File name:

Cospuri 498 Shinanoazur Lane 5011.zip

Full analysis: https://app.any.run/tasks/74c0e78f-10da-4604-b1e4-7f8aa760e44b
Verdict: Malicious activity
Analysis date: June 16, 2024, 11:51:43
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
autoit
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=store
MD5:

70C34C89B3596268870919213EF0AB7C

SHA1:

FF94DC49E33256CF678D53E87186CA9BEE535F1C

SHA256:

ADD45A723992F05E3F2B3F5A7EF21342FF2BE86BEE5624F61F528C3FA8CE1DF0

SSDEEP:

98304:3DiMaMVTfOYdbJ50GcqlbwaqfWhxgW5uUNZ0y3U96x/vOpcO5K4+OXdghIbvCerq:NK3QCKWl01u904h0iAZWr4BpTjtJR

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 3972)
      • 0.scr (PID: 1120)
    • Create files in the Startup directory

      • 0.scr (PID: 1120)
  • SUSPICIOUS

    • Starts CMD.EXE for commands execution

      • 0.scr (PID: 1120)
    • Executable content was dropped or overwritten

      • 0.scr (PID: 1120)
    • Reads the Internet Settings

      • info.exe (PID: 1816)
    • Reads security settings of Internet Explorer

      • info.exe (PID: 1816)
    • Potential Corporate Privacy Violation

      • info.exe (PID: 1816)
  • INFO

    • Manual execution by a user

      • 0.scr (PID: 1120)
      • rundll32.exe (PID: 1652)
      • info.exe (PID: 1816)
      • wmpnscfg.exe (PID: 2348)
    • Checks supported languages

      • 0.scr (PID: 1120)
      • info.exe (PID: 1816)
      • wmpnscfg.exe (PID: 2348)
    • Reads mouse settings

      • 0.scr (PID: 1120)
      • info.exe (PID: 1816)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3972)
    • Creates files or folders in the user directory

      • 0.scr (PID: 1120)
      • info.exe (PID: 1816)
    • Checks proxy server information

      • info.exe (PID: 1816)
    • Reads the computer name

      • info.exe (PID: 1816)
      • wmpnscfg.exe (PID: 2348)
    • Create files in a temporary directory

      • info.exe (PID: 1816)
    • Reads the machine GUID from the registry

      • info.exe (PID: 1816)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2024:05:18 12:27:54
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: Cospuri 498 Shinanoazur Lane 5011/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
44
Monitored processes
7
Malicious processes
0
Suspicious processes
2

Behavior graph

Click at the process to see the details
start winrar.exe 0.scr cmd.exe no specs PhotoViewer.dll no specs rundll32.exe no specs info.exe wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
864C:\Windows\system32\cmd.exe /c 1.jpgC:\Windows\System32\cmd.exe0.scr
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1120"C:\Users\admin\Desktop\Cospuri 498 Shinanoazur Lane 5011\0.scr" /SC:\Users\admin\Desktop\Cospuri 498 Shinanoazur Lane 5011\0.scr
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\cospuri 498 shinanoazur lane 5011\0.scr
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\version.dll
1652"C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\Desktop\Cospuri 498 Shinanoazur Lane 5011\readmeC:\Windows\System32\rundll32.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
1816"C:\Users\admin\Desktop\Cospuri 498 Shinanoazur Lane 5011\info.exe" C:\Users\admin\Desktop\Cospuri 498 Shinanoazur Lane 5011\info.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\users\admin\desktop\cospuri 498 shinanoazur lane 5011\info.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\version.dll
2040C:\Windows\system32\DllHost.exe /Processid:{76D0CB12-7604-4048-B83C-1005C7DDC503}C:\Windows\System32\dllhost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
COM Surrogate
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\dllhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2348"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
3972"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Cospuri 498 Shinanoazur Lane 5011.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
5 789
Read events
5 722
Write events
61
Delete events
6

