| File name: | Setup.zip |
| Full analysis: | https://app.any.run/tasks/3ee815c2-97bd-4442-8d6c-a8a6efe57a6a |
| Verdict: | Malicious activity |
| Threats: | A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection. |
| Analysis date: | July 14, 2021, 00:45:43 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | BB080BC4E0204172E699A31052C91B99 |
| SHA1: | C8691AF125E25DE8740217BC7A98954840036493 |
| SHA256: | DB8B919ECB43B5C41CBB43600AE1275D89BDCE01D1A6EA1A05504357197731BC |
| SSDEEP: | 393216:Qtm8O7sSzbomdOXZ7j28GEEUH9dSUpq7b/bJkjPgtvh:weom4BrbH9dSyq77bR |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipFileName: | data.dat |
|---|---|
| ZipUncompressedSize: | 11819661 |
| ZipCompressedSize: | 11626643 |
| ZipCRC: | 0xd63727b9 |
| ZipModifyDate: | 2021:07:03 14:27:12 |
| ZipCompression: | Deflated |
| ZipBitFlag: | - |
| ZipRequiredVersion: | 20 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 272 | "C:\Users\admin\AppData\Local\Temp\_ir_sf_temp_1\irsetup.exe" __IRAOFF:1796642 "__IRAFN:C:\Users\admin\AppData\Local\Temp\Setup_8854.exe" "__IRCT:0" "__IRTSS:0" "__IRSID:S-1-5-21-1302019708-1500728564-335382590-1000" | C:\Users\admin\AppData\Local\Temp\_ir_sf_temp_1\irsetup.exe | Setup_8854.exe | ||||||||||||
User: admin Company: Indigo Rose Corporation Integrity Level: HIGH Description: Setup Application Exit code: 0 Version: 9.5.1.0 Modules
| |||||||||||||||
| 324 | "sc.exe" failure WCAssistantService reset= 30 actions= restart/60000 | C:\Windows\system32\sc.exe | — | WebCompanionInstaller.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: A tool to aid in developing services for WindowsNT Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 340 | .\WebCompanionInstaller.exe --partner=AE190201 --campaign=494 --version=7.0.2417.4248 --prod --silent --partner=AE190201 --homepage=1 --search=1 --campaign=494 | C:\Users\admin\AppData\Local\Temp\7zS039B47E7\WebCompanionInstaller.exe | WcInstaller.exe | ||||||||||||
User: admin Company: Lavasoft Integrity Level: HIGH Description: Web Companion Exit code: 0 Version: 7.0.2417.4248 Modules
| |||||||||||||||
| 360 | C:\Windows\system32\cmd.exe /c ""C:\Program Files\MaskVPN\driver\win732\uninstall.bat" " | C:\Windows\system32\cmd.exe | — | maskvpn.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 384 | C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Windows\TEMP\RES5D91.tmp" "c:\Windows\Temp\CSC5D90.tmp" | C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.exe | — | csc.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft� Resource File To COFF Object Conversion Utility Exit code: 0 Version: 8.00.50727.5003 (Win7SP1GDR.050727-5400) Modules
| |||||||||||||||
| 544 | "C:\Program Files\Internet Explorer\iexplore.exe" http://dariasdoors.xyz/pgudonqntu/zmsaksepfx.php?xdl=mtn1co3fo4gs5vwq&cid=74449¶m=534 | C:\Program Files\Internet Explorer\iexplore.exe | cmd.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Internet Explorer Exit code: 1 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| 856 | "C:\Users\admin\AppData\Local\Temp\installerapp.exe" /qn CAMPAIGN="1981" | C:\Users\admin\AppData\Local\Temp\installerapp.exe | irsetup.exe | ||||||||||||
User: admin Company: AW Manager Integrity Level: HIGH Description: Windows Manager Installer Exit code: 0 Version: 1.0.0 Modules
| |||||||||||||||
| 1088 | "C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe" /noconfig /fullpaths @"C:\Users\admin\AppData\Local\Temp\acgvi4j_.cmdline" | C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe | — | WebCompanion.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Visual C# Command Line Compiler Exit code: 0 Version: 8.0.50727.5483 (Win7SP1GDR.050727-5400) Modules
| |||||||||||||||
