File name:

Cospuri 498 Shinanoazur Lane 5011.zip

Full analysis: https://app.any.run/tasks/74c0e78f-10da-4604-b1e4-7f8aa760e44b
Verdict: Malicious activity
Analysis date: June 16, 2024, 11:51:43
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
autoit
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=store
MD5:

70C34C89B3596268870919213EF0AB7C

SHA1:

FF94DC49E33256CF678D53E87186CA9BEE535F1C

SHA256:

ADD45A723992F05E3F2B3F5A7EF21342FF2BE86BEE5624F61F528C3FA8CE1DF0

SSDEEP:

98304:3DiMaMVTfOYdbJ50GcqlbwaqfWhxgW5uUNZ0y3U96x/vOpcO5K4+OXdghIbvCerq:NK3QCKWl01u904h0iAZWr4BpTjtJR

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 3972)
      • 0.scr (PID: 1120)
    • Create files in the Startup directory

      • 0.scr (PID: 1120)
  • SUSPICIOUS

    • Starts CMD.EXE for commands execution

      • 0.scr (PID: 1120)
    • Executable content was dropped or overwritten

      • 0.scr (PID: 1120)
    • Reads the Internet Settings

      • info.exe (PID: 1816)
    • Reads security settings of Internet Explorer

      • info.exe (PID: 1816)
    • Potential Corporate Privacy Violation

      • info.exe (PID: 1816)
  • INFO

    • Checks supported languages

      • 0.scr (PID: 1120)
      • info.exe (PID: 1816)
      • wmpnscfg.exe (PID: 2348)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3972)
    • Manual execution by a user

      • 0.scr (PID: 1120)
      • rundll32.exe (PID: 1652)
      • info.exe (PID: 1816)
      • wmpnscfg.exe (PID: 2348)
    • Reads mouse settings

      • 0.scr (PID: 1120)
      • info.exe (PID: 1816)
    • Creates files or folders in the user directory

      • 0.scr (PID: 1120)
      • info.exe (PID: 1816)
    • Checks proxy server information

      • info.exe (PID: 1816)
    • Reads the computer name

      • info.exe (PID: 1816)
      • wmpnscfg.exe (PID: 2348)
    • Reads the machine GUID from the registry

      • info.exe (PID: 1816)
    • Create files in a temporary directory

      • info.exe (PID: 1816)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2024:05:18 12:27:54
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: Cospuri 498 Shinanoazur Lane 5011/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
44
Monitored processes
7
Malicious processes
0
Suspicious processes
2

Behavior graph

Click at the process to see the details
start winrar.exe 0.scr cmd.exe no specs PhotoViewer.dll no specs rundll32.exe no specs info.exe wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
864C:\Windows\system32\cmd.exe /c 1.jpgC:\Windows\System32\cmd.exe0.scr
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1120"C:\Users\admin\Desktop\Cospuri 498 Shinanoazur Lane 5011\0.scr" /SC:\Users\admin\Desktop\Cospuri 498 Shinanoazur Lane 5011\0.scr
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\cospuri 498 shinanoazur lane 5011\0.scr
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\version.dll
1652"C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\Desktop\Cospuri 498 Shinanoazur Lane 5011\readmeC:\Windows\System32\rundll32.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
1816"C:\Users\admin\Desktop\Cospuri 498 Shinanoazur Lane 5011\info.exe" C:\Users\admin\Desktop\Cospuri 498 Shinanoazur Lane 5011\info.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\users\admin\desktop\cospuri 498 shinanoazur lane 5011\info.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\version.dll
2040C:\Windows\system32\DllHost.exe /Processid:{76D0CB12-7604-4048-B83C-1005C7DDC503}C:\Windows\System32\dllhost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
COM Surrogate
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\dllhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2348"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
3972"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Cospuri 498 Shinanoazur Lane 5011.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
5 789
Read events
5 722
Write events
61
Delete events
6

Modification events

(PID) Process:(3972) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3972) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3972) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3972) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3972) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3972) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(3972) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Cospuri 498 Shinanoazur Lane 5011.zip
(PID) Process:(3972) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3972) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3972) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
4
Suspicious files
0
Text files
35
Unknown types
0

