download:

/releases/SDI_R2309.zip

Full analysis: https://app.any.run/tasks/45cf65f4-dae8-4a2b-94eb-cdf72ac86424
Verdict: Malicious activity
Analysis date: November 07, 2023, 14:55:28
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

AB55D957BC67C671A0C06435EB3B1380

SHA1:

F2405E4E48839FD97F90DB19219E1866DBB2D345

SHA256:

A971E5387743BD87EC7652A24E1CE05CA4DE8846D4096ADCF976FF50D85A5B23

SSDEEP:

98304:qtZ5ETa92l+fSPV9Npf1c7ExvbvOOhLjvmT4CIF21YrOSEx4CzfFVw6S1EnGKFxR:vBlbcD2wxYe/

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • The process executes via Task Scheduler

      • sipnotify.exe (PID: 1448)
    • Application launched itself

      • WerFault.exe (PID: 332)
    • Reads the Internet Settings

      • sipnotify.exe (PID: 1448)
      • runonce.exe (PID: 2036)
    • Reads settings of System Certificates

      • sipnotify.exe (PID: 1448)
  • INFO

    • Manual execution by a user

      • SDI_R2309.exe (PID: 1820)
      • explorer.exe (PID: 3196)
      • IMEKLMG.EXE (PID: 352)
      • SDI_R2309.exe (PID: 1236)
      • runonce.exe (PID: 2036)
      • IMEKLMG.EXE (PID: 1988)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 3440)
    • Reads the time zone

      • runonce.exe (PID: 2036)
    • Reads the computer name

      • SDI_R2309.exe (PID: 1236)
      • IMEKLMG.EXE (PID: 352)
      • IMEKLMG.EXE (PID: 1988)
    • Checks supported languages

      • SDI_R2309.exe (PID: 1236)
      • IMEKLMG.EXE (PID: 352)
      • IMEKLMG.EXE (PID: 1988)
    • Reads the machine GUID from the registry

      • SDI_R2309.exe (PID: 1236)
    • Create files in a temporary directory

      • WerFault.exe (PID: 1312)
    • Process checks are UAC notifies on

      • IMEKLMG.EXE (PID: 352)
      • IMEKLMG.EXE (PID: 1988)
    • Reads security settings of Internet Explorer

      • sipnotify.exe (PID: 1448)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2018:09:29 00:24:14
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: drivers/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
91
Monitored processes
10
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs explorer.exe no specs sdi_r2309.exe no specs sdi_r2309.exe sipnotify.exe runonce.exe werfault.exe no specs werfault.exe no specs imeklmg.exe no specs imeklmg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
332"C:\Windows\System32\WerFault.exe" -k -rqC:\Windows\System32\WerFault.exerunonce.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Problem Reporting
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
352"C:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXE" /SetPreload /JPN /LogC:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Office IME 2010
Exit code:
1
Version:
14.0.4734.1000
Modules
Images
c:\program files\common files\microsoft shared\ime14\shared\imeklmg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\userenv.dll
1236"C:\Users\admin\Desktop\SDI_R2309.exe" C:\Users\admin\Desktop\SDI_R2309.exe
explorer.exe
User:
admin
Company:
www.SamLab.ws
Integrity Level:
HIGH
Description:
Snappy Driver Installer
Exit code:
0
Version:
1.23 1.23.9
Modules
Images
c:\users\admin\desktop\sdi_r2309.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\comctl32.dll
c:\windows\system32\gdi32.dll
1312C:\Windows\System32\WerFault.exe -k -qC:\Windows\System32\WerFault.exeWerFault.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Problem Reporting
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1448C:\Windows\system32\sipnotify.exe -LogonOrUnlockC:\Windows\System32\sipnotify.exe
taskeng.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
sipnotify
Exit code:
0
Version:
6.1.7602.20480 (win7sp1_ldr_escrow.191010-1716)
Modules
Images
c:\windows\system32\sipnotify.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1820"C:\Users\admin\Desktop\SDI_R2309.exe" C:\Users\admin\Desktop\SDI_R2309.exeexplorer.exe
User:
admin
Company:
www.SamLab.ws
Integrity Level:
MEDIUM
Description:
Snappy Driver Installer
Exit code:
3221226540
Version:
1.23 1.23.9
Modules
Images
c:\users\admin\desktop\sdi_r2309.exe
c:\windows\system32\ntdll.dll
1988"C:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXE" /SetPreload /KOR /LogC:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Office IME 2010
Exit code:
1
Version:
14.0.4734.1000
Modules
Images
c:\program files\common files\microsoft shared\ime14\shared\imeklmg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\userenv.dll
2036runonce.exe /ExplorerC:\Windows\System32\runonce.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Run Once Wrapper
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\runonce.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3196"C:\Windows\explorer.exe" C:\Windows\explorer.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3440"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\SDI_R2309.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
6 796
Read events
6 749
Write events
44
Delete events
3

