File name:

BMW Coding Tool.zip

Full analysis: https://app.any.run/tasks/3aa1b0e0-2717-4246-aaf3-c3e29e6a3b71
Verdict: Malicious activity
Analysis date: November 21, 2023, 00:00:24
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

5EF7E9585A60430B4FD1BDBEEDC93C73

SHA1:

23E1317DA5C50FC76D417F709FEADA36B6899094

SHA256:

C59BC077DEC52BC231AAE78D304AE3AD4B0110E9D5DCE95C556C33D613253A74

SSDEEP:

98304:6fdgIx7QoQq50pZezk5KxP+4qVUSoBEaBBGn0TFz2jVuD6tzqKGuNeEW501HVAF+:UdxI7PpeTIDR

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Registers / Runs the DLL via REGSVR32.EXE

      • pwsh.exe (PID: 3808)
    • The DLL Hijacking

      • regsvr32.exe (PID: 1276)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 3128)
    • Creates/Modifies COM task schedule object

      • regsvr32.exe (PID: 2084)
  • INFO

    • Manual execution by a user

      • BMW Coding Tool.exe (PID: 4048)
      • explorer.exe (PID: 3464)
      • pwsh.exe (PID: 3808)
      • wmpnscfg.exe (PID: 1820)
      • taskmgr.exe (PID: 2792)
      • msedge.exe (PID: 272)
      • BMW Coding Tool.exe (PID: 1560)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 3128)
    • Checks supported languages

      • BMW Coding Tool.exe (PID: 4048)
      • pwsh.exe (PID: 3808)
      • wmpnscfg.exe (PID: 1820)
      • BMW Coding Tool.exe (PID: 1560)
    • Reads the machine GUID from the registry

      • BMW Coding Tool.exe (PID: 4048)
      • wmpnscfg.exe (PID: 1820)
      • BMW Coding Tool.exe (PID: 1560)
    • Create files in a temporary directory

      • BMW Coding Tool.exe (PID: 4048)
      • BMW Coding Tool.exe (PID: 1560)
    • Reads Microsoft Office registry keys

      • BMW Coding Tool.exe (PID: 4048)
      • BMW Coding Tool.exe (PID: 1560)
    • Reads mouse settings

      • BMW Coding Tool.exe (PID: 4048)
      • regsvr32.exe (PID: 2084)
      • BMW Coding Tool.exe (PID: 1560)
    • Reads the computer name

      • pwsh.exe (PID: 3808)
      • wmpnscfg.exe (PID: 1820)
      • BMW Coding Tool.exe (PID: 1560)
    • Application launched itself

      • msedge.exe (PID: 272)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2019:05:23 22:01:10
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: BMW Coding Tool/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
68
Monitored processes
27
Malicious processes
2
Suspicious processes
2

Behavior graph

Click at the process to see the details
start winrar.exe no specs explorer.exe no specs bmw coding tool.exe no specs pwsh.exe wmpnscfg.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs bmw coding tool.exe no specs taskmgr.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
272"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --single-argument http://%22c/Users/admin/Desktop/BMW%20Coding%20Tool%22C:\Program Files\Microsoft\Edge\Application\msedge.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
292"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=109.0.5414.149 "--annotation=exe=C:\Program Files\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win32 "--annotation=prod=Microsoft Edge" --annotation=ver=109.0.1518.115 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xd8,0x6953f598,0x6953f5a8,0x6953f5b4C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
888"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2332 --field-trial-handle=1328,i,9272051188503368187,15206529647333209245,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1276"C:\Windows\system32\regsvr32.exe" .\comdlg32.dllC:\Windows\System32\regsvr32.exepwsh.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
4
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1560"C:\Users\admin\Desktop\BMW Coding Tool\BMW Coding Tool.exe" C:\Users\admin\Desktop\BMW Coding Tool\BMW Coding Tool.exeexplorer.exe
User:
admin
Company:
E.J. Paulissen
Integrity Level:
MEDIUM
Description:
BMW Coding Tool
Exit code:
0
Version:
2.05
Modules
Images
c:\users\admin\desktop\bmw coding tool\bmw coding tool.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
1820"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ole32.dll
1944"C:\Windows\system32\regsvr32.exe" .\comdlg32.ocxC:\Windows\System32\regsvr32.exepwsh.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2084"C:\Windows\system32\regsvr32.exe" .\mscomctl.ocxC:\Windows\System32\regsvr32.exepwsh.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2476"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --first-renderer-process --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=2328 --field-trial-handle=1328,i,9272051188503368187,15206529647333209245,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2792"C:\Windows\system32\taskmgr.exe" /4C:\Windows\System32\taskmgr.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Task Manager
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskmgr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
8 444
Read events
8 286
Write events
114
Delete events
44

