File name:

CRM9250NTest_V1.2B67.zip

Full analysis: https://app.any.run/tasks/b6c2997d-6870-4741-b3cd-a4bb720965dd
Verdict: Malicious activity
Analysis date: August 23, 2024, 03:11:51
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=store
MD5:

5F944A217E0946F65DC888B758791E5E

SHA1:

6F5F2805FF5CB5CC9A2C616D3BE0BFAA5D857A78

SHA256:

C64E3287C414B003C0011BB22B017179ADD8C08F150D9ABE7B187CC6B3118517

SSDEEP:

98304:A/CMEFjMw3moM6bwVkD9oowBn9wYKfQeGP0k8QvwyWWGSIzCZ+Cng4edpFbbaZdE:D+0ZHTAEb5Q0

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • The DLL Hijacking

      • MSACCESS.EXE (PID: 3544)
      • MSACCESS.EXE (PID: 3424)
  • SUSPICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 2396)
    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 2396)
    • Starts a Microsoft application from unusual location

      • taskkill.exe (PID: 3376)
      • taskkill.exe (PID: 3708)
    • Searches for installed software

      • MSACCESS.EXE (PID: 3544)
      • MSACCESS.EXE (PID: 3424)
    • Reads the Internet Settings

      • MSACCESS.EXE (PID: 3544)
      • MSACCESS.EXE (PID: 3424)
    • Reads settings of System Certificates

      • MSACCESS.EXE (PID: 3544)
      • MSACCESS.EXE (PID: 3424)
  • INFO

    • Checks supported languages

      • taskkill.exe (PID: 3376)
      • wmpnscfg.exe (PID: 3704)
      • MSACCESS.EXE (PID: 3544)
      • MSACCESS.EXE (PID: 3424)
      • taskkill.exe (PID: 3708)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2396)
    • Manual execution by a user

      • CRM9250NTest.exe (PID: 3576)
      • wmpnscfg.exe (PID: 3704)
      • MSACCESS.EXE (PID: 3544)
      • taskkill.exe (PID: 3376)
      • MSACCESS.EXE (PID: 3424)
      • taskkill.exe (PID: 3708)
      • CRM9250NTest.exe (PID: 3004)
    • Reads the computer name

      • taskkill.exe (PID: 3376)
      • wmpnscfg.exe (PID: 3704)
      • MSACCESS.EXE (PID: 3544)
      • MSACCESS.EXE (PID: 3424)
      • taskkill.exe (PID: 3708)
    • Reads Environment values

      • MSACCESS.EXE (PID: 3544)
      • MSACCESS.EXE (PID: 3424)
    • Reads Microsoft Office registry keys

      • MSACCESS.EXE (PID: 3544)
      • MSACCESS.EXE (PID: 3424)
    • Create files in a temporary directory

      • MSACCESS.EXE (PID: 3544)
      • MSACCESS.EXE (PID: 3424)
    • Creates files or folders in the user directory

      • MSACCESS.EXE (PID: 3544)
      • MSACCESS.EXE (PID: 3424)
    • Checks proxy server information

      • MSACCESS.EXE (PID: 3544)
      • MSACCESS.EXE (PID: 3424)
    • Process checks whether UAC notifications are on

      • MSACCESS.EXE (PID: 3544)
      • MSACCESS.EXE (PID: 3424)
    • Reads the software policy settings

      • MSACCESS.EXE (PID: 3544)
      • MSACCESS.EXE (PID: 3424)
    • Process checks computer location settings

      • MSACCESS.EXE (PID: 3544)
      • MSACCESS.EXE (PID: 3424)
    • Reads the machine GUID from the registry

      • MSACCESS.EXE (PID: 3424)
      • MSACCESS.EXE (PID: 3544)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2024:06:26 16:11:24
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: CRM9250NTest_V1.2B67/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
56
Monitored processes
8
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe crm9250ntest.exe no specs taskkill.exe no specs wmpnscfg.exe no specs msaccess.exe msaccess.exe taskkill.exe crm9250ntest.exe

