File name:

SpySheriff.zip

Full analysis: https://app.any.run/tasks/0cfb73d9-7507-45ff-8535-8605056b29a7
Verdict: Malicious activity
Analysis date: June 09, 2020, 14:08:58
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

5EC70A62B7FA20507AB4B70C3389BB37

SHA1:

68EE641337D66B3D6C31DD7F0729AFBF2BBDC069

SHA256:

D16DDDC1E9AD69C5EF67AFD93EB801C74CA5B95EC8B46741786C8C8EC47B1B1D

SSDEEP:

24576:VNgDMZ96GXyY03689pDhw0Ifxpa+7FLzMrn7a7gIWAxZjD9YenhEdNxA1P:7c05yY2vDhAraskS7p/NY2KA1P

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • SpySheriff.exe (PID: 2952)
    • Changes the autorun value in the registry

      • SpySheriff.exe (PID: 2952)
    • Application was dropped or rewritten from another process

      • SpySheriff.exe (PID: 2952)
    • Actions looks like stealing of personal data

      • WinRAR.exe (PID: 2392)
      • SpySheriff.exe (PID: 2952)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2392)
    • Reads Internet Cache Settings

      • SpySheriff.exe (PID: 2952)
  • INFO

    • Reads Internet Cache Settings

      • iexplore.exe (PID: 2856)
      • iexplore.exe (PID: 2240)
    • Manual execution by user

      • iexplore.exe (PID: 2856)
    • Reads Microsoft Office registry keys

      • SpySheriff.exe (PID: 2952)
    • Changes internet zones settings

      • iexplore.exe (PID: 2856)
    • Reads internet explorer settings

      • iexplore.exe (PID: 2240)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.xpi | Mozilla Firefox browser extension (66.6)
.zip | ZIP compressed archive (33.3)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0009
ZipCompression: Unknown (99)
ZipModifyDate: 2019:11:02 18:36:09
ZipCRC: 0xbc7d3614
ZipCompressedSize: 14778
ZipUncompressedSize: 15436
ZipFileName: base002.avd
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
36
Monitored processes
4
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start winrar.exe spysheriff.exe iexplore.exe no specs iexplore.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2240"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2856 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exeiexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2392"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\SpySheriff.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2856"C:\Program Files\Internet Explorer\iexplore.exe" C:\Program Files\Internet Explorer\iexplore.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
1
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2952"C:\Users\admin\AppData\Local\Temp\Rar$EXb2392.9422\SpySheriff.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb2392.9422\SpySheriff.exe
WinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\systemroot\system32\ntdll.dll
c:\users\admin\appdata\local\temp\rar$exb2392.9422\spysheriff.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
Total events
1 977
Read events
1 882
Write events
91
Delete events
4

Modification events

(PID) Process:(2392) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2392) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2392) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2392) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12F\52C64B7E
Operation:writeName:@C:\Windows\system32\NetworkExplorer.dll,-1
Value:
Network
(PID) Process:(2392) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\SpySheriff.zip
(PID) Process:(2392) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2392) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2392) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2392) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2392) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12F\52C64B7E
Operation:writeName:@C:\Windows\system32\notepad.exe,-469
Value:
Text Document
Executable files
8
Suspicious files
6
Text files
1
Unknown types
3

Dropped files

PID
Process
Filename
Type
2856iexplore.exeC:\Users\admin\AppData\Local\Temp\~DFF762251959BCBD95.TMP
MD5:
SHA256:
2856iexplore.exeC:\Users\admin\AppData\Local\Temp\~DFE54C5F24039900EB.TMP
MD5:
SHA256:
2856iexplore.exeC:\Users\admin\AppData\Local\Temp\~DFC93E80BF7EB1A448.TMP
MD5:
SHA256:
2856iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{F5339661-AA5A-11EA-8526-5254004A04AF}.dat
MD5:
SHA256:
2856iexplore.exeC:\Users\admin\AppData\Local\Temp\~DF807BDA126909A977.TMP
MD5:
SHA256:
2856iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{F533965F-AA5A-11EA-8526-5254004A04AF}.dat
MD5:
SHA256:
2392WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2392.9422\IESecurity.dllexecutable
MD5:04EA7F07722C9C03CF932876A841183A
SHA256:F407F96D71D6FA7597CE85ABB9BA4BDD95D02FE7F2EF46F0C343A4A0D6115C0D
2392WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2392.9422\notfound.wavwav
MD5:B6DB2D81423853CA8E82BD42E04E9AB2
SHA256:05C118E5A69FB0603C4E4D6357D3B92E3ACA6E93883955EB9EC08110EDC65FD5
2392WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2392.9422\SpySheriff.dvmbinary
MD5:4A656C63897CA241F5B162B885510C82
SHA256:E36B521029B99D1698724AA08C817D15382A27A81A7C736C12145364E2E94432
2392WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2392.9422\heur000.dllexecutable
MD5:CA4822789DA674E2AE4658EE4250ADB5
SHA256:16E8D6DC3E1C3562F8F7E98D492C152965FC08D7CC57E3846E35DE11AF49092E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info