File name:

loas-assetto-247908032.zip

Full analysis: https://app.any.run/tasks/d3df97ce-b8c0-4374-a28c-0655eafbd8f3
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: November 29, 2020, 07:50:36
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
adware
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

F3406F09CA8E1758F1C6C6F267DB2723

SHA1:

7DBFC75091D2A086A15E7133B74BFC933E0C0BC5

SHA256:

AE1DB6A1B90CC732CABB0C7C2404A6A84EA8917E78D159BC9553C35612BD8F28

SSDEEP:

393216:YJwGIe5uKKg4xEE9YaQ7ywThibRB9z5zcAyMsOXUuf5:YJwhe5uVEE9YewTwbRBPcVSXT

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • loas-assetto-247908032.exe (PID: 3236)
      • wmfdist.exe (PID: 3192)
      • VirtualDVT.exe (PID: 1776)
      • AudioMixer.exe (PID: 2272)
      • GLB2455.tmp (PID: 2968)
    • Drops executable file immediately after starts

      • loas-assetto-247908032.exe (PID: 3236)
      • loas-assetto-247908032.tmp (PID: 1404)
      • GLB2455.tmp (PID: 2968)
      • AudioMixer.exe (PID: 2272)
    • Loads dropped or rewritten executable

      • VirtualDVT.exe (PID: 1776)
      • GLB2455.tmp (PID: 2968)
  • SUSPICIOUS

    • Drops a file with a compile date too recent

      • WinRAR.exe (PID: 2960)
      • loas-assetto-247908032.tmp (PID: 1404)
      • AudioMixer.exe (PID: 2272)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2960)
      • loas-assetto-247908032.exe (PID: 3236)
      • loas-assetto-247908032.tmp (PID: 1404)
      • AudioMixer.exe (PID: 2272)
      • GLB2455.tmp (PID: 2968)
    • Drops a file that was compiled in debug mode

      • loas-assetto-247908032.tmp (PID: 1404)
    • Creates a directory in Program Files

      • loas-assetto-247908032.tmp (PID: 1404)
    • Drops a file with too old compile date

      • WinRAR.exe (PID: 2960)
      • loas-assetto-247908032.exe (PID: 3236)
      • loas-assetto-247908032.tmp (PID: 1404)
      • GLB2455.tmp (PID: 2968)
    • Creates files in the Windows directory

      • loas-assetto-247908032.tmp (PID: 1404)
      • GLB2455.tmp (PID: 2968)
    • Starts application with an unusual extension

      • AudioMixer.exe (PID: 2272)
    • Removes files from Windows directory

      • GLB2455.tmp (PID: 2968)
  • INFO

    • Manual execution by user

      • loas-assetto-247908032.exe (PID: 3236)
      • AudioMixer.exe (PID: 2272)
    • Creates a software uninstall entry

      • loas-assetto-247908032.tmp (PID: 1404)
    • Creates files in the program directory

      • loas-assetto-247908032.tmp (PID: 1404)
    • Loads dropped or rewritten executable

      • loas-assetto-247908032.tmp (PID: 1404)
    • Application was dropped or rewritten from another process

      • loas-assetto-247908032.tmp (PID: 1404)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2020:11:06 15:25:17
ZipCRC: 0xdfc8f222
ZipCompressedSize: 1924405
ZipUncompressedSize: 1941104
ZipFileName: AudioMixer.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
49
Monitored processes
7
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start drop and start drop and start drop and start drop and start winrar.exe loas-assetto-247908032.exe loas-assetto-247908032.tmp wmfdist.exe no specs virtualdvt.exe audiomixer.exe glb2455.tmp

