File name:

Coffalyser.Net.zip

Full analysis: https://app.any.run/tasks/ab088a12-a75b-40c5-ac79-82522f8eb62c
Verdict: Malicious activity
Analysis date: July 08, 2024, 09:42:39
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

BDF2133ED0094DC3BEF1C1AD2B8B3FD9

SHA1:

E564A09E8F6C6A8AD515CD63F1FE76E92BE7F43F

SHA256:

CF012EC8F7BC81F97692912B4962914D941F25CFF2358674BD52A8DDD03B22BC

SSDEEP:

98304:SFXUxzQIyNyTWr336Jq5BQwsXfJKB74Vf4aygMKR5vRsX8cZWUJNTTBp5GfLMer8:SV6hq8wsl+2N8K9pc

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 3380)
      • msiexec.exe (PID: 2948)
    • Creates a writable file in the system directory

      • CoffalyserServer.exe (PID: 2888)
  • SUSPICIOUS

    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 2948)
    • Process drops legitimate windows executable

      • msiexec.exe (PID: 2948)
      • msiexec.exe (PID: 2348)
    • Executes as Windows Service

      • VSSVC.exe (PID: 2428)
      • CoffalyserServer.exe (PID: 2888)
    • Reads security settings of Internet Explorer

      • msiexec.exe (PID: 4056)
      • CoffalyserClient.exe (PID: 2740)
      • CoffalyserClient.exe (PID: 2832)
      • CoffalyserClient.exe (PID: 3640)
      • CoffalyserServer.exe (PID: 2888)
    • Reads the Internet Settings

      • CoffalyserClient.exe (PID: 2740)
      • CoffalyserClient.exe (PID: 2832)
      • CoffalyserClient.exe (PID: 3640)
    • Application launched itself

      • CoffalyserClient.exe (PID: 2740)
      • CoffalyserClient.exe (PID: 2832)
  • INFO

    • Drops the executable file immediately after the start

      • msiexec.exe (PID: 2348)
    • Reads the computer name

      • msiexec.exe (PID: 2948)
      • msiexec.exe (PID: 3988)
      • msiexec.exe (PID: 4056)
      • CoffalyserClient.exe (PID: 2740)
      • CoffalyserClient.exe (PID: 2832)
      • CoffalyserClient.exe (PID: 3640)
      • CoffalyserServer.exe (PID: 2888)
      • wmpnscfg.exe (PID: 3444)
      • msiexec.exe (PID: 1980)
    • Application launched itself

      • msiexec.exe (PID: 2948)
    • Manual execution by a user

      • msiexec.exe (PID: 2348)
      • wmpnscfg.exe (PID: 3444)
    • Checks supported languages

      • msiexec.exe (PID: 2948)
      • msiexec.exe (PID: 1980)
      • msiexec.exe (PID: 3988)
      • msiexec.exe (PID: 4056)
      • CoffalyserClient.exe (PID: 2740)
      • CoffalyserClient.exe (PID: 2832)
      • CoffalyserClient.exe (PID: 3640)
      • CoffalyserServer.exe (PID: 2888)
      • wmpnscfg.exe (PID: 3444)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3380)
      • msiexec.exe (PID: 2948)
      • msiexec.exe (PID: 2348)
    • Reads the machine GUID from the registry

      • msiexec.exe (PID: 1980)
      • msiexec.exe (PID: 3988)
      • msiexec.exe (PID: 4056)
      • CoffalyserClient.exe (PID: 2740)
      • CoffalyserClient.exe (PID: 2832)
      • CoffalyserClient.exe (PID: 3640)
      • CoffalyserServer.exe (PID: 2888)
      • msiexec.exe (PID: 2948)
    • Create files in a temporary directory

      • msiexec.exe (PID: 3988)
      • msiexec.exe (PID: 2948)
      • msiexec.exe (PID: 1980)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 2948)
    • Creates files or folders in the user directory

