File name:

13637570622.zip

Full analysis: https://app.any.run/tasks/932dd450-a97f-4e5d-b56a-d6081d5921f2
Verdict: Malicious activity
Analysis date: December 20, 2023, 14:08:22
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

69498407112893D4B3C4C98B88581EFF

SHA1:

D3C6E0C131C388CF70E8D9433A70852CF22F4891

SHA256:

C9C71D98989AF8739C6C98D6A90A3FA47475330B1CC008FE02F96D008CB6D774

SSDEEP:

393216:l0E/pwkgv5Lw4MNIg+SehH/h4PkXsqXyIh8Z/sb01A:HpwF5s4tg+Se9W6nCZ/swC

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Advanced_IP_Scanner.exe (PID: 6136)
      • setup.exe (PID: 5588)
      • Advanced_IP_Scanner.tmp (PID: 1724)
      • Advanced_IP_Scanner.exe (PID: 2968)
  • SUSPICIOUS

    • Application launched itself

      • WinRAR.exe (PID: 5164)
    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 1904)
      • setup.exe (PID: 5588)
      • Advanced_IP_Scanner.tmp (PID: 1724)
    • Loads Python modules

      • pythonw.exe (PID: 4288)
      • pythonw.exe (PID: 776)
    • The process drops C-runtime libraries

      • setup.exe (PID: 5588)
    • Reads the Windows owner or organization settings

      • Advanced_IP_Scanner.tmp (PID: 1724)
  • INFO

    • Checks supported languages

      • TextInputHost.exe (PID: 2496)
      • setup.exe (PID: 5588)
      • Advanced_IP_Scanner.exe (PID: 6136)
      • Advanced_IP_Scanner.tmp (PID: 1724)
      • pythonw.exe (PID: 4288)
      • Advanced_IP_Scanner.exe (PID: 2968)
      • setup.exe (PID: 5408)
      • Advanced_IP_Scanner.tmp (PID: 1372)
      • pythonw.exe (PID: 776)
    • Reads the computer name

      • TextInputHost.exe (PID: 2496)
      • setup.exe (PID: 5588)
      • Advanced_IP_Scanner.tmp (PID: 1724)
      • setup.exe (PID: 5408)
      • Advanced_IP_Scanner.tmp (PID: 1372)
    • Process checks computer location settings

      • setup.exe (PID: 5588)
      • setup.exe (PID: 5408)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 1904)
    • Create files in a temporary directory

      • Advanced_IP_Scanner.exe (PID: 6136)
      • Advanced_IP_Scanner.tmp (PID: 1724)
      • Advanced_IP_Scanner.exe (PID: 2968)
    • Creates files or folders in the user directory

