URL:

http://www.zbshareware.com

Full analysis: https://app.any.run/tasks/05076f10-acdd-4e77-a4bb-c3d426ea12d7
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: March 10, 2024, 23:21:01
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
loader
Indicators:
MD5:

DB3E2344D72415E51AB736A34DCBE790

SHA1:

CABEF007DEA03DA53E9E2D14DEA8AD7D9346EA91

SHA256:

BD488DAFF440FACDC81B67010E3A531B6319DD2DDAE09F3017984E84E5B4AD81

SSDEEP:

3:N1KJS4vWVEI:Cc4Qh

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • USBGuardSetup6.9.exe (PID: 696)
      • USBGuardSetup6.9.exe (PID: 3912)
      • USBGuardSetup6.9.tmp (PID: 3308)
    • Changes the autorun value in the registry

      • USBGuardSetup6.9.tmp (PID: 3308)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • USBGuardSetup6.9.exe (PID: 696)
      • USBGuardSetup6.9.exe (PID: 3912)
      • USBGuardSetup6.9.tmp (PID: 3308)
    • Reads the Windows owner or organization settings

      • USBGuardSetup6.9.tmp (PID: 3308)
    • The process drops C-runtime libraries

      • USBGuardSetup6.9.tmp (PID: 3308)
    • Process drops legitimate windows executable

      • USBGuardSetup6.9.tmp (PID: 3308)
    • Non-standard symbols in registry

      • USBGuardSetup6.9.tmp (PID: 3308)
    • Reads the Internet Settings

      • USBGuard.exe (PID: 1352)
    • Reads security settings of Internet Explorer

      • USBGuard.exe (PID: 1352)
  • INFO

    • Drops the executable file immediately after the start

      • iexplore.exe (PID: 2920)
      • iexplore.exe (PID: 3700)
    • Application launched itself

      • iexplore.exe (PID: 3700)
    • Executable content was dropped or overwritten

      • iexplore.exe (PID: 3700)
      • iexplore.exe (PID: 2920)
    • Modifies the phishing filter of IE

      • iexplore.exe (PID: 3700)
    • The process uses the downloaded file

      • iexplore.exe (PID: 3700)
    • Checks supported languages

      • USBGuardSetup6.9.exe (PID: 696)
      • USBGuardSetup6.9.tmp (PID: 2960)
      • USBGuardSetup6.9.exe (PID: 3912)
      • USBGuardSetup6.9.tmp (PID: 3308)
      • USBGuard.exe (PID: 1352)
    • Create files in a temporary directory

      • USBGuardSetup6.9.exe (PID: 696)
      • USBGuardSetup6.9.exe (PID: 3912)
      • USBGuardSetup6.9.tmp (PID: 3308)
    • Reads the computer name

      • USBGuardSetup6.9.tmp (PID: 2960)
      • USBGuardSetup6.9.tmp (PID: 3308)
      • USBGuard.exe (PID: 1352)
    • Creates files in the program directory

      • USBGuardSetup6.9.tmp (PID: 3308)
    • Creates files or folders in the user directory

      • USBGuardSetup6.9.tmp (PID: 3308)
      • USBGuard.exe (PID: 1352)
    • Creates a software uninstall entry

      • USBGuardSetup6.9.tmp (PID: 3308)
    • Reads the machine GUID from the registry

      • USBGuard.exe (PID: 1352)
    • Checks proxy server information

      • USBGuard.exe (PID: 1352)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
48
Monitored processes
7
Malicious processes
4
Suspicious processes
2

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe usbguardsetup6.9.exe usbguardsetup6.9.tmp no specs usbguardsetup6.9.exe usbguardsetup6.9.tmp usbguard.exe

