| File name: | cimb-bizconverter-v1-2-0-4.zip |
| Full analysis: | https://app.any.run/tasks/24d6c4f7-0ed1-46f0-9adc-1d6bb135bd31 |
| Verdict: | Malicious activity |
| Analysis date: | January 29, 2024, 03:24:47 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | 3EE5AE037B0B7064B4C6B0D191CA98FC |
| SHA1: | 551145E8D9D1625239D12343DCB00925E8B0FF6B |
| SHA256: | C0A93AF0CB36715396645E1732C614187F83F537C867970621FC5AAAE6CFA03A |
| SSDEEP: | 98304:gPTjgX5QG3hWKMJZICjmdWCPN0QHprlxul+05t46AIzM/KUhEznqiVuLeEYnGw+g:/Tj6RPxgY8T4 |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | None |
| ZipModifyDate: | 2019:04:01 17:11:26 |
| ZipCRC: | 0x00000000 |
| ZipCompressedSize: | - |
| ZipUncompressedSize: | - |
| ZipFileName: | CIMB BizConverter v1.2.0.4/ |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2508 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2580.23289\CIMB BizConverter v1.2.0.4\DotNetFX40Client\dotNetFx40_Client_x86_x64.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2580.23289\CIMB BizConverter v1.2.0.4\DotNetFX40Client\dotNetFx40_Client_x86_x64.exe | — | WinRAR.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft .NET Framework 4 Setup Exit code: 3221226540 Version: 4.0.30319.01 Modules
| |||||||||||||||
| 2560 | "C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\Rar$EXa2580.18622\CIMB BizConverter v1.2.0.4\CIMBBizConverterSetup.msi" | C:\Windows\System32\msiexec.exe | WinRAR.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2580 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\cimb-bizconverter-v1-2-0-4.zip" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 2660 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2580.19641\CIMB BizConverter v1.2.0.4\WindowsInstaller3_1\WindowsInstaller-KB893803-v2-x86.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2580.19641\CIMB BizConverter v1.2.0.4\WindowsInstaller3_1\WindowsInstaller-KB893803-v2-x86.exe | — | WinRAR.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Update Package Exit code: 3221226540 Version: 3.1 Modules
| |||||||||||||||
| 2820 | c:\be6dcf97112291cbc5cca8ced586aa\UPDATE\update.exe | C:\be6dcf97112291cbc5cca8ced586aa\update\update.exe | — | WindowsInstaller-KB893803-v2-x86.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Service Pack Setup Exit code: 1603 Version: 6.1.0022.4 (SRV03_QFE.031113-0918) Modules
| |||||||||||||||
| 2944 | "C:\CIMB\CIMBBizConverter\CIMBBizConverter.exe" | C:\CIMB\CIMBBizConverter\CIMBBizConverter.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Integrity Level: MEDIUM Description: CIMBBizConverter Exit code: 0 Version: 1.2.0.4 Modules
| |||||||||||||||
| 3036 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2580.19641\CIMB BizConverter v1.2.0.4\WindowsInstaller3_1\WindowsInstaller-KB893803-v2-x86.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2580.19641\CIMB BizConverter v1.2.0.4\WindowsInstaller3_1\WindowsInstaller-KB893803-v2-x86.exe | WinRAR.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Update Package Exit code: 1603 Version: 3.1 Modules
| |||||||||||||||
| 3440 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2580.23289\CIMB BizConverter v1.2.0.4\DotNetFX40Client\dotNetFx40_Client_x86_x64.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2580.23289\CIMB BizConverter v1.2.0.4\DotNetFX40Client\dotNetFx40_Client_x86_x64.exe | WinRAR.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft .NET Framework 4 Setup Exit code: 0 Version: 4.0.30319.01 Modules
| |||||||||||||||
| 3568 | C:\edb09f2af11fd38720d15e48ce63\\Setup.exe /x86 /x64 /ia64 /web | C:\edb09f2af11fd38720d15e48ce63\Setup.exe | dotNetFx40_Client_x86_x64.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Setup Installer Exit code: 0 Version: 10.0.30319.1 built by: RTMRel Modules
| |||||||||||||||
| (PID) Process: | (2580) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2580) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (2580) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (2580) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (2580) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
| (PID) Process: | (2580) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2580) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2580) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2580) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (2580) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2580 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2580.18622\CIMB BizConverter v1.2.0.4\BizConverter_installation_guide.txt | text | |
MD5:F2AAFFE697244F9907B811406DF91F05 | SHA256:40439C02C4EE806BC359C2CD909E4F19A4CF65346C354465D5FDACE2E27DEDCE | |||
| 2580 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2580.18622\CIMB BizConverter v1.2.0.4\setup.exe | executable | |
MD5:7883F7FE717E0B329E8E8B1942B94D1F | SHA256:E3F67961ED52F52B98DD5A32AFD3A1E7CBF0CEB1ECC69E78EFF8BC8613C0603E | |||
| 2580 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2580.18622\CIMB BizConverter v1.2.0.4\CIMBBizConverterSetup.msi | executable | |
MD5:A3697E188F8BC195CDBF7CE89D099884 | SHA256:429000E5CB8AB5A5D20D030B8C865196F3C16C6B2425292F06872CEA35F50115 | |||
| 2580 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2580.18622\CIMB BizConverter v1.2.0.4\WindowsInstaller3_1\WindowsInstaller-KB893803-v2-x86.exe | executable | |
MD5:342F79337765760AD4E392EB67D5ED2C | SHA256:69B61B2C00323CEA3686315617D0F452E205DAE10C47E02CBE1EA96FEA38F582 | |||
| 2580 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2580.18622\CIMB BizConverter v1.2.0.4\DotNetFX40Client\dotNetFx40_Client_x86_x64.exe | executable | |
MD5:53406E9988306CBD4537677C5336ABA4 | SHA256:FA1AFFF978325F8818CE3A559D67A58297D9154674DE7FD8EB03656D93104425 | |||
| 2560 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\MSIAAE4.tmp | executable | |
MD5:5494165B1384FAEEFDD3D5133DF92F5A | SHA256:BA0AD3A4D2112B269E379A2231128E7EBE23E95D5D04878D6EE8815E657BB055 | |||
| 2560 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\MSIAB53.tmp | executable | |
MD5:5494165B1384FAEEFDD3D5133DF92F5A | SHA256:BA0AD3A4D2112B269E379A2231128E7EBE23E95D5D04878D6EE8815E657BB055 | |||
| 2580 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2580.19641\CIMB BizConverter v1.2.0.4\setup.exe | executable | |
MD5:7883F7FE717E0B329E8E8B1942B94D1F | SHA256:E3F67961ED52F52B98DD5A32AFD3A1E7CBF0CEB1ECC69E78EFF8BC8613C0603E | |||
| 2580 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2580.19641\CIMB BizConverter v1.2.0.4\CIMBBizConverterSetup.msi | executable | |
MD5:A3697E188F8BC195CDBF7CE89D099884 | SHA256:429000E5CB8AB5A5D20D030B8C865196F3C16C6B2425292F06872CEA35F50115 | |||
| 2580 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2580.19641\CIMB BizConverter v1.2.0.4\BizConverter_installation_guide.txt | text | |
MD5:F2AAFFE697244F9907B811406DF91F05 | SHA256:40439C02C4EE806BC359C2CD909E4F19A4CF65346C354465D5FDACE2E27DEDCE | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
Process | Message |
|---|---|
Setup.exe | The operation completed successfully.
|