File name:

SportZone_1.5.1.exe malware.zip

Full analysis: https://app.any.run/tasks/859fe38c-c761-44cc-862f-8cc7619f754c
Verdict: Malicious activity
Analysis date: November 28, 2019, 09:10:34
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

44A1D0E1A12D3EFC8921850444AB2AEB

SHA1:

994095A7E36EA6DFC99450C9DB52ED195B8DDC38

SHA256:

BF8148A6289BEADFFA2E2856699458E3EFA1688E05D672E87CC9996273A1D852

SSDEEP:

6144:tUCMRd24nX/Nn9fcoJn9Wq21z5t2h0G0KMkgZ51X:VNa1/J9W91zS0GtgZ7

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Install SportZone.exe (PID: 1296)
      • Install SportZone.exe (PID: 3452)
      • SportZone_1.5.1.exe (PID: 952)
      • SportZone_1.5.1.exe (PID: 2892)
      • Adobe AIR Application Installer.exe (PID: 2724)
      • Adobe AIR Installer.exe (PID: 3988)
      • AIRRuntimeInstaller.exe (PID: 2448)
      • Adobe AIR Application Installer.exe (PID: 1268)
      • SportZone.exe (PID: 3760)
      • Adobe AIR Updater.exe (PID: 2976)
    • Loads dropped or rewritten executable

      • Adobe AIR Installer.exe (PID: 3988)
      • Adobe AIR Application Installer.exe (PID: 2724)
      • Adobe AIR Application Installer.exe (PID: 1268)
      • Adobe AIR Updater.exe (PID: 2976)
      • SportZone.exe (PID: 3760)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1752)
      • SportZone_1.5.1.exe (PID: 952)
      • Install SportZone.exe (PID: 3452)
      • SportZone_1.5.1.exe (PID: 2892)
      • AIRRuntimeInstaller.exe (PID: 2448)
      • Adobe AIR Application Installer.exe (PID: 1268)
      • Adobe AIR Application Installer.exe (PID: 2724)
      • msiexec.exe (PID: 2184)
    • Reads Internet Cache Settings

      • Adobe AIR Application Installer.exe (PID: 2724)
      • Adobe AIR Updater.exe (PID: 2976)
    • Creates files in the user directory

      • Adobe AIR Application Installer.exe (PID: 2724)
      • SportZone.exe (PID: 3760)
      • Adobe AIR Updater.exe (PID: 2976)
    • Application launched itself

      • Adobe AIR Application Installer.exe (PID: 2724)
    • Creates files in the program directory

      • Adobe AIR Application Installer.exe (PID: 1268)
    • Connects to unusual port

      • SportZone.exe (PID: 3760)
    • Low-level read access rights to disk partition

      • msconfig.exe (PID: 3264)
    • Modifies the open verb of a shell class

      • msiexec.exe (PID: 2184)
  • INFO

    • Manual execution by user

      • SportZone_1.5.1.exe (PID: 952)
      • SportZone_1.5.1.exe (PID: 2892)
      • msconfig.exe (PID: 3264)
      • msconfig.exe (PID: 2696)
    • Reads settings of System Certificates

      • Adobe AIR Application Installer.exe (PID: 2724)
      • Adobe AIR Application Installer.exe (PID: 1268)
    • Creates files in the program directory

      • msiexec.exe (PID: 2184)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 2184)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2019:11:04 11:30:13
ZipCRC: 0xf474e0b2
ZipCompressedSize: 262993
ZipUncompressedSize: 327398
ZipFileName: SportZone_1.5.1.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
59
Monitored processes
14
Malicious processes
6
Suspicious processes
3

Behavior graph

Click at the process to see the details
start drop and start drop and start drop and start drop and start winrar.exe sportzone_1.5.1.exe install sportzone.exe sportzone_1.5.1.exe install sportzone.exe airruntimeinstaller.exe adobe air installer.exe no specs adobe air application installer.exe adobe air application installer.exe msiexec.exe sportzone.exe adobe air updater.exe msconfig.exe no specs msconfig.exe

