| File name: | 7z22.01-zstd-x64.exe |
| Full analysis: | https://app.any.run/tasks/660bd5d1-5ec2-40f0-9efa-c76d7f461e41 |
| Verdict: | Malicious activity |
| Analysis date: | January 04, 2025, 12:18:34 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32+ executable (GUI) x86-64, for MS Windows, 7 sections |
| MD5: | 7D06C28595BD248B9F85FDBDC9B93D91 |
| SHA1: | 2A1E624836FAFC706C50325793F029E4FF7B0AC1 |
| SHA256: | D542D78397BBED8E77C221F36CAD461A0D83F1263B993A7048E81DF40F403FB8 |
| SSDEEP: | 98304:VOH/iyeqQaBcz7aeP0jU2nkg0xsxOmh+g1oyf8chgr4RrysfE+ipb5Cdz0BceHsN:mM3Q |
| .exe | | | Win64 Executable (generic) (87.3) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (6.3) |
| .exe | | | DOS Executable Generic (6.3) |
| MachineType: | AMD AMD64 |
|---|---|
| TimeStamp: | 2023:06:18 13:18:53+00:00 |
| ImageFileCharacteristics: | Executable, Large address aware |
| PEType: | PE32+ |
| LinkerVersion: | 14.29 |
| CodeSize: | 86528 |
| InitializedDataSize: | 74240 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x8a54 |
| OSVersion: | 5.2 |
| ImageVersion: | - |
| SubsystemVersion: | 5.2 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 22.1.6.0 |
| ProductVersionNumber: | 22.1.6.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Igor Pavlov, Tino Reichardt |
| FileDescription: | 7-Zip Installer ZS |
| FileVersion: | 22.01 ZS v1.5.5 R3 |
| InternalName: | 7zipInstall |
| LegalCopyright: | Copyright (c) 1999-2022 Igor Pavlov, 2016-2023 Tino Reichardt |
| OriginalFileName: | 7zipInstall.exe |
| ProductName: | 7-Zip ZS |
| ProductVersion: | 22.01 ZS v1.5.5 R3 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 3032 | "C:\Users\admin\Desktop\7z22.01-zstd-x64.exe" | C:\Users\admin\Desktop\7z22.01-zstd-x64.exe | — | explorer.exe | |||||||||||
User: admin Company: Igor Pavlov, Tino Reichardt Integrity Level: MEDIUM Description: 7-Zip Installer ZS Exit code: 3221226540 Version: 22.01 ZS v1.5.5 R3 Modules
| |||||||||||||||
| 3840 | "C:\Users\admin\Desktop\7z22.01-zstd-x64.exe" | C:\Users\admin\Desktop\7z22.01-zstd-x64.exe | explorer.exe | ||||||||||||
User: admin Company: Igor Pavlov, Tino Reichardt Integrity Level: HIGH Description: 7-Zip Installer ZS Exit code: 0 Version: 22.01 ZS v1.5.5 R3 Modules
| |||||||||||||||
| (PID) Process: | (3840) 7z22.01-zstd-x64.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\7-Zip-Zstandard |
| Operation: | write | Name: | Path64 |
Value: C:\Program Files\7-Zip-Zstandard\ | |||
| (PID) Process: | (3840) 7z22.01-zstd-x64.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\7-Zip-Zstandard |
| Operation: | write | Name: | Path |
Value: C:\Program Files\7-Zip-Zstandard\ | |||
| (PID) Process: | (3840) 7z22.01-zstd-x64.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\7-Zip-Zstandard |
| Operation: | write | Name: | Path64 |
Value: C:\Program Files\7-Zip-Zstandard\ | |||
| (PID) Process: | (3840) 7z22.01-zstd-x64.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\7-Zip-Zstandard |
| Operation: | write | Name: | Path |
Value: C:\Program Files\7-Zip-Zstandard\ | |||
| (PID) Process: | (3840) 7z22.01-zstd-x64.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{23170F69-20BB-278A-1000-000100020000}\InprocServer32 |
| Operation: | write | Name: | ThreadingModel |
Value: Apartment | |||
| (PID) Process: | (3840) 7z22.01-zstd-x64.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{23170F69-20BB-278A-1000-000100020000}\InprocServer32 |
| Operation: | write | Name: | ThreadingModel |
Value: Apartment | |||
| (PID) Process: | (3840) 7z22.01-zstd-x64.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved |
| Operation: | write | Name: | {23170F69-20BB-278A-1000-000100020000} |
Value: 7-Zip Shell Extension | |||
| (PID) Process: | (3840) 7z22.01-zstd-x64.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved |
| Operation: | write | Name: | {23170F69-20BB-278A-1000-000100020000} |
Value: 7-Zip Shell Extension | |||
