File name:

NetTraffic Portable 1.71.0.zip

Full analysis: https://app.any.run/tasks/c2c626c1-cac6-4676-987e-96d43a8e2dc6
Verdict: Malicious activity
Analysis date: July 11, 2024, 10:46:45
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=store
MD5:

1B0507946724DC9A3EBB989C8AE5919D

SHA1:

A58CA5293B9C0F1A6D96ED47D3D7977A39F07287

SHA256:

A7952414CB3CFDFF3921A21237927526AE12A2D5F932EA9E98BEB522831DBF49

SSDEEP:

24576:rQOzIfHQrmWm4KYutpBSziKqE7JMs5PgFOz43blAkB:rQeIfHQrmWm4KYutpBSziKqE7JMs5PgP

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 3344)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 3344)
    • Uses ROUTE.EXE to obtain the routing table information

      • NetTraffic.exe (PID: 3532)
    • Process uses ARP to discover network configuration

      • NetTraffic.exe (PID: 3532)
    • Process uses IPCONFIG to discover network configuration

      • NetTraffic.exe (PID: 3532)
    • Get information on the list of running processes

      • NetTraffic.exe (PID: 3532)
    • The process executes via Task Scheduler

      • ctfmon.exe (PID: 1408)
      • sipnotify.exe (PID: 1580)
    • Reads the Internet Settings

      • sipnotify.exe (PID: 1580)
    • Reads settings of System Certificates

      • sipnotify.exe (PID: 1580)
  • INFO

    • Reads the computer name

      • NetTraffic.exe (PID: 3532)
      • wmpnscfg.exe (PID: 2404)
      • IMEKLMG.EXE (PID: 2096)
      • IMEKLMG.EXE (PID: 2104)
      • wmpnscfg.exe (PID: 2428)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3344)
    • Checks supported languages

      • NetTraffic.exe (PID: 3532)
      • IMEKLMG.EXE (PID: 2104)
      • wmpnscfg.exe (PID: 2404)
      • wmpnscfg.exe (PID: 2428)
      • IMEKLMG.EXE (PID: 2096)
    • Reads the machine GUID from the registry

      • NetTraffic.exe (PID: 3532)
    • Create files in a temporary directory

      • NetTraffic.exe (PID: 3532)
    • Reads security settings of Internet Explorer

      • sipnotify.exe (PID: 1580)
    • Process checks whether UAC notifications are on

      • IMEKLMG.EXE (PID: 2104)
      • IMEKLMG.EXE (PID: 2096)
    • Reads the software policy settings

      • sipnotify.exe (PID: 1580)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 2404)
      • IMEKLMG.EXE (PID: 2104)
      • IMEKLMG.EXE (PID: 2096)
      • wmpnscfg.exe (PID: 2428)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2023:09:25 23:44:42
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: NetTraffic/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
108
Monitored processes
15
Malicious processes
1
Suspicious processes
2

Behavior graph

Click at the process to see the details
start winrar.exe nettraffic.exe no specs hostname.exe no specs route.exe no specs tasklist.exe no specs arp.exe no specs netstat.exe no specs ipconfig.exe no specs tasklist.exe no specs ctfmon.exe no specs sipnotify.exe imeklmg.exe no specs imeklmg.exe no specs wmpnscfg.exe no specs wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
268"tasklist" /vC:\Windows\System32\tasklist.exeNetTraffic.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Lists the current running tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\tasklist.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
932"ipconfig" /allC:\Windows\System32\ipconfig.exeNetTraffic.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
IP Configuration Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ipconfig.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\ws2_32.dll
1408C:\Windows\System32\ctfmon.exe C:\Windows\System32\ctfmon.exetaskeng.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
CTF Loader
Exit code:
1073807364
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ctfmon.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msctfmonitor.dll
c:\windows\system32\msctf.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
1580C:\Windows\system32\sipnotify.exe -LogonOrUnlockC:\Windows\System32\sipnotify.exe
taskeng.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
sipnotify
Exit code:
0
Version:
6.1.7602.20480 (win7sp1_ldr_escrow.191010-1716)
Modules
Images
c:\windows\system32\sipnotify.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2096"C:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXE" /SetPreload /JPN /LogC:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Office IME 2010
Exit code:
1
Version:
14.0.4734.1000
Modules
Images
c:\program files\common files\microsoft shared\ime14\shared\imeklmg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\userenv.dll
2104"C:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXE" /SetPreload /KOR /LogC:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Office IME 2010
Exit code:
1
Version:
14.0.4734.1000
Modules
Images
c:\program files\common files\microsoft shared\ime14\shared\imeklmg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\userenv.dll
2404"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2428"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2852"tasklist"C:\Windows\System32\tasklist.exeNetTraffic.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Lists the current running tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\tasklist.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3176"route" printC:\Windows\System32\ROUTE.EXENetTraffic.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
TCP/IP Route Command
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\route.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
Total events
11 518
Read events
11 465
Write events
52
Delete events
1

