File name:

x-force autodesk 2025.7z

Full analysis: https://app.any.run/tasks/a910de26-7d6c-4912-a894-830623d33a74
Verdict: Malicious activity
Analysis date: April 28, 2025, 11:24:26
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
autoit
Indicators:
MIME: application/x-7z-compressed
File info: 7-zip archive data, version 0.4
MD5:

EC9A572E0F0546C3024D52CCD31CE5D7

SHA1:

1678CFFAB1AC1115EB20A236460ACD9A2CFAD1D5

SHA256:

AF1614463417769C730F22200045B98A56413D923DDD92F18D0CB583758A412C

SSDEEP:

98304:Pyu3043huZ0Ix/ktGfvF09/3KpwpIv3kFrqF3sv/mO7F0PmUcE+GdeXIdBrn4m6f:D/077IItYWJImipk/gMgMQSHDia3tVQ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads the Internet Settings

      • x-force autodesk 2025.exe (PID: 576)
      • x-force autodesk 2025.exe (PID: 3880)
    • Reads security settings of Internet Explorer

      • x-force autodesk 2025.exe (PID: 576)
      • x-force autodesk 2025.exe (PID: 3880)
    • Executing commands from a ".bat" file

      • x-force autodesk 2025.exe (PID: 576)
      • x-force autodesk 2025.exe (PID: 3880)
    • Starts CMD.EXE for commands execution

      • x-force autodesk 2025.exe (PID: 576)
      • cmd.exe (PID: 312)
      • x-force autodesk 2025.exe (PID: 3880)
      • cmd.exe (PID: 2740)
    • Get information on the list of running processes

      • cmd.exe (PID: 312)
      • cmd.exe (PID: 2740)
    • Application launched itself

      • cmd.exe (PID: 312)
      • cmd.exe (PID: 2740)
    • The executable file from the user directory is run by the CMD process

      • Dispatched.com (PID: 2604)
      • Dispatched.com (PID: 2652)
    • Using 'findstr.exe' to search for text patterns in files and output

      • cmd.exe (PID: 2740)
      • cmd.exe (PID: 312)
    • There is functionality for taking screenshot (YARA)

      • x-force autodesk 2025.exe (PID: 576)
    • Starts the AutoIt3 executable file

      • cmd.exe (PID: 2740)
      • cmd.exe (PID: 312)
    • Starts application with an unusual extension

      • cmd.exe (PID: 2740)
      • cmd.exe (PID: 312)
  • INFO

    • Create files in a temporary directory

      • x-force autodesk 2025.exe (PID: 576)
      • extrac32.exe (PID: 2916)
      • x-force autodesk 2025.exe (PID: 3880)
    • Checks supported languages

      • x-force autodesk 2025.exe (PID: 576)
      • x-force autodesk 2025.exe (PID: 3880)
      • Dispatched.com (PID: 2604)
    • Manual execution by a user

      • x-force autodesk 2025.exe (PID: 576)
      • x-force autodesk 2025.exe (PID: 3880)
      • WinRAR.exe (PID: 3300)
    • Reads the computer name

      • x-force autodesk 2025.exe (PID: 576)
      • x-force autodesk 2025.exe (PID: 3880)
      • Dispatched.com (PID: 2604)
    • Creates a new folder

      • cmd.exe (PID: 3104)
      • cmd.exe (PID: 2464)
    • Reads mouse settings

      • Dispatched.com (PID: 2604)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.7z | 7-Zip compressed archive (v0.4) (57.1)
.7z | 7-Zip compressed archive (gen) (42.8)

