File name:

Setup_for_Windows_64_32.zip

Full analysis: https://app.any.run/tasks/d4c41845-ddcf-4088-8bdf-0b58dcc20613
Verdict: Malicious activity
Threats:

Amadey is a formidable Windows infostealer threat, characterized by its persistence mechanisms, modular design, and ability to execute various malicious tasks.

Analysis date: March 31, 2023, 19:31:14
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
trojan
amadey
loader
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract
MD5:

67868EBAAB6B822187F155CA206C2977

SHA1:

D3FE25BADD2E2A7A52B8084D35560322A8C70458

SHA256:

C5D8BC4D847D8313F178F08C573EDD09B7EB37FD72E8A1E83B373C78EC5AF63A

SSDEEP:

196608:wybt5vlVbAl/rcx00r+U3lfD75Rf2eqn/dIM59:wU9KjcxHZVfD7nf2eqn//

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • oneetx.exe (PID: 3572)
    • Uses Task Scheduler to run other applications

      • oneetx.exe (PID: 3572)
    • Connects to the CnC server

      • oneetx.exe (PID: 3572)
    • AMADEY was detected

      • oneetx.exe (PID: 3572)
  • SUSPICIOUS

    • Reads the Internet Settings

      • Setup_for_Window`s_64_32.exe (PID: 2700)
      • oneetx.exe (PID: 3572)
    • Starts itself from another location

      • Setup_for_Window`s_64_32.exe (PID: 2700)
    • Application launched itself

      • cmd.exe (PID: 2708)
    • Starts CMD.EXE for commands execution

      • oneetx.exe (PID: 3572)
      • cmd.exe (PID: 2708)
    • Uses ICACLS.EXE to modify access control lists

      • cmd.exe (PID: 2708)
    • Connects to the server without a host name

      • oneetx.exe (PID: 3572)
    • The process executes via Task Scheduler

      • oneetx.exe (PID: 3836)
      • oneetx.exe (PID: 2464)
      • oneetx.exe (PID: 2712)
    • Executable content was dropped or overwritten

      • oneetx.exe (PID: 3572)
    • Uses RUNDLL32.EXE to load library

      • oneetx.exe (PID: 3572)
    • Process requests binary or script from the Internet

      • oneetx.exe (PID: 3572)
  • INFO

    • Reads the computer name

      • Setup_for_Window`s_64_32.exe (PID: 2700)
      • oneetx.exe (PID: 3572)
    • Checks supported languages

      • Setup_for_Window`s_64_32.exe (PID: 2700)
      • oneetx.exe (PID: 3572)
      • oneetx.exe (PID: 3836)
      • oneetx.exe (PID: 2712)
      • oneetx.exe (PID: 2464)
    • The process checks LSA protection

      • Setup_for_Window`s_64_32.exe (PID: 2700)
      • oneetx.exe (PID: 3572)
    • Reads the machine GUID from the registry

      • Setup_for_Window`s_64_32.exe (PID: 2700)
      • oneetx.exe (PID: 3572)
    • Create files in a temporary directory

      • Setup_for_Window`s_64_32.exe (PID: 2700)
      • oneetx.exe (PID: 3572)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2368)
    • Checks proxy server information

      • oneetx.exe (PID: 3572)
    • Creates files or folders in the user directory

      • oneetx.exe (PID: 3572)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: Setup_for_Window`s_64_32/
ZipUncompressedSize: -
ZipCompressedSize: -
ZipCRC: 0x00000000
ZipModifyDate: 2023:03:31 11:07:24
ZipCompression: None
ZipBitFlag: -
ZipRequiredVersion: 10
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
55
Monitored processes
16
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe setup_for_window`s_64_32.exe no specs setup_for_window`s_64_32.exe #AMADEY oneetx.exe schtasks.exe no specs cmd.exe no specs cmd.exe no specs cacls.exe no specs cacls.exe no specs cmd.exe no specs cacls.exe no specs cacls.exe no specs oneetx.exe no specs rundll32.exe no specs oneetx.exe no specs oneetx.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
852CACLS "oneetx.exe" /P "admin:N"C:\Windows\System32\cacls.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Control ACLs Program
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\cacls.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\apphelp.dll
884C:\Windows\system32\cmd.exe /S /D /c" echo Y"C:\Windows\System32\cmd.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1112C:\Windows\system32\cmd.exe /S /D /c" echo Y"C:\Windows\System32\cmd.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1272CACLS "..\eb256e24ee" /P "admin:R" /EC:\Windows\System32\cacls.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Control ACLs Program
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\cacls.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\apphelp.dll
1820"C:\Windows\System32\schtasks.exe" /Create /SC MINUTE /MO 1 /TN oneetx.exe /TR "C:\Users\admin\AppData\Local\Temp\eb256e24ee\oneetx.exe" /FC:\Windows\System32\schtasks.exeoneetx.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Manages scheduled tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
2368"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Setup_for_Windows_64_32.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\lpk.dll
c:\windows\system32\ntdll.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
2420CACLS "oneetx.exe" /P "admin:R" /EC:\Windows\System32\cacls.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Control ACLs Program
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\cacls.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\rpcrt4.dll
2464C:\Users\admin\AppData\Local\Temp\eb256e24ee\oneetx.exe C:\Users\admin\AppData\Local\Temp\eb256e24ee\oneetx.exetaskeng.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\eb256e24ee\oneetx.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
2624"C:\Windows\System32\rundll32.exe" C:\Users\admin\AppData\Roaming\8be7d7b3521979\clip.dll, MainC:\Windows\System32\rundll32.exeoneetx.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\kernel32.dll
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
2700"C:\Users\admin\AppData\Local\Temp\Rar$EXb2368.6800\Setup_for_Window`s_64_32\Setup_for_Window`s_64_32.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb2368.6800\Setup_for_Window`s_64_32\Setup_for_Window`s_64_32.exe
WinRAR.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb2368.6800\setup_for_window`s_64_32\setup_for_window`s_64_32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sspicli.dll
Total events
4 516
Read events
4 422
Write events
94
Delete events
0

