File name: | e0803899b962fe5d605e655e9c5290bf0f49cc9f06d735120cb90b253e3883c6.bin |
Full analysis: | https://app.any.run/tasks/5b1e1948-b2e3-4186-93a5-569514bacb2b |
Verdict: | Malicious activity |
Analysis date: | April 15, 2025, 18:08:23 |
OS: | Windows 11 Professional (build: 22000, 64 bit) |
Indicators: | |
MIME: | application/zip |
File info: | Zip archive data, at least v2.0 to extract, compression method=store |
MD5: | 3FE9D5F364080D892C32FF0D5B2DDC23 |
SHA1: | 53B188BD15AE78DBF17C3BFAEFC83DBD1A431C3A |
SHA256: | E0803899B962FE5D605E655E9C5290BF0F49CC9F06D735120CB90B253E3883C6 |
SSDEEP: | 786432:Rdw+vCTPXy6Ac+pmy1Ptdw+vjTPLMpSYAbhNA1Pv:Pw+vCTPi6N4mGjw+vjTPorA3AH |
.zip | | | ZIP compressed archive (100) |
---|
ZipRequiredVersion: | 20 |
---|---|
ZipBitFlag: | - |
ZipCompression: | None |
ZipModifyDate: | 2025:04:14 11:16:56 |
ZipCRC: | 0x00000000 |
ZipCompressedSize: | - |
ZipUncompressedSize: | - |
ZipFileName: | AllUsersSetupData/ |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
1160 | "C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\Desktop\e0803899b962fe5d605e655e9c5290bf0f49cc9f06d735120cb90b253e3883c6.bin.zip | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Version: 5.91.0 Modules
| |||||||||||||||
5256 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa1160.35486\CommonSetupData\App\mbo.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa1160.35486\CommonSetupData\App\mbo.exe | WinRAR.exe | ||||||||||||
User: admin Company: SpatialTEQ Inc. Integrity Level: MEDIUM Description: MapBusinessOnline Exit code: 0 Version: 8.8.000.78845 Modules
|
(PID) Process: | (1160) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtBMP |
Value: | |||
(PID) Process: | (1160) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtIcon |
Value: | |||
(PID) Process: | (1160) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\omni_23_10_2024_.zip | |||
(PID) Process: | (1160) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\chromium_ext.zip | |||
(PID) Process: | (1160) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\e0803899b962fe5d605e655e9c5290bf0f49cc9f06d735120cb90b253e3883c6.bin.zip | |||
(PID) Process: | (1160) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | name |
Value: 120 | |||
(PID) Process: | (1160) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | size |
Value: 80 | |||
(PID) Process: | (1160) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | type |
Value: 120 | |||
(PID) Process: | (1160) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | mtime |
Value: 100 | |||
(PID) Process: | (1160) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | ProxyBypass |
Value: 1 |
PID | Process | Filename | Type | |
---|---|---|---|---|
1160 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1160.35486\AllUsersSetupData\Viewer\META-INF\AIR\license.txt | text | |
MD5:A27A58DB55332D298DF7C822F4BB5DC8 | SHA256:949B215D4E9595C159772FF06930D9FB98ADDFB6E044672A042B24F7261BB341 | |||
1160 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1160.35486\CommonSetupData\App\mbo.swf | — | |
MD5:— | SHA256:— | |||
1160 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1160.35486\AllUsersSetupData\Viewer\META-INF\AIR\application.xml | xml | |
MD5:8A4C4A1305883DB0986DAFE7C4B9F919 | SHA256:7BF086FD64C8DFE80FB1A7F50AE2DCB0A99329A38D8CD01681DCF6E764304ED7 | |||
1160 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1160.35486\AllUsersSetupData\App\META-INF\AIR\license.txt | text | |
MD5:D29E8329D8D57F2116FB20CBF0991796 | SHA256:1811E01E12CD0E7C501389656070BC162ABE2D75C6B805B8DD98BEC3D4984928 | |||
1160 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1160.35486\AllUsersSetupData\App\META-INF\AIR\application.xml | xml | |
