File name:

WPJCleanUp.zip

Full analysis: https://app.any.run/tasks/5422f9a7-3376-431a-b351-a8fe749b83fc
Verdict: Malicious activity
Analysis date: November 08, 2024, 22:40:33
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-exec
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=store
MD5:

7F263A0FE41106EBB34CE3E8FC6BCB89

SHA1:

A84AE189732107DAFD2182B97AC928AF8B48D169

SHA256:

DA6A1126510AF787472F32B0535AF2920799E6460F5E46779AA2DADB6CAABCFF

SSDEEP:

49152:+SuQyygkw8300dRR/X1wPMm5/nIjs4pQYBLXdcXlo90kJB68300dRR/X1wPMm5/d:SUk0dR5YXkQYYXlo6kXfk0dR5YXkQYYD

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 6624)
  • SUSPICIOUS

    • Starts CMD.EXE for commands execution

      • cmd.exe (PID: 5324)
      • cmd.exe (PID: 6756)
      • cmd.exe (PID: 6908)
    • Application launched itself

      • cmd.exe (PID: 5324)
      • cmd.exe (PID: 6756)
      • cmd.exe (PID: 6908)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 6624)
    • Manual execution by a user

      • cmd.exe (PID: 5324)
      • notepad.exe (PID: 1500)
      • cmd.exe (PID: 6756)
      • cmd.exe (PID: 6908)
    • Checks operating system version

      • cmd.exe (PID: 5324)
      • cmd.exe (PID: 6756)
      • cmd.exe (PID: 6908)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2021:06:17 13:21:36
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: WPJCleanUp/WPJCleanUp/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
145
Monitored processes
15
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe rundll32.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs cleanupwpj_x86.exe no specs notepad.exe no specs cmd.exe conhost.exe no specs cmd.exe no specs cleanupwpj_x86.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs cleanupwpj_x86.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
700C:\Users\admin\Desktop\WPJCleanUp\WPJCleanUp\.\v2004\CleanupWPJ_X86.exe C:\Users\admin\Desktop\WPJCleanUp\WPJCleanUp\v2004\CleanupWPJ_X86.execmd.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\wpjcleanup\wpjcleanup\v2004\cleanupwpj_x86.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\combase.dll
c:\windows\syswow64\ucrtbase.dll
1500"C:\WINDOWS\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\WPJCleanUp\WPJCleanUp\output.txtC:\Windows\System32\notepad.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
2632C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
2980C:\WINDOWS\system32\cmd.exe /c verC:\Windows\System32\cmd.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
4128C:\Users\admin\Desktop\WPJCleanUp\WPJCleanUp\.\v2004\CleanupWPJ_X86.exe C:\Users\admin\Desktop\WPJCleanUp\WPJCleanUp\v2004\CleanupWPJ_X86.execmd.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\wpjcleanup\wpjcleanup\v2004\cleanupwpj_x86.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\combase.dll
c:\windows\syswow64\ucrtbase.dll
4516C:\WINDOWS\system32\cmd.exe /c verC:\Windows\System32\cmd.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
5324C:\WINDOWS\system32\cmd.exe /c ""C:\Users\admin\Desktop\WPJCleanUp\WPJCleanUp\WPJCleanUp.cmd" "C:\Windows\System32\cmd.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cmdext.dll
c:\windows\system32\advapi32.dll
5896\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6028\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6192C:\WINDOWS\system32\cmd.exe /c verC:\Windows\System32\cmd.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
Total events
2 526
Read events
2 494
Write events
19
Delete events
13

Modification events

(PID) Process:(6624) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\GoogleChromeEnterpriseBundle64.zip
(PID) Process:(6624) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\WPJCleanUp.zip
(PID) Process:(6624) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(6624) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(6624) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(6624) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(6624) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:delete valueName:15
Value:
(PID) Process:(6624) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:delete valueName:14
Value:
(PID) Process:(6624) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:delete valueName:13
Value:
(PID) Process:(6624) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:delete valueName:12
Value:
Executable files
12
Suspicious files
0
Text files
3
Unknown types
0