EXIF

ZIP

FileVersion: 7z v0.04
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
64
Monitored processes
27
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe no specs x-force autodesk 2025.exe no specs cmd.exe no specs tasklist.exe no specs findstr.exe no specs findstr.exe no specs tasklist.exe no specs cmd.exe no specs extrac32.exe no specs x-force autodesk 2025.exe no specs findstr.exe no specs cmd.exe no specs cmd.exe no specs dispatched.com no specs cmd.exe no specs choice.exe no specs tasklist.exe no specs findstr.exe no specs tasklist.exe no specs findstr.exe no specs cmd.exe no specs extrac32.exe no specs cmd.exe no specs cmd.exe no specs dispatched.com no specs choice.exe no specs winrar.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
148extrac32 /Y /E Benjamin.midC:\Windows\System32\extrac32.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft® CAB File Extract Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\extrac32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
312"C:\Windows\System32\cmd.exe" /c copy Alabama.mid Alabama.mid.bat & Alabama.mid.batC:\Windows\System32\cmd.exex-force autodesk 2025.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
576"C:\Users\admin\Desktop\x-force autodesk 2025.exe" C:\Users\admin\Desktop\x-force autodesk 2025.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\users\admin\desktop\x-force autodesk 2025.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
676findstr "SophosHealth bdservicehost AvastUI AVGUI nsWscSvc ekrn" C:\Windows\System32\findstr.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Find String (QGREP) Utility
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\findstr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
984tasklist C:\Windows\System32\tasklist.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Lists the current running tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\tasklist.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1548tasklist C:\Windows\System32\tasklist.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Lists the current running tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\tasklist.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1800findstr /I "opssvc wrsa" C:\Windows\System32\findstr.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Find String (QGREP) Utility
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\findstr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
1996findstr /V "Configuration" Webpage C:\Windows\System32\findstr.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Find String (QGREP) Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\findstr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
2100findstr /I "opssvc wrsa" C:\Windows\System32\findstr.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Find String (QGREP) Utility
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\findstr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
2384cmd /c copy /b 219955\Dispatched.com + Buyer + Instrumentation + Retailer + Exit + Vehicles + Physically + Projected + Fountain + Vaccine 219955\Dispatched.comC:\Windows\System32\cmd.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
4 609
Read events
4 579
Write events
30
Delete events
0

Modification events

(PID) Process:(2624) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2624) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2624) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2624) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
1
(PID) Process:(2624) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2624) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(2624) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(2624) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\x-force autodesk 2025.7z
(PID) Process:(2624) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2624) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
Executable files
0
Suspicious files
20
Text files
3
Unknown types
0

Dropped files

PID
Process
Filename
Type
2624WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb2624.30065\x-force autodesk 2025.exe
MD5:
SHA256:
576x-force autodesk 2025.exeC:\Users\admin\AppData\Local\Temp\Bundle.midbinary
MD5:CB69A485D8461B5820BE6200E10702E9
SHA256:153AB5578DD23BF88BF52CDFBB1089E10D112435C1435A7471A5F0C2409AA507
2916extrac32.exeC:\Users\admin\AppData\Local\Temp\Exitbinary
MD5:3D1FE3DDD8B93D95888B922EBA87B3D1
SHA256:1E1E78DF54BA727414DDD1D053A91800E9F697DB9BCCD10AA859B86950C470E0
576x-force autodesk 2025.exeC:\Users\admin\AppData\Local\Temp\Sublime.midbinary
MD5:44B363CB90EFB6441B884AC9B44973FD
SHA256:1E3091EF0F89999E02C484331662F41CC7E971B1326C6524349A3A39607EE730
576x-force autodesk 2025.exeC:\Users\admin\AppData\Local\Temp\Provisions.midbinary
MD5:B948F050C4B8B61A2ADA8FB36BD2EE7A
SHA256:B2BBCFEC2A025981F68939C4182D61E7DFEA80B606C28C9A0F8C211BAA823AF2
576x-force autodesk 2025.exeC:\Users\admin\AppData\Local\Temp\Vendors.midbinary
MD5:D28DC7B17E647CB706258648D7EDD523
SHA256:06EAE641F88DFE312FD1B5765E27C3406E8E0AEDC08EAAE0DEEA26961D6BAC89
576x-force autodesk 2025.exeC:\Users\admin\AppData\Local\Temp\Benjamin.midcompressed
MD5:94DE3DF17BDA146B666ABC31E9762535
SHA256:349CF34664651609B2BBE6DCB2DC72C96ED75ECD406CBC53128BC79ACDC7E49D
312cmd.exeC:\Users\admin\AppData\Local\Temp\Alabama.mid.battext
MD5:BCAD756C329332DFFA34013E2A01A5E2
SHA256:4DF80D34577FED23339298E9333D6339E6AEACB9B9AD939EFB115E527DB4635C
2916extrac32.exeC:\Users\admin\AppData\Local\Temp\Fountainbinary
MD5:881E6ECCE9781394F12FD48D921BE963
SHA256:2CED9A4DCB1BB023C970D30520A69AB20CB614A994EFA7CA9E70662A52B9FBAD
576x-force autodesk 2025.exeC:\Users\admin\AppData\Local\Temp\Alabama.midtext
MD5:BCAD756C329332DFFA34013E2A01A5E2
SHA256:4DF80D34577FED23339298E9333D6339E6AEACB9B9AD939EFB115E527DB4635C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
6
DNS requests
2
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 172.217.16.142
whitelisted
lcpYrDuoqTjy.lcpYrDuoqTjy
unknown

Threats

No threats detected
No debug info