analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

Archive.1.zip

Full analysis: https://app.any.run/tasks/b364394d-cd09-4c8b-a20f-d3789fbbb7f4
Verdict: Malicious activity
Analysis date: April 23, 2019, 14:58:35
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
macros
macros-on-open
maldoc-5
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

1F808914672FF3811F53EA170172CDFD

SHA1:

792DB393B44072F543EDB2A1DCB4AC62A81FDA51

SHA256:

CC9BEAA10378448483873A2AD35CBBB2300D718CF9F07B07DA14763A8E0BE518

SSDEEP:

1536:ga3iMLtsO+XuE2W2BUPm6wWCTu55Oh1eaPDbx1vVwzubb:gC3w12W2BUP7wtTGOh1RPTvRbb

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Unusual execution from Microsoft Office

      • EXCEL.EXE (PID: 4052)
    • Starts CMD.EXE for commands execution

      • EXCEL.EXE (PID: 4052)
    • Executes PowerShell scripts

      • cmD.exe (PID: 2432)
  • SUSPICIOUS

    • Starts CMD.EXE for commands execution

      • cmD.exe (PID: 2432)
    • Creates files in the user directory

      • powershell.exe (PID: 3644)
    • Uses RUNDLL32.EXE to load library

      • control.exe (PID: 2632)
      • control.exe (PID: 2144)
      • rundll32.exe (PID: 3608)
    • Application launched itself

      • rundll32.exe (PID: 3608)
  • INFO

    • Reads Microsoft Office registry keys

      • EXCEL.EXE (PID: 4052)
    • Creates files in the user directory

      • EXCEL.EXE (PID: 4052)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2008:09:24 13:29:15
ZipCRC: 0x5c7c8e5f
ZipCompressedSize: 1140
ZipUncompressedSize: 2253
ZipFileName: Italiano.bat
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
62
Monitored processes
21
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs cmd.exe no specs tzutil.exe no specs certutil.exe no specs regedit.exe no specs regedit.exe no specs regedit.exe excel.exe no specs cmd.exe no specs cmd.exe no specs powershell.exe no specs control.exe no specs rundll32.exe no specs control.exe no specs rundll32.exe no specs timedate.cpl no specs rundll32.exe no specs rundll32.exe no specs rundll32.exe no specs rundll32.exe no specs rundll32.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2300"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\Archive.1.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.60.0
3632cmd /c ""C:\Users\admin\Desktop\Italiano.bat" "C:\Windows\system32\cmd.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
3744tzutil /s "W. Europe Standard Time"C:\Windows\system32\tzutil.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Time Zone Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
3652certutil /decode "C:\Users\admin\AppData\Local\Temp\b64" "C:\Users\admin\AppData\Local\Temp\decoded" C:\Windows\system32\certutil.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
CertUtil.exe
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
3168regedit.exe /s "C:\Users\admin\AppData\Local\Temp\decoded"C:\Windows\regedit.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Registry Editor
Exit code:
3221226540
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
3544"C:\Windows\regedit.exe" /s "C:\Users\admin\AppData\Local\Temp\decoded"C:\Windows\regedit.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Registry Editor
Exit code:
3221226540
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
2340"C:\Windows\regedit.exe" /s "C:\Users\admin\AppData\Local\Temp\decoded"C:\Windows\regedit.exe
cmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Registry Editor
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
4052"C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /ddeC:\Program Files\Microsoft Office\Office14\EXCEL.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Excel
Version:
14.0.6024.1000
2432cmD /C " EchO/^^^&( $Env:COMSPec[4,15,25]-jOiN'') (NEw-oBJEct IO.COMpREsSION.DeflAtEsTREAm( [syStem.Io.MeMoRysTrEaM] [conVeRt]::FROMbasE64sTrINg( '' ), [SYsTeM.io.coMPReSsIoN.COmPreSsIOnModE]::deCOmPreSS )^^^| fOReAch-OBjECt{NEw-oBJEct iO.stREAmREADeR( $_,[TexT.eNCoDiNg]::aSCiI )}).readtOEnd() | pOwerShEll -exeCutioNp bypASs -nOprOFIle -NOnIntE -WinD hidDEN ${execUTIonCOnteXt}.InvokeCoMmAnd.InVokEsCripT( ${iNput} )"C:\Windows\system32\cmD.exeEXCEL.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
1680C:\Windows\system32\cmd.exe /S /D /c" EchO/^&( $Env:COMSPec[4,15,25]-jOiN'') (NEw-oBJEct IO.COMpREsSION.DeflAtEsTREAm( [syStem.Io.MeMoRysTrEaM] [conVeRt]::FROMbasE64sTrINg( '' ), [SYsTeM.io.coMPReSsIoN.COmPreSsIOnModE]::deCOmPreSS )^| fOReAch-OBjECt{NEw-oBJEct iO.stREAmREADeR( $_,[TexT.eNCoDiNg]::aSCiI )}).readtOEnd() "C:\Windows\system32\cmd.execmD.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Total events
1 608
Read events
1 071
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
3
Text files
7
Unknown types
2

Dropped files

PID
Process
Filename
Type
4052EXCEL.EXEC:\Users\admin\AppData\Local\Temp\CVRAA45.tmp.cvr
MD5:
SHA256:
3644powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\0IUCYURB5AKXZ4ZC4L61.temp
MD5:
SHA256:
3652certutil.exeC:\Users\admin\AppData\Local\Temp\decodedtext
MD5:41A3AEBDE41049E0271A220B09BE0546
SHA256:D60F682123C106A312C6A2E2BDA917E86031DFE07F7E1D18D94354C7313D7EE8
2300WinRAR.exeC:\Users\admin\Desktop\Doc. n 0394-2.19 del 23-04-2019 CL 5390.xlsdocument
MD5:61A416ACC0BB72A81A87F1159FA76383
SHA256:72510ED11B8E3375CF7E9B07E7C2A823E5E118B3DB469040C11E2E6A70C88E58
4052EXCEL.EXEC:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\index.dattext
MD5:8F31CCAC448DAA313197003875D90C2B
SHA256:8EE0B0788B56451B76CF7EE7BF9D6597A1690C3A60616238D25C9E0EE66134DB
3632cmd.exeC:\Users\admin\AppData\Local\Temp\b64text
MD5:76B1CB245BB8EFC84B95B1A28FA8CAE0
SHA256:64CDFA15E887F48785B5E2AD3966AFB00CE35B88CD5176A7659950884C6A3CCB
3644powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms~RFebad0.TMPbinary
MD5:131DC75F6D4142CA9244945A91A71E8D
SHA256:F17C463C77B5DA9E795770A82E0A7FB1023023F44397F6E080721E9811B2A0C4
4052EXCEL.EXEC:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\Doc. n 0394-2.19 del 23-04-2019 CL 5390.xls.LNKlnk
MD5:F26C00F454380841BB700053C3DBEA00
SHA256:1CF910BDB1DBCD424EEC8EBE739753165FAF5A329BA09ABB60AF28D77FA6F513
3644powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-msbinary
MD5:131DC75F6D4142CA9244945A91A71E8D
SHA256:F17C463C77B5DA9E795770A82E0A7FB1023023F44397F6E080721E9811B2A0C4
2300WinRAR.exeC:\Users\admin\Desktop\Italiano.battext
MD5:A23A6695360512AA6664FA404D2A98A5
SHA256:5DEC32B67112693409931B60AC89843C2EA08460900F61B609BD9D0DA23B933C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info