Modification events

(PID) Process:(3344) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3344) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3344) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3344) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3344) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3344) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(3344) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\NetTraffic Portable 1.71.0.zip
(PID) Process:(3344) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3344) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3344) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
1
Suspicious files
10
Text files
37
Unknown types
4

Dropped files

PID
Process
Filename
Type
3344WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3344.12443\NetTraffic\Lang\Lang_FA.xmlxml
MD5:2953415DB8C6CA5EAEBC32707CB38761
SHA256:D740C80C8794C68C3BA86870E1F8B7B2F85FBA514CA05D812D33A00E010D4C3D
3344WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3344.12443\NetTraffic\Lang\Lang_RO.xmlxml
MD5:CD537DF934EBF479678A5523DE56C585
SHA256:86C9FC49F7D4B5C11CD24D8C514F7C75BDE68747B67A672A1786C49C506B5E04
3344WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3344.12443\NetTraffic\Lang\Lang_CZ.xmlxml
MD5:0A724DF8EAEEA02372C057D70C259D2A
SHA256:1430592D7637A0AEE046240E326AFAD3CD2C6CC0209736B9A88640BD380BC027
3344WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3344.12443\NetTraffic\Lang\Lang_EE.xmlxml
MD5:1285B1E6C16241165D41C2EB44FC346E
SHA256:113D9391FB446200DB56D5B16F803138F84DE025123DAB80C8936F560EAD2324
3344WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3344.12443\NetTraffic\Lang\Lang_EL.xmlxml
MD5:1F1288F224BBFAE9DCEBAB8C07E209E6
SHA256:B84A484F963C6D9C3BD705E83489F6976D218D8EC728D4FBAA35EF00DA9D3EA3
3344WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3344.12443\NetTraffic\Lang\Lang_FI.xmlxml
MD5:2314ADC13AED0AC3CA8906E9AB5CDBFD
SHA256:B67D185678B7F3D4D97DE8343012BE327AC4B359772A4B3FF6CC289CFB92CF07
3344WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3344.12443\NetTraffic\Lang\Lang_FR.xmlxml
MD5:517BF4A95B7FBC6FAB1ACAD1F5C481F3
SHA256:D98791C94FD130CCEF2F0C277F20015A470D5CC5A858F842865A52116884AE1A
3344WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3344.12443\NetTraffic\Lang\Lang_EN.xmlxml
MD5:15560CB43BD4D4248D89BB8DC6DD88F6
SHA256:BCA03898347190CAC66E2871659DA57F5D13FA624B48F3EFF0A93D5C24916B12
3344WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3344.12443\NetTraffic\Lang\Lang_ES.xmlxml
MD5:96B83905F455FC5C55C8ED476E0E1408
SHA256:36B2A91950FD12E58917F848AB5ABA6C577866121BBB77E261F858B60D8860CF
3344WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3344.12443\NetTraffic\Lang\Lang_HU.xmlxml
MD5:574F6BD55775C1305766E2D84EBDE06F
SHA256:5AB0C3AEB8ECBD7836CF8B7517CD7BC4A59CDCC3739F8CF3F6D39A1A2A021A43
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
21
DNS requests
8
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1372
svchost.exe
GET
304
199.232.210.172:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?33775f6043c93e33
unknown
whitelisted
1060
svchost.exe
GET
304
199.232.210.172:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?a9f83325acc8ca75
unknown
whitelisted
1372
svchost.exe
GET
200
23.48.23.156:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1372
svchost.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1580
sipnotify.exe
HEAD
200
23.197.138.118:80
http://query.prod.cms.rt.microsoft.com/cms/api/am/binary/RE2JgkA?v=133651721432500000
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2564
svchost.exe
239.255.255.250:3702
whitelisted
1372
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1060
svchost.exe
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:138
whitelisted
1372
svchost.exe
199.232.210.172:80
ctldl.windowsupdate.com
FASTLY
US
unknown
1372
svchost.exe
23.48.23.156:80
crl.microsoft.com
Akamai International B.V.
DE
unknown
1372
svchost.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
1060
svchost.exe
199.232.210.172:80
ctldl.windowsupdate.com
FASTLY
US
unknown
1076
svchost.exe
224.0.0.252:5355
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 216.58.206.46
whitelisted
settings-win.data.microsoft.com
  • 4.231.128.59
whitelisted
ctldl.windowsupdate.com
  • 199.232.210.172
  • 199.232.214.172
whitelisted
crl.microsoft.com
  • 23.48.23.156
  • 23.48.23.143
whitelisted
www.microsoft.com
  • 23.35.229.160
whitelisted
172.210.232.199.in-addr.arpa
unknown
query.prod.cms.rt.microsoft.com
  • 23.197.138.118
whitelisted

Threats

No threats detected
No debug info