analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

MSIFAF1.tmp.zip

Full analysis: https://app.any.run/tasks/36c67dd3-df32-40fb-8429-33f592252d9d
Verdict: Malicious activity
Threats:

FlawedAmmmyy is a RAT type malware that can be used to perform actions remotely on an infected PC. This malware is well known for being featured in especially large campaigns with wide target demographics.

Analysis date: February 19, 2019, 13:18:01
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
rat
flawedammyy
ammyy
trojan
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

3D5C540AD22B9575D501B1DD39B90D91

SHA1:

B455350E75E808B509C8324FC70977015B2F7E61

SHA256:

C7980E9014B6ABF25861B0D65B455500EABEEB1CBA1CB97B46159759A2D57CAF

SSDEEP:

1536:7JtspR7uFo17B5G9h6ci1PHbgPufKuG8iQaLxc8g663:7J4oEuKvKuG8iA8O3

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • wsus.exe (PID: 3096)
      • MSI7B3E.exe (PID: 3184)
      • wsus.exe (PID: 2580)
    • Loads the Task Scheduler DLL interface

      • MSI7B3E.exe (PID: 3184)
    • Loads the Task Scheduler COM API

      • MSI7B3E.exe (PID: 3184)
    • Changes the autorun value in the registry

      • MSI7B3E.exe (PID: 3184)
    • FLAWEDAMMYY was detected

      • wsus.exe (PID: 3096)
    • Connects to CnC server

      • wsus.exe (PID: 3096)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2748)
      • MSI7B3E.exe (PID: 3184)
    • Starts CMD.EXE for commands execution

      • MSI7B3E.exe (PID: 3184)
    • Creates files in the program directory

      • MSI7B3E.exe (PID: 3184)
    • Creates files in the Windows directory

      • MSI7B3E.exe (PID: 3184)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 788
ZipBitFlag: 0x0001
ZipCompression: Deflated
ZipModifyDate: 2019:02:19 05:55:23
ZipCRC: 0xb9be10f9
ZipCompressedSize: 75922
ZipUncompressedSize: 144064
ZipFileName: MSI7B3E.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
38
Monitored processes
6
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start drop and start winrar.exe msi7b3e.exe #FLAWEDAMMYY wsus.exe cmd.exe no specs wsus.exe no specs cmd.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2748"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\MSIFAF1.tmp.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
3184"C:\Users\admin\AppData\Local\Temp\Rar$EXb2748.31722\MSI7B3E.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb2748.31722\MSI7B3E.exe
WinRAR.exe
User:
admin
Company:
IBM Controler' System Security Control
Integrity Level:
MEDIUM
Description:
IBM Controler' System Security Control
Exit code:
0
Version:
2.8.17228.1
3096"C:\ProgramData\Microsofts Help\wsus.exe"C:\ProgramData\Microsofts Help\wsus.exe
MSI7B3E.exe
User:
admin
Company:
Microsoft Block Security
Integrity Level:
MEDIUM
Description:
Microsoft Block Security
Version:
1.18.2.51920
1948"C:\Windows\system32\cmd.exe" /c del C:\Users\admin\AppData\Local\Temp\RAR$EX~1.317\MSI7B3E.exe >> NULC:\Windows\system32\cmd.exeMSI7B3E.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
2580"C:\ProgramData\Microsofts Help\wsus.exe" C:\ProgramData\Microsofts Help\wsus.exetaskeng.exe
User:
admin
Company:
Microsoft Block Security
Integrity Level:
MEDIUM
Description:
Microsoft Block Security
Exit code:
0
Version:
1.18.2.51920
2808"C:\Windows\system32\cmd.exe" /c del C:\Users\admin\AppData\Local\Temp\RAR$EX~1.317\MSI7B3E.exe >> NULC:\Windows\system32\cmd.exeMSI7B3E.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Total events
558
Read events
514
Write events
44
Delete events
0

Modification events

(PID) Process:(2748) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2748) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2748) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2748) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\MSIFAF1.tmp.zip
(PID) Process:(2748) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2748) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2748) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2748) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2748) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
(PID) Process:(2748) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
Executable files
2
Suspicious files
4
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
3184MSI7B3E.exeC:\Windows\Tasks\Microsoft System Protect.jobbinary
MD5:F7D937384A9F018743C9B1F5518D9DC5
SHA256:2D6BBB8AE69075600EA57FA5C55F1AF944EB6A6FE3D97068C4891744AA7897E6
3184MSI7B3E.exeC:\ProgramData\Microsofts Help\template_ece330.DATAHASHbinary
MD5:DA80F64698FDCBE7C3284DF94DCCC6F3
SHA256:1FA3B63B9FD44F2C93B4D513BA33839F56094A2D7886C8E151BB9F11132CF5CD
3184MSI7B3E.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RB73MZ6Y\dat1[1].omgbinary
MD5:DA80F64698FDCBE7C3284DF94DCCC6F3
SHA256:1FA3B63B9FD44F2C93B4D513BA33839F56094A2D7886C8E151BB9F11132CF5CD
2748WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2748.31722\MSI7B3E.exeexecutable
MD5:CE0F37D5932FF0B583B79C6DCF7DAC7E
SHA256:4EFE3097DAC309A1619415E1EF8654F0B30B516E601D6C4C061CFCD9DD876968
3184MSI7B3E.exeC:\ProgramData\Microsofts Help\wsus.exeexecutable
MD5:30B4E109CAAEBAB50007872085E8D208
SHA256:7ECFD68341FE276C17246DC51C5D70EE2C1BBC6801C85201C8A62956C23D872D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
2
DNS requests
0
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3184
MSI7B3E.exe
GET
200
185.17.120.235:80
http://185.17.120.235/dat1.omg
RU
binary
657 Kb
suspicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3096
wsus.exe
185.99.133.2:80
Zappie Host LLC
NZ
malicious
3184
MSI7B3E.exe
185.17.120.235:80
Leaseweb Deutschland GmbH
RU
suspicious

DNS requests

No data

Threats

PID
Process
Class
Message
3096
wsus.exe
A Network Trojan was detected
MALWARE [PTsecurity] FlawedAmmyy.RAT
3096
wsus.exe
A Network Trojan was detected
MALWARE [PTsecurity] AMMYY RAT
3096
wsus.exe
A Network Trojan was detected
ET TROJAN Win32/FlawedAmmyy RAT CnC Checkin
3096
wsus.exe
A Network Trojan was detected
MALWARE [PTsecurity] FlawedAmmyy.RAT Checkin
Process
Message
MSI7B3E.exe
C:\ProgramData\Microsofts Help\template_ece330.DATAHASH
MSI7B3E.exe
--End Dowload--