File name:

MW.zip

Full analysis: https://app.any.run/tasks/dbe2bae7-b026-414f-bc15-39e8d69cdeff
Verdict: Malicious activity
Analysis date: March 14, 2019, 20:57:44
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
autoit
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

B62D33BE0CEB7E65267333941A19710F

SHA1:

292CC051FE0205CD00738E4D4EAA06AD4B33E89C

SHA256:

B160A40F9B2EE0D821D1F3423EAE452A096EBE6D755CDBDB6E388CE323DAFB72

SSDEEP:

12288:7yQo3SB2r/hlonASybLEsus8G+KetJlhiFD1cG:lkSYrWKIs8TuD17

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • GoogleChrome.exe (PID: 3092)
      • GoogleChrome.exe (PID: 2348)
      • GoogleChrome.exe (PID: 2120)
    • Changes the autorun value in the registry

      • GoogleChrome.exe (PID: 2348)
      • GoogleChrome.exe (PID: 2120)
  • SUSPICIOUS

    • Writes to a desktop.ini file (may be used to cloak folders)

      • GoogleChrome.exe (PID: 3092)
      • GoogleChrome.exe (PID: 2348)
      • GoogleChrome.exe (PID: 2120)
    • Executable content was dropped or overwritten

      • GoogleChrome.exe (PID: 3092)
      • GoogleChrome.exe (PID: 2348)
      • GoogleChrome.exe (PID: 2120)
    • Starts itself from another location

      • GoogleChrome.exe (PID: 3092)
    • Uses NETSH.EXE for network configuration

      • GoogleChrome.exe (PID: 2348)
      • GoogleChrome.exe (PID: 2120)
    • Drop AutoIt3 executable file

      • GoogleChrome.exe (PID: 3092)
      • GoogleChrome.exe (PID: 2120)
      • GoogleChrome.exe (PID: 2348)
    • Starts CMD.EXE for commands execution

      • GoogleChrome.exe (PID: 3092)
    • Connects to unusual port

      • GoogleChrome.exe (PID: 2348)
    • Creates files in the program directory

      • GoogleChrome.exe (PID: 2348)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2015:03:05 18:05:28
ZipCRC: 0x998989ad
ZipCompressedSize: 55483
ZipUncompressedSize: 55463
ZipFileName: GoogleChrome.a3x
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
40
Monitored processes
7
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
start drop and start winrar.exe no specs googlechrome.exe googlechrome.exe cmd.exe no specs googlechrome.exe netsh.exe no specs netsh.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2120C:\GoogleChrome/GoogleChrome.exe C:\GoogleChrome/GoogleChrome.a3xC:\GoogleChrome\GoogleChrome.exe
cmd.exe
User:
admin
Company:
AutoIt Team
Integrity Level:
MEDIUM
Description:
AutoIt v3 Script
Exit code:
0
Version:
3, 3, 8, 1
Modules
Images
c:\googlechrome\googlechrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\version.dll
2332"C:\Windows\System32\netsh.exe" firewall add allowedprogram "C:\GoogleChrome\GoogleChrome.exe" "GoogleChrome.exe" ENABLEC:\Windows\System32\netsh.exeGoogleChrome.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Network Command Shell
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\netsh.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\credui.dll
c:\windows\system32\user32.dll
2348"C:\GoogleChrome\GoogleChrome.exe" /AutoIt3ExecuteScript C:\GoogleChrome\GoogleChrome.a3xC:\GoogleChrome\GoogleChrome.exe
GoogleChrome.exe
User:
admin
Company:
AutoIt Team
Integrity Level:
MEDIUM
Description:
AutoIt v3 Script
Exit code:
0
Version:
3, 3, 8, 1
Modules
Images
c:\googlechrome\googlechrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\version.dll
2688"C:\Windows\System32\cmd.exe" /c start C:\GoogleChrome/GoogleChrome.exe C:\GoogleChrome/GoogleChrome.a3xC:\Windows\System32\cmd.exeGoogleChrome.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2984"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\MW.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3092"C:\Users\admin\Desktop\GoogleChrome.exe" C:\Users\admin\Desktop\GoogleChrome.exe
explorer.exe
User:
admin
Company:
AutoIt Team
Integrity Level:
MEDIUM
Description:
AutoIt v3 Script
Exit code:
0
Version:
3, 3, 8, 1
Modules
Images
c:\users\admin\desktop\googlechrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\version.dll
3180"C:\Windows\System32\netsh.exe" firewall add allowedprogram "C:\GoogleChrome\GoogleChrome.exe" "GoogleChrome.exe" ENABLEC:\Windows\System32\netsh.exeGoogleChrome.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Network Command Shell
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\netsh.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\credui.dll
c:\windows\system32\user32.dll
Total events
1 603
Read events
1 365
Write events
237
Delete events
1

Modification events

(PID) Process:(2984) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2984) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2984) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2984) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\MW.zip
(PID) Process:(2984) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2984) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2984) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2984) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3092) GoogleChrome.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
Operation:writeName:NodeSlots
Value:
02020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202
(PID) Process:(3092) GoogleChrome.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
Operation:writeName:MRUListEx
Value:
0000000001000000020000000700000006000000030000000500000004000000FFFFFFFF
Executable files
3
Suspicious files
0
Text files
30
Unknown types
21

Dropped files

PID
Process
Filename
Type
2984WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2984.9163\GoogleChrome.a3x
MD5:
SHA256:
2984WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2984.9163\GoogleChrome.exe
MD5:
SHA256:
3092GoogleChrome.exeC:\GoogleChrome\collectionplaying.rtftext
MD5:
SHA256:
3092GoogleChrome.exeC:\GoogleChrome\iibelieve.rtftext
MD5:
SHA256:
2348GoogleChrome.exeC:\GoogleChrome\GoogleUpdate.lnklnk
MD5:
SHA256:
3092GoogleChrome.exeC:\GoogleChrome\menbuilt.rtftext
MD5:
SHA256:
2348GoogleChrome.exeC:\MozillaFirefox\clearasia.pngimage
MD5:
SHA256:
3092GoogleChrome.exeC:\GoogleChrome\printercarolina.jpgimage
MD5:
SHA256:
3092GoogleChrome.exeC:\GoogleChrome\palmmodule.jpgimage
MD5:
SHA256:
2348GoogleChrome.exeC:\GoogleChrome\WindowsUpdate.lnklnk
MD5:AB787A9AA4630CCE04A25689D4E05641
SHA256:47CE7C41BE5911A6B64E80FE334091C6E6B9DF37926C88795A0D3A19C6AF37F9
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
9
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2348
GoogleChrome.exe
195.22.4.21:1212
dmad.info
Claranet Ltd
PT
suspicious

DNS requests

Domain
IP
Reputation
dmad.info
  • 195.22.4.21
malicious

Threats

No threats detected
No debug info