| 1128 | "C:\Program Files\MaskVPN\mask_svc.exe" uninstall | C:\Program Files\MaskVPN\mask_svc.exe | — | maskvpn.tmp | |||||||||||
User: admin Company: Global Media (Thailand) Co., Ltd Integrity Level: HIGH Description: MaskVPN Service Exit code: 0 Version: 1.1.0.12 Modules
| |||||||||||||||
| 1164 | tapinstall.exe remove tap0901 | C:\Program Files\MaskVPN\driver\win732\tapinstall.exe | — | cmd.exe | |||||||||||
User: admin Company: Windows (R) Win 7 DDK provider Integrity Level: HIGH Description: Windows Setup API Exit code: 0 Version: 6.1.7600.16385 built by: WinDDK Modules
| |||||||||||||||
| (PID) Process: | (2052) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (2052) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (2052) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2052) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (2052) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Setup.zip | |||
| (PID) Process: | (2052) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2052) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2052) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2052) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (2052) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2052 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2052.40790\data.dat | — | |
MD5:— | SHA256:— | |||
| 2052 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2052.40790\Setup.exe | executable | |
MD5:— | SHA256:— | |||
| 2088 | irsetup.exe | C:\Users\admin\AppData\Local\Temp\Setup_8854.exe | executable | |
MD5:— | SHA256:— | |||
| 2088 | irsetup.exe | C:\Users\admin\AppData\Local\Temp\data.dat | binary | |
MD5:— | SHA256:— | |||
| 2088 | irsetup.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\204C1AA6F6114E6A513754A2AB5760FA_8AF12CCCEA7B166E05AA3A3A6D2A2BA3 | binary | |
MD5:— | SHA256:— | |||
| 2088 | irsetup.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157 | binary | |
MD5:— | SHA256:— | |||
| 2088 | irsetup.exe | C:\Users\admin\AppData\Local\Temp\_ir_sf_temp_0\irsetup.dat | binary | |
MD5:— | SHA256:— | |||
| 272 | irsetup.exe | C:\Users\admin\AppData\Local\Temp\_ir_sf_temp_1\irsetup.dat | binary | |
MD5:— | SHA256:— | |||
| 2088 | irsetup.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B2FAF7692FD9FFBD64EDE317E42334BA_D7393C8F62BDE4D4CB606228BC7A711E | der | |
MD5:— | SHA256:— | |||
| 2088 | irsetup.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B2FAF7692FD9FFBD64EDE317E42334BA_D7393C8F62BDE4D4CB606228BC7A711E | binary | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3672 | iexplore.exe | GET | 301 | 185.102.136.153:80 | http://dariasdoors.xyz/pgudonqntu/zmsaksepfx.php?xdl=mtn1co3fo4gs5vwq&cid=74449¶m=534 | RU | — | — | suspicious |
272 | irsetup.exe | GET | 200 | 13.225.84.66:80 | http://o.ss2.us//MEowSDBGMEQwQjAJBgUrDgMCGgUABBSLwZ6EW5gdYc9UaSEaaLjjETNtkAQUv1%2B30c7dH4b0W1Ws3NcQwg6piOcCCQCnDkpMNIK3fw%3D%3D | US | der | 1.70 Kb | whitelisted |
2088 | irsetup.exe | GET | 200 | 151.139.128.14:80 | http://ocsp.usertrust.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBRyyuDOSqb8BtprWZSAvBT9kFoYdwQU%2BftQxItnu2dk%2FoMhpqnOP1WEk5kCEQDdVs2lraG7N4ogwDjWaBIG | US | der | 472 b | whitelisted |
272 | irsetup.exe | GET | 200 | 46.101.214.246:80 | http://www.findmemolite.com/installer.exe | DE | executable | 3.45 Mb | whitelisted |
272 | irsetup.exe | GET | 200 | 5.182.39.129:80 | http://inlgfiles.com/windows/storage/IBInstaller_74449.exe | unknown | executable | 11.5 Mb | suspicious |
3040 | svrwebui.exe | POST | 200 | 5.252.179.5:1203 | http://5.252.179.5/fakeurl.htm | unknown | binary | 160 b | suspicious |
3040 | svrwebui.exe | GET | 200 | 62.172.138.35:80 | http://geo.netsupportsoftware.com/location/loca.asp | GB | text | 16 b | suspicious |
