analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

DOWNLOAD-100.zip

Full analysis: https://app.any.run/tasks/5fef0b0f-fb70-4786-8857-1515c1ef4b04
Verdict: Malicious activity
Analysis date: August 12, 2022, 21:29:05
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

3A857A5178641E533F2381540E366B2B

SHA1:

68DC53253FD79331C9D9920B6EBD160077C71F6F

SHA256:

CF8A0892A10B319CC7F82232FB4C2DFCF42FE27CEC9D15F7BD9DB576D83202BF

SSDEEP:

96:lgZr0lBsI+KelaCgZGacCGDUd9w6FRuhpXeAc0ATa2Sh7ae1vtJJunW26BhaGGeD:+LJx+ZXcCGUw6yddvn2c1lzF26BFG4zr

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • DOWNLOAD-100.exe (PID: 2496)
      • DOWNLOAD-100.exe (PID: 2156)
    • Drops executable file immediately after starts

      • WinRAR.exe (PID: 2384)
    • Changes settings of System certificates

      • DOWNLOAD-100.exe (PID: 2156)
  • SUSPICIOUS

    • Checks supported languages

      • WinRAR.exe (PID: 2384)
      • DOWNLOAD-100.exe (PID: 2496)
      • DOWNLOAD-100.exe (PID: 2156)
    • Drops a file with a compile date too recent

      • WinRAR.exe (PID: 2384)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2384)
    • Reads the computer name

      • WinRAR.exe (PID: 2384)
      • DOWNLOAD-100.exe (PID: 2496)
      • DOWNLOAD-100.exe (PID: 2156)
    • Adds / modifies Windows certificates

      • DOWNLOAD-100.exe (PID: 2156)
  • INFO

    • Manual execution by user

      • DOWNLOAD-100.exe (PID: 2496)
      • DOWNLOAD-100.exe (PID: 2156)
    • Reads settings of System Certificates

      • DOWNLOAD-100.exe (PID: 2496)
      • DOWNLOAD-100.exe (PID: 2156)
    • Checks Windows Trust Settings

      • DOWNLOAD-100.exe (PID: 2496)
      • DOWNLOAD-100.exe (PID: 2156)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: DOWNLOAD-100.exe
ZipUncompressedSize: 10240
ZipCompressedSize: 6740
ZipCRC: 0x853d617d
ZipModifyDate: 2022:05:23 17:16:04
ZipCompression: Deflated
ZipBitFlag: 0x0001
ZipRequiredVersion: 20
No data.
screenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
39
Monitored processes
3
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe download-100.exe download-100.exe

Process information

PID
CMD
Path
Indicators
Parent process
2384"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\DOWNLOAD-100.zip"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2496"C:\Users\admin\Desktop\DOWNLOAD-100.exe" C:\Users\admin\Desktop\DOWNLOAD-100.exe
Explorer.EXE
User:
admin
Company:
PoC-BootCamp
Integrity Level:
MEDIUM
Version:
1
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\desktop\download-100.exe
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2156"C:\Users\admin\Desktop\DOWNLOAD-100.exe" C:\Users\admin\Desktop\DOWNLOAD-100.exe
Explorer.EXE
User:
admin
Company:
PoC-BootCamp
Integrity Level:
MEDIUM
Version:
1
Modules
Images
c:\users\admin\desktop\download-100.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\rpcrt4.dll
Total events
8 803
Read events
8 700
Write events
100
Delete events
3

Modification events

(PID) Process:(2384) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2384) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2384) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2384) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(2384) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2384) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\DOWNLOAD-100.zip
(PID) Process:(2384) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2384) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2384) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2384) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
1
Suspicious files
5
Text files
1
Unknown types
3

