| File name: | suspicious-file-3 |
| Full analysis: | https://app.any.run/tasks/38209086-73f8-4c5a-82dd-663fe7c5f5b8 |
| Verdict: | No threats detected |
| Analysis date: | August 10, 2019, 16:26:14 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | 03E6EECC83239752FAC874BC880588FA |
| SHA1: | 28B9468949D5F3E4BE3207FD568D05E654493090 |
| SHA256: | B4CB839573156364FC2A10A2D0A57CCED697F076CE9FE4AA3604ADA0B7A77523 |
| SSDEEP: | 192:p5SV6+dLfCveoeFXg9OyAtPaXz8QGsaOY4+SQzIf6F50pxmSzxxi6yJPgH+tOMAa:pYLavfwyANaj9MOY4+3CDmSzxxiv8k |
| .xap | | | Silverlight Application Package (77.7) |
|---|---|---|
| .zip | | | ZIP compressed archive (22.2) |
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | 0x0800 |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2015:02:14 11:38:27 |
| ZipCRC: | 0x3e75bdf0 |
| ZipCompressedSize: | 15173 |
| ZipUncompressedSize: | 22016 |
| ZipFileName: | advfgrwqrefq32.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2392 | "C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\AppData\Local\Temp\suspicious-file-3.xap | C:\Windows\system32\rundll32.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (2392) rundll32.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache |
| Operation: | write | Name: | C:\Windows\system32\NOTEPAD.EXE |
Value: Notepad | |||
| (PID) Process: | (2392) rundll32.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache |
| Operation: | write | Name: | C:\PROGRA~1\MICROS~1\Office14\OIS.EXE |
Value: Microsoft Office 2010 | |||
| (PID) Process: | (2392) rundll32.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache |
| Operation: | write | Name: | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Value: Microsoft Word | |||