      • CoffalyserClient.exe (PID: 2740)
    • Reads Environment values

      • CoffalyserServer.exe (PID: 2888)
      • CoffalyserClient.exe (PID: 3640)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2024:02:29 15:34:22
ZipCRC: 0x2ebdb045
ZipCompressedSize: 3398002
ZipUncompressedSize: 4206901
ZipFileName: Coffalyser.Net v.220513.1739 & v.240129.1959 Reference Manual v03.pdf
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
56
Monitored processes
12
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe msiexec.exe msiexec.exe msiexec.exe no specs vssvc.exe no specs msiexec.exe no specs msiexec.exe no specs coffalyserclient.exe coffalyserclient.exe coffalyserclient.exe coffalyserserver.exe wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1980C:\Windows\system32\MsiExec.exe -Embedding 5EA1C4DF5134A824B671B2D903577074 CC:\Windows\System32\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2348"C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\Desktop\New folder\Coffalyser.Net.msi" C:\Windows\System32\msiexec.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2428C:\Windows\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2740"C:\Program Files\MRC-Holland\Coffalyser.Net\CoffalyserClient.exe"C:\Program Files\MRC-Holland\Coffalyser.Net\CoffalyserClient.exe
msiexec.exe
User:
admin
Company:
MRC-Holland / Berg IT Solutions (BITS)
Integrity Level:
MEDIUM
Description:
CoffalyserClient
Exit code:
999
Version:
1.1.8794.35975
Modules
Images
c:\program files\mrc-holland\coffalyser.net\coffalyserclient.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2832"C:\Program Files\MRC-Holland\Coffalyser.Net\CoffalyserClient.exe" /SERVICE_CONFIGUREC:\Program Files\MRC-Holland\Coffalyser.Net\CoffalyserClient.exe
CoffalyserClient.exe
User:
admin
Company:
MRC-Holland / Berg IT Solutions (BITS)
Integrity Level:
MEDIUM
Description:
CoffalyserClient
Exit code:
999
Version:
1.1.8794.35975
Modules
Images
c:\program files\mrc-holland\coffalyser.net\coffalyserclient.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2888"C:\Program Files\MRC-Holland\Coffalyser.Net\CoffalyserServer.exe"C:\Program Files\MRC-Holland\Coffalyser.Net\CoffalyserServer.exe
services.exe
User:
SYSTEM
Company:
MRC-Holland / Berg IT Solutions (BITS)
Integrity Level:
SYSTEM
Description:
CoffalyserServerEngine
Version:
1.1.8794.35974
Modules
Images
c:\program files\mrc-holland\coffalyser.net\coffalyserserver.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2948C:\Windows\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3380"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\Coffalyser.Net.zipC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3444"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
3640"C:\Program Files\MRC-Holland\Coffalyser.Net\CoffalyserClient.exe" /SERVICE_CONFIGUREC:\Program Files\MRC-Holland\Coffalyser.Net\CoffalyserClient.exe
CoffalyserClient.exe
User:
admin
Company:
MRC-Holland / Berg IT Solutions (BITS)
Integrity Level:
HIGH
Description:
CoffalyserClient
Exit code:
0
Version:
1.1.8794.35975
Modules
Images
c:\program files\mrc-holland\coffalyser.net\coffalyserclient.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
16 769
Read events
16 399
Write events
342
Delete events
28

Modification events

(PID) Process:(3380) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3380) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3380) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3380) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3380) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3380) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(3380) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Coffalyser.Net.zip
(PID) Process:(3380) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3380) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3380) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
35
Suspicious files
18
Text files
28
Unknown types
0