| (PID) Process: | (3840) 7z22.01-zstd-x64.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\7zFM.exe |
| Operation: | write | Name: | Path |
Value: C:\Program Files\7-Zip-Zstandard\ | |||
| (PID) Process: | (3840) 7z22.01-zstd-x64.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\7-Zip-Zstandard |
| Operation: | write | Name: | DisplayName |
Value: 7-Zip ZS 22.01 ZS v1.5.5 R3 (x64) | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3840 | 7z22.01-zstd-x64.exe | C:\Program Files\7-Zip-Zstandard\7-zip.dll | executable | |
MD5:8D783680585680BF17FFD4B5B4EEF375 | SHA256:86C055F0D90C71A595D806F8EB8BA57538E29370F52D476A72018D6B1C4E200D | |||
| 3840 | 7z22.01-zstd-x64.exe | C:\Program Files\7-Zip-Zstandard\7zG.exe | executable | |
MD5:81AD454E04520D15C9F90648362C4EBE | SHA256:BE4A492B2BB8A0CB149D12D6FFB1FD1CAAF2380D0EC2C41A245A1971958A6B65 | |||
| 3840 | 7z22.01-zstd-x64.exe | C:\Program Files\7-Zip-Zstandard\7-zip32.dll | executable | |
MD5:02C326E385FB8BD5A0F024E5E76DE255 | SHA256:E2A86745E36113106B9A981E48E30292770833D84AE9AA03F2247DA4C3FACB7A | |||
| 3840 | 7z22.01-zstd-x64.exe | C:\Program Files\7-Zip-Zstandard\7zCon.sfx | executable | |
MD5:50C4DF51DA71A054DD56D6DB8315E9D3 | SHA256:7275B11A94005FC9FE24B3C6F62F990091EAB78B2963BEA4A4A5D787FE3D300F | |||
| 3840 | 7z22.01-zstd-x64.exe | C:\Program Files\7-Zip-Zstandard\descript.ion | text | |
MD5:EB7E322BDC62614E49DED60E0FB23845 | SHA256:1DA513F5A4E8018B9AE143884EB3EAF72454B606FD51F2401B7CFD9BE4DBBF4F | |||
| 3840 | 7z22.01-zstd-x64.exe | C:\Program Files\7-Zip-Zstandard\7zFM.exe | executable | |
MD5:FEA2166E75330AA45D9CF1BCDB1C6D78 | SHA256:010415F21A405C9BA85223527AF2D147190819E8CD2CEFC1E8BD3ECACAC550FE | |||
| 3840 | 7z22.01-zstd-x64.exe | C:\Program Files\7-Zip-Zstandard\7z.dll | executable | |
MD5:E17D30C5150B1865380A781A938EE702 | SHA256:E497DF52D338EB930D7179BA2A5F87A44838797ECA8A7F34F9910C774CD64654 | |||
| 3840 | 7z22.01-zstd-x64.exe | C:\Program Files\7-Zip-Zstandard\7-zip.chm | chm | |
MD5:34208890A28244903621CD32CC3FBDFC | SHA256:4B6939646570C9DDB5BFD39B8503EED99D8C64337E72F6DD4F9DDCFB4AC76703 | |||
| 3840 | 7z22.01-zstd-x64.exe | C:\Program Files\7-Zip-Zstandard\History.txt | text | |
MD5:B1206A5ABF93BC64601A3CAA2DFF47D4 | SHA256:24A8A7C00F0BB8AC3096F58F53BD47FA392B8D220C1C43D372100BD692C68E5F | |||
| 3840 | 7z22.01-zstd-x64.exe | C:\Program Files\7-Zip-Zstandard\Lang\af.txt | text | |
MD5:FBBE51ACB879B525CC6B19D386697924 | SHA256:3793FB69EE9FD958CF15A272B1ED54E4B3D75592836EBCD085DC0E7B1400D1CB | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
4712 | MoUsoCoreWorker.exe | GET | 200 | 2.20.245.138:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
188 | svchost.exe | GET | 200 | 2.20.245.138:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
4712 | MoUsoCoreWorker.exe | GET | 200 | 23.38.73.129:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
188 | svchost.exe | GET | 200 | 23.38.73.129:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
— | — | POST | 204 | 2.19.80.27:443 | https://www.bing.com/threshold/xls.aspx | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4712 | MoUsoCoreWorker.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 192.168.100.255:138 | — | — | — | whitelisted |
188 | svchost.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 2.19.80.75:443 | www.bing.com | Akamai International B.V. | DE | whitelisted |
4712 | MoUsoCoreWorker.exe | 2.20.245.138:80 | crl.microsoft.com | Akamai International B.V. | SE | whitelisted |
188 | svchost.exe | 2.20.245.138:80 | crl.microsoft.com | Akamai International B.V. | SE | whitelisted |
4712 | MoUsoCoreWorker.exe | 23.38.73.129:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
188 | svchost.exe | 23.38.73.129:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
3976 | svchost.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
google.com |
| unknown |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
self.events.data.microsoft.com |
| whitelisted |