File name:

SportZone_1.5.1.exe malware.zip

Full analysis: https://app.any.run/tasks/859fe38c-c761-44cc-862f-8cc7619f754c
Verdict: Malicious activity
Analysis date: November 28, 2019, 09:10:34
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

44A1D0E1A12D3EFC8921850444AB2AEB

SHA1:

994095A7E36EA6DFC99450C9DB52ED195B8DDC38

SHA256:

BF8148A6289BEADFFA2E2856699458E3EFA1688E05D672E87CC9996273A1D852

SSDEEP:

6144:tUCMRd24nX/Nn9fcoJn9Wq21z5t2h0G0KMkgZ51X:VNa1/J9W91zS0GtgZ7

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • SportZone_1.5.1.exe (PID: 952)
      • Install SportZone.exe (PID: 1296)
      • Adobe AIR Installer.exe (PID: 3988)
      • Adobe AIR Application Installer.exe (PID: 2724)
      • SportZone_1.5.1.exe (PID: 2892)
      • Install SportZone.exe (PID: 3452)
      • AIRRuntimeInstaller.exe (PID: 2448)
      • Adobe AIR Application Installer.exe (PID: 1268)
      • SportZone.exe (PID: 3760)
      • Adobe AIR Updater.exe (PID: 2976)
    • Loads dropped or rewritten executable

      • Adobe AIR Installer.exe (PID: 3988)
      • Adobe AIR Application Installer.exe (PID: 2724)
      • Adobe AIR Application Installer.exe (PID: 1268)
      • SportZone.exe (PID: 3760)
      • Adobe AIR Updater.exe (PID: 2976)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1752)
      • SportZone_1.5.1.exe (PID: 2892)
      • Install SportZone.exe (PID: 3452)
      • AIRRuntimeInstaller.exe (PID: 2448)
      • SportZone_1.5.1.exe (PID: 952)
      • msiexec.exe (PID: 2184)
      • Adobe AIR Application Installer.exe (PID: 1268)
      • Adobe AIR Application Installer.exe (PID: 2724)
    • Application launched itself

      • Adobe AIR Application Installer.exe (PID: 2724)
    • Reads Internet Cache Settings

      • Adobe AIR Application Installer.exe (PID: 2724)
      • Adobe AIR Updater.exe (PID: 2976)
    • Creates files in the user directory

      • Adobe AIR Application Installer.exe (PID: 2724)
      • SportZone.exe (PID: 3760)
      • Adobe AIR Updater.exe (PID: 2976)
    • Modifies the open verb of a shell class

      • msiexec.exe (PID: 2184)
    • Creates files in the program directory

      • Adobe AIR Application Installer.exe (PID: 1268)
    • Connects to unusual port

      • SportZone.exe (PID: 3760)
    • Low-level read access rights to disk partition

      • msconfig.exe (PID: 3264)
  • INFO

    • Manual execution by user

      • SportZone_1.5.1.exe (PID: 2892)
      • SportZone_1.5.1.exe (PID: 952)
      • msconfig.exe (PID: 2696)
      • msconfig.exe (PID: 3264)
    • Reads settings of System Certificates

      • Adobe AIR Application Installer.exe (PID: 2724)
      • Adobe AIR Application Installer.exe (PID: 1268)
    • Creates files in the program directory

      • msiexec.exe (PID: 2184)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 2184)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2019:11:04 11:30:13
ZipCRC: 0xf474e0b2
ZipCompressedSize: 262993
ZipUncompressedSize: 327398
ZipFileName: SportZone_1.5.1.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
59
Monitored processes
14
Malicious processes
6
Suspicious processes
3

Behavior graph

Click at the process to see the details
start drop and start drop and start drop and start drop and start winrar.exe sportzone_1.5.1.exe install sportzone.exe sportzone_1.5.1.exe install sportzone.exe airruntimeinstaller.exe adobe air installer.exe no specs adobe air application installer.exe adobe air application installer.exe msiexec.exe sportzone.exe adobe air updater.exe msconfig.exe no specs msconfig.exe