      • setup.exe (PID: 5588)
    • Reads the machine GUID from the registry

      • pythonw.exe (PID: 4288)
      • pythonw.exe (PID: 776)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0009
ZipCompression: Deflated
ZipModifyDate: 1980:00:00 00:00:00
ZipCRC: 0x21e54071
ZipCompressedSize: 42581401
ZipUncompressedSize: 42569435
ZipFileName: 502f28c06338d9fc9c2994292be0f8dea3a199455ca749307b3bfc29fec5ca83
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
135
Monitored processes
11
Malicious processes
4
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe no specs textinputhost.exe no specs winrar.exe no specs setup.exe no specs advanced_ip_scanner.exe advanced_ip_scanner.tmp no specs pythonw.exe no specs setup.exe no specs advanced_ip_scanner.exe advanced_ip_scanner.tmp no specs pythonw.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
776C:\Users\admin\AppData\Local\Notepad\pythonw.exe C:\Users\admin\AppData\Local\Notepad\slv.pyC:\Users\admin\AppData\Local\Notepad\pythonw.exesetup.exe
User:
admin
Company:
Python Software Foundation
Integrity Level:
MEDIUM
Description:
Python
Exit code:
2
Version:
3.10.11
Modules
Images
c:\users\admin\appdata\local\notepad\pythonw.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\users\admin\appdata\local\notepad\vcruntime140.dll
c:\users\admin\appdata\local\notepad\python310.dll
c:\windows\system32\version.dll
c:\windows\system32\ws2_32.dll
1372"C:\Users\admin\AppData\Local\Temp\is-NRJK8.tmp\Advanced_IP_Scanner.tmp" /SL5="$4029A,20439558,139776,C:\Users\Public\Downloads\Advanced_IP_Scanner.exe" C:\Users\admin\AppData\Local\Temp\is-NRJK8.tmp\Advanced_IP_Scanner.tmpAdvanced_IP_Scanner.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
1
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-nrjk8.tmp\advanced_ip_scanner.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
1724"C:\Users\admin\AppData\Local\Temp\is-A2JFI.tmp\Advanced_IP_Scanner.tmp" /SL5="$30296,20439558,139776,C:\Users\Public\Downloads\Advanced_IP_Scanner.exe" C:\Users\admin\AppData\Local\Temp\is-A2JFI.tmp\Advanced_IP_Scanner.tmpAdvanced_IP_Scanner.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
2
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-a2jfi.tmp\advanced_ip_scanner.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
1904"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\Rar$DIb5164.32364\502f28c06338d9fc9c2994292be0f8dea3a199455ca749307b3bfc29fec5ca83.zipC:\Program Files\WinRAR\WinRAR.exeWinRAR.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
2496"C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\InputApp\TextInputHost.exe" -ServerName:InputApp.AppX9jnwykgrccxc8by3hsrsh07r423xzvav.mcaC:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\InputApp\TextInputHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Exit code:
0
Version:
2001.22012.0.3920
Modules
Images
c:\windows\systemapps\microsoftwindows.client.cbs_cw5n1h2txyewy\inputapp\textinputhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.27323.0_x64__8wekyb3d8bbwe\vcruntime140_app.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\msvcrt.dll
2968"C:\Users\Public\Downloads\Advanced_IP_Scanner.exe" C:\Users\Public\Downloads\Advanced_IP_Scanner.exe
setup.exe
User:
admin
Company:
Famatech Corp.
Integrity Level:
HIGH
Description:
Advanced IP Scanner Setup
Exit code:
1
Version:
2.5.4594.1
Modules
Images
c:\users\public\downloads\advanced_ip_scanner.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
4288C:\Users\admin\AppData\Local\Notepad\pythonw.exe C:\Users\admin\AppData\Local\Notepad\slv.pyC:\Users\admin\AppData\Local\Notepad\pythonw.exesetup.exe
User:
admin
Company:
Python Software Foundation
Integrity Level:
MEDIUM
Description:
Python
Exit code:
2
Version:
3.10.11
Modules
Images
c:\users\admin\appdata\local\notepad\pythonw.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\users\admin\appdata\local\notepad\vcruntime140.dll
c:\users\admin\appdata\local\notepad\python310.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\version.dll
5164"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Downloads\13637570622.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
5408"C:\Users\admin\AppData\Local\Temp\Rar$EXa1904.44083\setup.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa1904.44083\setup.exeWinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Secure Biometrics
Exit code:
2147942402
Version:
10.0.19041.1706 (WinBuild.160101.0800)
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa1904.44083\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iumsdk.dll
c:\users\admin\appdata\local\temp\rar$exa1904.44083\iumbase.dll
5588"C:\Users\admin\AppData\Local\Temp\Rar$EXa1904.33356\setup.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa1904.33356\setup.exeWinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Secure Biometrics
Exit code:
2147942402
Version:
10.0.19041.1706 (WinBuild.160101.0800)
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa1904.33356\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iumsdk.dll
c:\users\admin\appdata\local\temp\rar$exa1904.33356\iumbase.dll
Total events
4 573
Read events
4 514
Write events
55
Delete events
4

Modification events

(PID) Process:(5164) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\General
Operation:writeName:VerInfo
Value:
003C050012F8FE6A437AD701
(PID) Process:(5164) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\SpybotAntiBeaconPortable-safer-networking.org_3.7.0.paf.zip
(PID) Process:(5164) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\MicrosoftEdgePolicyTemplates.cab
(PID) Process:(5164) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\MicrosoftEdgePolicyTemplates.zip
(PID) Process:(5164) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(5164) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(5164) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(5164) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(5164) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Downloads\13637570622.zip
(PID) Process:(5164) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:name
Value:
256
Executable files
85
Suspicious files
40
Text files
281
Unknown types
1