Modification events

(PID) Process:(2368) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16D\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2368) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(2368) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2368) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(2368) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2368) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2368) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2368) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2368) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2368) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
Executable files
22
Suspicious files
18
Text files
334
Unknown types
0

Dropped files

PID
Process
Filename
Type
2368WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2368.6800\Setup_for_Window`s_64_32\Language\Deutsch.xmlxml
MD5:
SHA256:
2368WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2368.6800\Setup_for_Window`s_64_32\Language\English.xmlxml
MD5:
SHA256:
2368WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2368.6800\Setup_for_Window`s_64_32\Language\Japanese.xmlxml
MD5:
SHA256:
2368WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2368.6800\Setup_for_Window`s_64_32\Language\italiano.xmlxml
MD5:
SHA256:
2368WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2368.6800\Setup_for_Window`s_64_32\Language\Chinese.xmlxml
MD5:343825705C23B0A9C7FBA9BEEAAC05F5
SHA256:5707276F6917AADB4978DD13F7A421FD0A2514E17BF1352BABCDC993B22835ED
2368WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2368.6800\Setup_for_Window`s_64_32\Globalization\Time Zone\timezones.xmlxml
MD5:18E0EF07E9049182AB229930E12E85F0
SHA256:B906F2F0C6DAB2B02A4008D101A6711125DAB9C94712953DA72B1F66421143EC
2368WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2368.6800\Setup_for_Window`s_64_32\Globalization\Time Zone\timezoneMapping.xmlxml
MD5:F0281D2A00DDBBD90C9721F235B3124F
SHA256:D133EE1969118CC6048B31507497D3AF16C724A0D9CA4F666F5316785FC8A952
2368WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2368.6800\Setup_for_Window`s_64_32\Language\Danish.xmlxml
MD5:5CE313B8625ADE15150CCAC62B960D75
SHA256:04E16CB9E1E30093CE06604457140A76D6674AF1EC5F8DD3E2014FC88C0DA376
2368WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2368.6800\Setup_for_Window`s_64_32\Language\Chinese Traditional.xmlxml
MD5:71E8150855B133EFC2FB99396EAC84EA
SHA256:A8113C836E805EB82FA1B26E99BFC9D230CA375AD05F2A1311F921BD18B76A5C
2368WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2368.6800\Setup_for_Window`s_64_32\Language\Czech.xmlxml
MD5:B52A08B22245AA6737809A046994BA07
SHA256:F64F326B26F5100822DBB0F4D78291E474A0AA4F44A9332864589CD57BC8E300
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
2
DNS requests
0
Threats
10

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3572
oneetx.exe
POST
200
77.91.78.118:80
http://77.91.78.118/u83mfdS2/index.php?scr=1
RU
malicious
3572
oneetx.exe
GET
200
77.91.78.118:80
http://77.91.78.118/u83mfdS2/Plugins/clip.dll
RU
executable
89.0 Kb
malicious
3572
oneetx.exe
GET
404
77.91.78.118:80
http://77.91.78.118/u83mfdS2/Plugins/cred.dll
RU
html
162 b
malicious
3572
oneetx.exe
POST
200
77.91.78.118:80
http://77.91.78.118/u83mfdS2/index.php
RU
text
6 b
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3572
oneetx.exe
77.91.78.118:80
Foton Telecom CJSC
RU
malicious

DNS requests

No data

Threats

PID
Process
Class
Message
3572
oneetx.exe
A Network Trojan was detected
AV TROJAN Agent.DHOA System Info Exfiltration
3572
oneetx.exe
Unknown Classtype
ET MALWARE Amadey CnC Check-In
3572
oneetx.exe
A Network Trojan was detected
ET MALWARE Amadey Bot Activity (POST)
3572
oneetx.exe
Potentially Bad Traffic
ET INFO Dotted Quad Host DLL Request
3572
oneetx.exe
Potential Corporate Privacy Violation
AV POLICY HTTP request for .dll file with no User-Agent
3572
oneetx.exe
Potentially Bad Traffic
ET INFO Dotted Quad Host DLL Request
3572
oneetx.exe
Potential Corporate Privacy Violation
AV POLICY HTTP request for .dll file with no User-Agent
3572
oneetx.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
3572
oneetx.exe
Potentially Bad Traffic
ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download
3572
oneetx.exe
Misc activity
ET INFO EXE IsDebuggerPresent (Used in Malware Anti-Debugging)
No debug info