Process information

PID
CMD
Path
Indicators
Parent process
952"C:\Users\admin\Desktop\SportZone_1.5.1.exe" C:\Users\admin\Desktop\SportZone_1.5.1.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
11
Modules
Images
c:\users\admin\desktop\sportzone_1.5.1.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
1268"C:\Users\admin\AppData\Local\Temp\AIR13B3.tmp\Adobe AIR\Versions\1.0\Adobe AIR Application Installer.exe" -stdio \\.\pipe\AIR_2724_0 -runtime C:\Users\admin\AppData\Local\Temp\AIR13B3.tmp -silent -logToStdout -withRuntime -url -location "C:\Program Files" -desktopShortcut -programMenu C:\Users\admin\AppData\Local\Temp\AIRA336.tmp\SportZoneC:\Users\admin\AppData\Local\Temp\AIR13B3.tmp\Adobe AIR\Versions\1.0\Adobe AIR Application Installer.exe
Adobe AIR Application Installer.exe
User:
admin
Company:
Adobe
Integrity Level:
HIGH
Description:
Adobe AIR Application Installer
Exit code:
0
Version:
32.0.0.125
Modules
Images
c:\users\admin\appdata\local\temp\air13b3.tmp\adobe air\versions\1.0\adobe air application installer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
1296"C:\Users\admin\AppData\Local\Temp\AIR286D.tmp\Install SportZone.exe" C:\Users\admin\AppData\Local\Temp\AIR286D.tmp\Install SportZone.exe
SportZone_1.5.1.exe
User:
admin
Company:
Adobe Systems Inc.
Integrity Level:
MEDIUM
Description:
Adobe Bootstrapping Utility
Exit code:
11
Version:
23.0.0.257
Modules
Images
c:\users\admin\appdata\local\temp\air286d.tmp\install sportzone.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1752"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\SportZone_1.5.1.exe malware.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2184C:\Windows\system32\msiexec.exe /VC:\Windows\system32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2448"C:\Users\admin\AppData\Local\Temp\AIRRuntimeInstaller.exe" -x1 "C:\Users\admin\AppData\Local\Temp\AIRA336.tmp\SportZone"C:\Users\admin\AppData\Local\Temp\AIRRuntimeInstaller.exe
Install SportZone.exe
User:
admin
Company:
Adobe
Integrity Level:
MEDIUM
Description:
Adobe AIR Installer
Exit code:
0
Version:
32.0.0.125
Modules
Images
c:\users\admin\appdata\local\temp\airruntimeinstaller.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
2696"C:\Windows\system32\msconfig.exe" C:\Windows\system32\msconfig.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
System Configuration Utility
Exit code:
3221226540
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msconfig.exe
c:\systemroot\system32\ntdll.dll
2724"C:\Users\admin\AppData\Local\Temp\AIR13B3.tmp\Adobe AIR\Versions\1.0\Adobe AIR Application Installer.exe" -runtime C:\Users\admin\AppData\Local\Temp\AIR13B3.tmp -withRuntime -url C:\Users\admin\AppData\Local\Temp\AIRA336.tmp\SportZoneC:\Users\admin\AppData\Local\Temp\AIR13B3.tmp\Adobe AIR\Versions\1.0\Adobe AIR Application Installer.exe
Adobe AIR Installer.exe
User:
admin
Company:
Adobe
Integrity Level:
MEDIUM
Description:
Adobe AIR Application Installer
Exit code:
0
Version:
32.0.0.125
Modules
Images
c:\users\admin\appdata\local\temp\air13b3.tmp\adobe air\versions\1.0\adobe air application installer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
2892"C:\Users\admin\Desktop\SportZone_1.5.1.exe" C:\Users\admin\Desktop\SportZone_1.5.1.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\sportzone_1.5.1.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2976"C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe" -updatecheckC:\Program Files\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe
SportZone.exe
User:
admin
Company:
Adobe
Integrity Level:
MEDIUM
Description:
Adobe AIR Installer
Exit code:
0
Version:
32.0.0.125
Modules
Images
c:\program files\common files\adobe air\versions\1.0\resources\adobe air updater.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
Total events
3 034
Read events
2 657
Write events
354
Delete events
23

Modification events

(PID) Process:(1752) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1752) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1752) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1752) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\SportZone_1.5.1.exe malware.zip
(PID) Process:(1752) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1752) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1752) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1752) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1296) Install SportZone.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Install SportZone_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(1296) Install SportZone.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Install SportZone_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
Executable files
37
Suspicious files
15
Text files
91
Unknown types
35

