| File name: | fgdfgd.zip |
| Full analysis: | https://app.any.run/tasks/e9206164-354b-4daa-bc93-6a18a87d8e63 |
| Verdict: | Malicious activity |
| Analysis date: | November 23, 2023, 08:19:16 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v1.0 to extract |
| MD5: | D6F1439E833A3D442DEDE6B442E53718 |
| SHA1: | D269AB71B70242FD6904EBC5960AC1E5244B56C2 |
| SHA256: | B7705940D5D3E933CA7367ED37CAB08277CBA05C86E23E451F2FA33EA9DBEB06 |
| SSDEEP: | 49152:4EFZU9OJOXinbIaMV4lwksVZPr1hjw3d86dx4JDxhzUhegqXBJ5LNOChhgkwTZUd:EKvnvC1L15wN86ahzUhe7r0CbgkwTJR0 |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 10 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | None |
| ZipModifyDate: | 2023:11:23 12:16:22 |
| ZipCRC: | 0x00000000 |
| ZipCompressedSize: | - |
| ZipUncompressedSize: | - |
| ZipFileName: | fdf - ?????/ |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2932 | "C:\Windows\system32\winver.exe" | C:\Windows\System32\winver.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Version Reporter Applet Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3124 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3428 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\fgdfgd.zip" | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 3920 | "C:\Users\admin\Desktop\msoobe.exe" | C:\Users\admin\Desktop\msoobe.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: MSOOBE EXE Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| (PID) Process: | (3428) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\17A\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3428) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (3428) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (3428) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (3428) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3428) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3428) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3428) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (3124) wmpnscfg.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{B3A380BD-512A-4A65-86AF-0D3223AB95A6}\{728BE687-1F81-4BF3-BBAA-739BDF1A7BD8} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (3124) wmpnscfg.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{B3A380BD-512A-4A65-86AF-0D3223AB95A6} |
| Operation: | delete key | Name: | (default) |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3428 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3428.10084\fdf - копия\ru-RU\OOBE_HELP_Opt_in_Details.rtf | text | |
MD5:EA4EA96C8283A88B8A33879135D06A9B | SHA256:015755D585CCE45A7347B4FC2C815A7AAA051DCF9046064AFE9AB9C0F3CDBEC6 | |||
| 3428 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3428.10084\fdf - копия\msoobeui.dll | executable | |
MD5:12781DEF12CF5A6C82F29F1B01732D62 | SHA256:28C41968FF0308C13C75C672000A8FDE7F9154D6114D76EC4258910446AB2945 | |||
| 3428 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3428.10084\fdf - копия\ru-RU\OOBE_HELP_Change_Computer_Name.rtf | text | |
MD5:F7B4FC13BF7D0DC14AAAC46DEC8CD1C4 | SHA256:77A77F48A3396478A5BE41638D4D0740E0830D68B1B9AF974BD4E55C4D4F6B90 | |||
| 3428 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3428.10084\fdf - копия\ru-RU\OOBE_HELP_What_is_HomeGroup.rtf | text | |
MD5:52E265A58BF391F03018C9EA279B5332 | SHA256:1F41C79F63C2CA57935D94E8EEACB6AB7E71DD435A12C24105311088EBFFA139 | |||
| 3428 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3428.10084\fdf - копия\ru-RU\msoobeui.dll.mui | executable | |
MD5:C6F28E71987B294488345FD83E048E71 | SHA256:C91FBE7A2FBE0C77246D8E605D7C65BAC15CA883A41DCF48990BA98ECBE74AD7 | |||
| 3428 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3428.10084\fdf - копия\ru-RU\audit.exe.mui | executable | |
MD5:63A3927EAD62B4286665B236125F0E5E | SHA256:D244C0FB1AE9995FABE865F83C3AE18688A92F8359CC0EA9E0051F556227B320 | |||
| 3428 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3428.10084\fdf - копия\ru-RU\pnpibs.dll.mui | executable | |
MD5:AC4302C5A47A3D78E1F897E44145AE95 | SHA256:3E33FED2C59FFA6395A39049B4A1BCE67017957B98B9885CA3AD5662176089E3 | |||
| 3428 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3428.10084\fdf - копия\ru-RU\setup.exe.mui | executable | |
MD5:B16EF6533A121EA904AA00ECDDA06D5D | SHA256:278C045E46D5EE15FD19AAEE8D4EDC2C9FB5254C204DB9965B7920D279A5A0CF | |||
| 3428 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3428.10084\fdf - копия\ru-RU\W32UIRes.dll.mui | executable | |
MD5:6D777804B5E86163A0F1C9C1CBBAE220 | SHA256:1FB35B6998DBB02FC42CDD5EEC9AF0AED6B05D904EC0C97DD44D8DDD2D2183EB | |||
| 3428 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3428.10084\fdf - копия\background.bmp | image | |
MD5:4862993593987F57980FD1E70FB5FAE4 | SHA256:F990418BF60C3DF79D415E41D5F034050ECDC7F480DED4289E6443F8406B9629 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
868 | svchost.exe | 95.101.148.135:80 | armmf.adobe.com | Akamai International B.V. | NL | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
Domain | IP | Reputation |
|---|---|---|
armmf.adobe.com |
| whitelisted |