| File name: | WormGPT[n0xi0s].zip |
| Full analysis: | https://app.any.run/tasks/e124e6f2-bb52-4810-ad3d-85442c4b4e70 |
| Verdict: | Malicious activity |
| Analysis date: | February 01, 2024, 23:44:37 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | 4CB437F7445AA07B4B72361D2BCA9FC2 |
| SHA1: | 645485CD88F4E15BFF9233CA85F57B4D6312CB48 |
| SHA256: | A86816009A819CE6796F09645FEC7C131104F7580B0EA76E7D723015C9C8A107 |
| SSDEEP: | 48:2a0NtnaBoBsZPFTP+1i8pRhFYQq5AgpFJFEgm:2aoaeBkPFL+1i8pPl0ZHwgm |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 788 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2023:12:26 19:03:16 |
| ZipCRC: | 0x0ca6d5c2 |
| ZipCompressedSize: | 122 |
| ZipUncompressedSize: | 161 |
| ZipFileName: | method.txt |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 752 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\WormGPT[n0xi0s].zip" | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 2204 | "C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\AppData\Local\Temp\Rar$DIa752.12257\method.txt | C:\Windows\System32\notepad.exe | — | WinRAR.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Notepad Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2776 | "C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\Desktop\advertisingtel.rtf" | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Word Exit code: 0 Version: 14.0.6024.1000 Modules
| |||||||||||||||
| 3244 | "C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\AppData\Local\Temp\Rar$DIa752.12257\method.txt | C:\Windows\System32\notepad.exe | — | WinRAR.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Notepad Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3564 | "C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\AppData\Local\Temp\Rar$DIa752.10930\method.txt | C:\Windows\System32\notepad.exe | — | WinRAR.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Notepad Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3728 | "C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\AppData\Local\Temp\Rar$DIa752.23174\method.txt | C:\Windows\System32\notepad.exe | — | WinRAR.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Notepad Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (752) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (752) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (752) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (752) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (752) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
| (PID) Process: | (752) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (752) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (752) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (752) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (752) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\ArcColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2776 | WINWORD.EXE | C:\Users\admin\AppData\Local\Temp\CVR7A3C.tmp.cvr | — | |
MD5:— | SHA256:— | |||
| 2776 | WINWORD.EXE | C:\Users\admin\AppData\Roaming\Microsoft\Templates\~$Normal.dotm | binary | |
MD5:2DAE076239E8B5D79F3AE6391F7FBEF6 | SHA256:8E59A490B319BA34E2619B49DF5411364146F2D8A7136422E2A99CD8EFE78EC9 | |||
| 2776 | WINWORD.EXE | C:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\index.dat | text | |
MD5:CA8304E1D5365E2E4EFA80FFDD8DC07E | SHA256:AA3E5D35CD1857A98E48A997B7686AA0D9AD66948CE4FD85F9E38FF898DAA317 | |||
| 2776 | WINWORD.EXE | C:\Users\admin\Desktop\~$vertisingtel.rtf | binary | |
MD5:B1F65DE042CC0D577561B4360E0F51C2 | SHA256:80480CA698F5569B35C5EB75976D4EFC28DD87567F630C106CDDD85A9329CC11 | |||
| 752 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DIa752.23174\method.txt | text | |
MD5:0C429ADB577AC745FA3BA6ECD923CF73 | SHA256:2C5B7833D3B66A82FD805E8BF514599E01F59A8C4CB4DA2406B7BFB25A217BEB | |||
| 2776 | WINWORD.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{919F4BAD-378E-4F90-9BA6-77A34734BB50}.tmp | binary | |
MD5:9BA7C1189961BF1C045EE23BFEA64DE4 | SHA256:EFB8E7F326B4743DCFF28649B459657DAF338125416EC24C7487675FF6BEAA19 | |||
| 2776 | WINWORD.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRF{4320DB29-4481-4C63-AA88-CFB352E62FF3}.tmp | binary | |
MD5:26CCB6DB8CA0C17D2EDD14B9662A5CDB | SHA256:F4F7E8EEDDE40F51F1B14E3336BF453F2D07AB80EC8B017FDC452C695C4A630C | |||
| 752 | WinRAR.exe | C:\Users\admin\AppData\Roaming\Microsoft\HTML Help\hh.dat | binary | |
MD5:54339081FECC850448492C6837B6F3AD | SHA256:FC1B9FB17F4F69E8DF4B24B0320ACD5B2E171600174C836647ACECD10816AD72 | |||
| 752 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DIa752.10930\method.txt | text | |
MD5:0C429ADB577AC745FA3BA6ECD923CF73 | SHA256:2C5B7833D3B66A82FD805E8BF514599E01F59A8C4CB4DA2406B7BFB25A217BEB | |||
| 752 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\~DFEDB387CEFE84C8FE.TMP | binary | |
MD5:BF619EAC0CDF3F68D496EA9344137E8B | SHA256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |