File name:

1.zip

Full analysis: https://app.any.run/tasks/d4ae936f-ffc2-46c6-89d5-4d079b23608c
Verdict: Malicious activity
Threats:

Gootkit is an advanced banking trojan. It is extremely good at evading detection and has an incredibly effective persistence mechanism, making it a dangerous malware that researchers and organizations should be aware of.

Analysis date: January 18, 2019, 13:09:27
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
trojan
gootkit
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

FD331EE5DCA1704EB579B2A536CF124A

SHA1:

B63D7B251ABB3C11BE9644FE1284D0CBB1DC2DAD

SHA256:

D6CDCE2A29DCD4B15980E422411849BE36AE42DB724B877473C208B160E52812

SSDEEP:

196608:gBBKFGrGBuUBLg7eRI1ONZUgJ+XK1akR+iU1w:UQklN7EOO35IX8xi2

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • tcmd921ax32_64.exe (PID: 3448)
      • tcmd921ax32_64.exe (PID: 2188)
      • 1.exe (PID: 2280)
      • 1.exe (PID: 3468)
      • TOTALCMD.EXE (PID: 3772)
    • Loads dropped or rewritten executable

      • TOTALCMD.EXE (PID: 3772)
    • Detected GootKit

      • 1.exe (PID: 2280)
    • Changes internet zones settings

      • 1.exe (PID: 2280)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3176)
      • tcmd921ax32_64.exe (PID: 2188)
    • Creates files in the user directory

      • tcmd921ax32_64.exe (PID: 2188)
    • Creates a software uninstall entry

      • tcmd921ax32_64.exe (PID: 2188)
  • INFO

    • Dropped object may contain Bitcoin addresses

      • TOTALCMD.EXE (PID: 3772)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 788
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2019:01:11 12:34:04
ZipCRC: 0x2cb0ad60
ZipCompressedSize: 214237
ZipUncompressedSize: 258048
ZipFileName: 1.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
42
Monitored processes
7
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe tcmd921ax32_64.exe no specs tcmd921ax32_64.exe totalcmd.exe no specs taskmgr.exe no specs #GOOTKIT 1.exe 1.exe

Process information

PID
CMD
Path
Indicators
Parent process
1228"C:\Windows\system32\taskmgr.exe" /4C:\Windows\system32\taskmgr.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Task Manager
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskmgr.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2188"C:\Users\admin\Desktop\tcmd921ax32_64.exe" C:\Users\admin\Desktop\tcmd921ax32_64.exe
explorer.exe
User:
admin
Company:
Ghisler Software GmbH
Integrity Level:
HIGH
Description:
Total Commander Installer
Exit code:
0
Version:
9.21
Modules
Images
c:\users\admin\desktop\tcmd921ax32_64.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2280"C:\Users\admin\Desktop\1.exe" C:\Users\admin\Desktop\1.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\1.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3176"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\1.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3448"C:\Users\admin\Desktop\tcmd921ax32_64.exe" C:\Users\admin\Desktop\tcmd921ax32_64.exeexplorer.exe
User:
admin
Company:
Ghisler Software GmbH
Integrity Level:
MEDIUM
Description:
Total Commander Installer
Exit code:
3221226540
Version:
9.21
Modules
Images
c:\users\admin\desktop\tcmd921ax32_64.exe
c:\systemroot\system32\ntdll.dll
3468C:\Users\admin\Desktop\1.exe --vwxyzC:\Users\admin\Desktop\1.exe
1.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\1.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3772"C:\totalcmd\TOTALCMD.EXE" C:\totalcmd\TOTALCMD.EXEexplorer.exe
User:
admin
Company:
Ghisler Software GmbH
Integrity Level:
MEDIUM
Description:
Total Commander 32 bit
Exit code:
0
Version:
9.21
Modules
Images
c:\totalcmd\totalcmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
Total events
1 542
Read events
932
Write events
610
Delete events
0

Modification events

(PID) Process:(3176) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3176) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3176) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3176) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\1.zip
(PID) Process:(3176) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3176) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3176) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3176) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3176) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath
Operation:writeName:0
Value:
C:\Users\admin\Desktop
(PID) Process:(3176) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
Executable files
35
Suspicious files
3
Text files
79
Unknown types
6

Dropped files

PID
Process
Filename
Type
3176WinRAR.exeC:\Users\admin\Desktop\1.exeexecutable
MD5:
SHA256:
3176WinRAR.exeC:\Users\admin\Desktop\tcmd921ax32_64.exeexecutable
MD5:
SHA256:
2188tcmd921ax32_64.exeC:\totalcmd\KEYBOARD.TXTtext
MD5:7A4E6F15F1021D196932447949470365
SHA256:BFE42E35DE6B0790A137DFD76F0FB87A6EF625BBEE092912CD7AF051A91DC123
2188tcmd921ax32_64.exeC:\totalcmd\LANGUAGE\WCMD_DEU.LNGtext
MD5:204FF34EBC1865D7CFB94EEC6F7D5929
SHA256:86319A4E54FEA63005DB9CAB2C97DF951E89F3144A52C2E9C259BB703C76F837
2188tcmd921ax32_64.exeC:\totalcmd\LANGUAGE\WCMD_DEU.MNUtext
MD5:071ABBEBABC98916675719777FC84DD0
SHA256:96504F3FBF117B12FB2720F5C4FDF181D3F31B43277148C00FAE8279233CD541
2188tcmd921ax32_64.exeC:\totalcmd\LANGUAGE\WCMD_DAN.INCtext
MD5:2C970AFCC36F0C4474EAD9D0135CF2FA
SHA256:15676A2CD1107859E1ACF384BE658BBF6FEA209CE2E277270E1EB3B99636C335
2188tcmd921ax32_64.exeC:\totalcmd\LANGUAGE\WCMD_DUT.LNGtext
MD5:CA497DE753B4A00E7E6283F0283DA0E8
SHA256:06097327121F172C7381D7F96C02CED8ADBFA4AAB2469C3427A9B200727AA088
2188tcmd921ax32_64.exeC:\totalcmd\LANGUAGE\WCMD_DUT.INCtext
MD5:2A33D7D9AE91A3F492D8BE34BF14B20B
SHA256:6A7173F2260E7C293A586FDE513DA82295F7CC3983FF5AD2738435BC2879C709
2188tcmd921ax32_64.exeC:\totalcmd\LANGUAGE\WCMD_ESP.LNGtext
MD5:788EC435276281E135A7FE55B06EFD71
SHA256:EB187C08634AFB183082641FECB8C3DB99DA9BE61A1B00102FD5D6355A583EA9
2188tcmd921ax32_64.exeC:\totalcmd\LANGUAGE\WCMD_CZ.LNGtext
MD5:ADAD053363D15B2EBD8973FC90D1ABA1
SHA256:5177A6EA9053A1291CB3615F6A0821A3421B6727D9524904AD243D440BF57654
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

Domain
IP
Reputation
drk.fm604.com
malicious

Threats

No threats detected
Process
Message
1.exe
MP3 file corrupted
1.exe
WMA 0
1.exe
OGG 0