| File name: | e0803899b962fe5d605e655e9c5290bf0f49cc9f06d735120cb90b253e3883c6.bin |
| Full analysis: | https://app.any.run/tasks/5b1e1948-b2e3-4186-93a5-569514bacb2b |
| Verdict: | Malicious activity |
| Analysis date: | April 15, 2025, 18:08:23 |
| OS: | Windows 11 Professional (build: 22000, 64 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract, compression method=store |
| MD5: | 3FE9D5F364080D892C32FF0D5B2DDC23 |
| SHA1: | 53B188BD15AE78DBF17C3BFAEFC83DBD1A431C3A |
| SHA256: | E0803899B962FE5D605E655E9C5290BF0F49CC9F06D735120CB90B253E3883C6 |
| SSDEEP: | 786432:Rdw+vCTPXy6Ac+pmy1Ptdw+vjTPLMpSYAbhNA1Pv:Pw+vCTPi6N4mGjw+vjTPorA3AH |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | None |
| ZipModifyDate: | 2025:04:14 11:16:56 |
| ZipCRC: | 0x00000000 |
| ZipCompressedSize: | - |
| ZipUncompressedSize: | - |
| ZipFileName: | AllUsersSetupData/ |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1160 | "C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\Desktop\e0803899b962fe5d605e655e9c5290bf0f49cc9f06d735120cb90b253e3883c6.bin.zip | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Version: 5.91.0 Modules
| |||||||||||||||
| 5256 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa1160.35486\CommonSetupData\App\mbo.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa1160.35486\CommonSetupData\App\mbo.exe | WinRAR.exe | ||||||||||||
User: admin Company: SpatialTEQ Inc. Integrity Level: MEDIUM Description: MapBusinessOnline Exit code: 0 Version: 8.8.000.78845 Modules
| |||||||||||||||
| (PID) Process: | (1160) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (1160) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (1160) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\omni_23_10_2024_.zip | |||
| (PID) Process: | (1160) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\chromium_ext.zip | |||
| (PID) Process: | (1160) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\e0803899b962fe5d605e655e9c5290bf0f49cc9f06d735120cb90b253e3883c6.bin.zip | |||
| (PID) Process: | (1160) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (1160) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (1160) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (1160) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (1160) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1160 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1160.35486\CommonSetupData\App\Adobe AIR\Versions\1.0\Resources\CaptiveAppEntry.exe | executable | |
MD5:71D1F4F9DC8386999BAE8BA9FF3535F8 | SHA256:79A41762D56BEE543D6AA555814047F63C7549F3CF6DBE3B48EA1CE6C0AB479F | |||
| 1160 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1160.35486\CommonSetupData\App\mbo.swf | — | |
MD5:— | SHA256:— | |||
| 1160 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1160.35486\AllUsersSetupData\App\META-INF\AIR\license.txt | text | |
MD5:D29E8329D8D57F2116FB20CBF0991796 | SHA256:1811E01E12CD0E7C501389656070BC162ABE2D75C6B805B8DD98BEC3D4984928 | |||
| 1160 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1160.35486\AllUsersSetupData\App\META-INF\AIR\application.xml | xml | |
MD5:4E81BE42825736B98169F34F6BDDCE42 | SHA256:2291A8F0E2ACF9BE479222D2A3516B09E3D6BDE7F8938B25F52B7149C3A7135F | |||
| 1160 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1160.35486\CommonSetupData\App\Adobe AIR\Versions\1.0\Resources\Licenses\cairo\COPYING-LGPL-2.1 | text | |
MD5:86CE596BC517E1D7C5FE6149C75B1BDF | SHA256:6F900E8ACD64A5451373D39271CDB4FF55E073855574B0B1AD99A86C728545A5 | |||
| 1160 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1160.35486\CommonSetupData\App\Adobe AIR\Versions\1.0\Resources\Licenses\pixman\COPYING | text | |
MD5:1168F6DA9F901D48731A7D51940FECAD | SHA256:6E9F39A63E6E8AE87DE8AFDF5E7E9571B964A52717614EDB84675016042F6AFC | |||
| 1160 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1160.35486\AllUsersSetupData\Viewer\META-INF\AIR\application.xml | xml | |
MD5:8A4C4A1305883DB0986DAFE7C4B9F919 | SHA256:7BF086FD64C8DFE80FB1A7F50AE2DCB0A99329A38D8CD01681DCF6E764304ED7 | |||
| 1160 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1160.35486\AllUsersSetupData\Viewer\META-INF\AIR\license.txt | text | |
MD5:A27A58DB55332D298DF7C822F4BB5DC8 | SHA256:949B215D4E9595C159772FF06930D9FB98ADDFB6E044672A042B24F7261BB341 | |||
| 1160 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1160.35486\CommonSetupData\App\Adobe AIR\Versions\1.0\Resources\Licenses\pcre2\COPYING | text | |
MD5:1F800C179F381B72E818AAB4BA25C504 | SHA256:4F8DEFD8B03D6E0DF53C3A37FD37CAF2BD8A5E8E77F7886FE3557BA4CDA45E8C | |||
| 1160 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1160.35486\CommonSetupData\App\libssl-3-x64.dll | executable | |
MD5:22DFCA41DC84B5A133C06DA33B79CD61 | SHA256:B3B9BEA158EB0D4B0E2D8ED8504CDCDFA7C26B5536B915E40792EC9896459400 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3640 | svchost.exe | GET | 200 | 23.50.131.200:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?c6613fd91ef18acd | unknown | — | — | whitelisted |
4312 | MoUsoCoreWorker.exe | GET | 200 | 23.50.131.200:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?f7300bf7f859b77b | unknown | — | — | whitelisted |
3640 | svchost.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
2488 | smartscreen.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
5256 | mbo.exe | GET | 200 | 192.124.249.41:80 | http://ocsp.godaddy.com//MEIwQDA%2BMDwwOjAJBgUrDgMCGgUABBQdI2%2BOBkuXH93foRUj4a7lAr4rGwQUOpqFBxBnKLbv9r0FQW4gwZTaD94CAQc%3D | unknown | — | — | whitelisted |
1352 | svchost.exe | GET | 200 | 184.24.77.4:80 | http://www.msftconnecttest.com/connecttest.txt | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
1352 | svchost.exe | 184.24.77.24:80 | — | Akamai International B.V. | DE | unknown |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
3640 | svchost.exe | 40.126.31.130:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4312 | MoUsoCoreWorker.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
3640 | svchost.exe | 23.50.131.200:80 | ctldl.windowsupdate.com | Akamai International B.V. | DE | whitelisted |
4312 | MoUsoCoreWorker.exe | 23.50.131.200:80 | ctldl.windowsupdate.com | Akamai International B.V. | DE | whitelisted |
3640 | svchost.exe | 2.17.190.73:80 | ocsp.digicert.com | AKAMAI-AS | DE | whitelisted |
2488 | smartscreen.exe | 4.209.164.61:443 | checkappexec.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
2488 | smartscreen.exe | 2.17.190.73:80 | ocsp.digicert.com | AKAMAI-AS | DE | whitelisted |
1352 | svchost.exe | 184.24.77.4:80 | — | Akamai International B.V. | DE | unknown |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
login.live.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
checkappexec.microsoft.com |
| whitelisted |
fs.microsoft.com |
| whitelisted |
dns.msftncsi.com |
| whitelisted |
www.mapbusinessonline.com |
| unknown |
map.mapbusinessonline.com |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
1352 | svchost.exe | Misc activity | ET INFO Microsoft Connection Test |
Process | Message |
|---|---|
mbo.exe | versionFunctions: Not supported on OpenGL ES
|