File name:

4.zip

Full analysis: https://app.any.run/tasks/4961a045-784b-45bc-9aa0-1a56910b9069
Verdict: Malicious activity
Analysis date: May 06, 2019, 06:31:25
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract
MD5:

1F53FB6BCB7D0BF7DAD1015E94BB7B87

SHA1:

396C7EFEFAE47594625D93019EBCB77DB34633FC

SHA256:

BBA1A83AB7F2221FD58543D1D66AB90CEA11E878C6404CC752AA667228663AE7

SSDEEP:

49152:aegpr3fOsFY0/FdswvsYk+Gcwu/KKXwZ5q+aa5QOOX1gTagMo8awhzpNOCrMJv+G:afr3fOsFX/FdscbMNKXwTq+rOWPopN1Q

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 3216)
      • COSY V1 - Spotify Checker.exe (PID: 3984)
    • Application was dropped or rewritten from another process

      • COSY V1 - Spotify Checker.exe (PID: 2224)
      • COSY V1 - Spotify Checker.exe (PID: 3984)
      • love.exe (PID: 1836)
      • file_exe.exe (PID: 1704)
      • COSY V1 - Spotify Checker.exe (PID: 2180)
      • Win32.exe (PID: 3140)
    • Loads the Task Scheduler COM API

      • mmc.exe (PID: 1856)
      • schtasks.exe (PID: 2724)
    • Changes settings of System certificates

      • Win32.exe (PID: 3140)
    • Uses Task Scheduler to run other applications

      • love.exe (PID: 1836)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 4004)
      • COSY V1 - Spotify Checker.exe (PID: 3984)
      • file_exe.exe (PID: 1704)
      • COSY V1 - Spotify Checker.exe (PID: 2224)
      • love.exe (PID: 1836)
    • Starts itself from another location

      • love.exe (PID: 1836)
    • Loads Python modules

      • COSY V1 - Spotify Checker.exe (PID: 3984)
    • Starts CMD.EXE for commands execution

      • COSY V1 - Spotify Checker.exe (PID: 3984)
    • Creates files in the user directory

      • love.exe (PID: 1836)
    • Adds / modifies Windows certificates

      • Win32.exe (PID: 3140)
    • Uses NETSTAT.EXE to discover network connections

      • cmd.exe (PID: 1972)
  • INFO

    • Reads settings of System Certificates

      • Win32.exe (PID: 3140)
    • Application was crashed

      • COSY V1 - Spotify Checker.exe (PID: 2180)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2019:05:05 07:12:22
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: Combos.txt
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
57
Monitored processes
14
Malicious processes
3
Suspicious processes
5

Behavior graph

Click at the process to see the details
start drop and start drop and start drop and start winrar.exe searchprotocolhost.exe no specs cosy v1 - spotify checker.exe cosy v1 - spotify checker.exe cmd.exe no specs file_exe.exe love.exe cosy v1 - spotify checker.exe mmc.exe no specs mmc.exe schtasks.exe no specs win32.exe cmd.exe netstat.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
756C:\Windows\system32\cmd.exe /c file_exe.exeC:\Windows\system32\cmd.exeCOSY V1 - Spotify Checker.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1704file_exe.exeC:\Users\admin\Desktop\file_exe.exe
cmd.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Exit code:
0
Version:
0.0.0.0
Modules
Images
c:\users\admin\desktop\file_exe.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1836"C:\Users\admin\AppData\Local\Temp\love.exe" C:\Users\admin\AppData\Local\Temp\love.exe
file_exe.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\love.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1856"C:\Windows\system32\mmc.exe" "C:\Windows\system32\taskschd.msc" /sC:\Windows\system32\mmc.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Management Console
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\mmc.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\mfc42u.dll
1972"C:\Windows\System32\cmd.exe" C:\Windows\System32\cmd.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2180"C:\Users\admin\AppData\Local\Temp\COSY V1 - Spotify Checker.exe" C:\Users\admin\AppData\Local\Temp\COSY V1 - Spotify Checker.exe
file_exe.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Spotify Checker
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\cosy v1 - spotify checker.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2224"C:\Users\admin\Desktop\COSY V1 - Spotify Checker.exe" C:\Users\admin\Desktop\COSY V1 - Spotify Checker.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\cosy v1 - spotify checker.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\apphelp.dll
2688"C:\Windows\system32\mmc.exe" "C:\Windows\system32\taskschd.msc" /sC:\Windows\system32\mmc.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Management Console
Exit code:
3221226540
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\mmc.exe
c:\systemroot\system32\ntdll.dll
2724schtasks /create /f /sc ONLOGON /RL HIGHEST /tn LimeRAT-Admin /tr "'C:\Users\admin\AppData\Roaming\Win32.exe'"C:\Windows\system32\schtasks.exelove.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Manages scheduled tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
3140"C:\Users\admin\AppData\Roaming\Win32.exe" C:\Users\admin\AppData\Roaming\Win32.exe
love.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\roaming\win32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
1 786
Read events
1 668
Write events
118
Delete events
0