Process information

PID
CMD
Path
Indicators
Parent process
1404"C:\Users\admin\AppData\Local\Temp\is-3UH01.tmp\loas-assetto-247908032.tmp" /SL5="$90158,11040685,50688,C:\Users\admin\Desktop\loas-assetto-247908032.exe" C:\Users\admin\AppData\Local\Temp\is-3UH01.tmp\loas-assetto-247908032.tmp
loas-assetto-247908032.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-3uh01.tmp\loas-assetto-247908032.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
1776"C:\Program Files\VirtualDVT\VirtualDVT.exe" loas-assetto-247908032.exeC:\Program Files\VirtualDVT\VirtualDVT.exe
loas-assetto-247908032.tmp
User:
admin
Company:
Power Software Ltd
Integrity Level:
HIGH
Description:
AnyBurn
Exit code:
3221225477
Version:
6, 1, 0, 1
Modules
Images
c:\program files\virtualdvt\virtualdvt.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\virtualdvt\sqlite3.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winmm.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
2272"C:\Users\admin\Desktop\AudioMixer.exe" C:\Users\admin\Desktop\AudioMixer.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\audiomixer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\apphelp.dll
2960"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\loas-assetto-247908032.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2968C:\Users\admin\AppData\Local\Temp\GLB2455.tmp 4736 C:\Users\admin\Desktop\AUDIOM~1.EXEC:\Users\admin\AppData\Local\Temp\GLB2455.tmp
AudioMixer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\glb2455.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
3192"C:\Program Files\VirtualDVT\wmfdist.exe" /Q:A /R:NC:\Program Files\VirtualDVT\wmfdist.exeloas-assetto-247908032.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Media Component Setup Application
Exit code:
0
Version:
9.00.00.2926
Modules
Images
c:\program files\virtualdvt\wmfdist.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3236"C:\Users\admin\Desktop\loas-assetto-247908032.exe" C:\Users\admin\Desktop\loas-assetto-247908032.exe
explorer.exe
User:
admin
Company:
oysoft
Integrity Level:
HIGH
Description:
Reg monitor control module.
Exit code:
0
Version:
6.1.0.1
Modules
Images
c:\users\admin\desktop\loas-assetto-247908032.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
Total events
676
Read events
635
Write events
41
Delete events
0

Modification events

(PID) Process:(2960) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2960) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2960) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2960) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\loas-assetto-247908032.zip
(PID) Process:(2960) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2960) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2960) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2960) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2960) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
(PID) Process:(2960) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\General
Operation:writeName:LastFolder
Value:
C:\Users\admin\AppData\Local\Temp
Executable files
25
Suspicious files
2
Text files
26
Unknown types
4

Dropped files

PID
Process
Filename
Type
1404loas-assetto-247908032.tmpC:\Program Files\VirtualDVT\is-9OJCS.tmp
MD5:
SHA256:
1404loas-assetto-247908032.tmpC:\Program Files\VirtualDVT\is-QQRFA.tmp
MD5:
SHA256:
1404loas-assetto-247908032.tmpC:\Program Files\VirtualDVT\is-IKHVN.tmp
MD5:
SHA256:
1404loas-assetto-247908032.tmpC:\Program Files\VirtualDVT\is-C9H72.tmp
MD5:
SHA256:
1404loas-assetto-247908032.tmpC:\Program Files\VirtualDVT\is-HLUM2.tmp
MD5:
SHA256:
1404loas-assetto-247908032.tmpC:\Windows\system32\VirtualDVD InstallData\x86\is-5O0K6.tmp
MD5:
SHA256:
1404loas-assetto-247908032.tmpC:\Windows\system32\VirtualDVD InstallData\x64\is-DHBB6.tmp
MD5:
SHA256:
1404loas-assetto-247908032.tmpC:\Windows\system32\VirtualDVD InstallData\is-B3DVD.tmp
MD5:
SHA256:
1404loas-assetto-247908032.tmpC:\Windows\system32\VirtualDVD InstallData\is-I84AO.tmp
MD5:
SHA256:
1404loas-assetto-247908032.tmpC:\Windows\system32\VirtualDVD Windows10 InstallData\x86\is-A1A2M.tmp
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
1
DNS requests
1
Threats
3

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1776
VirtualDVT.exe
POST
172.67.188.36:80
http://opengolad.com/v2/events
US
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
172.67.188.36:80
opengolad.com
US
malicious

DNS requests

Domain
IP
Reputation
opengolad.com
  • 172.67.188.36
  • 104.27.182.150
  • 104.27.183.150
unknown

Threats

PID
Process
Class
Message
1776
VirtualDVT.exe
A Network Trojan was detected
ET MALWARE DownloadAssistant Activity
1776
VirtualDVT.exe
Misc activity
ADWARE [PTsecurity] Possible DownloadAssistant
1776
VirtualDVT.exe
Misc activity
ADWARE [PTsecurity] DownloadAssistant
No debug info