File name:

AYANTE_USB.zip

Full analysis: https://app.any.run/tasks/0a393db6-d394-497e-ab6a-2c52755aa033
Verdict: Malicious activity
Analysis date: May 16, 2025, 07:28:00
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-exec
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

33A7CAC8246009F744C3E86CAFBDC6E3

SHA1:

FD88FC838ED8929DF3D50F9693A408C500DD5E4B

SHA256:

B427AA14AC18CD9B73E812266F45A622DD739576E42F165FCAC40FAAC3C9E1B5

SSDEEP:

24576:cgmkXAJoHy12cFaLHwOgkq/oxcshROEII+0ub10Bp7m0lcqeSFztxJ:cgtXAJoHy12cFaLQOgkq/oxcshROEIIB

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 5528)
    • Changes appearance of the Explorer extensions

      • Adobe Online.com (PID: 7012)
      • System Volume Information .scr (PID: 6700)
    • Create files in the Startup directory

      • System Volume Information .scr (PID: 6700)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • System Volume Information .scr (PID: 6700)
    • Starts itself from another location

      • System Volume Information .scr (PID: 6700)
      • Adobe Online.com (PID: 7012)
    • Reads security settings of Internet Explorer

      • System Volume Information .scr (PID: 6700)
    • Starts application with an unusual extension

      • System Volume Information .scr (PID: 6700)
      • Adobe Online.com (PID: 7012)
    • Creates file in the systems drive root

      • System Volume Information .scr (PID: 6700)
      • Adobe Online.com (PID: 7012)
  • INFO

    • Manual execution by a user

      • System Volume Information .scr (PID: 6700)
    • Creates files or folders in the user directory

      • System Volume Information .scr (PID: 6700)
    • Checks supported languages

      • System Volume Information .scr (PID: 6700)
      • Adobe Online.com (PID: 7012)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 5528)
    • Reads the computer name

      • System Volume Information .scr (PID: 6700)
      • Adobe Online.com (PID: 7012)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2021:03:23 08:39:00
ZipCRC: 0xc115c87c
ZipCompressedSize: 61
ZipUncompressedSize: 96
ZipFileName: Autorun.inf
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
184
Monitored processes
57
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe sppextcomobj.exe no specs slui.exe no specs system volume information .scr adobe update.com no specs adobe online.com no specs adobe update.com no specs adobe update.com no specs adobe update.com no specs rundll32.exe no specs adobe update.com no specs adobe update.com no specs adobe update.com no specs adobe update.com no specs adobe update.com no specs adobe update.com no specs adobe update.com no specs adobe update.com no specs adobe update.com no specs adobe update.com no specs adobe update.com no specs adobe update.com no specs adobe update.com no specs adobe update.com no specs adobe update.com no specs adobe update.com no specs adobe update.com no specs adobe update.com no specs adobe update.com no specs adobe update.com no specs adobe update.com no specs adobe update.com no specs adobe update.com no specs adobe update.com no specs adobe update.com no specs adobe update.com no specs adobe update.com no specs adobe update.com no specs adobe update.com no specs adobe update.com no specs adobe update.com no specs adobe update.com no specs adobe update.com no specs adobe update.com no specs adobe update.com no specs adobe update.com no specs adobe update.com no specs adobe update.com no specs adobe update.com no specs adobe update.com no specs adobe update.com no specs adobe update.com no specs adobe update.com no specs adobe update.com no specs adobe update.com no specs adobe update.com no specs adobe update.com no specs

Process information

PID
CMD
Path
Indicators
Parent process
456C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
536"C:\USERS\ADMIN\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\Adobe update.com"C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe update.comAdobe Online.com
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\roaming\microsoft\windows\start menu\programs\startup\adobe update.com
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
632"C:\USERS\ADMIN\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\Adobe update.com"C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe update.comAdobe Online.com
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\roaming\microsoft\windows\start menu\programs\startup\adobe update.com
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
668"C:\USERS\ADMIN\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\Adobe update.com"C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe update.comAdobe Online.com
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\roaming\microsoft\windows\start menu\programs\startup\adobe update.com
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
672"C:\USERS\ADMIN\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\Adobe update.com"C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe update.comAdobe Online.com
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\roaming\microsoft\windows\start menu\programs\startup\adobe update.com
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
812"C:\USERS\ADMIN\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\Adobe update.com"C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe update.comAdobe Online.com
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\roaming\microsoft\windows\start menu\programs\startup\adobe update.com
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
856"C:\USERS\ADMIN\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\Adobe update.com"C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe update.comAdobe Online.com
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\roaming\microsoft\windows\start menu\programs\startup\adobe update.com
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
960"C:\USERS\ADMIN\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\Adobe update.com"C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe update.comAdobe Online.com
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\roaming\microsoft\windows\start menu\programs\startup\adobe update.com
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
1040"C:\USERS\ADMIN\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\Adobe update.com"C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe update.comAdobe Online.com
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\roaming\microsoft\windows\start menu\programs\startup\adobe update.com
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
1116"C:\USERS\ADMIN\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\Adobe update.com"C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe update.comAdobe Online.com
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\roaming\microsoft\windows\start menu\programs\startup\adobe update.com
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
Total events
10 861
Read events
10 222
Write events
571
Delete events
68

