| File name: | StartIsBack.Plus.full.2.8.LTSoft.zip |
| Full analysis: | https://app.any.run/tasks/24ade1df-12ff-4bfa-99d6-2d63b39aeda8 |
| Verdict: | Malicious activity |
| Analysis date: | November 28, 2023, 18:48:58 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | 22106C66B755AFD87CDB42B9F744A590 |
| SHA1: | FEA0C880AD4D8153C945E17154B1298D10B96593 |
| SHA256: | DBF0B5EA45F55AE7926D4A9E18C2F6498E59489D4FA1EEAD63670D8BDB133240 |
| SSDEEP: | 98304:Sf0qk70i28nNBQ2XQ7QjIKnMxC136VeCb0kRRFaGmoGM21W/UqVXCc0Sy6FJnn0F:AHMTW3nA029 |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | None |
| ZipModifyDate: | 2018:12:15 02:50:56 |
| ZipCRC: | 0x00000000 |
| ZipCompressedSize: | - |
| ZipUncompressedSize: | - |
| ZipFileName: | StartIsBack.Plus.full.2.8.LTSoft/ |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 240 | "C:\Users\admin\Desktop\StartIsBack.Plus.full.2.8.LTSoft\StartIsBackPlusPlus_setup.exe" | C:\Users\admin\Desktop\StartIsBack.Plus.full.2.8.LTSoft\StartIsBackPlusPlus_setup.exe | — | explorer.exe | |||||||||||
User: admin Company: www.startisback.com Integrity Level: MEDIUM Description: StartIsBack++ setup SFX Exit code: 1 Version: 1.0.0 Modules
| |||||||||||||||
| 476 | "C:\Windows\System32\cmd.exe" /C "C:\Users\admin\Desktop\StartIsBack.Plus.full.2.8.LTSoft\Silent Installation.cmd" | C:\Windows\System32\cmd.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 1 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 580 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=15 --mojo-platform-channel-handle=2244 --field-trial-handle=1172,i,14248751011837322132,5107324755860437732,131072 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 880 | "C:\Users\admin\Desktop\StartIsBack.Plus.full.2.8.LTSoft\StartIsBack AIO 1.0.3.exe" | C:\Users\admin\Desktop\StartIsBack.Plus.full.2.8.LTSoft\StartIsBack AIO 1.0.3.exe | explorer.exe | ||||||||||||
User: admin Company: StartIsBack AIO Integrity Level: HIGH Description: StartIsBack AIO 1.0.3 Setup Exit code: 1 Version: 1.0.3 Modules
| |||||||||||||||
| 888 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\StartIsBack.Plus.full.2.8.LTSoft.zip" | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 1232 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=quarantine.mojom.Quarantine --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=3136 --field-trial-handle=1172,i,14248751011837322132,5107324755860437732,131072 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 1360 | "C:\Users\admin\AppData\Local\Temp\is-CDOH6.tmp\StartIsBack AIO 1.0.3.tmp" /SL5="$B0210,2083835,145920,C:\Users\admin\Desktop\StartIsBack.Plus.full.2.8.LTSoft\StartIsBack AIO 1.0.3.exe" | C:\Users\admin\AppData\Local\Temp\is-CDOH6.tmp\StartIsBack AIO 1.0.3.tmp | — | StartIsBack AIO 1.0.3.exe | |||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 1 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 1728 | "C:\Users\admin\Desktop\StartIsBack.Plus.full.2.8.LTSoft\StartIsBack AIO 1.0.3.exe" | C:\Users\admin\Desktop\StartIsBack.Plus.full.2.8.LTSoft\StartIsBack AIO 1.0.3.exe | explorer.exe | ||||||||||||
User: admin Company: StartIsBack AIO Integrity Level: HIGH Description: StartIsBack AIO 1.0.3 Setup Exit code: 1 Version: 1.0.3 Modules
| |||||||||||||||
| 2080 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3352 --field-trial-handle=1172,i,14248751011837322132,5107324755860437732,131072 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 2232 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=13 --mojo-platform-channel-handle=3152 --field-trial-handle=1172,i,14248751011837322132,5107324755860437732,131072 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| (PID) Process: | (888) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\17F\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (888) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (888) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (888) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (888) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (888) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (888) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (888) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (3400) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
| (PID) Process: | (3400) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1728 | StartIsBack AIO 1.0.3.exe | C:\Users\admin\AppData\Local\Temp\is-CDOH6.tmp\StartIsBack AIO 1.0.3.tmp | executable | |
MD5:1BD953A4B09EBD622BAC7E242C38B23B | SHA256:958298D55D1213B85C885EFA506EA9D04B4B9F51126FF9807F4DF855EF29A7DA | |||