Modification events

(PID) Process:(3440) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\17A\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3440) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(3440) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3440) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3440) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3440) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3440) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3440) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3440) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
(PID) Process:(3440) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\General
Operation:writeName:LastFolder
Value:
C:\Users\admin\Desktop
Executable files
2
Suspicious files
4
Text files
245
Unknown types
0

Dropped files

PID
Process
Filename
Type
3440WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3440.44823\SDI_x64_R2309.exeexecutable
MD5:9C0486D19C98BDDB8176031B3F18CAF8
SHA256:B046BEA69BA1860FF625B245B9553BA9B82D6FACB347CB24CE88B213D44E4916
3440WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3440.44823\tools\SDI\langs\czech.txttext
MD5:898076B87800DEA4582E047AD919F128
SHA256:92E556B79C7A9AA1B8255FDAC3759375D0CF2BA9AA53FA64F53B323730A307EB
3440WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3440.44823\tools\SDI\langs\armenian.txttext
MD5:8C12D4A4463BAF32E3714A5C58476022
SHA256:A5FC6D54254ECD4BF53E4495C58BD0564DEC89CE6D7462E989CD1F4E233652AC
3440WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3440.44823\SDI_R2309.exeexecutable
MD5:819DBA1EA42A664867132539887AD8C6
SHA256:69BCA876721C019072B4E28651B5AF0E114F762D78A8E32564A5340C8D60D1E6
3440WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3440.44823\tools\SDI\langs\azerbaijan.txttext
MD5:505B0DE7B97212F78BA4266BB5A055E1
SHA256:4543E9820A0C7E0C807D18B423C0018FF8015BC8664E7F10673EF53282AFD9DA
3440WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3440.44823\tools\SDI\langs\catalan.txttext
MD5:76D31CEA7C4689EA1975E9F9F6776F91
SHA256:5006A1541C92CCB8AF1516677731FE97F0EADC25B5DCAD5E11DCC35E5D27792D
3440WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3440.44823\tools\SDI\langs\croatian.txttext
MD5:B4B3114DA6380F1566C577934EFD3272
SHA256:6710177EB1CF25611A1B0560A7ED1840769A97BE26D141F366E2BA87802802AD
3440WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3440.44823\tools\SDI\langs\belarusian.txttext
MD5:D3027F02B6B46F426891EBD063AB94CA
SHA256:B0917EF1C1C48FFCA4B2286DF41C5BF969767830D9F6F01285B5F7B3C3A9E9CB
3440WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3440.44823\tools\SDI\langs\bulgarian.txttext
MD5:DE2D9D6F623D56381CDC1DA5D1573362
SHA256:2C322B33AB54FC9399EEE4F194353351DD23C508931F9CDC822BA9C94804AB33
3440WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3440.44823\tools\SDI\langs\chinese.txttext
MD5:49040B8AC3F1047494418AC916C4F21D
SHA256:489C0CBFB84A40C2EF7B9015F550D0F53221588024BFCE00303D9F9FE9EFD553
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
8
DNS requests
5
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1448
sipnotify.exe
HEAD
200
23.197.138.118:80
http://query.prod.cms.rt.microsoft.com/cms/api/am/binary/RE2JgkA?v=133438426056560000
unknown
unknown
1236
SDI_R2309.exe
GET
200
185.26.122.80:80
http://driveroff.net/SDI_Update.torrent
unknown
binary
405 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
2588
svchost.exe
239.255.255.250:1900
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
1236
SDI_R2309.exe
185.26.122.80:80
driveroff.net
Hostland LTD
RU
unknown
1116
svchost.exe
224.0.0.252:5355
unknown
1448
sipnotify.exe
23.197.138.118:80
query.prod.cms.rt.microsoft.com
Akamai International B.V.
US
unknown

DNS requests

Domain
IP
Reputation
router.bittorrent.com
  • 67.215.246.10
shared
router.utorrent.com
  • 82.221.103.244
whitelisted
router.bitcomet.com
unknown
driveroff.net
  • 185.26.122.80
unknown
query.prod.cms.rt.microsoft.com
  • 23.197.138.118
whitelisted

Threats

PID
Process
Class
Message
1236
SDI_R2309.exe
Potential Corporate Privacy Violation
ET P2P Possible Torrent Download via HTTP Request
1236
SDI_R2309.exe
Potential Corporate Privacy Violation
ET P2P BitTorrent - Torrent File Downloaded
No debug info