Process information

PID
CMD
Path
Indicators
Parent process
952"C:\Users\admin\Desktop\SportZone_1.5.1.exe" C:\Users\admin\Desktop\SportZone_1.5.1.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
11
Modules
Images
c:\users\admin\desktop\sportzone_1.5.1.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
1268"C:\Users\admin\AppData\Local\Temp\AIR13B3.tmp\Adobe AIR\Versions\1.0\Adobe AIR Application Installer.exe" -stdio \\.\pipe\AIR_2724_0 -runtime C:\Users\admin\AppData\Local\Temp\AIR13B3.tmp -silent -logToStdout -withRuntime -url -location "C:\Program Files" -desktopShortcut -programMenu C:\Users\admin\AppData\Local\Temp\AIRA336.tmp\SportZoneC:\Users\admin\AppData\Local\Temp\AIR13B3.tmp\Adobe AIR\Versions\1.0\Adobe AIR Application Installer.exe
Adobe AIR Application Installer.exe
User:
admin
Company:
Adobe
Integrity Level:
HIGH
Description:
Adobe AIR Application Installer
Exit code:
0
Version:
32.0.0.125
Modules
Images
c:\users\admin\appdata\local\temp\air13b3.tmp\adobe air\versions\1.0\adobe air application installer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
1296"C:\Users\admin\AppData\Local\Temp\AIR286D.tmp\Install SportZone.exe" C:\Users\admin\AppData\Local\Temp\AIR286D.tmp\Install SportZone.exe
SportZone_1.5.1.exe
User:
admin
Company:
Adobe Systems Inc.
Integrity Level:
MEDIUM
Description:
Adobe Bootstrapping Utility
Exit code:
11
Version:
23.0.0.257
Modules
Images
c:\users\admin\appdata\local\temp\air286d.tmp\install sportzone.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1752"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\SportZone_1.5.1.exe malware.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2184C:\Windows\system32\msiexec.exe /VC:\Windows\system32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2448"C:\Users\admin\AppData\Local\Temp\AIRRuntimeInstaller.exe" -x1 "C:\Users\admin\AppData\Local\Temp\AIRA336.tmp\SportZone"C:\Users\admin\AppData\Local\Temp\AIRRuntimeInstaller.exe
Install SportZone.exe
User:
admin
Company:
Adobe
Integrity Level:
MEDIUM
Description:
Adobe AIR Installer
Exit code:
0
Version:
32.0.0.125
Modules
Images
c:\users\admin\appdata\local\temp\airruntimeinstaller.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
2696"C:\Windows\system32\msconfig.exe" C:\Windows\system32\msconfig.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
System Configuration Utility
Exit code:
3221226540
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msconfig.exe
c:\systemroot\system32\ntdll.dll
2724"C:\Users\admin\AppData\Local\Temp\AIR13B3.tmp\Adobe AIR\Versions\1.0\Adobe AIR Application Installer.exe" -runtime C:\Users\admin\AppData\Local\Temp\AIR13B3.tmp -withRuntime -url C:\Users\admin\AppData\Local\Temp\AIRA336.tmp\SportZoneC:\Users\admin\AppData\Local\Temp\AIR13B3.tmp\Adobe AIR\Versions\1.0\Adobe AIR Application Installer.exe
Adobe AIR Installer.exe
User:
admin
Company:
Adobe
Integrity Level:
MEDIUM
Description:
Adobe AIR Application Installer
Exit code:
0
Version:
32.0.0.125
Modules
Images
c:\users\admin\appdata\local\temp\air13b3.tmp\adobe air\versions\1.0\adobe air application installer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
2892"C:\Users\admin\Desktop\SportZone_1.5.1.exe" C:\Users\admin\Desktop\SportZone_1.5.1.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\sportzone_1.5.1.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2976"C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe" -updatecheckC:\Program Files\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe
SportZone.exe
User:
admin
Company:
Adobe
Integrity Level:
MEDIUM
Description:
Adobe AIR Installer
Exit code:
0
Version:
32.0.0.125
Modules
Images
c:\program files\common files\adobe air\versions\1.0\resources\adobe air updater.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
Total events
3 034
Read events
2 657
Write events
354
Delete events
23

Modification events

(PID) Process:(1752) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1752) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1752) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1752) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\SportZone_1.5.1.exe malware.zip
(PID) Process:(1752) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1752) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1752) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1752) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1296) Install SportZone.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Install SportZone_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(1296) Install SportZone.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Install SportZone_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
Executable files
37
Suspicious files
15
Text files
91
Unknown types
35