Process information

PID
CMD
Path
Indicators
Parent process
2396"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\CRM9250NTest_V1.2B67.zipC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3004"C:\Users\admin\Desktop\CRM9250NTest_V1.2B67\CRM9250NTest.exe" C:\Users\admin\Desktop\CRM9250NTest_V1.2B67\CRM9250NTest.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
CRM9250NTest
Exit code:
3221225781
Version:
V1.0
Modules
Images
c:\users\admin\desktop\crm9250ntest_v1.2b67\crm9250ntest.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\desktop\crm9250ntest_v1.2b67\crm9250nvdll.dll
c:\users\admin\desktop\crm9250ntest_v1.2b67\siusbxp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
3376"C:\Users\admin\Desktop\CRM9250NTest_V1.2B67\taskkill.exe" C:\Users\admin\Desktop\CRM9250NTest_V1.2B67\taskkill.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Kill Process
Exit code:
1
Version:
5.1.2600.5512 (xpsp.080413-2105)
Modules
Images
c:\users\admin\desktop\crm9250ntest_v1.2b67\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3424"C:\Program Files\Microsoft Office\Office14\MSACCESS.EXE" /NOSTARTUP "C:\Users\admin\Desktop\CRM9250NTest_V1.2B67\CRM9250Nb.mdb" C:\Program Files\microsoft office\Office14\MSACCESS.EXE
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Access
Exit code:
0
Version:
14.0.6024.1000
Modules
Images
c:\program files\microsoft office\office14\msaccess.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3544"C:\Program Files\Microsoft Office\Office14\MSACCESS.EXE" /NOSTARTUP "C:\Users\admin\Desktop\CRM9250NTest_V1.2B67\CRM9250N.mdb" C:\Program Files\microsoft office\Office14\MSACCESS.EXE
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Access
Exit code:
0
Version:
14.0.6024.1000
Modules
Images
c:\program files\microsoft office\office14\msaccess.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3576"C:\Users\admin\Desktop\CRM9250NTest_V1.2B67\CRM9250NTest.exe" C:\Users\admin\Desktop\CRM9250NTest_V1.2B67\CRM9250NTest.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
CRM9250NTest
Exit code:
3221225781
Version:
V1.0
Modules
Images
c:\users\admin\desktop\crm9250ntest_v1.2b67\crm9250ntest.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\desktop\crm9250ntest_v1.2b67\crm9250nvdll.dll
c:\users\admin\desktop\crm9250ntest_v1.2b67\siusbxp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
3704"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
3708"C:\Users\admin\Desktop\CRM9250NTest_V1.2B67\taskkill.exe" C:\Users\admin\Desktop\CRM9250NTest_V1.2B67\taskkill.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Kill Process
Exit code:
1
Version:
5.1.2600.5512 (xpsp.080413-2105)
Modules
Images
c:\users\admin\desktop\crm9250ntest_v1.2b67\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
18 182
Read events
17 844
Write events
145
Delete events
193

Modification events

(PID) Process:(2396) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2396) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2396) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2396) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(2396) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2396) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(2396) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\CRM9250NTest_V1.2B67.zip
(PID) Process:(2396) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2396) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2396) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
12
Suspicious files
6
Text files
17
Unknown types
1

