analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

download

Full analysis: https://app.any.run/tasks/ec6f7459-ca9a-4dd8-af8d-6c50d840bf6b
Verdict: Malicious activity
Analysis date: May 15, 2019, 15:33:12
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

EECB0439202E1FB6CB376F3D6CC621C5

SHA1:

00B9C97DF0EF2DC08762A0696F802EF746A89E1F

SHA256:

D2540567C93462DF972B9BE5020415AB72C567521E8D7C77C9454F4B17514C51

SSDEEP:

6144:b0DMpm+XHB61YTJQJSIPdJpM5+kr2bb7E6kEbVp7K7sNFbnZDpi1p:bKMpDXHB61kQSIPdJW+Ggb7E6hbVp7Kj

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • lcA89D.tmp (PID: 2944)
    • Changes the autorun value in the registry

      • reg.exe (PID: 3952)
  • SUSPICIOUS

    • Starts Internet Explorer

      • cmd.exe (PID: 2360)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2932)
      • msiexec.exe (PID: 3104)
      • MsiExec.exe (PID: 2380)
    • Starts Microsoft Installer

      • WinRAR.exe (PID: 2932)
    • Creates files in the user directory

      • cmd.exe (PID: 2360)
      • MsiExec.exe (PID: 2380)
    • Starts CMD.EXE for commands execution

      • MsiExec.exe (PID: 2380)
    • Uses REG.EXE to modify Windows registry

      • cmd.exe (PID: 3496)
    • Reads Internet Cache Settings

      • MsiExec.exe (PID: 2380)
  • INFO

    • Application launched itself

      • msiexec.exe (PID: 3104)
      • iexplore.exe (PID: 3644)
    • Reads settings of System Certificates

      • iexplore.exe (PID: 3644)
    • Creates files in the user directory

      • iexplore.exe (PID: 2204)
    • Changes internet zones settings

      • iexplore.exe (PID: 3644)
    • Reads Internet Cache Settings

      • iexplore.exe (PID: 2204)
    • Reads internet explorer settings

      • iexplore.exe (PID: 2204)
    • Starts application with an unusual extension

      • MsiExec.exe (PID: 2380)
    • Adds / modifies Windows certificates

      • iexplore.exe (PID: 3644)
    • Changes settings of System certificates

      • iexplore.exe (PID: 3644)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: NF03849238867426874.msi
ZipUncompressedSize: 654336
ZipCompressedSize: 301096
ZipCRC: 0x2a427c14
ZipModifyDate: 2019:05:12 20:59:25
ZipCompression: Deflated
ZipBitFlag: -
ZipRequiredVersion: 20
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
54
Monitored processes
14
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start drop and start winrar.exe msiexec.exe no specs msiexec.exe msiexec.exe cmd.exe no specs iexplore.exe iexplore.exe cmd.exe no specs cmd.exe no specs cmd.exe no specs reg.exe shutdown.exe no specs shutdown.exe no specs lca89d.tmp no specs

Process information

PID
CMD
Path
Indicators
Parent process
2932"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\download.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.60.0
3808"C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\Rar$EXa2932.43823\NF03849238867426874.msi" C:\Windows\System32\msiexec.exeWinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
3104C:\Windows\system32\msiexec.exe /VC:\Windows\system32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
2380C:\Windows\system32\MsiExec.exe -Embedding 154324DC4231C7A7513C3253F376B64BC:\Windows\system32\MsiExec.exe
msiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
2360"C:\Windows\System32\cmd.exe" /C start /MAX https://adobe.ly/2RY5GJRC:\Windows\System32\cmd.exeMsiExec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
3644"C:\Program Files\Internet Explorer\iexplore.exe" -nohomeC:\Program Files\Internet Explorer\iexplore.exe
cmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
1073807364
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
2204"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3644 CREDAT:71937C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
3496"C:\Windows\System32\cmd.exe" /C start /MIN reg add HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v LrNKtd /t reg_sz /d "C:\Users\admin\AppData\Roaming\AnyDesk\LrNKtd\LrNKtd.exe"C:\Windows\System32\cmd.exeMsiExec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
3652"C:\Windows\System32\cmd.exe" /C shutdown -r -f -t 0C:\Windows\System32\cmd.exeMsiExec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
3852"C:\Windows\system32\cmd.exe" /c shutdown /r /t 1 /fC:\Windows\system32\cmd.exeMsiExec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1115
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Total events
1 559
Read events
1 433
Write events
0
Delete events
0