Process information

PID
CMD
Path
Indicators
Parent process
696"C:\Users\admin\Downloads\USBGuardSetup6.9.exe" C:\Users\admin\Downloads\USBGuardSetup6.9.exe
iexplore.exe
User:
admin
Company:
Zbshareware Lab
Integrity Level:
MEDIUM
Description:
USB Disk Security Setup
Exit code:
0
Version:
6.9.0.0
Modules
Images
c:\users\admin\downloads\usbguardsetup6.9.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1352"C:\Program Files\USB Disk Security\USBGuard.exe"C:\Program Files\USB Disk Security\USBGuard.exe
USBGuardSetup6.9.tmp
User:
admin
Company:
Zbshareware Lab
Integrity Level:
MEDIUM
Description:
USB Disk Security
Exit code:
0
Version:
6.5.0.0
Modules
Images
c:\program files\usb disk security\usbguard.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\program files\usb disk security\mfc80u.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2920"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3700 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2960"C:\Users\admin\AppData\Local\Temp\is-GD6TS.tmp\USBGuardSetup6.9.tmp" /SL5="$C0162,3559286,126976,C:\Users\admin\Downloads\USBGuardSetup6.9.exe" C:\Users\admin\AppData\Local\Temp\is-GD6TS.tmp\USBGuardSetup6.9.tmpUSBGuardSetup6.9.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-gd6ts.tmp\usbguardsetup6.9.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3308"C:\Users\admin\AppData\Local\Temp\is-17Q7E.tmp\USBGuardSetup6.9.tmp" /SL5="$1B0164,3559286,126976,C:\Users\admin\Downloads\USBGuardSetup6.9.exe" /SPAWNWND=$D010C /NOTIFYWND=$C0162 C:\Users\admin\AppData\Local\Temp\is-17Q7E.tmp\USBGuardSetup6.9.tmp
USBGuardSetup6.9.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-17q7e.tmp\usbguardsetup6.9.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3700"C:\Program Files\Internet Explorer\iexplore.exe" "http://www.zbshareware.com"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
3912"C:\Users\admin\Downloads\USBGuardSetup6.9.exe" /SPAWNWND=$D010C /NOTIFYWND=$C0162 C:\Users\admin\Downloads\USBGuardSetup6.9.exe
USBGuardSetup6.9.tmp
User:
admin
Company:
Zbshareware Lab
Integrity Level:
HIGH
Description:
USB Disk Security Setup
Exit code:
0
Version:
6.9.0.0
Modules
Images
c:\users\admin\downloads\usbguardsetup6.9.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
Total events
26 215
Read events
26 002
Write events
156
Delete events
57

Modification events

(PID) Process:(3700) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
1
(PID) Process:(3700) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchLowDateTime
Value:
(PID) Process:(3700) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
31093569
(PID) Process:(3700) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateLowDateTime
Value:
(PID) Process:(3700) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
31093569
(PID) Process:(3700) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(3700) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3700) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3700) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(3700) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
55
Suspicious files
25
Text files
46
Unknown types
18