Dropped files

PID
Process
Filename
Type
3380WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3380.9173\Coffalyser.Net v.220513.1739 & v.240129.1959 Reference Manual v03.pdf
MD5:
SHA256:
2948msiexec.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
3380WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3380.9173\Coffalyser.Net.msiexecutable
MD5:ADDD9D4F6F554012ABD98B0CFAEEEFE6
SHA256:D15A9C675609D588840194282816C6E62446D4D7D9F581132B16018298D12C9D
2948msiexec.exeC:\System Volume Information\SPP\OnlineMetadataCache\{ace34be5-eed1-4b4c-8b34-8cf04a2eab8d}_OnDiskSnapshotPropbinary
MD5:12AE35DC67AFE3AA6B619B0F0F232ADB
SHA256:0F8F06EE9AA175ED8D59437B546682EEFE38D19EC09F3792950F8799365A8CB7
2948msiexec.exeC:\System Volume Information\SPP\snapshot-2binary
MD5:12AE35DC67AFE3AA6B619B0F0F232ADB
SHA256:0F8F06EE9AA175ED8D59437B546682EEFE38D19EC09F3792950F8799365A8CB7
2348msiexec.exeC:\Users\admin\AppData\Local\Temp\MSI41F3.tmpexecutable
MD5:684F2D21637CB5835172EDAD55B6A8D9
SHA256:DA1FE86141C446921021BB26B6FE2BD2D1BB51E3E614F46F8103FFAD8042F2C0
3380WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3380.9173\Coffalyser.Net v.240129.1959 Installation Manual v01.pdfpdf
MD5:3349426CF16F91E4EA74A4C010838AA6
SHA256:DC1B41770B799CA734BC00C6E403941AEE513B719355693CEDE9FDAF8B2CAAE3
2348msiexec.exeC:\Users\admin\AppData\Local\Temp\MSI4127.tmpexecutable
MD5:684F2D21637CB5835172EDAD55B6A8D9
SHA256:DA1FE86141C446921021BB26B6FE2BD2D1BB51E3E614F46F8103FFAD8042F2C0
3380WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3380.9173\setup.exeexecutable
MD5:A6BFD232CD3F026CC10D2D7597007E2E
SHA256:71D5516B46E73E7CE162AAB263F02E12A45491F9F6877DDFBA0FF4955515ABC9
2948msiexec.exeC:\Windows\Installer\58593.msiexecutable
MD5:ADDD9D4F6F554012ABD98B0CFAEEEFE6
SHA256:D15A9C675609D588840194282816C6E62446D4D7D9F581132B16018298D12C9D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
11
DNS requests
6
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1372
svchost.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
unknown
1372
svchost.exe
GET
304
199.232.214.172:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?33775f6043c93e33
unknown
unknown
1372
svchost.exe
GET
200
2.16.241.19:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
unknown
1060
svchost.exe
GET
304
23.53.40.65:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?11acddbe1ebd82b3
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
2564
svchost.exe
239.255.255.250:3702
whitelisted
1060
svchost.exe
224.0.0.252:5355
whitelisted
1372
svchost.exe
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1372
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
1372
svchost.exe
199.232.214.172:80
ctldl.windowsupdate.com
FASTLY
US
unknown
1372
svchost.exe
2.16.241.19:80
crl.microsoft.com
Akamai International B.V.
DE
unknown
1372
svchost.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
unknown
1060
svchost.exe
23.53.40.65:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown

DNS requests

Domain
IP
Reputation
dns.msftncsi.com
  • 131.107.255.255
shared
settings-win.data.microsoft.com
  • 40.127.240.158
whitelisted
ctldl.windowsupdate.com
  • 199.232.214.172
  • 199.232.210.172
  • 23.53.40.65
  • 23.53.40.18
  • 23.53.40.67
  • 23.53.40.56
  • 23.53.40.35
  • 23.53.40.72
  • 23.53.40.83
whitelisted
crl.microsoft.com
  • 2.16.241.19
  • 2.16.241.12
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted

Threats

No threats detected
Process
Message
CoffalyserClient.exe
CoffalyserClient.exe Information: 0 :
CoffalyserClient.exe
skipped the text trace listener
CoffalyserClient.exe
CoffalyserClient.exe Warning: 0 :
CoffalyserClient.exe
trying to restart the application (file name: C:\Program Files\MRC-Holland\Coffalyser.Net\CoffalyserClient.exe, verb: , arguments: /SERVICE_CONFIGURE)
CoffalyserClient.exe
CoffalyserClient.exe Information: 0 :
CoffalyserClient.exe
skipped the text trace listener
CoffalyserClient.exe
CoffalyserClient.exe Warning: 0 :
CoffalyserClient.exe
user requested the service configuration (with argument)
CoffalyserClient.exe
CoffalyserClient.exe Error: 0 :
CoffalyserClient.exe
the service config requires administrative privileges which are not available