Dropped files

PID
Process
Filename
Type
6624WinRAR.exeC:\Users\admin\Desktop\WPJCleanUp\WPJCleanUp\v1709\cleanup.cmdtext
MD5:043083618BAA65A3D09A8A7FD6C0F23A
SHA256:1A989F9DD27C799F62834F5343B1461B12FFA57EF14423604ED457468BBE37F2
6624WinRAR.exeC:\Users\admin\Desktop\WPJCleanUp\WPJCleanUp\v1803\cleanup.cmdtext
MD5:043083618BAA65A3D09A8A7FD6C0F23A
SHA256:1A989F9DD27C799F62834F5343B1461B12FFA57EF14423604ED457468BBE37F2
6624WinRAR.exeC:\Users\admin\Desktop\WPJCleanUp\WPJCleanUp\v1709\PsExec.exeexecutable
MD5:C590A84B8C72CF18F35AE166F815C9DF
SHA256:57492D33B7C0755BB411B22D2DFDFDF088CBBFCD010E30DD8D425D5FE66ADFF4
6624WinRAR.exeC:\Users\admin\Desktop\WPJCleanUp\WPJCleanUp\v1709\CleanupWPJ_AMD64.exeexecutable
MD5:3F1B91308035E6F16D7C06D73AA8DA65
SHA256:159F8DCC695D98B447600E3054A19D475562A2966655D7193730BA27B4B9F4BD
6624WinRAR.exeC:\Users\admin\Desktop\WPJCleanUp\WPJCleanUp\v1803\PsExec.exeexecutable
MD5:C590A84B8C72CF18F35AE166F815C9DF
SHA256:57492D33B7C0755BB411B22D2DFDFDF088CBBFCD010E30DD8D425D5FE66ADFF4
6624WinRAR.exeC:\Users\admin\Desktop\WPJCleanUp\WPJCleanUp\v1803\CleanupWPJ_AMD64.exeexecutable
MD5:358651D770BA438605A43A307F37B3B4
SHA256:646900B6FF39F9A62280CAA7C699DC1A473F3242EF8C2F8551B7FF4C2DA6463D
6624WinRAR.exeC:\Users\admin\Desktop\WPJCleanUp\WPJCleanUp\v1709\CleanupWPJ_X86.exeexecutable
MD5:C59ECB915E686FAE79C7612893E4C34D
SHA256:FA2E38A1A4BF60543D3191FFD62703A58AC521522862C60F0D160A6F126C3466
6624WinRAR.exeC:\Users\admin\Desktop\WPJCleanUp\WPJCleanUp\v1809\CleanupWPJ_X86.exeexecutable
MD5:FC3927858EBFD6C5167BCF4CEA555540
SHA256:B5C96610F6877704218B761DF29A12DB166ED668EFB95AEDBC137585F69E3CCF
6624WinRAR.exeC:\Users\admin\Desktop\WPJCleanUp\WPJCleanUp\v1809\CleanupWPJ_AMD64.exeexecutable
MD5:BA5253B2A31C5DD09507D038776D609E
SHA256:C973AFE1F219D46BA9C0E95024835B85E1D1E2AB85F908545B3A0EDFFC4101A4
6624WinRAR.exeC:\Users\admin\Desktop\WPJCleanUp\WPJCleanUp\v1903\CleanupWPJ_AMD64.exeexecutable
MD5:11173A6F452323C9068A5273DF203580
SHA256:98CC064CE20DF84E385B2DD1EB89F89A0C7DEAF448D7A37BF9DEED99CDA1AE31
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
42
DNS requests
21
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.48.23.143:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
23.37.237.227:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
4004
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
3004
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
6612
SIHClient.exe
GET
200
23.37.237.227:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6612
SIHClient.exe
GET
200
23.37.237.227:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
6944
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
5488
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
23.48.23.143:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
23.37.237.227:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4360
SearchApp.exe
2.16.204.148:443
www.bing.com
Akamai International B.V.
DE
whitelisted
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
4
System
192.168.100.255:138
whitelisted
4004
svchost.exe
20.190.159.68:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 40.127.240.158
  • 51.104.136.2
whitelisted
google.com
  • 142.250.185.174
whitelisted
crl.microsoft.com
  • 23.48.23.143
  • 23.48.23.156
whitelisted
www.microsoft.com
  • 23.37.237.227
whitelisted
www.bing.com
  • 2.16.204.148
  • 2.16.204.146
  • 2.16.204.150
  • 2.16.204.161
  • 2.16.204.135
  • 2.16.204.157
  • 2.16.204.145
  • 2.16.204.138
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 20.190.159.68
  • 40.126.31.67
  • 20.190.159.23
  • 20.190.159.2
  • 20.190.159.4
  • 20.190.159.64
  • 20.190.159.75
  • 20.190.159.71
whitelisted
th.bing.com
  • 2.16.204.135
  • 2.16.204.157
  • 2.16.204.138
whitelisted
go.microsoft.com
  • 23.218.210.69
whitelisted
slscr.update.microsoft.com
  • 4.245.163.56
whitelisted

Threats

No threats detected
No debug info