Modification events

(PID) Process:(3972) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3972) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3972) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3972) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3972) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3972) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(3972) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Cospuri 498 Shinanoazur Lane 5011.zip
(PID) Process:(3972) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3972) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3972) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
4
Suspicious files
0
Text files
35
Unknown types
0

Dropped files

PID
Process
Filename
Type
3972WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3972.3314\Cospuri 498 Shinanoazur Lane 5011\0.screxecutable
MD5:6CBBF6FD42173A836D36E97B0439E8F9
SHA256:28FD6817E73D063F2AEB8990DDEC202B45457B18A7FA92963399FB388DB51D6A
3972WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3972.3314\Cospuri 498 Shinanoazur Lane 5011\11__5011e962785a0236.jpgimage
MD5:94251BBA4D3F17390F59E46A171B7425
SHA256:06C6A152AED166E13FD11E34F35A4D66C72B8911E01D0E48612B9F22646B750E
3972WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3972.3314\Cospuri 498 Shinanoazur Lane 5011\15__5011e962785a0236.jpgimage
MD5:169B6BD3760A34971A219A90D909656E
SHA256:69413033494607F763F790CE9090F16464266A449DF04C68EA323A638EC17F41
3972WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3972.3314\Cospuri 498 Shinanoazur Lane 5011\1.jpgimage
MD5:B0647992329086F75EB6CCF1921FC021
SHA256:99B5F8DF445CD1E4E30FB2B2EB42D426121F24EA768CEA2664676CF270B45DF0
3972WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3972.3314\Cospuri 498 Shinanoazur Lane 5011\12__5011e962785a0236.jpgimage
MD5:05BFBAF3CBB0B600E3C3A79E1073A128
SHA256:6400C07BBD75B1817AF625B47C09C2A1D5C5F85B65436DE906DB937431A612EE
3972WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3972.3314\Cospuri 498 Shinanoazur Lane 5011\10__5011e962785a0236.jpgimage
MD5:4E0D37A2E239BDC401F039BF50B766B0
SHA256:BDDC5D54B219E533E5936DA0D0116EBEA4EC23E73238BEBA764141EB30854273
3972WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3972.3314\Cospuri 498 Shinanoazur Lane 5011\14__5011e962785a0236.jpgimage
MD5:9E960711AEBCCC2DB1ED70A1A2182416
SHA256:23D670C4DDC26ADE46F153A41C68E945E01BCE986863A30670EF0FEA85A4BB61
3972WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3972.3314\Cospuri 498 Shinanoazur Lane 5011\13__5011e962785a0236.jpgimage
MD5:81063D5EF580734B2C413A91DBC21BB0
SHA256:CBAA3AF7EFCD3B9A69168A4AB7E2E63B9F337D085AF1DDEB8F0C68F2829ADD52
3972WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3972.3314\Cospuri 498 Shinanoazur Lane 5011\21__5011e962785a0236.jpgimage
MD5:5359744E3CB58780CD6E25900A58F045
SHA256:8B8CFD439BFEF4037F206293587EFD0FBD5E945DA6ED2A5DD9420246EA86D37F
3972WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3972.3314\Cospuri 498 Shinanoazur Lane 5011\24__5011e962785a0236.jpgimage
MD5:1380A24B75C6745258159A66D01FE519
SHA256:2B55D85CE253263C11989463B60F0D9D1EB56FCFA68C7AABFD9D4CFECA716A57
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
5
DNS requests
1
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1816
info.exe
GET
77.81.120.23:80
http://forum.helenheaven.xyz/c.7z
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
224.0.0.252:5355
unknown
1088
svchost.exe
224.0.0.252:5355
unknown
1816
info.exe
77.81.120.23:80
forum.helenheaven.xyz
KnownSRV Ltd.
NL
unknown

DNS requests

Domain
IP
Reputation
forum.helenheaven.xyz
  • 77.81.120.23
unknown

Threats

PID
Process
Class
Message
1816
info.exe
Potential Corporate Privacy Violation
ET POLICY Autoit Windows Automation tool User-Agent in HTTP Request - Possibly Hostile
1 ETPRO signatures available at the full report
No debug info