Dropped files

PID
Process
Filename
Type
2920iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\MRB2XEJP.htmhtml
MD5:39EDF0510A37BDAF8B70D31B86CDAD68
SHA256:AE6BBA4652DD9AA2F053C41C3DFDDE6165E44CC3D04CA2E152FCE027E732CBA3
2920iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EAbinary
MD5:FB13179BB9402BDD2BD203D47976EB41
SHA256:AE82A841D2B7C8965FC2F28C110DCF37D1E191CE4831DA0D01E52F877E751846
2920iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EAder
MD5:7E8F359F842F63D4F8E11B673E763622
SHA256:F04843E27AB3A622E565EEA01945462567D713146B1CBCA62C89D2495E924450
2920iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:236FE0CC734BEE87F55AEA1C19359751
SHA256:3D07FB9A596636C60EC2265C09AD09C97919C507A3ED118A1EDDB3F2EA522DF7
2920iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\F07644E38ED7C9F37D11EEC6D4335E02_AAF7FF9044AB6407BDF615F886CED769der
MD5:5C3766581BC252BCD24D751D69550479
SHA256:795BDA23AC05E5B07A296C526CEE3537A096A15D37704862AFF3FE6F1A2562B9
2920iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\zbshareware_index[1].csstext
MD5:0B31E537B68D815810025DBD0198CEF1
SHA256:18548D2997A718AFD81956AEB92B47665EB5A2886856633E48D8FA87D0D01076
2920iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\CAF4703619713E3F18D8A9D5D88D6288_A7725538C46DE2D0088EE44974E2CEBAder
MD5:AC89A852C2AAA3D389B2D2DD312AD367
SHA256:0B720E19270C672F9B6E0EC40B468AC49376807DE08A814573FE038779534F45
2920iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\CAF4703619713E3F18D8A9D5D88D6288_A7725538C46DE2D0088EE44974E2CEBAbinary
MD5:14706C7B3F976758C066E8768B24ACA6
SHA256:2F74D63694168760D13AB7CEA147EB21AD0DC0A55C891B1F9A1AB4DD25C425FD
2920iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\V4ERP3DH.txttext
MD5:3E2976A34BA9E60ACACF2775BFBFBB3E
SHA256:A4911AE9534D9A7B29CED937D3954B3639D19DF716153996F4B1D2EAE3BB16A9
3700iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\EAF8AA29A62AB29E614331747385D816_F9E4DC0B9D5C777357D7DB8DEF51118Ader
MD5:A88028032B2F21C56D1EBCF81CD72FEE
SHA256:DEB77E66751B5330F93CC98E697E473EC8BEEB9C19743582C7D0FFC68D3C2D79
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
20
TCP/UDP connections
30
DNS requests
20
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3700
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAxq6XzO1ZmDhpCgCp6lMhQ%3D
unknown
binary
471 b
unknown
3700
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA177el9ggmWelJjG4vdGL0%3D
unknown
binary
471 b
unknown
2920
iexplore.exe
GET
200
50.116.10.192:80
http://www.zbshareware.com/
unknown
html
2.25 Kb
unknown
2920
iexplore.exe
GET
200
50.116.10.192:80
http://www.zbshareware.com/index/style/zbshareware_index.css
unknown
text
1.88 Kb
unknown
2920
iexplore.exe
GET
304
2.18.121.202:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?a08f35fbea17b647
unknown
unknown
2920
iexplore.exe
GET
304
2.18.121.71:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?545e1839169dd0e6
unknown
unknown
2920
iexplore.exe
GET
200
142.250.181.227:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
unknown
binary
1.41 Kb
unknown
2920
iexplore.exe
GET
200
142.250.181.227:80
http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFNZazTHGPUBUGY%3D
unknown
binary
724 b
unknown
2920
iexplore.exe
GET
200
142.250.181.227:80
http://ocsp.pki.goog/gts1c3/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEQCimReIRyQtphKmdTNhBzaE
unknown
binary
472 b
unknown
2920
iexplore.exe
GET
200
50.116.10.192:80
http://www.zbshareware.com/index/images/zbshareware.gif
unknown
image
20.2 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
2920
iexplore.exe
50.116.10.192:80
www.zbshareware.com
Linode, LLC
US
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
2920
iexplore.exe
142.250.185.174:443
www.google-analytics.com
GOOGLE
US
whitelisted
2920
iexplore.exe
2.18.121.71:80
ctldl.windowsupdate.com
AKAMAI-AS
FR
unknown
2920
iexplore.exe
2.18.121.202:80
ctldl.windowsupdate.com
AKAMAI-AS
FR
unknown
2920
iexplore.exe
142.250.181.227:80
ocsp.pki.goog
GOOGLE
US
whitelisted
3700
iexplore.exe
50.116.10.192:80
www.zbshareware.com
Linode, LLC
US
unknown
3700
iexplore.exe
2.19.176.88:443
www.bing.com
Akamai International B.V.
IE
unknown

DNS requests

Domain
IP
Reputation
www.zbshareware.com
  • 50.116.10.192
malicious
www.google-analytics.com
  • 142.250.185.174
whitelisted
ctldl.windowsupdate.com
  • 2.18.121.202
  • 2.18.121.71
whitelisted
ocsp.pki.goog
  • 142.250.181.227
whitelisted
api.bing.com
  • 13.107.5.80
whitelisted
www.bing.com
  • 2.19.176.88
  • 2.19.176.91
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
iecvlist.microsoft.com
  • 152.199.19.161
whitelisted
r20swj13mr.microsoft.com
  • 152.199.19.161
whitelisted
www.zbshareware.net
  • 50.116.10.192
unknown

Threats

PID
Process
Class
Message
2920
iexplore.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
No debug info