Dropped files

PID
Process
Filename
Type
1752WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1752.28546\SportZone_1.5.1.exeexecutable
MD5:946C86867655B804D510A1F42A623988
SHA256:49AD0D1C94A41CB234CEBE97A8660CFFF82E562171A2D61DDF1C29D1CAC60794
1296Install SportZone.exeC:\Users\admin\AppData\Local\Adobe\AIR\logs\Install.logtext
MD5:
SHA256:
952SportZone_1.5.1.exeC:\Users\admin\AppData\Local\Temp\AIR286D.tmp\.launchtext
MD5:410AA7C4ADE1DAB2E8D3E6E0D9BFBE7F
SHA256:5BF92A7A179DDC88C834781CC3B4767423B2FA5409D76D268301E60835E602EE
952SportZone_1.5.1.exeC:\Users\admin\AppData\Local\Temp\AIR286D.tmp\SportZone\icons\icon_128.pngimage
MD5:942E611B22AA0290663DB9AA065C26A5
SHA256:2135FF309A45ECE5848E8327289A602A8A76DC93D4FAFF1C3A62556D010949E9
952SportZone_1.5.1.exeC:\Users\admin\AppData\Local\Temp\AIR286D.tmp\SportZone\META-INF\AIR\application.xmlxml
MD5:01650EEC8202DAFD6E0899FC3EF6F7F8
SHA256:E7A721A48B2737ACFF5CD7C64A7126FCDC79092B4D4B6580DCA4A9414770CF29
952SportZone_1.5.1.exeC:\Users\admin\AppData\Local\Temp\AIR286D.tmp\SportZone\icons\icon_48.pngimage
MD5:7AF3E8EEE49F2201CF68EAC55463828B
SHA256:47F25C4E00A22FCA00BB93B8698766AB3F47433D6A91D2ECDB9F93D194B2E758
952SportZone_1.5.1.exeC:\Users\admin\AppData\Local\Temp\AIR286D.tmp\SportZone\setup.msiexecutable
MD5:46E99D83D9E48D6043088AEBEA1A6D52
SHA256:08EF4A304C26D6671321626052270659388684BFBA78245038221493486FA6BF
952SportZone_1.5.1.exeC:\Users\admin\AppData\Local\Temp\AIR286D.tmp\SportZone\icons\icon_32.pngimage
MD5:4DD258D2B4ECB7CE46BBD1309A6B8558
SHA256:8B9D7C41FB0B148C5CFC50124A70E52701F3A30B60B05C893A039A3D51F1CAC9
952SportZone_1.5.1.exeC:\Users\admin\AppData\Local\Temp\AIR286D.tmp\SportZone\mimetypetext
MD5:60649E4365437442732EE45233B18F0C
SHA256:D3FA026FCE131CA31A82D2340F2D0AA2012EF764DE81D7ACA91AFF7255DCB757
952SportZone_1.5.1.exeC:\Users\admin\AppData\Local\Temp\AIR286D.tmp\Install SportZone.exeexecutable
MD5:517198A9B67BB967C244D07F01CDBD72
SHA256:3A6108CBB45B549C11355E04D9E982664C11FFC5233C97A78240E70CA82606BA
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
14
DNS requests
8
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2724
Adobe AIR Application Installer.exe
GET
200
93.184.220.29:80
http://ts-crl.ws.symantec.com/tss-ca-g2.crl
US
der
477 b
whitelisted
3452
Install SportZone.exe
GET
200
104.109.64.182:80
http://crl.adobe.com/cds.crl
NL
der
637 b
whitelisted
3452
Install SportZone.exe
GET
301
23.210.248.251:80
http://airdownload.adobe.com/air/3/nai/windows6.1/x86/installer
NL
whitelisted
3452
Install SportZone.exe
GET
301
23.210.248.251:80
http://airdownload.adobe.com/air/3/nai/windows6.1/x86/installer.p7
NL
whitelisted
2724
Adobe AIR Application Installer.exe
GET
200
93.184.220.29:80
http://crl.thawte.com/ThawteTimestampingCA.crl
US
der
341 b
whitelisted
3452
Install SportZone.exe
GET
200
104.109.64.182:80
http://crl.adobe.com/prodSvce.crl
NL
der
425 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1296
Install SportZone.exe
23.210.248.251:80
airdownload.adobe.com
Akamai International B.V.
NL
whitelisted
3452
Install SportZone.exe
23.210.248.251:443
airdownload.adobe.com
Akamai International B.V.
NL
whitelisted
3452
Install SportZone.exe
104.109.64.182:80
crl.adobe.com
Akamai International B.V.
NL
whitelisted
3760
SportZone.exe
95.211.209.47:443
LeaseWeb Netherlands B.V.
NL
unknown
3452
Install SportZone.exe
23.210.248.251:80
airdownload.adobe.com
Akamai International B.V.
NL
whitelisted
3760
SportZone.exe
185.49.69.55:443
Leaseweb Deutschland GmbH
DE
unknown
2724
Adobe AIR Application Installer.exe
93.184.220.29:80
crl.thawte.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
2976
Adobe AIR Updater.exe
23.210.248.251:443
airdownload.adobe.com
Akamai International B.V.
NL
whitelisted
3760
SportZone.exe
93.189.57.254:1935
Melbikomas UAB
NL
unknown
3760
SportZone.exe
95.211.209.47:1935
LeaseWeb Netherlands B.V.
NL
unknown

DNS requests

Domain
IP
Reputation
airdownload.adobe.com
  • 23.210.248.251
whitelisted
dns.msftncsi.com
  • 131.107.255.255
shared
crl.adobe.com
  • 104.109.64.182
whitelisted
crl.thawte.com
  • 93.184.220.29
whitelisted
ts-crl.ws.symantec.com
  • 93.184.220.29
whitelisted

Threats

PID
Process
Class
Message
2724
Adobe AIR Application Installer.exe
Potential Corporate Privacy Violation
ET POLICY Outdated Flash Version M1
No debug info