Modification events

(PID) Process:(4004) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(4004) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(4004) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(4004) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\4.zip
(PID) Process:(4004) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(4004) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(4004) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(4004) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(4004) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
Operation:writeName:@C:\Windows\system32\notepad.exe,-469
Value:
Text Document
(PID) Process:(3216) SearchProtocolHost.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\62\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
Executable files
17
Suspicious files
0
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
2224COSY V1 - Spotify Checker.exeC:\Users\admin\AppData\Local\Temp\_MEI22242\bz2.pydexecutable
MD5:
SHA256:
2224COSY V1 - Spotify Checker.exeC:\Users\admin\AppData\Local\Temp\_MEI22242\_hashlib.pydexecutable
MD5:
SHA256:
2224COSY V1 - Spotify Checker.exeC:\Users\admin\AppData\Local\Temp\_MEI22242\output.exe.manifestxml
MD5:
SHA256:
4004WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa4004.31221\xNet.dllexecutable
MD5:3DF8D87A482EFAD957D83819ADB3020F
SHA256:2AC175B4D44245EE8E7AEE9CC36DF86925EF903D8516F20A2C51D84E35F23DA4
4004WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa4004.31221\Newtonsoft.Json.dllexecutable
MD5:D827DD8A8C4B2A2CFA23C7F90F3CCE95
SHA256:B66749B81E1489FCD8D754B2AD39EBE0DB681344E392A3F49DC9235643BDBD06
2224COSY V1 - Spotify Checker.exeC:\Users\admin\AppData\Local\Temp\_MEI22242\Microsoft.VC90.CRT.manifestxml
MD5:FEDFDF2256720BADEFF9205E784B5DC8
SHA256:6373FB8261AF01506DC57DEE535A0BE800F3A59B18B0CC1E276807C746329FF6
2224COSY V1 - Spotify Checker.exeC:\Users\admin\AppData\Local\Temp\_MEI22242\select.pydexecutable
MD5:
SHA256:
4004WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa4004.31221\Leaf.xNet.dllexecutable
MD5:4D31626E5B7D07DEE2375E49B4671C99
SHA256:06E2EEC80A75C45CC1CA63ABC7D3DA907E49AC60FA1A24E94520DA6E61F44FE5
2224COSY V1 - Spotify Checker.exeC:\Users\admin\AppData\Local\Temp\_MEI22242\unicodedata.pydexecutable
MD5:
SHA256:
3984COSY V1 - Spotify Checker.exeC:\Users\admin\Desktop\file_exe.exeexecutable
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
3
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3140
Win32.exe
185.209.23.138:5050
NovoServe B.V.
NL
unknown
3140
Win32.exe
104.20.209.21:443
pastebin.com
Cloudflare Inc
US
shared

DNS requests

Domain
IP
Reputation
pastebin.com
  • 104.20.209.21
  • 104.20.208.21
malicious

Threats

No threats detected
Process
Message
mmc.exe
Constructor: Microsoft.TaskScheduler.SnapIn.TaskSchedulerSnapIn
mmc.exe
OnInitialize: Microsoft.TaskScheduler.SnapIn.TaskSchedulerSnapIn
mmc.exe
AddIcons: Microsoft.TaskScheduler.SnapIn.TaskSchedulerSnapIn
mmc.exe
ProcessCommandLineArguments: Microsoft.TaskScheduler.SnapIn.TaskSchedulerSnapIn