Dropped files

PID
Process
Filename
Type
3972WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3972.3314\Cospuri 498 Shinanoazur Lane 5011\17__5011e962785a0236.jpgimage
MD5:1A2D8B22F23B3D781F14504A60D4ABCE
SHA256:2C196662A6D6DED7E876FE2D1959C6B585B3494381BA7C7A35587E46DDBAD11A
3972WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3972.3314\Cospuri 498 Shinanoazur Lane 5011\13__5011e962785a0236.jpgimage
MD5:81063D5EF580734B2C413A91DBC21BB0
SHA256:CBAA3AF7EFCD3B9A69168A4AB7E2E63B9F337D085AF1DDEB8F0C68F2829ADD52
3972WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3972.3314\Cospuri 498 Shinanoazur Lane 5011\19__5011e962785a0236.jpgimage
MD5:A4C129582817AD002D58628E45C5C094
SHA256:70A8B34A6C2506459BABB6E6EF0BCA0FD052D1D6DD276E63F377244611E736A4
3972WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3972.3314\Cospuri 498 Shinanoazur Lane 5011\12__5011e962785a0236.jpgimage
MD5:05BFBAF3CBB0B600E3C3A79E1073A128
SHA256:6400C07BBD75B1817AF625B47C09C2A1D5C5F85B65436DE906DB937431A612EE
3972WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3972.3314\Cospuri 498 Shinanoazur Lane 5011\14__5011e962785a0236.jpgimage
MD5:9E960711AEBCCC2DB1ED70A1A2182416
SHA256:23D670C4DDC26ADE46F153A41C68E945E01BCE986863A30670EF0FEA85A4BB61
3972WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3972.3314\Cospuri 498 Shinanoazur Lane 5011\15__5011e962785a0236.jpgimage
MD5:169B6BD3760A34971A219A90D909656E
SHA256:69413033494607F763F790CE9090F16464266A449DF04C68EA323A638EC17F41
3972WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3972.3314\Cospuri 498 Shinanoazur Lane 5011\1__5011e962785a0236.jpgimage
MD5:4958CC520CD4F0CC4D68FE94EE19E6E8
SHA256:4F9601765BE0B001B906535EDCADC88B739C2AB2456FFFE0F075028FF0791E34
3972WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3972.3314\Cospuri 498 Shinanoazur Lane 5011\16__5011e962785a0236.jpgimage
MD5:92ECA9828ECFB32285CEB6C7805CD5FD
SHA256:4E8705150A3298F5B2830B03D830CD06A820FB37D5A29866115D4CF8D1968284
3972WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3972.3314\Cospuri 498 Shinanoazur Lane 5011\18__5011e962785a0236.jpgimage
MD5:D9F4BB7337BED38123804E9506BB8CA3
SHA256:2DB7FE6038582A06E624BA6ADCA31760B406DD8E265E6487C8F0430DEB26BF7C
3972WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3972.3314\Cospuri 498 Shinanoazur Lane 5011\21__5011e962785a0236.jpgimage
MD5:5359744E3CB58780CD6E25900A58F045
SHA256:8B8CFD439BFEF4037F206293587EFD0FBD5E945DA6ED2A5DD9420246EA86D37F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
5
DNS requests
1
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1816
info.exe
GET
77.81.120.23:80
http://forum.helenheaven.xyz/c.7z
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
unknown
4
System
192.168.100.255:138
unknown
224.0.0.252:5355
unknown
1088
svchost.exe
224.0.0.252:5355
unknown
1816
info.exe
77.81.120.23:80
forum.helenheaven.xyz
KnownSRV Ltd.
NL
unknown

DNS requests

Domain
IP
Reputation
forum.helenheaven.xyz
  • 77.81.120.23
unknown

Threats

PID
Process
Class
Message
Potential Corporate Privacy Violation
ET POLICY Autoit Windows Automation tool User-Agent in HTTP Request - Possibly Hostile
1 ETPRO signatures available at the full report
No debug info