analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

Mbr Owerwrite.zip

Full analysis: https://app.any.run/tasks/57a9d60d-bd37-4442-9838-10dc26f2fd66
Verdict: Malicious activity
Analysis date: March 27, 2021, 10:39:50
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

95D238DA651401A19CC55D9864A9A27B

SHA1:

6E5FD47EC95A3C66552CB234FCFC8552BAE908A6

SHA256:

C25594D76A8034F7227A7B4497870FBB26166A78F507B378802719C07E473C79

SSDEEP:

196608:MuP3TuU9/mykaTn0k++dNeH+TSZuP53Dso3N7yRF9AAyOesGcEI4i/F6YkNWj10l:9ruU9eyzr3+4WZo3oo9+RFQ6FFyg47k0

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • MBR - Image Builder.exe (PID: 3052)
      • 1.exe (PID: 2996)
      • 1.exe (PID: 1892)
      • MBR - Note Builder.exe (PID: 3900)
      • MBR - Image Builder.exe (PID: 1144)
    • Low-level write access rights to disk partition

      • 1.exe (PID: 2996)
  • SUSPICIOUS

    • Application launched itself

      • 1.exe (PID: 1892)
    • Low-level read access rights to disk partition

      • 1.exe (PID: 2996)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3072)
      • MBR - Note Builder.exe (PID: 3900)
    • Drops a file with too old compile date

      • MBR - Note Builder.exe (PID: 3900)
      • WinRAR.exe (PID: 3072)
  • INFO

    • Manual execution by user

      • WINWORD.EXE (PID: 280)
      • cmd.exe (PID: 2652)
      • 1.exe (PID: 1892)
      • MBR - Note Builder.exe (PID: 3900)
      • MBR - Image Builder.exe (PID: 3052)
      • MBR - Image Builder.exe (PID: 1144)
    • Creates files in the user directory

      • WINWORD.EXE (PID: 280)
    • Reads Microsoft Office registry keys

      • WINWORD.EXE (PID: 280)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: MBR - Image Builder.exe
ZipUncompressedSize: 11808256
ZipCompressedSize: 11289513
ZipCRC: 0x2872551f
ZipModifyDate: 2019:11:03 03:16:14
ZipCompression: Deflated
ZipBitFlag: -
ZipRequiredVersion: 20
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
55
Monitored processes
9
Malicious processes
5
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe mbr - image builder.exe no specs mbr - note builder.exe winword.exe no specs 1.exe no specs 1.exe cmd.exe no specs bcdedit.exe no specs mbr - image builder.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3072"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Mbr Owerwrite.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
3052"C:\Users\admin\Desktop\MBR - Image Builder.exe" C:\Users\admin\Desktop\MBR - Image Builder.exeexplorer.exe
User:
admin
Company:
WobbyChip
Integrity Level:
MEDIUM
Description:
Create Custom MBR With Your Image
Exit code:
0
Version:
1.0.0.0
3900"C:\Users\admin\Desktop\MBR - Note Builder.exe" C:\Users\admin\Desktop\MBR - Note Builder.exe
explorer.exe
User:
admin
Company:
WobbyChip
Integrity Level:
MEDIUM
Description:
Create Custom MBR With Your Text And Colors
Exit code:
0
Version:
3.1.0.0
280"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\Desktop\franciscochat.rtf"C:\Program Files\Microsoft Office\Office14\WINWORD.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Word
Exit code:
0
Version:
14.0.6024.1000
1892"C:\Users\admin\Desktop\1.exe" C:\Users\admin\Desktop\1.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
2996"C:\Users\admin\Desktop\1.exe" C:\Users\admin\Desktop\1.exe
1.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
2652"C:\Windows\system32\cmd.exe" C:\Windows\system32\cmd.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
3221225786
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
2424bcdedit /fixmbrC:\Windows\system32\bcdedit.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Boot Configuration Data Editor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
1144"C:\Users\admin\Desktop\MBR - Image Builder.exe" C:\Users\admin\Desktop\MBR - Image Builder.exeexplorer.exe
User:
admin
Company:
WobbyChip
Integrity Level:
MEDIUM
Description:
Create Custom MBR With Your Image
Exit code:
0
Version:
1.0.0.0
Total events
1 373
Read events
1 229
Write events
0
Delete events
0

Modification events

No data
Executable files
5
Suspicious files
0
Text files
0
Unknown types
1

Dropped files

PID
Process
Filename
Type
3072WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3072.45123\MBR - Image Builder.exe
MD5:
SHA256:
280WINWORD.EXEC:\Users\admin\AppData\Local\Temp\CVRE568.tmp.cvr
MD5:
SHA256:
280WINWORD.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{B280FE5C-583A-4A66-B392-3A5D10268599}.tmp
MD5:
SHA256:
3900MBR - Note Builder.exeC:\Users\admin\Desktop\1.exeexecutable
MD5:5104102084B4CAB24504A6B09F0F6455
SHA256:6DEF97B4612DEEFE6863507F54D749A4569F1F4008F2BADC4DFC9FD4607D3B08
280WINWORD.EXEC:\Users\admin\AppData\Roaming\Microsoft\Templates\~$Normal.dotmpgc
MD5:0173633075FD2D6AAC2DC249B75EB92B
SHA256:8A3DE4505B2DD4D45E7BCDFE86C635DC628D433E914CA0B5F7FA879036068CD1
3072WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3072.45312\MBR - Note Builder.exeexecutable
MD5:631E45F7BD3D32363362F09CBFBDFBAE
SHA256:FEF9F05FBB339B16A15848A1B4D743857CCCA6E347818CAD687DFC78119803E0
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info