Dropped files

PID
Process
Filename
Type
952SportZone_1.5.1.exeC:\Users\admin\AppData\Local\Temp\AIR286D.tmp\SportZone\icons\icon_32.pngimage
MD5:4DD258D2B4ECB7CE46BBD1309A6B8558
SHA256:8B9D7C41FB0B148C5CFC50124A70E52701F3A30B60B05C893A039A3D51F1CAC9
952SportZone_1.5.1.exeC:\Users\admin\AppData\Local\Temp\AIR286D.tmp\SportZone\META-INF\AIR\application.xmlxml
MD5:01650EEC8202DAFD6E0899FC3EF6F7F8
SHA256:E7A721A48B2737ACFF5CD7C64A7126FCDC79092B4D4B6580DCA4A9414770CF29
2892SportZone_1.5.1.exeC:\Users\admin\AppData\Local\Temp\AIRA336.tmp\.launchtext
MD5:410AA7C4ADE1DAB2E8D3E6E0D9BFBE7F
SHA256:5BF92A7A179DDC88C834781CC3B4767423B2FA5409D76D268301E60835E602EE
952SportZone_1.5.1.exeC:\Users\admin\AppData\Local\Temp\AIR286D.tmp\SportZone\icons\icon_16.pngimage
MD5:8111AE0F83EA20460109DC59739E2AC2
SHA256:CED8CFC8344BB52F76F4FE5B08D0E2569F2CE9591E6756A9E05FC56302173216
952SportZone_1.5.1.exeC:\Users\admin\AppData\Local\Temp\AIR286D.tmp\SportZone\META-INF\AIR\hashbinary
MD5:49D7A9D707F89D3B118E89CFE4DC9AC7
SHA256:E1C83BC40F8DA70DADE73C4725ED0C7C37B2ACE406B96E97255E31987787D411
952SportZone_1.5.1.exeC:\Users\admin\AppData\Local\Temp\AIR286D.tmp\SportZone\icons\icon_48.pngimage
MD5:7AF3E8EEE49F2201CF68EAC55463828B
SHA256:47F25C4E00A22FCA00BB93B8698766AB3F47433D6A91D2ECDB9F93D194B2E758
1752WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1752.28546\SportZone_1.5.1.exeexecutable
MD5:946C86867655B804D510A1F42A623988
SHA256:49AD0D1C94A41CB234CEBE97A8660CFFF82E562171A2D61DDF1C29D1CAC60794
952SportZone_1.5.1.exeC:\Users\admin\AppData\Local\Temp\AIR286D.tmp\.launchtext
MD5:410AA7C4ADE1DAB2E8D3E6E0D9BFBE7F
SHA256:5BF92A7A179DDC88C834781CC3B4767423B2FA5409D76D268301E60835E602EE
952SportZone_1.5.1.exeC:\Users\admin\AppData\Local\Temp\AIR286D.tmp\SportZone\SportZone.exeexecutable
MD5:9530B545FC98C9409A6A55561E58C332
SHA256:03B2ABDB095A207D151FB332C0F55B29E61639CAAFD61B050B5F321020BC518B
2892SportZone_1.5.1.exeC:\Users\admin\AppData\Local\Temp\AIRA336.tmp\SportZone\icons\icon_16.pngimage
MD5:8111AE0F83EA20460109DC59739E2AC2
SHA256:CED8CFC8344BB52F76F4FE5B08D0E2569F2CE9591E6756A9E05FC56302173216
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
14
DNS requests
8
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3452
Install SportZone.exe
GET
301
23.210.248.251:80
http://airdownload.adobe.com/air/3/nai/windows6.1/x86/installer
NL
whitelisted
2724
Adobe AIR Application Installer.exe
GET
200
93.184.220.29:80
http://crl.thawte.com/ThawteTimestampingCA.crl
US
der
341 b
whitelisted
2724
Adobe AIR Application Installer.exe
GET
200
93.184.220.29:80
http://ts-crl.ws.symantec.com/tss-ca-g2.crl
US
der
477 b
whitelisted
3452
Install SportZone.exe
GET
200
104.109.64.182:80
http://crl.adobe.com/prodSvce.crl
NL
der
425 b
whitelisted
3452
Install SportZone.exe
GET
301
23.210.248.251:80
http://airdownload.adobe.com/air/3/nai/windows6.1/x86/installer.p7
NL
whitelisted
3452
Install SportZone.exe
GET
200
104.109.64.182:80
http://crl.adobe.com/cds.crl
NL
der
637 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3452
Install SportZone.exe
23.210.248.251:80
airdownload.adobe.com
Akamai International B.V.
NL
whitelisted
3452
Install SportZone.exe
104.109.64.182:80
crl.adobe.com
Akamai International B.V.
NL
whitelisted
2724
Adobe AIR Application Installer.exe
93.184.220.29:80
crl.thawte.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
3452
Install SportZone.exe
23.210.248.251:443
airdownload.adobe.com
Akamai International B.V.
NL
whitelisted
3760
SportZone.exe
185.49.69.55:443
Leaseweb Deutschland GmbH
DE
unknown
3760
SportZone.exe
95.211.209.47:443
LeaseWeb Netherlands B.V.
NL
unknown
3760
SportZone.exe
95.211.209.47:1935
LeaseWeb Netherlands B.V.
NL
unknown
3760
SportZone.exe
185.49.69.55:1935
Leaseweb Deutschland GmbH
DE
unknown
3760
SportZone.exe
93.189.57.254:1935
Melbikomas UAB
NL
unknown
1296
Install SportZone.exe
23.210.248.251:80
airdownload.adobe.com
Akamai International B.V.
NL
whitelisted

DNS requests

Domain
IP
Reputation
airdownload.adobe.com
  • 23.210.248.251
whitelisted
dns.msftncsi.com
  • 131.107.255.255
shared
crl.adobe.com
  • 104.109.64.182
whitelisted
crl.thawte.com
  • 93.184.220.29
whitelisted
ts-crl.ws.symantec.com
  • 93.184.220.29
whitelisted

Threats

PID
Process
Class
Message
2724
Adobe AIR Application Installer.exe
Potential Corporate Privacy Violation
ET POLICY Outdated Flash Version M1
No debug info