| File name: | Password is 1234321.zip |
| Full analysis: | https://app.any.run/tasks/174da95b-bc12-416c-bf01-38cf6a913e84 |
| Verdict: | Malicious activity |
| Analysis date: | June 06, 2024, 12:55:42 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v5.1 to extract, compression method=AES Encrypted |
| MD5: | 806B2482E03DD0288FB14561AC18B75B |
| SHA1: | E052AED4C9E87E4A8320ED0D1DD63EA51FD36828 |
| SHA256: | B3BA4101E67DF45C5465A3E736A007CFF2A0E07B4D064E157C3CD16622347FC3 |
| SSDEEP: | 98304:RTMeXGDjogLmi6KOR81zlm4T2hNaRh2yIiLgN3eCdEWRZYtIfY/kml7xOg+eY1iP:L10jMAL5918FV2AidjXwGT3 |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 51 |
|---|---|
| ZipBitFlag: | 0x0801 |
| ZipCompression: | Unknown (99) |
| ZipModifyDate: | 2021:10:03 15:34:54 |
| ZipCRC: | 0x00000000 |
| ZipCompressedSize: | 9796351 |
| ZipUncompressedSize: | 9985967 |
| ZipFileName: | Сведения о помfdp.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 316 | "C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\AppData\Local\Temp\RarSFX0\Meow_meow.docx" | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | — | Сведения о помexe.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Word Exit code: 0 Version: 14.0.6024.1000 Modules
| |||||||||||||||
| 580 | "C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\Desktop\aexe | C:\Windows\System32\rundll32.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 972 | "C:\Windows\System32\attrib.exe" +h +s mm.exe | C:\Windows\System32\attrib.exe | — | a.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Attribute Utility Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1116 | "C:\Windows\System32\attrib.exe" +h +s mm.exe | C:\Windows\System32\attrib.exe | — | Сведения о помfdp.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Attribute Utility Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1380 | "C:\Users\admin\Desktop\a.exe" | C:\Users\admin\Desktop\a.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 1660 | "C:\Windows\System32\attrib.exe" +h +s mm.exe | C:\Windows\System32\attrib.exe | — | Сведения о помexe.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Attribute Utility Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1764 | "C:\Users\admin\Desktop\Сведения о помexe.exe" | C:\Users\admin\Desktop\Сведения о помexe.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 2324 | "C:\Windows\System32\attrib.exe" +h +s mm.exe | C:\Windows\System32\attrib.exe | — | a.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Attribute Utility Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2328 | "C:\Windows\system32\cmd.exe" | C:\Windows\System32\cmd.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 3221225786 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2408 | "C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\AppData\Local\Temp\RarSFX0\Meow_meow.docx" | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | — | a.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Word Exit code: 0 Version: 14.0.6024.1000 Modules
| |||||||||||||||
| (PID) Process: | (3964) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3964) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3964) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3964) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (3964) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (3964) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
| (PID) Process: | (3964) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Password is 1234321.zip | |||
| (PID) Process: | (3964) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3964) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3964) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 4036 | WINWORD.EXE | C:\Users\admin\AppData\Local\Temp\CVR65E0.tmp.cvr | — | |
MD5:— | SHA256:— | |||
| 316 | WINWORD.EXE | C:\Users\admin\AppData\Local\Temp\CVR1951.tmp.cvr | — | |
MD5:— | SHA256:— | |||
| 4004 | Сведения о помfdp.exe | C:\Users\admin\AppData\Local\Temp\RarSFX0\Meow_meow.docx | document | |
MD5:2973F78C3CD75A24C8736B78C77E2674 | SHA256:3F41AA9FACF70BD0BB1D1AF8AF383420660EBDDB425025F8D29FDEFB572749F3 | |||
| 4004 | Сведения о помfdp.exe | C:\Users\admin\AppData\Local\Temp\RarSFX0\mm.exe | executable | |
MD5:4C2774D2C1CE1416B5FC598297EA4A31 | SHA256:1DD4A6D221601754CF3E1EEA251E9F134CDAAC4C47FEFA42D5F16E5534103509 | |||
| 2408 | WINWORD.EXE | C:\Users\admin\AppData\Local\Temp\CVR533.tmp.cvr | — | |
MD5:— | SHA256:— | |||
| 3964 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb3964.36800\Сведения о помfdp.exe | executable | |
MD5:91DD0FECFD1349A5C433F52CCC428C65 | SHA256:1836DB6FC52BC016C35734454F0FD00BF1691568A2769B98F4D3F267772E88A3 | |||
| 4036 | WINWORD.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{D87D88D6-829D-4348-AA20-C80A17EF17FC}.tmp | binary | |
MD5:0F4C51A4EFD78D6758C89681C48582FA | SHA256:B7A6713E12B1D6B08A5DC0600C529D07DA2D48DF57914496C42383D1BB7AB9B2 | |||
| 1764 | Сведения о помexe.exe | C:\Users\admin\AppData\Local\Temp\RarSFX0\mm.exe | executable | |
MD5:4C2774D2C1CE1416B5FC598297EA4A31 | SHA256:1DD4A6D221601754CF3E1EEA251E9F134CDAAC4C47FEFA42D5F16E5534103509 | |||
| 4036 | WINWORD.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{36460A40-3B51-486A-B59A-7A7D5CA9C8A1}.tmp | binary | |
MD5:1D98E60E38680D53EF5A0DF1CA766431 | SHA256:29FC6E1CCC93165149081172C0FC64027E9D25FCF3A5EF46FDFE497D8523D66A | |||
| 3964 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb3964.38239\Сведения о помfdp.exe | executable | |
MD5:91DD0FECFD1349A5C433F52CCC428C65 | SHA256:1836DB6FC52BC016C35734454F0FD00BF1691568A2769B98F4D3F267772E88A3 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | unknown |
1088 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |