File name:

Q9om3ev2DO1d6cA6F9KbTA(1).zip

Full analysis: https://app.any.run/tasks/8cce8c77-0276-4357-88d7-414c7d0e47a8
Verdict: Malicious activity
Analysis date: November 15, 2018, 02:46:42
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

9059962192E58A0F89A3B05C871A5F89

SHA1:

C2B8A2FD5F2D1543D2E5A331800B0A5E3D65BA87

SHA256:

CA4467AA603DB93689AD3969149D588CF7C7F6F170F437A8BFE026003DEE67A0

SSDEEP:

393216:uhcSwW4rtvUtKwzeF/+HhoeMKaGUP3jkK:uB2UwwzeF/+BzMKaGUPgK

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • PhotoViewer_v1.4.0.9_sem2_001.exe (PID: 588)
      • PhotoViewer_v1.4.0.9_sem2_001.exe (PID: 2452)
      • PdfReader.exe (PID: 3556)
      • PhotoViewer.exe (PID: 3500)
      • Report.exe (PID: 2592)
      • UpdateCheck.exe (PID: 2852)
      • Report.exe (PID: 4088)
      • PhotoViewer.exe (PID: 3268)
      • PhotoViewer.exe (PID: 3124)
    • Registers / Runs the DLL via REGSVR32.EXE

      • PhotoViewer_v1.4.0.9_sem2_001.exe (PID: 2452)
    • Loads the Task Scheduler COM API

      • PhotoViewer_v1.4.0.9_sem2_001.exe (PID: 2452)
      • PhotoViewer.exe (PID: 3500)
      • PhotoViewer.exe (PID: 3268)
    • Loads dropped or rewritten executable

      • PhotoViewer.exe (PID: 3124)
      • regsvr32.exe (PID: 3572)
      • svchost.exe (PID: 1772)
      • PdfReader.exe (PID: 3556)
      • regsvr32.exe (PID: 348)
      • svchost.exe (PID: 832)
      • PhotoViewer.exe (PID: 3500)
      • PhotoViewer.exe (PID: 3268)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3564)
      • PhotoViewer_v1.4.0.9_sem2_001.exe (PID: 2452)
    • Uses TASKKILL.EXE to kill process

      • PhotoViewer_v1.4.0.9_sem2_001.exe (PID: 2452)
    • Creates files in the user directory

      • PhotoViewer_v1.4.0.9_sem2_001.exe (PID: 2452)
    • Creates COM task schedule object

      • regsvr32.exe (PID: 348)
    • Creates a software uninstall entry

      • PhotoViewer_v1.4.0.9_sem2_001.exe (PID: 2452)
    • Creates or modifies windows services

      • regsvr32.exe (PID: 3572)
    • Creates files in the Windows directory

      • svchost.exe (PID: 832)
    • Modifies the open verb of a shell class

      • PhotoViewer.exe (PID: 3124)
      • PdfReader.exe (PID: 3556)
    • Reads Internet Cache Settings

      • PhotoViewer.exe (PID: 3500)
    • Reads internet explorer settings

      • PhotoViewer.exe (PID: 3500)
      • PhotoViewer.exe (PID: 3268)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0009
ZipCompression: Deflated
ZipModifyDate: 2018:11:15 02:39:05
ZipCRC: 0x80219d79
ZipCompressedSize: 15102957
ZipUncompressedSize: 16168352
ZipFileName: PhotoViewer_v1.4.0.9_sem2_001.exe_
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
67
Monitored processes
21
Malicious processes
8
Suspicious processes
1

Behavior graph

Click at the process to see the details
start drop and start drop and start drop and start drop and start winrar.exe photoviewer_v1.4.0.9_sem2_001.exe no specs photoviewer_v1.4.0.9_sem2_001.exe taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs svchost.exe no specs photoviewer.exe no specs pdfreader.exe no specs photoviewer.exe report.exe svchost.exe updatecheck.exe report.exe photoviewer.exe

Process information

PID
CMD
Path
Indicators
Parent process
348"C:\Windows\system32\regsvr32.exe" /s C:\Users\admin\AppData\Roaming\PhotoViewer\ShellExt.dllC:\Windows\system32\regsvr32.exePhotoViewer_v1.4.0.9_sem2_001.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
588"C:\Users\admin\Desktop\PhotoViewer_v1.4.0.9_sem2_001.exe" C:\Users\admin\Desktop\PhotoViewer_v1.4.0.9_sem2_001.exeexplorer.exe
User:
admin
Company:
上海展盟网络科技有限公司
Integrity Level:
MEDIUM
Description:
ABC看图安装包
Exit code:
3221226540
Version:
1.4.0.9
Modules
Images
c:\users\admin\desktop\photoviewer_v1.4.0.9_sem2_001.exe
c:\systemroot\system32\ntdll.dll
832C:\Windows\system32\svchost.exe -k netsvcsC:\Windows\System32\svchost.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1772C:\Windows\System32\svchost.exe -k PhotoviewerCheckerC:\Windows\System32\svchost.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\svchost.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\users\admin\appdata\roaming\photoviewer\checker.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
1996"C:\Windows\system32\regsvr32.exe" /s /u C:\Users\admin\AppData\Roaming\PhotoViewer\Checker.dllC:\Windows\system32\regsvr32.exePhotoViewer_v1.4.0.9_sem2_001.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
3
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2452"C:\Users\admin\Desktop\PhotoViewer_v1.4.0.9_sem2_001.exe" C:\Users\admin\Desktop\PhotoViewer_v1.4.0.9_sem2_001.exe
explorer.exe
User:
admin
Company:
上海展盟网络科技有限公司
Integrity Level:
HIGH
Description:
ABC看图安装包
Exit code:
0
Version:
1.4.0.9
Modules
Images
c:\users\admin\desktop\photoviewer_v1.4.0.9_sem2_001.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2484"C:\Windows\System32\taskkill.exe" /f /im Report.exeC:\Windows\System32\taskkill.exePhotoViewer_v1.4.0.9_sem2_001.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
2592"C:\Users\admin\AppData\Roaming\PhotoViewer\Report.exe" C:\Users\admin\AppData\Roaming\PhotoViewer\Report.exe
PhotoViewer_v1.4.0.9_sem2_001.exe
User:
admin
Company:
上海展盟网络科技有限公司
Integrity Level:
HIGH
Description:
看图上报程序
Exit code:
0
Version:
1.4.0.9
Modules
Images
c:\users\admin\appdata\roaming\photoviewer\report.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2852"c:\users\admin\appdata\roaming\photoviewer\UpdateCheck.exe"c:\users\admin\appdata\roaming\photoviewer\UpdateCheck.exe
svchost.exe
User:
admin
Company:
上海展盟网络科技有限公司
Integrity Level:
HIGH
Description:
ABC看图检查更新程序
Exit code:
2048
Version:
1.0.0.1
Modules
Images
c:\users\admin\appdata\roaming\photoviewer\updatecheck.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
3096"C:\Windows\system32\regsvr32.exe" /s /u C:\Users\admin\AppData\Roaming\PhotoViewer\ShellExt.dllC:\Windows\system32\regsvr32.exePhotoViewer_v1.4.0.9_sem2_001.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
3
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
3 707
Read events
2 664
Write events
964
Delete events
79

Modification events

(PID) Process:(3564) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3564) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3564) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3564) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Q9om3ev2DO1d6cA6F9KbTA(1).zip
(PID) Process:(3564) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3564) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3564) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3564) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3564) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
(PID) Process:(832) svchost.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1302019708-1500728564-335382590-1000
Operation:writeName:RefCount
Value:
2
Executable files
22
Suspicious files
0
Text files
114
Unknown types
11

