File name:

Fakin The Funk 3.0.0.139 (1).zip

Full analysis: https://app.any.run/tasks/fbf4bdd5-30f8-455b-b19f-a49d1a842a69
Verdict: Malicious activity
Analysis date: November 18, 2020, 19:42:16
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

5FB39D4EA6568DDEE2A36FED62243932

SHA1:

0ABF1D4A47FFEE9578B028C6DFCD4A75190E0735

SHA256:

B400A2F2465BF3E0CA03E083C6A1B34B85AA8C83531F1462E025ECCE9A026C3D

SSDEEP:

12288:TXolzN1FVEk4EczdUXCp+uC5jIHrt3bNerjr3ST7r7ydyeNY:D2FH4Hc6ijI1BobSHiNY

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Fakin The Funk 3.0.0.139.exe (PID: 2688)
      • Fakin The Funk 3.0.0.139.exe (PID: 1484)
      • sihost.exe (PID: 2508)
    • Loads the Task Scheduler COM API

      • schtasks.exe (PID: 3964)
      • schtasks.exe (PID: 2668)
    • Uses Task Scheduler to run other applications

      • sihost.exe (PID: 2508)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Fakin The Funk 3.0.0.139.exe (PID: 2688)
      • Fakin The Funk 3.0.0.139.exe (PID: 1484)
      • 7za.exe (PID: 332)
      • Fakin The Funk 3.0.0.139.tmp (PID: 2788)
    • Reads the Windows organization settings

      • Fakin The Funk 3.0.0.139.tmp (PID: 2788)
    • Reads Windows owner or organization settings

      • Fakin The Funk 3.0.0.139.tmp (PID: 2788)
    • Creates files in the user directory

      • Fakin The Funk 3.0.0.139.tmp (PID: 2788)
      • sihost.exe (PID: 2508)
    • Executed via COM

      • explorer.exe (PID: 2780)
  • INFO

    • Manual execution by user

      • Fakin The Funk 3.0.0.139.exe (PID: 2688)
    • Application was dropped or rewritten from another process

      • Fakin The Funk 3.0.0.139.tmp (PID: 3372)
      • Fakin The Funk 3.0.0.139.tmp (PID: 2788)
      • 7za.exe (PID: 980)
      • 7za.exe (PID: 332)
      • 7za.exe (PID: 2584)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0001
ZipCompression: Deflated
ZipModifyDate: 2020:11:18 22:41:29
ZipCRC: 0xa474f777
ZipCompressedSize: 685439
ZipUncompressedSize: 759314
ZipFileName: Fakin The Funk 3.0.0.139.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
56
Monitored processes
14
Malicious processes
4
Suspicious processes
1

Behavior graph

Click at the process to see the details
start drop and start drop and start drop and start drop and start drop and start drop and start winrar.exe no specs fakin the funk 3.0.0.139.exe fakin the funk 3.0.0.139.tmp no specs fakin the funk 3.0.0.139.exe fakin the funk 3.0.0.139.tmp 7za.exe no specs 7za.exe 7za.exe no specs sihost.exe no specs schtasks.exe no specs schtasks.exe no specs explorer.exe no specs explorer.exe no specs notepad.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
332"C:\Users\admin\AppData\Local\Temp\is-6PS6S.tmp\7za.exe" x "C:\Users\admin\AppData\Local\Temp\is-6PS6S.tmp\form.res" -p"b1lig@n_vl"C:\Users\admin\AppData\Local\Temp\is-6PS6S.tmp\7za.exe
Fakin The Funk 3.0.0.139.tmp
User:
admin
Company:
Igor Pavlov
Integrity Level:
HIGH
Description:
7-Zip Standalone Console
Exit code:
0
Version:
4.65
Modules
Images
c:\users\admin\appdata\local\temp\is-6ps6s.tmp\7za.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
980"C:\Users\admin\AppData\Local\Temp\is-6PS6S.tmp\7za.exe" x "C:\Users\admin\AppData\Local\Temp\is-6PS6S.tmp\sub.res" -p"b1lig@n_vl"C:\Users\admin\AppData\Local\Temp\is-6PS6S.tmp\7za.exeFakin The Funk 3.0.0.139.tmp
User:
admin
Company:
Igor Pavlov
Integrity Level:
HIGH
Description:
7-Zip Standalone Console
Exit code:
0
Version:
4.65
Modules
Images
c:\users\admin\appdata\local\temp\is-6ps6s.tmp\7za.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
1484"C:\Users\admin\Desktop\Fakin The Funk 3.0.0.139.exe" /SPAWNWND=$20176 /NOTIFYWND=$3017E C:\Users\admin\Desktop\Fakin The Funk 3.0.0.139.exe
Fakin The Funk 3.0.0.139.tmp
User:
admin
Company:
Integrity Level:
HIGH
Description:
Exit code:
0
Version:
23.55
Modules
Images
c:\users\admin\desktop\fakin the funk 3.0.0.139.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1768"explorer.exe" "C:\Users\admin\Desktop\Fakin The Funk 3.0.0.139"C:\Windows\explorer.exeFakin The Funk 3.0.0.139.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2364"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Fakin The Funk 3.0.0.139 (1).zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2508"C:\Users\admin\AppData\Roaming\ToolSysHost\sihost.exe" -cr -tu 6C:\Users\admin\AppData\Roaming\ToolSysHost\sihost.exeFakin The Funk 3.0.0.139.tmp
User:
admin
Integrity Level:
HIGH
Description:
System Info Client
Exit code:
0
Version:
2.0.82.55
Modules
Images
c:\users\admin\appdata\roaming\toolsyshost\sihost.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2584"C:\Users\admin\AppData\Local\Temp\is-6PS6S.tmp\7za.exe" x "C:\Users\admin\AppData\Local\Temp\is-6PS6S.tmp\misc.res" -p"b1lig@n_vl"C:\Users\admin\AppData\Local\Temp\is-6PS6S.tmp\7za.exeFakin The Funk 3.0.0.139.tmp
User:
admin
Company:
Igor Pavlov
Integrity Level:
HIGH
Description:
7-Zip Standalone Console
Exit code:
0
Version:
4.65
Modules
Images
c:\users\admin\appdata\local\temp\is-6ps6s.tmp\7za.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
2668"C:\Windows\system32\schtasks.exe" /Create /f /XML "C:\Users\admin\AppData\Roaming\ToolSysHost\data.xml" /tn "Microsoft\Windows\Windows Error Reporting\SysInfo"C:\Windows\system32\schtasks.exesihost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Manages scheduled tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
2688"C:\Users\admin\Desktop\Fakin The Funk 3.0.0.139.exe" C:\Users\admin\Desktop\Fakin The Funk 3.0.0.139.exe
explorer.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Exit code:
0
Version:
23.55
Modules
Images
c:\users\admin\desktop\fakin the funk 3.0.0.139.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2780C:\Windows\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -EmbeddingC:\Windows\explorer.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
1 321
Read events
1 204
Write events
117
Delete events
0