Modification events

(PID) Process:(3128) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\17A\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3128) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(3128) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3128) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3128) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3128) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3128) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3128) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3128) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
(PID) Process:(3128) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\General
Operation:writeName:LastFolder
Value:
C:\Users\admin\Desktop
Executable files
5
Suspicious files
27
Text files
34
Unknown types
0

Dropped files

PID
Process
Filename
Type
3128WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3128.32445\BMW Coding Tool\Windows6.1-KB977206-x64.msu
MD5:
SHA256:
3808pwsh.exeC:\Users\admin\AppData\Local\Microsoft\PowerShell\7.2.11\update1_v7.4.0_2023-11-16
MD5:
SHA256:
3128WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3128.32445\BMW Coding Tool\BMW Coding Tool.exeexecutable
MD5:0F18AE46F51E1CD48F6175C47EBEA20C
SHA256:40287A9CEFA6575955BDD573BB8D740D9D2F44A578C35E8994CB1F681ABC40BF
3128WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3128.32445\BMW Coding Tool\Translations.csvtext
MD5:88697461B2A717CE064095503D554FC6
SHA256:F02F60DEDCA0FB973D30C4919C625C1AD3A03C6EED88B97785B2515B416F9F1C
272msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF1af241.TMP
MD5:
SHA256:
272msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
3128WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3128.32445\BMW Coding Tool\comdlg32.dllexecutable
MD5:D1DE1EAFDE97BE41CF6585027FF3E732
SHA256:76F17D4DF440D6734DC8157092D94EB18C2A73A0A49BEEA289E7B3EDE30E86A2
3128WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3128.32445\BMW Coding Tool\mscomctl.ocxexecutable
MD5:714CF24FC19A20AE0DC701B48DED2CF6
SHA256:09F126E65D90026C3F659FF41B1287671B8CC1AA16240FC75DAE91079A6B9712
3128WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3128.32445\BMW Coding Tool\Codinglog.txttext
MD5:AF7A383C0CB25F86B3B0DA5B5657F6E2
SHA256:A69EC954315390A67A027B1E6CCAE6F9918027D7B2071BC1AE7AD73F958E50AD
272msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\c4f7a8c7-2b1c-4514-affb-b3d68f87ea89.tmpbinary
MD5:51F0600DD6FE99C79437169A68882FF9
SHA256:919AD0E5BBA014C56DD7E58FAF3001D25CFD9E77A581E5CC6F851FFA7831B7BA
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
15
DNS requests
15
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2588
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
3808
pwsh.exe
23.47.113.237:443
aka.ms
AKAMAI-AS
AE
unknown
3808
pwsh.exe
52.239.160.36:443
pscoretestdata.blob.core.windows.net
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
3808
pwsh.exe
13.69.106.208:443
dc.services.visualstudio.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
unknown
3080
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
272
msedge.exe
239.255.255.250:1900
whitelisted
3080
msedge.exe
204.79.197.239:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown

DNS requests

Domain
IP
Reputation
aka.ms
  • 23.47.113.237
whitelisted
pscoretestdata.blob.core.windows.net
  • 52.239.160.36
unknown
dc.services.visualstudio.com
  • 13.69.106.208
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
edge.microsoft.com
  • 204.79.197.239
  • 13.107.21.239
whitelisted
google.com
  • 142.250.186.174
  • 172.217.18.14
whitelisted
msedgeextensions.sf.tlu.dl.delivery.mp.microsoft.com
  • 8.241.122.252
  • 8.241.80.124
  • 8.238.206.252
whitelisted
www.bing.com
  • 104.126.37.162
  • 104.126.37.128
  • 104.126.37.163
  • 104.126.37.136
  • 104.126.37.139
  • 104.126.37.178
whitelisted

Threats

No threats detected
Process
Message
pwsh.exe
Profiler was prevented from loading notification profiler due to app settings. Process ID (decimal): 3808. Message ID: [0x2509].