| File name: | AME Wizard Beta.zip |
| Full analysis: | https://app.any.run/tasks/478858f6-0487-42a6-bf72-2501128ee6e0 |
| Verdict: | Malicious activity |
| Analysis date: | September 25, 2024, 03:13:24 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract, compression method=deflate |
| MD5: | 2BE41DB4186F769FF9108231E75C1DA5 |
| SHA1: | 935B4A8EC709220A43228AEBB32C3EEFC1A777D4 |
| SHA256: | C982B80CFFB5CF6958CC145D4524E3D434D4047280E21EEF6EE5770C3A50E435 |
| SSDEEP: | 98304:c4/cb3SAdO3U8Cv5ykY/btM3THiYETbKscNQzTHO+rw1K+EMxNgNl9jFA5YXZ1n5:btZh+S3guCfyS03PT |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2024:09:09 19:25:42 |
| ZipCRC: | 0xffa81c28 |
| ZipCompressedSize: | 10741019 |
| ZipUncompressedSize: | 18487808 |
| ZipFileName: | AME Wizard Beta.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 644 | "C:\Program Files\Mozilla Firefox\firefox.exe" | C:\Program Files\Mozilla Firefox\firefox.exe | — | explorer.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 1644 | "C:\Program Files\Mozilla Firefox\firefox.exe" | C:\Program Files\Mozilla Firefox\firefox.exe | firefox.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 2256 | C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s Dnscache | C:\Windows\System32\svchost.exe | services.exe | ||||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2892 | "C:\Users\admin\Desktop\AME Wizard Beta.exe" | C:\Users\admin\Desktop\AME Wizard Beta.exe | explorer.exe | ||||||||||||
User: admin Company: Ameliorated LLC Integrity Level: MEDIUM Description: AME Wizard Version: 0.7.6 Modules
| |||||||||||||||
| 2936 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=2288 -parentBuildID 20240213221259 -prefsHandle 2280 -prefMapHandle 2276 -prefsLen 30537 -prefMapSize 244343 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {1a828a1d-137c-45d0-8292-cde4c0052a51} 1644 "\\.\pipe\gecko-crash-server-pipe.1644" 2ac08d80b10 socket | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 3880 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=4500 -childID 2 -isForBrowser -prefsHandle 4496 -prefMapHandle 4492 -prefsLen 36263 -prefMapSize 244343 -jsInitHandle 1356 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {384eb45f-a645-42df-9ba7-9710840719a3} 1644 "\\.\pipe\gecko-crash-server-pipe.1644" 2ac1c629bd0 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 4688 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=6052 -childID 5 -isForBrowser -prefsHandle 6060 -prefMapHandle 6064 -prefsLen 31161 -prefMapSize 244343 -jsInitHandle 1356 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {2055bfb0-a2a9-4a86-a460-84298b8f6ba3} 1644 "\\.\pipe\gecko-crash-server-pipe.1644" 2ac2073ba10 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 5268 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5696 -childID 3 -isForBrowser -prefsHandle 5456 -prefMapHandle 5608 -prefsLen 31161 -prefMapSize 244343 -jsInitHandle 1356 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {a8272d73-feed-4ab2-9a1d-b3686181a7f1} 1644 "\\.\pipe\gecko-crash-server-pipe.1644" 2ac2073bd90 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 5512 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\AME Wizard Beta.zip" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 5888 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5904 -childID 4 -isForBrowser -prefsHandle 5816 -prefMapHandle 5820 -prefsLen 31161 -prefMapSize 244343 -jsInitHandle 1356 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {3a1a2e2b-0310-43ce-85ab-93e78e8a5f67} 1644 "\\.\pipe\gecko-crash-server-pipe.1644" 2ac2073b850 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| (PID) Process: | (5512) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\GoogleChromeEnterpriseBundle64.zip | |||
| (PID) Process: | (5512) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\AME Wizard Beta.zip | |||
| (PID) Process: | (5512) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (5512) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (5512) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (5512) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (5512) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\MainWin |
| Operation: | write | Name: | Placement |
Value: 2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF1E01000033000000DE0400001C020000 | |||
| (PID) Process: | (5512) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths |
| Operation: | write | Name: | name |
Value: 256 | |||