Dropped files

PID
Process
Filename
Type
5164WinRAR.exeC:\Users\admin\Downloads\__rzi_5164.32162
MD5:
SHA256:
5164WinRAR.exeC:\Users\admin\Downloads\13637570622.zip
MD5:
SHA256:
5164WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DIb5164.32364\502f28c06338d9fc9c2994292be0f8dea3a199455ca749307b3bfc29fec5ca83.zip
MD5:
SHA256:
1904WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1904.33356\iumbase.dll
MD5:
SHA256:
1904WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1904.33356\advanced_ip_scanner_uk_ua.qmqm
MD5:EE64BC556D9E554E5122531BBA368240
SHA256:11D722019F26DAEF74AF7EAE33823B4625D4EBBC33352D5EFAC85D19B2BA0658
1904WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1904.33356\details_panel_en_us.tplhtml
MD5:04C416BEC9FE7DEC52E2F368353FF1F9
SHA256:10946712CE123E177350A9D96F61B2011FFCCC90597880F256E3A24676CD4B30
1904WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1904.33356\service_probesbinary
MD5:637FB65A1755C4B6DC1E0428E69B634E
SHA256:B3B1FF7E3D1D4F438E40208464CEBFB641B434F5BF5CF18B7CEC2D189F52C1B6
1904WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1904.33356\printsupport\windowsprintersupport.dllexecutable
MD5:1184F4FB8EFAE468729C62787C9ED80B
SHA256:C075C95D5153DE4005F0E6804EB4F783886D10B683712ED00EF09A6629D6917A
5164WinRAR.exeC:\Users\admin\AppData\Roaming\WinRAR\version.datbinary
MD5:5AE463027726476C4534B67189671A87
SHA256:DE22A4DDB59CEB55F8A8DD4DDF3817CEE2CAE3370D5C1EBFE7DB61E40DDB5FB0
1904WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1904.33356\setup.exeexecutable
MD5:A6CF19D44ED3E7B17CF1568577DED266
SHA256:CCC68738CC7DA7516A9C8B35C23CFF8B9C278E8B059C698FA2C4BE31C7A5A4E4
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
12
TCP/UDP connections
37
DNS requests
15
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1092
svchost.exe
POST
302
23.35.238.131:80
http://go.microsoft.com/fwlink/?LinkID=252669&clcid=0x409
unknown
unknown
2580
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
binary
471 b
unknown
1092
svchost.exe
POST
302
23.35.238.131:80
http://go.microsoft.com/fwlink/?LinkID=252669&clcid=0x409
unknown
unknown
3200
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
binary
418 b
unknown
3200
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
binary
409 b
unknown
2908
svchost.exe
GET
200
23.212.210.158:80
http://x1.c.lencr.org/
unknown
binary
717 b
unknown
1092
svchost.exe
POST
302
23.35.238.131:80
http://go.microsoft.com/fwlink/?LinkID=252669&clcid=0x409
unknown
unknown
1092
svchost.exe
POST
302
23.35.238.131:80
http://go.microsoft.com/fwlink/?LinkID=252669&clcid=0x409
unknown
unknown
1092
svchost.exe
POST
302
23.35.238.131:80
http://go.microsoft.com/fwlink/?LinkID=252669&clcid=0x409
unknown
unknown
1092
svchost.exe
POST
302
23.35.238.131:80
http://go.microsoft.com/fwlink/?LinkID=252669&clcid=0x409
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3720
svchost.exe
239.255.255.250:1900
whitelisted
5612
MoUsoCoreWorker.exe
40.127.240.158:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
2580
svchost.exe
40.126.31.67:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1092
svchost.exe
23.35.238.131:80
go.microsoft.com
AKAMAI-AS
DE
unknown
4
System
192.168.100.255:137
whitelisted
1092
svchost.exe
20.231.121.79:80
dmd.metaservices.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
2580
svchost.exe
192.229.221.95:80
EDGECAST
US
whitelisted
1092
svchost.exe
138.91.171.81:80
dmd.metaservices.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
3200
SIHClient.exe
13.85.23.86:443
slscr.update.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3200
SIHClient.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
unknown

DNS requests

Domain
IP
Reputation
login.live.com
  • 40.126.31.67
  • 20.190.159.71
  • 40.126.31.71
  • 20.190.159.75
  • 20.190.159.68
  • 20.190.159.2
  • 40.126.31.73
  • 20.190.159.23
whitelisted
go.microsoft.com
  • 23.35.238.131
whitelisted
dmd.metaservices.microsoft.com
  • 20.231.121.79
  • 138.91.171.81
  • 52.142.223.178
whitelisted
slscr.update.microsoft.com
  • 13.85.23.86
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.166.126.56
whitelisted
x1.c.lencr.org
  • 23.212.210.158
whitelisted
self.events.data.microsoft.com
  • 40.79.141.152
whitelisted
dns.msftncsi.com
  • 131.107.255.255
shared

Threats

No threats detected
No debug info