Dropped files

PID
Process
Filename
Type
2452PhotoViewer_v1.4.0.9_sem2_001.exeC:\Users\admin\AppData\Local\Temp\ABCPhotoView.7z
MD5:
SHA256:
3564WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3564.3830\PhotoViewer_v1.4.0.9_sem2_001.exe_executable
MD5:
SHA256:
832svchost.exeC:\Windows\appcompat\programs\RecentFileCache.bcftxt
MD5:
SHA256:
2452PhotoViewer_v1.4.0.9_sem2_001.exeC:\Users\admin\AppData\Local\Temp\CheckABCPhotoView.7z.md5text
MD5:
SHA256:
2452PhotoViewer_v1.4.0.9_sem2_001.exeC:\Users\admin\AppData\Roaming\PhotoViewer\PdfReader.exeexecutable
MD5:
SHA256:
2452PhotoViewer_v1.4.0.9_sem2_001.exeC:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exeexecutable
MD5:
SHA256:
2452PhotoViewer_v1.4.0.9_sem2_001.exeC:\Users\admin\AppData\Roaming\PhotoViewer\Checker.dllexecutable
MD5:
SHA256:
2452PhotoViewer_v1.4.0.9_sem2_001.exeC:\Users\admin\AppData\Roaming\PhotoViewer\Report.exeexecutable
MD5:
SHA256:
2452PhotoViewer_v1.4.0.9_sem2_001.exeC:\Users\admin\AppData\Roaming\PhotoViewer\Uninst.exeexecutable
MD5:
SHA256:
2452PhotoViewer_v1.4.0.9_sem2_001.exeC:\Users\admin\AppData\Roaming\PhotoViewer\PhotoManager.exeexecutable
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
16
TCP/UDP connections
33
DNS requests
9
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3500
PhotoViewer.exe
GET
200
221.204.58.110:80
http://ktnews.7654.com/css/reset.css
CN
text
915 b
malicious
3500
PhotoViewer.exe
GET
200
221.204.58.110:80
http://ktnews.7654.com/
CN
html
625 b
malicious
3500
PhotoViewer.exe
GET
200
221.204.58.110:80
http://ktnews.7654.com/css/index.css
CN
text
449 b
malicious
3500
PhotoViewer.exe
GET
200
221.204.58.110:80
http://ktnews.7654.com/css/reset.css
CN
text
915 b
malicious
3500
PhotoViewer.exe
GET
200
221.204.58.110:80
http://ktnews.7654.com/imgs/news_logo.png
CN
image
824 b
malicious
3500
PhotoViewer.exe
GET
200
221.204.58.110:80
http://ktnews.7654.com/imgs/img_ktnews.png
CN
image
151 Kb
malicious
3500
PhotoViewer.exe
GET
200
221.204.58.110:80
http://ktnews.7654.com/js/data.js
CN
text
643 b
malicious
3500
PhotoViewer.exe
GET
200
221.204.58.110:80
http://ktnews.7654.com/js/index.js
CN
html
357 b
malicious
2592
Report.exe
GET
200
117.50.8.146:80
http://kantu.shzhanmeng.com/2.gif?proj=kantu&food=D5CmfVa3GLYOp7vJfg4eJzBqmNAKk4D5s4iWrN493HliZr6wPa/CkXSxSZeMkN3tRtfydHIcsV42Yzqrr7+GtJJBI5QFK8z8U2RX8GLddccSGIoJg7vNdjWpw+ZrQgGaLfjlF0vKjuYXrZ9Mt7VXiZHYoT/CQsAIbplnJQkJ/X7SB+cm3zLQ/v+QM4SihKRgD0GmsjWNgFLv20Z9bFnvcskH
CN
image
43 b
malicious
2592
Report.exe
GET
200
117.50.8.146:80
http://kantu.shzhanmeng.com/2.gif?proj=kantu&food=D5CmfVa3GLYOp7vJfg4eJzBqmNAKk4D5s4iWrN493HliZr6wPa/CkXSxSZeMkN3tRtfydHIcsV42Yzqrr7+GtJJBI5QFK8z8U2RX8GLddccSGIoJg7vNdjWpw+ZrQgGaLfjlF0vKjuYXrZ9Mt7VXiZHYoT/CQsAIbplnJQkJ/X7SB+cm3zLQ/v+QM4SihKRgD0GmsjWNgFLv20d6bFnvcskAlAAiiASZhV5q+N8=
CN
image
43 b
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2592
Report.exe
117.50.8.146:80
kantu.shzhanmeng.com
China Unicom Beijing Province Network
CN
malicious
3500
PhotoViewer.exe
221.204.58.110:80
ktnews.7654.com
CHINA UNICOM China169 Backbone
CN
suspicious
3500
PhotoViewer.exe
221.204.166.22:80
ktnews.7654.com
CHINA UNICOM China169 Backbone
CN
malicious
3500
PhotoViewer.exe
43.224.184.222:80
down2.abckantu.com
Computer Network Information Center
CN
suspicious
2592
Report.exe
43.224.184.222:80
down2.abckantu.com
Computer Network Information Center
CN
suspicious
2592
Report.exe
43.224.184.221:80
down2.abckantu.com
Computer Network Information Center
CN
unknown
3500
PhotoViewer.exe
43.224.184.221:80
down2.abckantu.com
Computer Network Information Center
CN
unknown
2592
Report.exe
43.224.184.217:80
down2.abckantu.com
Computer Network Information Center
CN
unknown
2592
Report.exe
43.224.184.235:80
down2.abckantu.com
Computer Network Information Center
CN
unknown
2592
Report.exe
43.224.184.219:80
down2.abckantu.com
Computer Network Information Center
CN
unknown

DNS requests

Domain
IP
Reputation
kantu.shzhanmeng.com
  • 117.50.8.146
malicious
ktnews.7654.com
  • 221.204.58.110
  • 125.211.204.209
  • 221.204.166.22
  • 36.248.26.201
  • 221.204.60.63
  • 123.6.6.112
  • 125.211.204.225
  • 211.91.160.204
  • 218.11.8.104
  • 112.132.32.105
  • 221.204.166.36
  • 221.204.60.123
  • 221.204.166.20
  • 221.204.166.38
  • 121.29.54.65
malicious
down2.abckantu.com
  • 43.224.184.222
  • 43.224.184.221
  • 43.224.184.217
  • 43.224.184.235
  • 43.224.184.219
  • 43.224.184.234
  • 43.224.184.220
  • 43.224.184.218
unknown
cdn3.guangsuss.com
  • 221.204.166.22
  • 36.248.26.201
  • 221.204.60.63
  • 123.6.6.112
  • 125.211.204.225
  • 211.91.160.204
  • 218.11.8.104
  • 112.132.32.105
  • 221.204.166.36
  • 221.204.60.123
  • 221.204.166.20
  • 221.204.166.38
  • 121.29.54.65
  • 221.204.58.110
  • 125.211.204.209
malicious
dns.msftncsi.com
  • 131.107.255.255
shared

Threats

No threats detected
Process
Message
PhotoViewer.exe
~ImageProxy()
PhotoViewer.exe
~ImageProxy()
PhotoViewer.exe
~ImageProxy()
PhotoViewer.exe
~ImageProxy()
PhotoViewer.exe
~ImageProxy()
PhotoViewer.exe
~ImageProxy()
PhotoViewer.exe
~ImageProxy()
PhotoViewer.exe
~ImageProxy()