| (PID) Process: | (5512) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (5512) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths |
| Operation: | write | Name: | psize |
Value: 80 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2892 | AME Wizard Beta.exe | C:\Users\admin\AppData\Local\Temp\AME\Ben.Demystifier.dll | executable | |
MD5:965D07F46CD56AE2A4F310921230C206 | SHA256:F49EC56E6D8DD1029F990C08DBFC8CA7C5E8EDD353D8D7BA35FAE2C6ADCAA1C9 | |||
| 2892 | AME Wizard Beta.exe | C:\Users\admin\AppData\Local\Temp\AME\DiscUtils.Iso9660.dll | executable | |
MD5:C7340CDF1E4AF72C007FE68694B7ECB5 | SHA256:4AA30F253343F3E130F4FF8DF0E955232134F339FFCB279CB8FE22A05ACC727D | |||
| 5512 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa5512.33300\AME Wizard Beta.exe | executable | |
MD5:3725BE198E6BC6B8AEC46060F3CFC2E4 | SHA256:AC2C0A54AC444CD2B093CC74BCDE2EAE1C9B154F1D1393C312165C8BECEB8347 | |||
| 2892 | AME Wizard Beta.exe | C:\Users\admin\AppData\Local\Temp\AME\7za.dll | executable | |
MD5:58FDBF10D3DCE4D2E270C03E8311D9DB | SHA256:0BBCC7BFC688A512911FBE679BBD279928F1B463431139685EBE39A98798134E | |||
| 2892 | AME Wizard Beta.exe | C:\Users\admin\AppData\Local\Temp\AME\client-helper.dll | executable | |
MD5:37FAF38D69284BDA23E383C000D946A3 | SHA256:0C84C4F52A981B57DA3C639D7F96DE0BD3E366C241B14972BA8A5F6D396DBD54 | |||
| 2892 | AME Wizard Beta.exe | C:\Users\admin\AppData\Local\Temp\AME\Newtonsoft.Json.dll | executable | |
MD5:195FFB7167DB3219B217C4FD439EEDD6 | SHA256:E1E27AF7B07EEEDF5CE71A9255F0422816A6FC5849A483C6714E1B472044FA9D | |||
| 2892 | AME Wizard Beta.exe | C:\Users\admin\AppData\Local\Temp\AME\msvcp140.dll | executable | |
MD5:1BA6D1CF0508775096F9E121A24E5863 | SHA256:74892D9B4028C05DEBAF0B9B5D9DC6D22F7956FA7D7EEE00C681318C26792823 | |||
| 2892 | AME Wizard Beta.exe | C:\Users\admin\AppData\Local\Temp\AME\7zxa.dll | executable | |
MD5:BC3754B7C77DFB6AED1722EF7F53B414 | SHA256:B54CAC90E649EBBF7C27CF1772F5C1644F4600DB88F0D51419A3529A5A5F95FC | |||
| 2892 | AME Wizard Beta.exe | C:\Users\admin\AppData\Local\Temp\AME\Microsoft.Bcl.TimeProvider.dll | executable | |
MD5:37E25D107CE1385DF1474780CBFA4636 | SHA256:693242B67DA91AF78DDA4B91D6020E0B8CDA08D4C9102177A12522009EF9B940 | |||
| 2892 | AME Wizard Beta.exe | C:\Users\admin\AppData\Local\Temp\AME\Microsoft.Win32.TaskScheduler.dll | executable | |
MD5:A844AC745A4005FBD3F51D79FF88583C | SHA256:74FE1A6A1E36BE7D893E31BBB4D4BD83BF4B927E715276CD5607982139818EBD | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
6660 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
5104 | svchost.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
1644 | firefox.exe | POST | 200 | 2.16.168.6:80 | http://r11.o.lencr.org/ | unknown | — | — | unknown |
1644 | firefox.exe | POST | 200 | 95.101.54.131:80 | http://r10.o.lencr.org/ | unknown | — | — | unknown |
1644 | firefox.exe | POST | 200 | 95.101.54.131:80 | http://r10.o.lencr.org/ | unknown | — | — | unknown |
1644 | firefox.exe | POST | 200 | 142.250.186.131:80 | http://o.pki.goog/wr2 | unknown | — | — | unknown |
1644 | firefox.exe | POST | 200 | 95.101.54.131:80 | http://r10.o.lencr.org/ | unknown | — | — | unknown |
1644 | firefox.exe | POST | 200 | 95.101.54.131:80 | http://r10.o.lencr.org/ | unknown | — | — | unknown |
1644 | firefox.exe | POST | 200 | 142.250.186.131:80 | http://o.pki.goog/wr2 | unknown | — | — | unknown |
7200 | SIHClient.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3888 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
5104 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4652 | RUXIMICS.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
2120 | MoUsoCoreWorker.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
5104 | svchost.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5104 | svchost.exe | 184.30.21.171:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
2892 | AME Wizard Beta.exe | 140.82.121.6:443 | api.github.com | GITHUB | US | whitelisted |
6660 | svchost.exe | 20.190.159.73:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
api.github.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
detectportal.firefox.com |
| whitelisted |
prod.detectportal.prod.cloudops.mozgcp.net |
| whitelisted |
contile.services.mozilla.com |
| whitelisted |
spocs.getpocket.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2256 | svchost.exe | Potentially Bad Traffic | ET DNS Query for .cc TLD |
2256 | svchost.exe | Potentially Bad Traffic | ET DNS Query for .cc TLD |
2256 | svchost.exe | Potentially Bad Traffic | ET DNS Query for .cc TLD |