| File name: | cocosenor-outlook-password-tuner.zip |
| Full analysis: | https://app.any.run/tasks/c59419dd-747e-45ea-bc40-cc8925765946 |
| Verdict: | Malicious activity |
| Analysis date: | November 24, 2023, 05:55:49 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | 889898727E08AA9A0943A8DAA3B6F6FE |
| SHA1: | 7CDF6AB174523FB5B0966096EFFF1E0E18314CBE |
| SHA256: | C8C436AA153BBE80AFBE523A2C045A0E6E6724409D8E7D8B2C09F5BEA8C90A42 |
| SSDEEP: | 98304:Igph3YYffNQdBhgq8wUtVpglt7Jl2a+/FikBH+2Y3YovlaUUYc5Fr4EmNR5i8mk6:V+WUbDcMLChMyjb |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2023:11:24 11:22:26 |
| ZipCRC: | 0xaccdfec2 |
| ZipCompressedSize: | 6825334 |
| ZipUncompressedSize: | 7003682 |
| ZipFileName: | cocosenor-outlook-password-tuner.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 280 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3868 --field-trial-handle=1284,i,17462505162318745625,5248715078688146360,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1032 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --first-renderer-process --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=2300 --field-trial-handle=1284,i,17462505162318745625,5248715078688146360,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1228 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3796 --field-trial-handle=1284,i,17462505162318745625,5248715078688146360,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1508 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2316 --field-trial-handle=1284,i,17462505162318745625,5248715078688146360,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1584 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3828 --field-trial-handle=1284,i,17462505162318745625,5248715078688146360,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1644 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1988 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --use-gl=angle --use-angle=swiftshader-webgl --mojo-platform-channel-handle=1468 --field-trial-handle=1284,i,17462505162318745625,5248715078688146360,131072 /prefetch:2 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 2112 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=3768 --field-trial-handle=1284,i,17462505162318745625,5248715078688146360,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 2136 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=1360 --field-trial-handle=1284,i,17462505162318745625,5248715078688146360,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 2628 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3664 --field-trial-handle=1284,i,17462505162318745625,5248715078688146360,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| (PID) Process: | (3460) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\17A\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3460) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (3460) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (3460) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (3460) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3460) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3460) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3460) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (3460) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (3460) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3500 | cocosenor-outlook-password-tuner.exe | C:\Program Files\Cocosenor Outlook Password Tuner\CocosenorDictionary.txt | — | |
MD5:— | SHA256:— | |||
| 3500 | cocosenor-outlook-password-tuner.exe | C:\Program Files\Cocosenor Outlook Password Tuner\iconv.dll | executable | |
MD5:73AF5773BF5627FE771BF6809EC839F9 | SHA256:6CD69191469BF13F0CEA70837BAC9B1E7871C116F5F6F18BEF5A6A9575C020C9 | |||
| 3500 | cocosenor-outlook-password-tuner.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Cocosenor Outlook Password Tuner\Cocosenor Outlook Password Tuner.lnk | binary | |
MD5:D2F1EECBAE40D41EE3DDD4A0EF6BD2AF | SHA256:9AC4816A06AA74D4827F1AB28351275AA03444F262F8D94C589424A8E287224C | |||
| 3500 | cocosenor-outlook-password-tuner.exe | C:\Users\admin\Desktop\Cocosenor Outlook Password Tuner.lnk | binary | |
MD5:B2BF18708AD11307EFE1D8D094BC7074 | SHA256:5C8BB8C8CE72A678598788FC9D3AC84767F80692906F0CD26F71050F577DB4D7 | |||
| 3500 | cocosenor-outlook-password-tuner.exe | C:\Program Files\Cocosenor Outlook Password Tuner\Images\Button_Top_BuyNow.png | image | |
MD5:C337DB311C615B7CB955CEEE342DCA89 | SHA256:9DADE4B7275BB6F39979E70A5F3D97E89750D482882C7EF95091DB2F878D3719 | |||
| 3500 | cocosenor-outlook-password-tuner.exe | C:\Users\admin\AppData\Local\Temp\nsy8D9F.tmp\modern-wizard.bmp | image | |
MD5:29A6DC98F847F233800E38427542A595 | SHA256:98E25AD506510DAB2191A1666ADDFDB0CBF6E3D4B15266D09D1B0EBF6E6F9B24 | |||
| 3500 | cocosenor-outlook-password-tuner.exe | C:\Program Files\Cocosenor Outlook Password Tuner\Images\Button_Top_About.png | image | |
MD5:E70D13EB681BD7F1277E6090E366AD8F | SHA256:17DE079DCBFD7F4DC303337C04DF2CD280325BDA35BEF36308347BC4E185B2B7 | |||
| 3500 | cocosenor-outlook-password-tuner.exe | C:\Program Files\Cocosenor Outlook Password Tuner\Images\Button_OpenFile.png | image | |
MD5:7C5A4B8CD247344083CDBC056A197CD3 | SHA256:D0A00837F7080721D7EE46FDBC6FBD1ADC293C5979D6020C61C2CC7E46D5D3E1 | |||
| 3500 | cocosenor-outlook-password-tuner.exe | C:\Program Files\Cocosenor Outlook Password Tuner\Images\Button_Top_OpenFile.png | image | |
MD5:52A5144CE7E5110F6F2337329C2069FC | SHA256:C87744EC54AB5A1EE03EFDEA69B2A62553BE5C65A95063806EFFCB944196159B | |||
| 3500 | cocosenor-outlook-password-tuner.exe | C:\Program Files\Cocosenor Outlook Password Tuner\Images\Button_Top_Stop.png | image | |
MD5:F4FDDC1B147899D7C18BDD0BD6E38258 | SHA256:66EA0BC88C880913DCCA466C8C1F508BECEA63F91EEBC0D80FCAFCCD873BE018 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4020 | msedge.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
3696 | msedge.exe | 13.107.42.16:443 | config.edge.skype.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
3696 | msedge.exe | 162.241.172.26:443 | www.cocosenor.com | UNIFIEDLAYER-AS-1 | US | unknown |
3696 | msedge.exe | 20.105.95.163:443 | nav-edge.smartscreen.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
3696 | msedge.exe | 204.79.197.239:443 | edge.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
3696 | msedge.exe | 104.20.218.77:443 | www.statcounter.com | CLOUDFLARENET | — | unknown |
Domain | IP | Reputation |
|---|---|---|
config.edge.skype.com |
| whitelisted |
www.cocosenor.com |
| unknown |
nav-edge.smartscreen.microsoft.com |
| whitelisted |
edge.microsoft.com |
| whitelisted |
data-edge.smartscreen.microsoft.com |
| whitelisted |
www.statcounter.com |
| whitelisted |
ajax.googleapis.com |
| whitelisted |
c.disquscdn.com |
| shared |
www.google-analytics.com |
| whitelisted |
www.googleadservices.com |
| whitelisted |