Dropped files

PID
Process
Filename
Type
2496DOWNLOAD-100.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6BADA8974A10C4BD62CC921D13E43B18_28DEA62A0AE77228DD387E155AD0BA27binary
MD5:DFA16ED67239E43220BD301563025ED5
SHA256:A5868B30AD159205E299B836E9B0194B20FF88AFE40DD94E12277E85D1B35C46
2496DOWNLOAD-100.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:7ABF46135A3C77E80B67C72CEF7FAACB
SHA256:1C29D9CE3BA9BCA912F8FAC04CBFAB9F208240ABBA82FCABBAC98B526366B2E4
2156DOWNLOAD-100.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\CAF4703619713E3F18D8A9D5D88D6288_A7725538C46DE2D0088EE44974E2CEBAder
MD5:5A11C6099B9E5808DFB08C5C9570C92F
SHA256:91291A5EDC4E10A225D3C23265D236ECC74473D9893BE5BD07E202D95B3FB172
2156DOWNLOAD-100.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EAder
MD5:FC4A5A9D19C073BF2FCB2090CE0F8D1E
SHA256:33DEFDCBE87BC5E257D30F2FA45683F7898FF0FF1327D1E6753BD51A657A3DA2
2156DOWNLOAD-100.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EAbinary
MD5:6C678CB3531E86FED73F7C8803B954B7
SHA256:EE9FD18E0BEABACEA60E305653AE1552D30CE0E2AD1B0E532D7B9053E6BADDDE
2496DOWNLOAD-100.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157compressed
MD5:F7DCB24540769805E5BB30D193944DCE
SHA256:6B88C6AC55BBD6FEA0EBE5A760D1AD2CFCE251C59D0151A1400701CB927E36EA
2156DOWNLOAD-100.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\CAF4703619713E3F18D8A9D5D88D6288_A7725538C46DE2D0088EE44974E2CEBAbinary
MD5:E0872E5F4E7701BA2979C79350F0962C
SHA256:E8F46FEFD7DEE8659291E16C3AD44F2DEC52CB3516EEB9B7DF6A46D8ABE7E1EA
2156DOWNLOAD-100.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\dfirsena[1].htmhtml
MD5:41AD004A88D8E3BCA44B4087B29937CD
SHA256:F2F77FAA891FF110D4F268887E09AC09464482E622D3F1E17714F0BF791A7CDD
2384WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb2384.41302\DOWNLOAD-100.exeexecutable
MD5:95801AF084F016C65FE03CA79EB1B996
SHA256:603488E403F45E7EECC5B738057C255533AE704450B00F94CCB03F6C714042BF
2496DOWNLOAD-100.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6BADA8974A10C4BD62CC921D13E43B18_28DEA62A0AE77228DD387E155AD0BA27der
MD5:953BBBF2C62EB6DFC48AAC1AA78AA47F
SHA256:FB2030E7F3083D281DA52246BD5AD19971B1A2A7B9FA91F8ACDD1C4E0F43AF3C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
7
DNS requests
6
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2496
DOWNLOAD-100.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEAo3h2ReX7SMIk79G%2B0UDDw%3D
US
der
1.47 Kb
whitelisted
2156
DOWNLOAD-100.exe
GET
200
142.250.186.67:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
US
der
1.41 Kb
whitelisted
2156
DOWNLOAD-100.exe
GET
142.250.186.67:80
http://ocsp.pki.goog/gts1c3/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEQCJ0LMUWb9%2FFgo%2FwIbO2Mkq
US
whitelisted
2156
DOWNLOAD-100.exe
GET
200
142.250.186.67:80
http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFNZazTHGPUBUGY%3D
US
der
724 b
whitelisted
2496
DOWNLOAD-100.exe
GET
200
8.253.95.121:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?7d388210155f3d20
US
compressed
4.70 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2496
DOWNLOAD-100.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
2496
DOWNLOAD-100.exe
104.20.139.65:443
tinyurl.com
Cloudflare Inc
US
suspicious
2496
DOWNLOAD-100.exe
8.253.95.121:80
ctldl.windowsupdate.com
Global Crossing
US
suspicious
104.20.139.65:443
tinyurl.com
Cloudflare Inc
US
suspicious
2156
DOWNLOAD-100.exe
104.20.138.65:443
tinyurl.com
Cloudflare Inc
US
suspicious
2156
DOWNLOAD-100.exe
142.250.186.67:80
ocsp.pki.goog
Google Inc.
US
whitelisted
2156
DOWNLOAD-100.exe
142.250.185.129:443
c.tenor.com
Google Inc.
US
whitelisted

DNS requests

Domain
IP
Reputation
tinyurl.com
  • 104.20.139.65
  • 104.20.138.65
  • 172.67.1.225
shared
ctldl.windowsupdate.com
  • 8.253.95.121
  • 8.248.137.254
  • 8.248.117.254
  • 67.27.235.254
  • 8.248.143.254
whitelisted
ocsp.digicert.com
  • 93.184.220.29
whitelisted
dns.msftncsi.com
  • 131.107.255.255
shared
c.tenor.com
  • 142.250.185.129
whitelisted
ocsp.pki.goog
  • 142.250.186.67
whitelisted

Threats

No threats detected
No debug info