Modification events

No data
Executable files
12
Suspicious files
3
Text files
25
Unknown types
19

Dropped files

PID
Process
Filename
Type
3644iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H6QNMHE9\favicon[1].ico
MD5:
SHA256:
3644iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
MD5:
SHA256:
2204iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\History\Low\History.IE5\index.datdat
MD5:027953A150DEF7531608B32C27EF79D8
SHA256:B1C33D560008C9B85DE9E387BE220625D6B57D64CB8E5D85808873FD3ADE5ABA
2204iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\index.datdat
MD5:52D61E0F5B0DB201DACD83BA4023217D
SHA256:38965B702734006DF0F8D6C8AF33F0051F3B5E843F1ED69322D99646BDD7A414
2932WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2932.43823\NF03849238867426874.msiexecutable
MD5:F1CEB408E9E673B6C71FB14968920BFD
SHA256:0AE98D4F944E0733F80732EBBBE519A0B102249EC9A2DF4041E35B863BC5AAD0
2204iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\admin@adobe[1].txttext
MD5:073D2AA874401FFB9F30756592895CEF
SHA256:76357B98705119250F6460672939BB2666211A8309FCCD03C3E7E3F597DE52BC
3104msiexec.exeC:\Windows\Installer\15587a.msiexecutable
MD5:F1CEB408E9E673B6C71FB14968920BFD
SHA256:0AE98D4F944E0733F80732EBBBE519A0B102249EC9A2DF4041E35B863BC5AAD0
2204iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FLAR3RZW\terms[1].htmlhtml
MD5:EA2EE123839F554CCF4BE7156D16CF2B
SHA256:3FD6C46E873D77AF25C49CF57ADAABCCC10318896B0F942532EDD4AF26CA9AD1
2204iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\RCP6HZZC\adobe.min.fp-9f089e57989ec2e6fb36add7a91cbd7b[1].csstext
MD5:E128187D03C3440C7C4F881BDDFD5075
SHA256:0AF569746751282665C23B2BD8CFF33477EDAA223DBA31C38891A256973334A7
2204iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\index.datdat
MD5:0EB2A09B1C2E41A632DE66D63247229E
SHA256:50502398E3CFEEE85F2BD5B90D93077A4B4BCF23153C723379BC7466B07FCEF7
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
18
DNS requests
7
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3644
iexplore.exe
GET
200
204.79.197.200:80
http://www.bing.com/favicon.ico
US
image
237 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3644
iexplore.exe
204.79.197.200:80
www.bing.com
Microsoft Corporation
US
whitelisted
216.58.205.228:80
www.google.com
Google Inc.
US
whitelisted
2380
MsiExec.exe
52.218.104.170:443
s3-eu-west-1.amazonaws.com
Amazon.com, Inc.
IE
unknown
2204
iexplore.exe
67.199.248.13:443
adobe.ly
Bitly Inc
US
shared
3644
iexplore.exe
23.0.43.123:443
www.adobe.com
Akamai Technologies, Inc.
NL
whitelisted
2204
iexplore.exe
23.0.43.123:443
www.adobe.com
Akamai Technologies, Inc.
NL
whitelisted
2204
iexplore.exe
23.38.53.224:443
use.typekit.com
Akamai International B.V.
NL
whitelisted

DNS requests

Domain
IP
Reputation
s3-eu-west-1.amazonaws.com
  • 52.218.104.170
shared
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
adobe.ly
  • 67.199.248.13
  • 67.199.248.12
suspicious
www.adobe.com
  • 23.0.43.123
whitelisted
use.typekit.com
  • 23.38.53.224
whitelisted
p.typekit.net
  • 23.38.53.224
shared
www.google.com
  • 216.58.205.228
whitelisted

Threats

No threats detected
No debug info