File name:

setup.iso

Full analysis: https://app.any.run/tasks/430b60e8-19e8-486d-a6fb-70b17a30a2ef
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: May 20, 2019, 14:53:04
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
adware
prepscram
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract
MD5:

2451C6FF4A7CE618DA13544AD9F7B1C5

SHA1:

5BD816C86359502A29AD45DEA19F114649E3BB88

SHA256:

DF75B3FFD12D2AB6F20A31AA46D01FACD6CC214E9A149463BE4D8054E3417FA3

SSDEEP:

24576:Izloou2DEul82P9efctM01SUEt1QuFlPM:GNuXulQ8M01OQ6lPM

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Download-The Sitter 2017 720p WEBRip x264 LLG mp4.exe (PID: 1876)
      • Download-The Sitter 2017 720p WEBRip x264 LLG mp4.exe (PID: 3228)
    • Connects to CnC server

      • Download-The Sitter 2017 720p WEBRip x264 LLG mp4.exe (PID: 3228)
    • PREPSCRAM was detected

      • Download-The Sitter 2017 720p WEBRip x264 LLG mp4.exe (PID: 3228)
  • SUSPICIOUS

    • Application launched itself

      • Download-The Sitter 2017 720p WEBRip x264 LLG mp4.exe (PID: 1876)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3016)
  • INFO

    • Manual execution by user

      • WinRAR.exe (PID: 3016)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.iso | ISO 9660 CD image (56)
.zip | ZIP compressed archive (43.9)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2019:05:20 14:45:24
ZipCRC: 0x33aa3b65
ZipCompressedSize: 1064960
ZipUncompressedSize: 1064960
ZipFileName: Download-The Sitter 2017 720p WEBRip x264 LLG mp4.iso
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
40
Monitored processes
5
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
start drop and start rundll32.exe no specs winrar.exe no specs winrar.exe download-the sitter 2017 720p webrip x264 llg mp4.exe no specs #PREPSCRAM download-the sitter 2017 720p webrip x264 llg mp4.exe

Process information

PID
CMD
Path
Indicators
Parent process
456"C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\AppData\Local\Temp\setup.isoC:\Windows\system32\rundll32.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
1308"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\setup.iso"C:\Program Files\WinRAR\WinRAR.exerundll32.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
1876"C:\Users\admin\AppData\Local\Temp\Rar$EXa3016.3387\Download-The Sitter 2017 720p WEBRip x264 LLG mp4.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3016.3387\Download-The Sitter 2017 720p WEBRip x264 LLG mp4.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3016.3387\download-the sitter 2017 720p webrip x264 llg mp4.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ws2_32.dll
3016"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\Download-The Sitter 2017 720p WEBRip x264 LLG mp4.iso"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3228"C:\Users\admin\AppData\Local\Temp\Rar$EXa3016.3387\Download-The Sitter 2017 720p WEBRip x264 LLG mp4.exe" "C:\Users\admin\AppData\Local\Temp\Rar$EXa3016.3387\Download-The Sitter 2017 720p WEBRip x264 LLG mp4.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3016.3387\Download-The Sitter 2017 720p WEBRip x264 LLG mp4.exe
Download-The Sitter 2017 720p WEBRip x264 LLG mp4.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3016.3387\download-the sitter 2017 720p webrip x264 llg mp4.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ws2_32.dll
Total events
1 694
Read events
1 577
Write events
117
Delete events
0

Modification events

(PID) Process:(456) rundll32.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(456) rundll32.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
Operation:writeName:@C:\Windows\System32\isoburn.exe,-350
Value:
Disc Image File
(PID) Process:(456) rundll32.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.iso\OpenWithProgids
Operation:writeName:Windows.IsoFile
Value:
(PID) Process:(456) rundll32.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Operation:writeName:LangID
Value:
0904
(PID) Process:(456) rundll32.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
Operation:writeName:@%SystemRoot%\System32\isoburn.exe,-352
Value:
Windows Disc Image Burner
(PID) Process:(456) rundll32.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Operation:writeName:C:\Windows\System32\isoburn.exe
Value:
Windows Disc Image Burner
(PID) Process:(456) rundll32.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Operation:writeName:C:\Program Files\WinRAR\WinRAR.exe
Value:
WinRAR archiver
(PID) Process:(456) rundll32.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Operation:writeName:C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe
Value:
Adobe Acrobat Reader DC
(PID) Process:(456) rundll32.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Operation:writeName:C:\Windows\eHome\ehshell.exe
Value:
Windows Media Center
(PID) Process:(456) rundll32.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Operation:writeName:C:\Program Files\Internet Explorer\iexplore.exe
Value:
Internet Explorer
Executable files
1
Suspicious files
1
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
1308WinRAR.exeC:\Users\admin\Desktop\Download-The Sitter 2017 720p WEBRip x264 LLG mp4.isocompressed
MD5:
SHA256:
3016WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3016.3387\Download-The Sitter 2017 720p WEBRip x264 LLG mp4.exeexecutable
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
2
DNS requests
2
Threats
3

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3228
Download-The Sitter 2017 720p WEBRip x264 LLG mp4.exe
GET
200
54.88.21.193:80
http://my.sodadirt.info/offer.php?affId=1464&trackingId=414413835&instId=805&ho_trackingid=HO414413835&cc=US&sb=x86&wv=7sp1&db=InternetExplorer&uac=1&cid=5d979308c3b6ea5ad7e984e628c8cac1&v=3&net=4.6.01055&ie=8%2e0%2e7601%2e17514&res=1280x720&osd=592&kid=hqmrb21b83ba3st64e6
US
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3228
Download-The Sitter 2017 720p WEBRip x264 LLG mp4.exe
54.88.21.193:80
my.sodadirt.info
Amazon.com, Inc.
US
whitelisted
3228
Download-The Sitter 2017 720p WEBRip x264 LLG mp4.exe
13.32.222.8:80
d1hq9wbcfo7dcl.cloudfront.net
Amazon.com, Inc.
US
unknown

DNS requests

Domain
IP
Reputation
d1hq9wbcfo7dcl.cloudfront.net
  • 13.32.222.8
  • 13.32.222.135
  • 13.32.222.80
  • 13.32.222.14
shared
my.sodadirt.info
  • 54.88.21.193
malicious

Threats

PID
Process
Class
Message
3228
Download-The Sitter 2017 720p WEBRip x264 LLG mp4.exe
Unknown Traffic
ET INFO Suspicious User-Agent (1 space)
3228
Download-The Sitter 2017 720p WEBRip x264 LLG mp4.exe
Misc activity
ADWARE [PTsecurity] SoftwareBundler:Win32/Prepscram
1 ETPRO signatures available at the full report
No debug info