| File name: | e0803899b962fe5d605e655e9c5290bf0f49cc9f06d735120cb90b253e3883c6.bin |
| Full analysis: | https://app.any.run/tasks/5b1e1948-b2e3-4186-93a5-569514bacb2b |
| Verdict: | Malicious activity |
| Analysis date: | April 15, 2025, 18:08:23 |
| OS: | Windows 11 Professional (build: 22000, 64 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract, compression method=store |
| MD5: | 3FE9D5F364080D892C32FF0D5B2DDC23 |
| SHA1: | 53B188BD15AE78DBF17C3BFAEFC83DBD1A431C3A |
| SHA256: | E0803899B962FE5D605E655E9C5290BF0F49CC9F06D735120CB90B253E3883C6 |
| SSDEEP: | 786432:Rdw+vCTPXy6Ac+pmy1Ptdw+vjTPLMpSYAbhNA1Pv:Pw+vCTPi6N4mGjw+vjTPorA3AH |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | None |
| ZipModifyDate: | 2025:04:14 11:16:56 |
| ZipCRC: | 0x00000000 |
| ZipCompressedSize: | - |
| ZipUncompressedSize: | - |
| ZipFileName: | AllUsersSetupData/ |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1160 | "C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\Desktop\e0803899b962fe5d605e655e9c5290bf0f49cc9f06d735120cb90b253e3883c6.bin.zip | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Version: 5.91.0 Modules
| |||||||||||||||
| 5256 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa1160.35486\CommonSetupData\App\mbo.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa1160.35486\CommonSetupData\App\mbo.exe | WinRAR.exe | ||||||||||||
User: admin Company: SpatialTEQ Inc. Integrity Level: MEDIUM Description: MapBusinessOnline Exit code: 0 Version: 8.8.000.78845 Modules
| |||||||||||||||
| (PID) Process: | (1160) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (1160) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (1160) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\omni_23_10_2024_.zip | |||
| (PID) Process: | (1160) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\chromium_ext.zip | |||
| (PID) Process: | (1160) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\e0803899b962fe5d605e655e9c5290bf0f49cc9f06d735120cb90b253e3883c6.bin.zip | |||
| (PID) Process: | (1160) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (1160) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (1160) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (1160) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (1160) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1160 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1160.35486\CommonSetupData\App\d3dcompiler_47.dll | executable | |
MD5:0DCAEA8480DADB2EB9684A638C82598A | SHA256:FD5A416760961D88D59C8D2B98FD1E937024D7953663B2DEA6E97A4C6F5B2CF8 | |||
| 1160 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1160.35486\CommonSetupData\App\mbo.swf | — | |
MD5:— | SHA256:— | |||
| 1160 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1160.35486\CommonSetupData\App\Adobe AIR\Versions\1.0\Resources\Licenses\cairo\COPYING | text | |
MD5:EF5A4E944085278EB1A7B7A881CCEAF6 | SHA256:4FDCDE2E1F6AEB1DF3D767A8330AFF6ED6E6C0031D3C8EA72E95620613B4F827 | |||
| 1160 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1160.35486\CommonSetupData\App\Adobe AIR\Versions\1.0\Resources\Licenses\cairo\COPYING-MPL-1.1 | text | |
MD5:1B8B981CBB6B2B3F93C43B1915BDF812 | SHA256:FA01277004AFF314888151EA523BDF390992892E13523984F221695D48C7455B | |||
| 1160 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1160.35486\AllUsersSetupData\Viewer\META-INF\AIR\application.xml | xml | |
MD5:8A4C4A1305883DB0986DAFE7C4B9F919 | SHA256:7BF086FD64C8DFE80FB1A7F50AE2DCB0A99329A38D8CD01681DCF6E764304ED7 | |||
