| File name: | Windows Loader.iso |
| Full analysis: | https://app.any.run/tasks/bb575cdf-0d20-4927-a9d5-fc7742de665c |
| Verdict: | Malicious activity |
| Analysis date: | November 09, 2023, 18:53:54 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-iso9660-image |
| File info: | ISO 9660 CD-ROM filesystem data '20160312_1540' |
| MD5: | 5FF25C64153C4AA535B040C4CB291964 |
| SHA1: | 9B5A3FD13458C98332E89A4442CD0088A19F308A |
| SHA256: | A823806E80EC2AA3DB37150EE17AD02D57995570640EB108CA19057967B70BE0 |
| SSDEEP: | 98304:M6bbMU95DKW3xsUVaGHPZoxTEAURJGtXKnNBk0SFbLHGUUl2bnuC9KtZrswbm:V |
| .iso | | | ISO 9660 CD image (27.6) |
|---|---|---|
| .atn | | | Photoshop Action (27.1) |
| .gmc | | | Game Music Creator Music (6.1) |
| VolumeName: | 20160312_1540 |
|---|---|
| VolumeBlockCount: | 2345 |
| VolumeBlockSize: | 2048 |
| RootDirectoryCreateDate: | 2016:03:12 15:40:47+00:00 |
| VolumeSetName: | 20160312_1540 |
| Publisher: | MagicISO v5.2 COPYRIGHT (C) 2001-2006 MagicISO, Inc. |
| DataPreparer: | MagicISO v5.2 COPYRIGHT (C) 2001-2006 MagicISO, Inc. |
| VolumeCreateDate: | 20160312154431 |
| VolumeModifyDate: | 20160312154431 |
| VolumeSize: | 4.6 MiB |
|---|
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 528 | cmd.exe /A /C "cscript.exe //nologo %SystemRoot%\system32\slmgr.vbs -rilc 2>NUL>NUL" | C:\Windows\System32\cmd.exe | — | WAT Fix.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 588 | sc stop uodin64 | C:\Windows\System32\sc.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: A tool to aid in developing services for WindowsNT Exit code: 1060 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 664 | cmd.exe /A /C "ren %SystemRoot%\system32\slmgr.vbs.removewat slmgr.vbs 2>NUL>NUL" | C:\Windows\System32\cmd.exe | — | WAT Fix.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 1 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 756 | cmd.exe /A /C "sc config sppuinotify start= demand 2>NUL>NUL" | C:\Windows\System32\cmd.exe | — | WAT Fix.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1232 | cmd.exe /A /C "sc delete uodin86 2>NUL>NUL" | C:\Windows\System32\cmd.exe | — | WAT Fix.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 1060 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1376 | net start sppsvc | C:\Windows\System32\net.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Net Command Exit code: 2 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1640 | sc delete uodin86 | C:\Windows\System32\sc.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: A tool to aid in developing services for WindowsNT Exit code: 1060 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1752 | cmd.exe /A /C "net start sppuinotify 2>NUL>NUL" | C:\Windows\System32\cmd.exe | — | WAT Fix.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1760 | C:\Windows\system32\net1 start sppsvc | C:\Windows\System32\net1.exe | — | net.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Net Command Exit code: 2 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1892 | cscript.exe //nologo C:\Windows\system32\slmgr.vbs -rilc | C:\Windows\System32\cscript.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft ® Console Based Script Host Exit code: 0 Version: 5.8.7600.16385 Modules
| |||||||||||||||
| (PID) Process: | (3428) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\17A\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3428) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (3428) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (3428) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (3428) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3428) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3428) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3428) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (3428) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (3428) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3428 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3428.7011\checksums.md5 | text | |
MD5:CAB45D50BE4C1FC788D29593464B1F35 | SHA256:C083F57AC4D8A5EAF9BC934F08204A691FA9E4FD275F90AAADFD195A4EEF820F | |||
| 4012 | WAT Fix.exe | C:\undo.bat | text | |
MD5:0D9B4627193F4F5509D8C2B9FAD108B8 | SHA256:73DE311C8AB30A40D9CEB5749187336F7AF79CA47D2089AEEEB2A8D87FCD803A | |||
| 3428 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3428.8942\checksums.md5 | text | |
MD5:CAB45D50BE4C1FC788D29593464B1F35 | SHA256:C083F57AC4D8A5EAF9BC934F08204A691FA9E4FD275F90AAADFD195A4EEF820F | |||
| 3428 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3428.8942\Keys.ini | text | |
MD5:3BA4950BCF43B1C7B714A1D93B57EA86 | SHA256:1384C5FD758A1BD8C9372594503E22D71B0877D332886A1B7D50CB86C4A0A13C | |||
| 3428 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3428.7011\Windows Loader.exe | executable | |
MD5:323C0FD51071400B51EEDB1BE90A8188 | SHA256:2F2ABA1E074F5F4BAA08B524875461889F8F04D4FFC43972AC212E286022AB94 | |||
| 3428 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3428.7011\Keys.ini | text | |
MD5:3BA4950BCF43B1C7B714A1D93B57EA86 | SHA256:1384C5FD758A1BD8C9372594503E22D71B0877D332886A1B7D50CB86C4A0A13C | |||
| 3428 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3428.8942\Read me.txt | text | |
MD5:D82C50EE472476C01D4CDC5AB3DA4531 | SHA256:559685D98F34E3F7E48DDD1DB091E90497AF9ACDC7A8BE98C717626A505229B8 | |||
| 3428 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3428.7011\Read me.txt | text | |
MD5:D82C50EE472476C01D4CDC5AB3DA4531 | SHA256:559685D98F34E3F7E48DDD1DB091E90497AF9ACDC7A8BE98C717626A505229B8 | |||
| 3428 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DIa3428.4958\Read me.txt | text | |
MD5:D82C50EE472476C01D4CDC5AB3DA4531 | SHA256:559685D98F34E3F7E48DDD1DB091E90497AF9ACDC7A8BE98C717626A505229B8 | |||
| 3428 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3428.8942\WAT Fix.exe | executable | |
MD5:0A1023D7FD543F6B73AD2A4CA553BBA1 | SHA256:D2BEF451A44457EF4B1DA38982F568E1E75402FBD2FEDC6EAA5F761CD6A5E751 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |