File name:

M109_00501_2024-02-14_05_17_50.165.zip

Full analysis: https://app.any.run/tasks/420a0600-d03b-46c9-9045-cd3801b1917a
Verdict: No threats detected
Analysis date: February 14, 2024, 05:21:12
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v4.5 to extract, compression method=deflate
MD5:

03BF884F87680BE2B16F2EFB1CDC4917

SHA1:

29D08327C66D36CD47B710C3E94E11CCFDE19B74

SHA256:

BA9850036181A10FF5EFC9D0DA4A69304E42CE17D1AC67A799A4097F2D554276

SSDEEP:

49152:LfMsM+iBO+1Ks7lt6aDlFxTVHYnuAGk/GZXowwjBsojIPqbD6q1eeWezwpoN5HcZ:Lf6BD1Ks7v6c5T+XV/MYw8Bsfm6QeFeU

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 3720)
      • WinRAR.exe (PID: 3656)
    • Application launched itself

      • WinRAR.exe (PID: 3656)
    • Starts CMD.EXE for commands execution

      • Etabs_2016_v16_kg.exe (PID: 3660)
      • Etabs_2016_v16_kg.exe (PID: 3068)
      • Etabs_2016_v16_kg.exe (PID: 2900)
  • INFO

    • Checks supported languages

      • Etabs_2016_v16_kg.exe (PID: 3660)
      • wmpnscfg.exe (PID: 2636)
      • Etabs_2016_v16_kg.exe (PID: 2900)
      • Etabs_2016_v16_kg.exe (PID: 3068)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3720)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 3720)
    • Reads the computer name

      • Etabs_2016_v16_kg.exe (PID: 3660)
      • wmpnscfg.exe (PID: 2636)
      • Etabs_2016_v16_kg.exe (PID: 3068)
      • Etabs_2016_v16_kg.exe (PID: 2900)
    • Reads the machine GUID from the registry

      • Etabs_2016_v16_kg.exe (PID: 3660)
      • Etabs_2016_v16_kg.exe (PID: 3068)
      • Etabs_2016_v16_kg.exe (PID: 2900)
    • Create files in a temporary directory

      • Etabs_2016_v16_kg.exe (PID: 3660)
      • Etabs_2016_v16_kg.exe (PID: 3068)
      • Etabs_2016_v16_kg.exe (PID: 2900)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 2636)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0801
ZipCompression: Deflated
ZipModifyDate: 1980:00:00 00:00:00
ZipCRC: 0x76089976
ZipCompressedSize: 1670862
ZipUncompressedSize: 1670776
ZipFileName: Device/HarddiskVolume4/ETABS VEDIOS/CSI ETABS Version 16.0.0 Build 1488/Patch.zip
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
48
Monitored processes
9
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs winrar.exe etabs_2016_v16_kg.exe no specs cmd.exe no specs wmpnscfg.exe no specs etabs_2016_v16_kg.exe no specs cmd.exe no specs etabs_2016_v16_kg.exe no specs cmd.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3656"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\M109_00501_2024-02-14_05_17_50.165.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3720"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\Rar$DIb3656.7483\Patch.zipC:\Program Files\WinRAR\WinRAR.exe
WinRAR.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3660"C:\Users\admin\AppData\Local\Temp\Rar$EXa3720.9283\Patch\Etabs_2016_v16_kg.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3720.9283\Patch\Etabs_2016_v16_kg.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3720.9283\patch\etabs_2016_v16_kg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
2444C:\Windows\system32\cmd.exe /c pauseC:\Windows\System32\cmd.exeEtabs_2016_v16_kg.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2636"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
3068"C:\Users\admin\AppData\Local\Temp\Rar$EXa3720.12743\Patch\Etabs_2016_v16_kg.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3720.12743\Patch\Etabs_2016_v16_kg.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3720.12743\patch\etabs_2016_v16_kg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
2432C:\Windows\system32\cmd.exe /c pauseC:\Windows\System32\cmd.exeEtabs_2016_v16_kg.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2900"C:\Users\admin\AppData\Local\Temp\Rar$EXa3720.16113\Patch\Etabs_2016_v16_kg.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3720.16113\Patch\Etabs_2016_v16_kg.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3720.16113\patch\etabs_2016_v16_kg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
1340C:\Windows\system32\cmd.exe /c pauseC:\Windows\System32\cmd.exeEtabs_2016_v16_kg.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
8 893
Read events
8 844
Write events
49
Delete events
0

Modification events

(PID) Process:(3656) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3656) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3656) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3656) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3656) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3656) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(3656) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\M109_00501_2024-02-14_05_17_50.165.zip
(PID) Process:(3656) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3656) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3656) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
3
Suspicious files
5
Text files
6
Unknown types
1

Dropped files

PID
Process
Filename
Type
3660Etabs_2016_v16_kg.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3720.9283\Patch\lservrcbinary
MD5:8FD6B7A749B241BF080784A51B2AD489
SHA256:5513905DF8FC841389ACBF05F809D9DAB37BB76A27B5AF81E37D77911D0C11A9
3720WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DIb3656.7483\__rzi_3720.12366compressed
MD5:791950869591AED5C5E270B8BF8667C8
SHA256:DCFA3F84E285A5B4D609A3A2FE5947303F613D9BA7E95EAEF85B6E4AC5D83667
3720WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DIb3656.7483\Patch.zipcompressed
MD5:791950869591AED5C5E270B8BF8667C8
SHA256:DCFA3F84E285A5B4D609A3A2FE5947303F613D9BA7E95EAEF85B6E4AC5D83667
3720WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3720.12743\Patch\Etabs_2016_v16_kg.exeexecutable
MD5:D72F173835B65D8246669462A51E3BFE
SHA256:C240855C63A61F0BA15BCB26B3C194EC63AACE4AF023D0D6E47EA09BF9C8373E
3720WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3720.12743\Patch\Read Me.txttext
MD5:0D012BE9D6A9852967CD5A87FE42EA5A
SHA256:A80633DA999FDC934421185DAAF7D5A3C7508BAB8E870F69E5E8EDFC0B4E64E3
3720WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3720.12743\Patch\LAVteam.nfotext
MD5:6E7836DBE04D5CD88034BA98CB9CE0C8
SHA256:556ED809A576ED21A50583105372F6FCA72281D237CE309FCEEA5440D03071F6
3720WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3720.16113\Patch\lservrcbinary
MD5:8FD6B7A749B241BF080784A51B2AD489
SHA256:5513905DF8FC841389ACBF05F809D9DAB37BB76A27B5AF81E37D77911D0C11A9
3720WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3720.16113\Patch\Etabs_2016_v16_kg.exeexecutable
MD5:D72F173835B65D8246669462A51E3BFE
SHA256:C240855C63A61F0BA15BCB26B3C194EC63AACE4AF023D0D6E47EA09BF9C8373E
3720WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3720.9283\Patch\Read Me.txttext
MD5:0D012BE9D6A9852967CD5A87FE42EA5A
SHA256:A80633DA999FDC934421185DAAF7D5A3C7508BAB8E870F69E5E8EDFC0B4E64E3
3720WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3720.16113\Patch\LAVteam.nfotext
MD5:6E7836DBE04D5CD88034BA98CB9CE0C8
SHA256:556ED809A576ED21A50583105372F6FCA72281D237CE309FCEEA5440D03071F6
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
unknown
4
System
192.168.100.255:137
unknown
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info