Modification events

(PID) Process:(5528) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(5528) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(5528) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(5528) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(5528) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(5528) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\AYANTE_USB.zip
(PID) Process:(5528) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(5528) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(5528) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(5528) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
8
Suspicious files
2
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
5528WinRAR.exeC:\Users\admin\Desktop\System Volume Information\WPSettings.datbinary
MD5:A70FEBC377B449883BB8D54524B97C10
SHA256:08951F48E03D0ABFD4D74537A5EF1E43017F3C69079FAE071CC83B99DD917E04
5528WinRAR.exeC:\Users\admin\Desktop\Autorun.inftext
MD5:2AF83684758FC1EBA21D0ECACFDAE001
SHA256:A53BA853F1708C9DB71F9F4A787718FCEF8E9940182BC9C59CB73941FF731B4A
5528WinRAR.exeC:\Users\admin\Desktop\Thumbs.comexecutable
MD5:20F1B63D80ACA45206AEDF66FE20A5AA
SHA256:97BFA55DF8D6D8F94DA54FEB832CE5F7C27E934DACAD6FB31F8FE92C1206B61B
6700System Volume Information .scrC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe update.comexecutable
MD5:20F1B63D80ACA45206AEDF66FE20A5AA
SHA256:97BFA55DF8D6D8F94DA54FEB832CE5F7C27E934DACAD6FB31F8FE92C1206B61B
6700System Volume Information .scrC:\Users\admin\AppData\Local\VirtualStore\Thumbs .dbexecutable
MD5:EB101353EB67B770823C7244BCD58E67
SHA256:0780FBF45A70A8F74BCFF5F6E49686F9B2467D1DE5A81BB8B48D7B84A5E10720
5528WinRAR.exeC:\Users\admin\Desktop\Thumbs .dbexecutable
MD5:EB101353EB67B770823C7244BCD58E67
SHA256:0780FBF45A70A8F74BCFF5F6E49686F9B2467D1DE5A81BB8B48D7B84A5E10720
6700System Volume Information .scrC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Online.comexecutable
MD5:20F1B63D80ACA45206AEDF66FE20A5AA
SHA256:97BFA55DF8D6D8F94DA54FEB832CE5F7C27E934DACAD6FB31F8FE92C1206B61B
6700System Volume Information .scrC:\Users\admin\AppData\Local\VirtualStore\Windows\Thumbs .dbexecutable
MD5:EB101353EB67B770823C7244BCD58E67
SHA256:0780FBF45A70A8F74BCFF5F6E49686F9B2467D1DE5A81BB8B48D7B84A5E10720
7012Adobe Online.comC:\Users\admin\Desktop\Autoexec.battext
MD5:8ABE1CAA24A11AAF22799EB55B508BB6
SHA256:606C23353F5CA4EB665B1D08A407514CDE1ADD63EF68E21675D6672CF1A48F7C
5528WinRAR.exeC:\Users\admin\Desktop\System Volume Information .screxecutable
MD5:20F1B63D80ACA45206AEDF66FE20A5AA
SHA256:97BFA55DF8D6D8F94DA54FEB832CE5F7C27E934DACAD6FB31F8FE92C1206B61B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
16
DNS requests
9
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
23.216.77.10:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6148
SIHClient.exe
GET
200
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6148
SIHClient.exe
GET
200
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
40.127.240.158:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
5496
MoUsoCoreWorker.exe
23.216.77.10:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5496
MoUsoCoreWorker.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
2316
RUXIMICS.exe
40.127.240.158:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
4
System
192.168.100.255:138
whitelisted
2104
svchost.exe
40.127.240.158:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
3216
svchost.exe
172.211.123.249:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6148
SIHClient.exe
20.109.210.53:443
slscr.update.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6148
SIHClient.exe
23.219.150.101:80
www.microsoft.com
AKAMAI-AS
CL
whitelisted

DNS requests

Domain
IP
Reputation
crl.microsoft.com
  • 23.216.77.10
  • 23.216.77.11
  • 23.216.77.18
  • 23.216.77.37
  • 23.216.77.36
  • 23.216.77.29
  • 23.216.77.19
  • 23.216.77.23
whitelisted
www.microsoft.com
  • 23.35.229.160
  • 23.219.150.101
whitelisted
google.com
  • 142.250.185.174
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
slscr.update.microsoft.com
  • 20.109.210.53
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.3.187.198
whitelisted

Threats

No threats detected
No debug info