63C6A9A9403245F0F58B6F14E88DC1
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
21
DNS requests
8
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1372
svchost.exe
GET
304
199.232.210.172:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?33775f6043c93e33
unknown
whitelisted
1060
svchost.exe
GET
304
199.232.210.172:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?a9f83325acc8ca75
unknown
whitelisted
1372
svchost.exe
GET
200
23.48.23.156:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1580
sipnotify.exe
HEAD
200
23.197.138.118:80
http://query.prod.cms.rt.microsoft.com/cms/api/am/binary/RE2JgkA?v=133651721432500000
unknown
whitelisted
1372
svchost.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2564
svchost.exe
239.255.255.250:3702
whitelisted
1372
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1060
svchost.exe
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:138
whitelisted
1372
svchost.exe
199.232.210.172:80
ctldl.windowsupdate.com
FASTLY
US
unknown
1372
svchost.exe
23.48.23.156:80
crl.microsoft.com
Akamai International B.V.
DE
unknown
1372
svchost.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
1060
svchost.exe
199.232.210.172:80
ctldl.windowsupdate.com
FASTLY
US
unknown
1076
svchost.exe
224.0.0.252:5355
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 216.58.206.46
whitelisted
settings-win.data.microsoft.com
  • 4.231.128.59
whitelisted
ctldl.windowsupdate.com
  • 199.232.210.172
  • 199.232.214.172
whitelisted
crl.microsoft.com
  • 23.48.23.156
  • 23.48.23.143
whitelisted
www.microsoft.com
  • 23.35.229.160
whitelisted
172.210.232.199.in-addr.arpa
unknown
query.prod.cms.rt.microsoft.com
  • 23.197.138.118
whitelisted

Threats

No threats detected
No debug info