| 888 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa888.34423\StartIsBack.Plus.full.2.8.LTSoft\StartIsBackPlusPlus_setup.exe | executable | |
MD5:1BBFB2EFD485C3110732B3FF050C8216 | SHA256:1F5C72F156AC64C6BCB0299C0CAEE312F517F26EB32A8164C4D255574A13413C | |||
| 888 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa888.34423\StartIsBack.Plus.full.2.8.LTSoft\LT SOFT » download your necessary app.website | text | |
MD5:14AB02EEE603892A4BDB4FC1F168E6A3 | SHA256:9BF607D79765E9B29C5597D560C9DB89337ED1A991ABFB3592CCACFE066F03A1 | |||
| 240 | StartIsBackPlusPlus_setup.exe | C:\Users\admin\AppData\Local\Temp\SIBSFX.CA8330F0\Styles\Windows 7.msstyles | executable | |
MD5:D8026912ADA984285D8D5FD35B30D76A | SHA256:076B3BF570EC4AF0A01CBC2C6723F380CD57C71A637BE1A1BB0FE3D6557CE92F | |||
| 240 | StartIsBackPlusPlus_setup.exe | C:\Users\admin\AppData\Local\Temp\SIBSFX.CA8330F0\Styles\Plain8.msstyles | executable | |
MD5:9E19B7AE140206BB27D60CE27B34B7D7 | SHA256:615BC56E20DE8E73115B087FF969EF0F41B113322DBEA981181D4B817E3F3495 | |||
| 888 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa888.34423\StartIsBack.Plus.full.2.8.LTSoft\Silent Installation.cmd | text | |
MD5:5A8536DC6536988A558CE229AD8BDF30 | SHA256:6D542C04BA1D727C19F4F1CBC7EB14E1B0B7FE8ECB02D6ADDC2402CCF5D5DF20 | |||
| 240 | StartIsBackPlusPlus_setup.exe | C:\Users\admin\AppData\Local\Temp\SIBSFX.CA8330F0\Orbs\StartIsBack_Ei8htOrb_v2_by_PainteR.bmp | image | |
MD5:641328C75E6B117545211DB22DAFCAA0 | SHA256:76A72C9AD77843B58223DD588483AC1265A31C15AAEB47EE66D1925DE787644B | |||
| 240 | StartIsBackPlusPlus_setup.exe | C:\Users\admin\AppData\Local\Temp\SIBSFX.CA8330F0\startscreen.exe | executable | |
MD5:2C0C1DBE02BCAB48F5005418625B96A3 | SHA256:623F79D2DA9C3B48198C7105B7BA7AF4180C436260334ECCDA3D2E498C993E12 | |||
| 240 | StartIsBackPlusPlus_setup.exe | C:\Users\admin\AppData\Local\Temp\SIBSFX.CA8330F0\UpdateCheck.exe | executable | |
MD5:71AF6F38F6813897C75DE6D5FB35185F | SHA256:31C1C4D758C7B4C2081AFC21698C7345696313AE9510B6B633DDB10061F80C01 | |||
| 880 | StartIsBack AIO 1.0.3.exe | C:\Users\admin\AppData\Local\Temp\is-EFHV0.tmp\StartIsBack AIO 1.0.3.tmp | executable | |
MD5:1BD953A4B09EBD622BAC7E242C38B23B | SHA256:958298D55D1213B85C885EFA506EA9D04B4B9F51126FF9807F4DF855EF29A7DA | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3424 | chrome.exe | GET | 400 | 95.101.148.135:80 | http://95.101.148.135/ | unknown | html | 209 b | unknown |
3424 | chrome.exe | GET | 400 | 95.101.148.135:80 | http://95.101.148.135/favicon.ico | unknown | html | 255 b | unknown |
3424 | chrome.exe | GET | — | 95.101.148.135:8080 | http://95.101.148.135:8080/ | unknown | — | — | unknown |
3424 | chrome.exe | GET | 400 | 95.101.148.135:80 | http://95.101.148.135/ | unknown | html | 209 b | unknown |
3424 | chrome.exe | GET | 400 | 95.101.148.135:80 | http://95.101.148.135/favicon.ico | unknown | html | 255 b | unknown |
3424 | chrome.exe | GET | — | 95.101.148.135:443 | http://95.101.148.135:443/ | unknown | — | — | unknown |
3424 | chrome.exe | GET | — | 95.101.148.135:443 | http://95.101.148.135:443/ | unknown | — | — | unknown |
3424 | chrome.exe | GET | — | 95.101.148.135:443 | http://95.101.148.135:443/ | unknown | — | — | unknown |
868 | svchost.exe | HEAD | 403 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvYWM3QUFZQV9zN2JXZFNHTWhCbGtIMVUwdw/1.0.0.14_llkgjffcdpffmhiakmfcdcblohccpfmo.crx | unknown | — | — | unknown |
3424 | chrome.exe | GET | — | 95.101.148.135:443 | http://95.101.148.135:443/ | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
868 | svchost.exe | 95.101.148.135:80 | — | Akamai International B.V. | NL | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
868 | svchost.exe | 2.20.40.170:80 | armmf.adobe.com | AKAMAI-AS | NL | unknown |
3424 | chrome.exe | 142.250.187.227:443 | clientservices.googleapis.com | GOOGLE | US | whitelisted |
3400 | chrome.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
3424 | chrome.exe | 66.102.1.84:443 | accounts.google.com | GOOGLE | US | unknown |
3424 | chrome.exe | 172.217.169.4:443 | www.google.com | GOOGLE | US | whitelisted |
3400 | chrome.exe | 224.0.0.251:5353 | — | — | — | unknown |
3424 | chrome.exe | 142.250.180.3:443 | www.gstatic.com | GOOGLE | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
armmf.adobe.com |
| whitelisted |
clientservices.googleapis.com |
| whitelisted |
accounts.google.com |
| shared |
www.google.com |
| whitelisted |
www.gstatic.com |
| whitelisted |
update.googleapis.com |
| whitelisted |
optimizationguide-pa.googleapis.com |
| whitelisted |
encrypted-tbn0.gstatic.com |
| whitelisted |
www.googleapis.com |
| whitelisted |
dns.msftncsi.com |
| shared |