File name:

f99b9_Mask and Fever Thermometer supply From China.pdf.gz

Full analysis: https://app.any.run/tasks/862b99e5-9272-419b-9d1a-b7dd054caba9
Verdict: Malicious activity
Analysis date: March 31, 2020, 08:33:41
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

F99B93C705D8C6EF80D3D4B405D3D0F0

SHA1:

E014FD533FCE3DA979F30FBA8F60A0F1F5081B93

SHA256:

CEE1680F36A1A1DD7EC5BC86BFD960299649C3B6990B87161E1A449FDC856EE8

SSDEEP:

384:VfczVl3LvPOJsSDgq/w48OJmKzaO3RfhqduY5m8hu02nepIXKtkIs4MUivf:VUV1vPusmnQO4eJh6mnv6tkIs4nivf

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Mask and Fever Thermometer supply From China.pdf.exe (PID: 3912)
      • Mask and Fever Thermometer supply From China.pdf.exe (PID: 3428)
    • Actions looks like stealing of personal data

      • Mask and Fever Thermometer supply From China.pdf.exe (PID: 3912)
    • Changes settings of System certificates

      • Mask and Fever Thermometer supply From China.pdf.exe (PID: 3912)
  • SUSPICIOUS

    • Application launched itself

      • Mask and Fever Thermometer supply From China.pdf.exe (PID: 3428)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3200)
    • Reads Internet Cache Settings

      • Mask and Fever Thermometer supply From China.pdf.exe (PID: 3912)
    • Creates files in the user directory

      • Mask and Fever Thermometer supply From China.pdf.exe (PID: 3912)
    • Adds / modifies Windows certificates

      • Mask and Fever Thermometer supply From China.pdf.exe (PID: 3912)
  • INFO

    • Reads settings of System Certificates

      • Mask and Fever Thermometer supply From China.pdf.exe (PID: 3912)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
37
Monitored processes
3
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start winrar.exe mask and fever thermometer supply from china.pdf.exe no specs mask and fever thermometer supply from china.pdf.exe

Process information

PID
CMD
Path
Indicators
Parent process
3200"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\f99b9_Mask and Fever Thermometer supply From China.pdf.gz.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3428"C:\Users\admin\AppData\Local\Temp\Rar$EXa3200.47107\Mask and Fever Thermometer supply From China.pdf.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3200.47107\Mask and Fever Thermometer supply From China.pdf.exeWinRAR.exe
User:
admin
Company:
WONderware
Integrity Level:
MEDIUM
Description:
Stiklings
Exit code:
0
Version:
1.00
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3200.47107\mask and fever thermometer supply from china.pdf.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
3912"C:\Users\admin\AppData\Local\Temp\Rar$EXa3200.47107\Mask and Fever Thermometer supply From China.pdf.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3200.47107\Mask and Fever Thermometer supply From China.pdf.exe
Mask and Fever Thermometer supply From China.pdf.exe
User:
admin
Company:
WONderware
Integrity Level:
MEDIUM
Description:
Stiklings
Exit code:
0
Version:
1.00
Modules
Images
c:\windows\system32\mfc40.dll
c:\users\admin\appdata\local\temp\rar$exa3200.47107\mask and fever thermometer supply from china.pdf.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt40.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
Total events
4 437
Read events
482
Write events
2 639
Delete events
1 316

Modification events

(PID) Process:(3200) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3200) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3200) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3200) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\f99b9_Mask and Fever Thermometer supply From China.pdf.gz.rar
(PID) Process:(3200) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3200) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3200) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3200) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3200) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(3200) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
Executable files
1
Suspicious files
4
Text files
1
Unknown types
2

Dropped files

PID
Process
Filename
Type
3912Mask and Fever Thermometer supply From China.pdf.exeC:\Users\admin\AppData\Local\Temp\CabD8B5.tmp
MD5:
SHA256:
3912Mask and Fever Thermometer supply From China.pdf.exeC:\Users\admin\AppData\Local\Temp\TarD8B6.tmp
MD5:
SHA256:
3200WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3200.47107\Mask and Fever Thermometer supply From China.pdf.exeexecutable
MD5:
SHA256:
3912Mask and Fever Thermometer supply From China.pdf.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6BADA8974A10C4BD62CC921D13E43B18_D9817BD5013875AD517DA73475345203binary
MD5:
SHA256:
3912Mask and Fever Thermometer supply From China.pdf.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6BADA8974A10C4BD62CC921D13E43B18_D9817BD5013875AD517DA73475345203der
MD5:
SHA256:
3912Mask and Fever Thermometer supply From China.pdf.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6BADA8974A10C4BD62CC921D13E43B18_C9FB72B5AE80778A08024D8B0FDECC6Fbinary
MD5:
SHA256:
3912Mask and Fever Thermometer supply From China.pdf.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6BADA8974A10C4BD62CC921D13E43B18_C9FB72B5AE80778A08024D8B0FDECC6Fder
MD5:
SHA256:
3912Mask and Fever Thermometer supply From China.pdf.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\TXVRE35Z.txttext
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
4
DNS requests
4
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3912
Mask and Fever Thermometer supply From China.pdf.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEAtqs7A%2Bsan2xGCSaqjN%2FrM%3D
US
der
1.47 Kb
whitelisted
3912
Mask and Fever Thermometer supply From China.pdf.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA8sEMlbBsCTf7jUSfg%2BhWk%3D
US
der
1.47 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3912
Mask and Fever Thermometer supply From China.pdf.exe
13.107.42.13:443
onedrive.live.com
Microsoft Corporation
US
malicious
3912
Mask and Fever Thermometer supply From China.pdf.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
3912
Mask and Fever Thermometer supply From China.pdf.exe
13.107.42.12:443
4apotw.bn.files.1drv.com
Microsoft Corporation
US
suspicious
3912
Mask and Fever Thermometer supply From China.pdf.exe
212.227.15.142:587
smtp.1and1.es
1&1 Internet SE
DE
suspicious

DNS requests

Domain
IP
Reputation
onedrive.live.com
  • 13.107.42.13
shared
ocsp.digicert.com
  • 93.184.220.29
whitelisted
4apotw.bn.files.1drv.com
  • 13.107.42.12
whitelisted
smtp.1and1.es
  • 212.227.15.142
  • 212.227.15.158
malicious

Threats

PID
Process
Class
Message
3912
Mask and Fever Thermometer supply From China.pdf.exe
Generic Protocol Command Decode
SURICATA Applayer Detect protocol only one direction
No debug info