| 1160 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1160.35486\AllUsersSetupData\App\META-INF\AIR\license.txt | text | |
MD5:D29E8329D8D57F2116FB20CBF0991796 | SHA256:1811E01E12CD0E7C501389656070BC162ABE2D75C6B805B8DD98BEC3D4984928 | |||
| 1160 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1160.35486\CommonSetupData\App\Adobe AIR\Versions\1.0\Adobe AIR.dll | executable | |
MD5:4A9E829FF180BCB0EF7AE946B4306F07 | SHA256:B368B7CA2E9F0F7EFB62960C3688A4714AD77E03E4B22C7E519449F2989C70F9 | |||
| 1160 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1160.35486\CommonSetupData\App\Adobe AIR\Versions\1.0\Resources\Licenses\pcre2\COPYING | text | |
MD5:1F800C179F381B72E818AAB4BA25C504 | SHA256:4F8DEFD8B03D6E0DF53C3A37FD37CAF2BD8A5E8E77F7886FE3557BA4CDA45E8C | |||
| 1160 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1160.35486\AllUsersSetupData\App\META-INF\AIR\application.xml | xml | |
MD5:4E81BE42825736B98169F34F6BDDCE42 | SHA256:2291A8F0E2ACF9BE479222D2A3516B09E3D6BDE7F8938B25F52B7149C3A7135F | |||
| 1160 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1160.35486\CommonSetupData\App\imageformats\qjpeg.dll | executable | |
MD5:AEE5A9A371A9969FD740F94165A26A93 | SHA256:2E70AFCE4FE74575F8E4548369CB6CF373B86EF49E5B5B8DFF5B7423DFF636AE | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3640 | svchost.exe | GET | 200 | 23.50.131.200:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?c6613fd91ef18acd | unknown | — | — | whitelisted |
4312 | MoUsoCoreWorker.exe | GET | 200 | 23.50.131.200:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?f7300bf7f859b77b | unknown | — | — | whitelisted |
3640 | svchost.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
1352 | svchost.exe | GET | 200 | 184.24.77.4:80 | http://www.msftconnecttest.com/connecttest.txt | unknown | — | — | whitelisted |
5256 | mbo.exe | GET | 200 | 192.124.249.41:80 | http://ocsp.godaddy.com//MEIwQDA%2BMDwwOjAJBgUrDgMCGgUABBQdI2%2BOBkuXH93foRUj4a7lAr4rGwQUOpqFBxBnKLbv9r0FQW4gwZTaD94CAQc%3D | unknown | — | — | whitelisted |
2488 | smartscreen.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
1352 | svchost.exe | 184.24.77.24:80 | — | Akamai International B.V. | DE | unknown |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
3640 | svchost.exe | 40.126.31.130:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4312 | MoUsoCoreWorker.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
3640 | svchost.exe | 23.50.131.200:80 | ctldl.windowsupdate.com | Akamai International B.V. | DE | whitelisted |
4312 | MoUsoCoreWorker.exe | 23.50.131.200:80 | ctldl.windowsupdate.com | Akamai International B.V. | DE | whitelisted |
3640 | svchost.exe | 2.17.190.73:80 | ocsp.digicert.com | AKAMAI-AS | DE | whitelisted |
2488 | smartscreen.exe | 4.209.164.61:443 | checkappexec.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
2488 | smartscreen.exe | 2.17.190.73:80 | ocsp.digicert.com | AKAMAI-AS | DE | whitelisted |
1352 | svchost.exe | 184.24.77.4:80 | — | Akamai International B.V. | DE | unknown |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
login.live.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
checkappexec.microsoft.com |
| whitelisted |
fs.microsoft.com |
| whitelisted |
dns.msftncsi.com |
| whitelisted |
www.mapbusinessonline.com |
| unknown |
map.mapbusinessonline.com |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
1352 | svchost.exe | Misc activity | ET INFO Microsoft Connection Test |
Process | Message |
|---|---|
mbo.exe | versionFunctions: Not supported on OpenGL ES
|