Dropped files

PID
Process
Filename
Type
2396WinRAR.exeC:\Users\admin\Desktop\CRM9250NTest_V1.2B67\CRM9250N.mdb
MD5:
SHA256:
2396WinRAR.exeC:\Users\admin\Desktop\CRM9250NTest_V1.2B67\CRM9250Nb.mdb
MD5:
SHA256:
2396WinRAR.exeC:\Users\admin\Desktop\CRM9250NTest_V1.2B67\help.chm
MD5:
SHA256:
2396WinRAR.exeC:\Users\admin\Desktop\CRM9250NTest_V1.2B67\CRM9250DCSet.iniini
MD5:DCC31229FCEA1BDF20A4E0EF8D4B8C16
SHA256:F120E97E7EFA6FD4C7AB1E7885F18A260B5C42E22DFBF515D2C33BDA43A1DFA7
2396WinRAR.exeC:\Users\admin\Desktop\CRM9250NTest_V1.2B67\CRM9250NVDll.dllexecutable
MD5:6527EC66E899F0919E446A638CA046A8
SHA256:4ECA76BDFAB2391FE1BEA171C1E96176E432255B9DC4AE88696D29141952B36E
2396WinRAR.exeC:\Users\admin\Desktop\CRM9250NTest_V1.2B67\CRM9250DevDll.dllexecutable
MD5:C820C71926E85A6A348B1CE1E4874F61
SHA256:A3DB6CBC1AECBB287A66806088963CCF5CF0FABDFAF2B69C23176194E3986467
2396WinRAR.exeC:\Users\admin\Desktop\CRM9250NTest_V1.2B67\NvApi.dllexecutable
MD5:C25AE139E743F235A5869574D833CE22
SHA256:295F320FB3398791E735160E14F28E050A1343290803DCF1928BF5A1984C85E8
2396WinRAR.exeC:\Users\admin\Desktop\CRM9250NTest_V1.2B67\GRGDTATM_CommCfg.initext
MD5:2236E3D993E8C4D890B3F92D277E4ECB
SHA256:E0D39A69CA0460B1EAA8562427E3C03BFA552FD354C6337B21A66218C0538E80
2396WinRAR.exeC:\Users\admin\Desktop\CRM9250NTest_V1.2B67\PlusInfo.initext
MD5:99FF391E1C7BFA044BBA55DE63733596
SHA256:86AAEFD9DEEB785E6F0A8D01A3D8BD040AD3A9E63943EDE5AD70E21F9E3E151D
2396WinRAR.exeC:\Users\admin\Desktop\CRM9250NTest_V1.2B67\CRM9250NTest.exeexecutable
MD5:6AC1A6E4E19C96B3BD15C2BEDC5F156C
SHA256:81821F7B67D444EF46CA4DA64A8830F63ED137300F1A5EED51FAF21A47346706
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
10
TCP/UDP connections
14
DNS requests
8
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3424
MSACCESS.EXE
POST
302
184.28.89.167:80
http://go.microsoft.com/fwlink/?LinkID=120752
unknown
whitelisted
1372
svchost.exe
GET
304
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?33775f6043c93e33
unknown
whitelisted
3544
MSACCESS.EXE
POST
302
184.30.17.189:80
http://go.microsoft.com/fwlink/?LinkID=120750
unknown
whitelisted
1372
svchost.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1060
svchost.exe
GET
304
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?67a3611ec3c0260d
unknown
whitelisted
3544
MSACCESS.EXE
POST
302
184.30.17.189:80
http://go.microsoft.com/fwlink/?LinkID=120751
unknown
whitelisted
1372
svchost.exe
GET
200
23.32.238.107:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
3544
MSACCESS.EXE
POST
302
184.30.17.189:80
http://go.microsoft.com/fwlink/?LinkID=120752
unknown
whitelisted
3424
MSACCESS.EXE
POST
302
184.28.89.167:80
http://go.microsoft.com/fwlink/?LinkID=120750
unknown
whitelisted
3424
MSACCESS.EXE
POST
302
184.28.89.167:80
http://go.microsoft.com/fwlink/?LinkID=120751
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
224.0.0.252:5355
whitelisted
1372
svchost.exe
51.124.78.146:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1060
svchost.exe
224.0.0.252:5355
whitelisted
1372
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
1372
svchost.exe
93.184.221.240:80
ctldl.windowsupdate.com
EDGECAST
GB
whitelisted
1372
svchost.exe
23.32.238.107:80
crl.microsoft.com
Akamai International B.V.
DE
unknown
1372
svchost.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
unknown
3544
MSACCESS.EXE
184.30.17.189:80
go.microsoft.com
AKAMAI-AS
DE
unknown

DNS requests

Domain
IP
Reputation
google.com
  • 216.58.206.46
whitelisted
settings-win.data.microsoft.com
  • 40.127.240.158
whitelisted
ctldl.windowsupdate.com
  • 93.184.221.240
whitelisted
crl.microsoft.com
  • 23.32.238.107
  • 23.32.238.112
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
go.microsoft.com
  • 184.30.17.189
  • 184.28.89.167
whitelisted
activation.sls.microsoft.com
  • 40.91.76.224
whitelisted

Threats

No threats detected
Process
Message
MSACCESS.EXE
C:\Users\admin\AppData\Roaming\Microsoft\Access\System.mdw