272 | irsetup.exe | GET | 200 | 143.204.101.124:80 | http://ocsp.rootg2.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBSIfaREXmfqfJR3TkMYnD7O5MhzEgQUnF8A36oB1zArOIiiuG1KnPIRkYMCEwZ%2FlEoqJ83z%2BsKuKwH5CO65xMY%3D | US | der | 1.51 Kb | whitelisted |
3040 | svrwebui.exe | POST | 200 | 5.252.179.5:1203 | http://5.252.179.5/fakeurl.htm | unknown | binary | 61 b | suspicious |
272 | irsetup.exe | GET | 200 | 143.204.101.42:80 | http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwZ%2FlFeFh%2Bisd96yUzJbvJmLVg0%3D | US | der | 1.39 Kb | shared |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2088 | irsetup.exe | 23.55.58.106:80 | ctldl.windowsupdate.com | Akamai International B.V. | NL | unknown |
272 | irsetup.exe | 208.95.112.1:80 | ip-api.com | IBURST | — | malicious |
2088 | irsetup.exe | 151.139.128.14:80 | ocsp.comodoca.com | Highwinds Network Group, Inc. | US | suspicious |
272 | irsetup.exe | 46.101.214.246:80 | www.findmemolite.com | Digital Ocean, Inc. | DE | suspicious |
272 | irsetup.exe | 52.84.193.75:443 | duzlwewk2uk96.cloudfront.net | Amazon.com, Inc. | US | unknown |
272 | irsetup.exe | 13.225.84.66:80 | o.ss2.us | — | US | suspicious |
2088 | irsetup.exe | 23.109.93.100:443 | filedn.com | — | NL | unknown |
272 | irsetup.exe | 143.204.101.124:80 | ocsp.rootg2.amazontrust.com | — | US | whitelisted |
272 | irsetup.exe | 143.204.101.42:80 | ocsp.rootg2.amazontrust.com | — | US | whitelisted |
3844 | MsiExec.exe | 54.226.29.2:443 | collect.installeranalytics.com | Amazon.com, Inc. | US | malicious |
Domain | IP | Reputation |
|---|---|---|
filedn.com |
| suspicious |
ctldl.windowsupdate.com |
| whitelisted |
ocsp.comodoca.com |
| whitelisted |
ocsp.usertrust.com |
| whitelisted |
ip-api.com |
| malicious |
www.findmemolite.com |
| whitelisted |
duzlwewk2uk96.cloudfront.net |
| whitelisted |
o.ss2.us |
| whitelisted |
ocsp.rootg2.amazontrust.com |
| whitelisted |
ocsp.rootca1.amazontrust.com |
| shared |
PID | Process | Class | Message |
|---|---|---|---|
272 | irsetup.exe | Potential Corporate Privacy Violation | ET POLICY External IP Lookup ip-api.com |
272 | irsetup.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
272 | irsetup.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
272 | irsetup.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
272 | irsetup.exe | Misc activity | ET INFO EXE - Served Attached HTTP |
3672 | iexplore.exe | Potentially Bad Traffic | AV INFO HTTP Request to a *.xyz domain |
272 | irsetup.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
272 | irsetup.exe | Misc activity | ET INFO EXE - Served Attached HTTP |
3952 | pmropn.exe | Potential Corporate Privacy Violation | ET INFO Suspected PUP/PUA User-Agent (OSSProxy) |
3952 | pmropn.exe | Potentially Bad Traffic | AV INFO HTTP Request to a *.xyz domain |
Process | Message |
|---|---|
WebCompanionInstaller.exe | Detecting windows culture
|
WebCompanionInstaller.exe | 7/14/2021 1:47:04 AM :-> Starting installer 7.0.2417.4248 with: .\WebCompanionInstaller.exe --partner=AE190201 --campaign=494 --version=7.0.2417.4248 --prod --silent --partner=AE190201 --homepage=1 --search=1 --campaign=494, Run as admin: True
|
WebCompanionInstaller.exe | Preparing for installing Web Companion
|
WebCompanionInstaller.exe | 7/14/2021 1:47:05 AM :-> Generating Machine and Install Id ...
|
WebCompanionInstaller.exe | 7/14/2021 1:47:05 AM :-> Machine Id and Install Id has been generated
|
WebCompanionInstaller.exe | 7/14/2021 1:47:05 AM :-> Checking prerequisites ...
|
WebCompanionInstaller.exe | 7/14/2021 1:47:05 AM :-> Antivirus not detected
|
WebCompanionInstaller.exe | 7/14/2021 1:47:06 AM :-> vm_check False
|
WebCompanionInstaller.exe | 7/14/2021 1:47:06 AM :-> reg_check :False
|
WebCompanionInstaller.exe | 7/14/2021 1:47:06 AM :-> Installed .Net framework is V40
|