analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

db2475e26f5b9bed2b55f81f0a55c895c08fce3a6472f3e1f4dbfed83651d83a

Full analysis: https://app.any.run/tasks/80b83f4e-9b00-4920-b48a-ed1ee6fc5795
Verdict: Malicious activity
Analysis date: February 18, 2019, 09:52:06
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

E8A8673913C1AAAF3DAA9BC95D017A36

SHA1:

65114DBF6AFF51EE3D629D3EFC7F54D193727223

SHA256:

DB2475E26F5B9BED2B55F81F0A55C895C08FCE3A6472F3E1F4DBFED83651D83A

SSDEEP:

6144:KLRRgaZ6GN4HUeBZpRsTgF8agBFYLCI2lqfAG1TamSKaAw+rI4smsp5BnYxLH:yRjN4HUoZpOMcHYLx4MP14KaAw+k4sr8

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • reg.exe (PID: 3416)
      • reg.exe (PID: 3900)
  • SUSPICIOUS

    • Uses REG.EXE to modify Windows registry

      • javaw.exe (PID: 3496)
      • javaw.exe (PID: 3052)
    • Application launched itself

      • javaw.exe (PID: 3052)
    • Executes JAVA applets

      • javaw.exe (PID: 3052)
    • Creates files in the user directory

      • javaw.exe (PID: 3052)
    • Connects to unusual port

      • javaw.exe (PID: 3496)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.jar | Java Archive (78.3)
.zip | ZIP compressed archive (21.6)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0800
ZipCompression: Deflated
ZipModifyDate: 2018:02:09 19:44:21
ZipCRC: 0xab68524d
ZipCompressedSize: 54
ZipUncompressedSize: 56
ZipFileName: META-INF/MANIFEST.MF
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
37
Monitored processes
4
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start javaw.exe no specs reg.exe javaw.exe reg.exe

Process information

PID
CMD
Path
Indicators
Parent process
3052"C:\Program Files\Java\jre1.8.0_92\bin\javaw.exe" -jar "C:\Users\admin\Desktop\db2475e26f5b9bed2b55f81f0a55c895c08fce3a6472f3e1f4dbfed83651d83a.jar"C:\Program Files\Java\jre1.8.0_92\bin\javaw.exeexplorer.exe
User:
admin
Company:
Oracle Corporation
Integrity Level:
MEDIUM
Description:
Java(TM) Platform SE binary
Exit code:
0
Version:
8.0.920.14
3416reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ /v mac /t REG_SZ /d C:\Users\admin\AppData\Roaming\mac /fC:\Windows\system32\reg.exe
javaw.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Registry Console Tool
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
3496"C:\Program Files\Java\jre1.8.0_92\bin\javaw" -jar C:\Users\admin\AppData\Roaming\macC:\Program Files\Java\jre1.8.0_92\bin\javaw.exe
javaw.exe
User:
admin
Company:
Oracle Corporation
Integrity Level:
MEDIUM
Description:
Java(TM) Platform SE binary
Version:
8.0.920.14
3900reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ /v mac.jar /t REG_SZ /d "C:\Program Files\Java\jre1.8.0_92\bin\javaw.exe -jar "C:\Users\admin\AppData\Roaming\mac"" /fC:\Windows\system32\reg.exe
javaw.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Registry Console Tool
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Total events
16
Read events
14
Write events
2
Delete events
0

Modification events

(PID) Process:(3416) reg.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:mac
Value:
C:\Users\admin\AppData\Roaming\mac
(PID) Process:(3900) reg.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:mac.jar
Value:
C:\Program Files\Java\jre1.8.0_92\bin\javaw.exe -jar C:\Users\admin\AppData\Roaming\mac
Executable files
0
Suspicious files
1
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
3052javaw.exeC:\Users\admin\AppData\Roaming\maccompressed
MD5:FAF2DDFEACAE61333BB1DBFAC2A8CE3C
SHA256:3C55D7B334CDB5752B1DA90D60C31ED6F7EEFCB7A707305EDBBE9F934C336EB0
3052javaw.exeC:\Users\admin\.oracle_jre_usage\90737d32e3abaa4.timestamptext
MD5:0D9D4E82F765D4BECF4F7FCB2669F709
SHA256:FE2FA39DCC356792DDC47F318DBE6F7ED40DE108E2A1B5E1E10A94641BD56000
3496javaw.exeC:\Users\admin\.oracle_jre_usage\90737d32e3abaa4.timestamptext
MD5:0D1576FF14996543731E8AE0C019DA5B
SHA256:293B66489628962F3D5C9E23DB59FA6D7869E42EFB696314DBC77EFF7087B04D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
10
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3496
javaw.exe
145.249.104.47:1336
Quasi Networks LTD.
ES
suspicious

DNS requests

No data

Threats

No threats detected
No debug info