MD5:4E81BE42825736B98169F34F6BDDCE42 | SHA256:2291A8F0E2ACF9BE479222D2A3516B09E3D6BDE7F8938B25F52B7149C3A7135F | |||
1160 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1160.35486\CommonSetupData\App\Adobe AIR\Versions\1.0\Adobe AIR.dll | executable | |
MD5:4A9E829FF180BCB0EF7AE946B4306F07 | SHA256:B368B7CA2E9F0F7EFB62960C3688A4714AD77E03E4B22C7E519449F2989C70F9 | |||
1160 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1160.35486\CommonSetupData\App\Adobe AIR\Versions\1.0\Resources\Licenses\cairo\COPYING-LGPL-2.1 | text | |
MD5:86CE596BC517E1D7C5FE6149C75B1BDF | SHA256:6F900E8ACD64A5451373D39271CDB4FF55E073855574B0B1AD99A86C728545A5 | |||
1160 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1160.35486\CommonSetupData\App\Adobe AIR\Versions\1.0\Resources\CaptiveAppEntry.exe | executable | |
MD5:71D1F4F9DC8386999BAE8BA9FF3535F8 | SHA256:79A41762D56BEE543D6AA555814047F63C7549F3CF6DBE3B48EA1CE6C0AB479F | |||
1160 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1160.35486\CommonSetupData\App\Adobe AIR\Versions\1.0\Resources\Licenses\cairo\COPYING | text | |
MD5:EF5A4E944085278EB1A7B7A881CCEAF6 | SHA256:4FDCDE2E1F6AEB1DF3D767A8330AFF6ED6E6C0031D3C8EA72E95620613B4F827 | |||
1160 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1160.35486\CommonSetupData\App\Adobe AIR\Versions\1.0\Resources\Licenses\cairo\COPYING-MPL-1.1 | text | |
MD5:1B8B981CBB6B2B3F93C43B1915BDF812 | SHA256:FA01277004AFF314888151EA523BDF390992892E13523984F221695D48C7455B |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
3640 | svchost.exe | GET | 200 | 23.50.131.200:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?c6613fd91ef18acd | unknown | — | — | whitelisted |
4312 | MoUsoCoreWorker.exe | GET | 200 | 23.50.131.200:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?f7300bf7f859b77b | unknown | — | — | whitelisted |
2488 | smartscreen.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
3640 | svchost.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
1352 | svchost.exe | GET | 200 | 184.24.77.4:80 | http://www.msftconnecttest.com/connecttest.txt | unknown | — | — | whitelisted |
5256 | mbo.exe | GET | 200 | 192.124.249.41:80 | http://ocsp.godaddy.com//MEIwQDA%2BMDwwOjAJBgUrDgMCGgUABBQdI2%2BOBkuXH93foRUj4a7lAr4rGwQUOpqFBxBnKLbv9r0FQW4gwZTaD94CAQc%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
1352 | svchost.exe | 184.24.77.24:80 | — | Akamai International B.V. | DE | unknown |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
3640 | svchost.exe | 40.126.31.130:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4312 | MoUsoCoreWorker.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
3640 | svchost.exe | 23.50.131.200:80 | ctldl.windowsupdate.com | Akamai International B.V. | DE | whitelisted |
4312 | MoUsoCoreWorker.exe | 23.50.131.200:80 | ctldl.windowsupdate.com | Akamai International B.V. | DE | whitelisted |
3640 | svchost.exe | 2.17.190.73:80 | ocsp.digicert.com | AKAMAI-AS | DE | whitelisted |
2488 | smartscreen.exe | 4.209.164.61:443 | checkappexec.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
2488 | smartscreen.exe | 2.17.190.73:80 | ocsp.digicert.com | AKAMAI-AS | DE | whitelisted |
1352 | svchost.exe | 184.24.77.4:80 | — | Akamai International B.V. | DE | unknown |
Domain | IP | Reputation |
---|---|---|
google.com |
| whitelisted |
login.live.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
checkappexec.microsoft.com |
| whitelisted |
fs.microsoft.com |
| whitelisted |
dns.msftncsi.com |
| whitelisted |
www.mapbusinessonline.com |
| unknown |
map.mapbusinessonline.com |
| unknown |
PID | Process | Class | Message |
---|---|---|---|
— | — | Misc activity | ET INFO Microsoft Connection Test |
Process | Message |
---|---|
mbo.exe | versionFunctions: Not supported on OpenGL ES
|