Modification events

(PID) Process:(2364) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2364) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2364) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2364) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Fakin The Funk 3.0.0.139 (1).zip
(PID) Process:(2364) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2364) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2364) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2364) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2364) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
(PID) Process:(2788) Fakin The Funk 3.0.0.139.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
E40A0000B80CD005E3BDD601
Executable files
5
Suspicious files
3
Text files
5
Unknown types
0

Dropped files

PID
Process
Filename
Type
2364WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb2364.39574\Fakin The Funk 3.0.0.139.exe
MD5:
SHA256:
2788Fakin The Funk 3.0.0.139.tmpC:\Users\admin\AppData\Local\Temp\{27E261B6-96C4-4FE7-B230-0B42BC00AF06}\is-LS0SR.tmp
MD5:
SHA256:
2788Fakin The Funk 3.0.0.139.tmpC:\Users\admin\AppData\Local\Temp\{27E261B6-96C4-4FE7-B230-0B42BC00AF06}\license.txt
MD5:
SHA256:
2508sihost.exeC:\Users\admin\AppData\Roaming\ToolSysHost\data.xml
MD5:
SHA256:
2788Fakin The Funk 3.0.0.139.tmpC:\Users\admin\Desktop\Fakin The Funk 3.0.0.139\license.txttext
MD5:
SHA256:
2788Fakin The Funk 3.0.0.139.tmpC:\Users\admin\AppData\Local\Temp\is-6PS6S.tmp\7za.exeexecutable
MD5:E92604E043F51C604B6D1AC3BCD3A202
SHA256:FA252E501332B7486A972E7E471CF6915DAA681AF35C6AA102213921093EB2A3
2788Fakin The Funk 3.0.0.139.tmpC:\Users\admin\AppData\Local\Temp\is-6PS6S.tmp\sub.rescompressed
MD5:AE50AD46B7EF3517F5DF5EDF2B96443E
SHA256:F4A2B3FA7460606D58AD078D320AFCEAD400285304DC49E8F2BA3FA9800854DC
2788Fakin The Funk 3.0.0.139.tmpC:\Users\admin\AppData\Local\Temp\is-6PS6S.tmp\misc.rescompressed
MD5:4276E4182A04700263891F395FD74B65
SHA256:436DB65389AFD9020211E47F28A090AB12A5D0E2AF5961BB6C491074F73E30D6
2788Fakin The Funk 3.0.0.139.tmpC:\Users\admin\AppData\Local\Temp\is-6PS6S.tmp\form.rescompressed
MD5:7800761CC3B383E401C7C30DA69AA3B2
SHA256:CF7C7338FFA5E647704E91650A106B7B2A364A43A87E2D63029843B5D93E372F
2788Fakin The Funk 3.0.0.139.tmpC:\Users\admin\AppData\Roaming\ToolSysHost\sihost.exeexecutable
MD5:3FA993C3B6585A26F4F46305D5A5A94F
SHA256:CE4067D7C902FBE7FFCAB46922836957182904F8905E02FAAB563312DC00E49B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
2
DNS requests
3
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2788
Fakin The Funk 3.0.0.139.tmp
POST
200
172.217.22.110:80
http://www.google-analytics.com/collect
US
image
35 b
whitelisted
2788
Fakin The Funk 3.0.0.139.tmp
POST
200
172.217.22.110:80
http://www.google-analytics.com/collect
US
image
35 b
whitelisted
2788
Fakin The Funk 3.0.0.139.tmp
GET
200
104.28.30.94:80
http://video-box.org/getchannel
US
binary
1 b
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2788
Fakin The Funk 3.0.0.139.tmp
172.217.22.110:80
www.google-analytics.com
Google Inc.
US
whitelisted
2788
Fakin The Funk 3.0.0.139.tmp
104.28.30.94:80
video-box.org
Cloudflare Inc
US
shared

DNS requests

Domain
IP
Reputation
www.google-analytics.com
  • 172.217.22.110
whitelisted
video-box.org
  • 104.28.30.94
  • 104.28.31.94
  • 172.67.133.234
malicious

Threats

No threats detected
No debug info