File name:

SE NOTIFICA ACTUACION JUDICIAL; SENTENCIA Radicado 860003221-31-21-003-2025.zip

Full analysis: https://app.any.run/tasks/66d9c7fb-c206-4d10-a2e9-177097e1618b
Verdict: Malicious activity
Threats:

Remote access trojans (RATs) are a type of malware that enables attackers to establish complete to partial control over infected computers. Such malicious programs often have a modular design, offering a wide range of functionalities for conducting illicit activities on compromised systems. Some of the most common features of RATs include access to the users’ data, webcam, and keystrokes. This malware is often distributed through phishing emails and links.

Analysis date: January 22, 2025, 12:18:05
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
remcos
rat
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

07C8BD0A00715BB03CDDAC4DA0843194

SHA1:

A456ED79B5390001A144D8A8214789F7FD6140FB

SHA256:

E3F151D76B46D063C711CE164D945DA72843BDC6BF93BFBEF80330D63C3CE905

SSDEEP:

98304:86AqZ52X1oh7XMdNsdjycwoak83or/NHEk/RHcikQGlUqR32TuwUiLJu8ZpMW4gN:JGy7sPs3

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • REMCOS has been detected

      • SE NOTIFICA ACTUACION JUDICIAL; SENTENCIA Radicado 860003221-31-21-003-2025..exe (PID: 3696)
    • REMCOS mutex has been found

      • SE NOTIFICA ACTUACION JUDICIAL; SENTENCIA Radicado 860003221-31-21-003-2025..exe (PID: 3696)
      • SE NOTIFICA ACTUACION JUDICIAL; SENTENCIA Radicado 860003221-31-21-003-2025..exe (PID: 1536)
      • SE NOTIFICA ACTUACION JUDICIAL; SENTENCIA Radicado 860003221-31-21-003-2025..exe (PID: 4596)
    • Changes the autorun value in the registry

      • SE NOTIFICA ACTUACION JUDICIAL; SENTENCIA Radicado 860003221-31-21-003-2025..exe (PID: 1796)
      • SE NOTIFICA ACTUACION JUDICIAL; SENTENCIA Radicado 860003221-31-21-003-2025..exe (PID: 5200)
  • SUSPICIOUS

    • Application launched itself

      • SE NOTIFICA ACTUACION JUDICIAL; SENTENCIA Radicado 860003221-31-21-003-2025..exe (PID: 4320)
      • SE NOTIFICA ACTUACION JUDICIAL; SENTENCIA Radicado 860003221-31-21-003-2025..exe (PID: 5200)
      • SE NOTIFICA ACTUACION JUDICIAL; SENTENCIA Radicado 860003221-31-21-003-2025..exe (PID: 1796)
    • Connects to unusual port

      • SE NOTIFICA ACTUACION JUDICIAL; SENTENCIA Radicado 860003221-31-21-003-2025..exe (PID: 3696)
  • INFO

    • Checks supported languages

      • SE NOTIFICA ACTUACION JUDICIAL; SENTENCIA Radicado 860003221-31-21-003-2025..exe (PID: 4320)
      • SE NOTIFICA ACTUACION JUDICIAL; SENTENCIA Radicado 860003221-31-21-003-2025..exe (PID: 3696)
      • SE NOTIFICA ACTUACION JUDICIAL; SENTENCIA Radicado 860003221-31-21-003-2025..exe (PID: 1796)
      • SE NOTIFICA ACTUACION JUDICIAL; SENTENCIA Radicado 860003221-31-21-003-2025..exe (PID: 4596)
      • SE NOTIFICA ACTUACION JUDICIAL; SENTENCIA Radicado 860003221-31-21-003-2025..exe (PID: 5200)
      • SE NOTIFICA ACTUACION JUDICIAL; SENTENCIA Radicado 860003221-31-21-003-2025..exe (PID: 1536)
    • The sample compiled with english language support

      • WinRAR.exe (PID: 3608)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3608)
    • Reads the computer name

      • SE NOTIFICA ACTUACION JUDICIAL; SENTENCIA Radicado 860003221-31-21-003-2025..exe (PID: 3696)
    • Manual execution by a user

      • SE NOTIFICA ACTUACION JUDICIAL; SENTENCIA Radicado 860003221-31-21-003-2025..exe (PID: 5200)
      • SE NOTIFICA ACTUACION JUDICIAL; SENTENCIA Radicado 860003221-31-21-003-2025..exe (PID: 1796)
    • The process uses the downloaded file

      • WinRAR.exe (PID: 3608)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0009
ZipCompression: Deflated
ZipModifyDate: 2025:01:21 10:15:46
ZipCRC: 0xdd003a07
ZipCompressedSize: 2640619
ZipUncompressedSize: 5077504
ZipFileName: SE NOTIFICA ACTUACION JUDICIAL; SENTENCIA Radicado 860003221-31-21-003-2025..exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
133
Monitored processes
7
Malicious processes
6
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe se notifica actuacion judicial; sentencia radicado 860003221-31-21-003-2025..exe no specs #REMCOS se notifica actuacion judicial; sentencia radicado 860003221-31-21-003-2025..exe se notifica actuacion judicial; sentencia radicado 860003221-31-21-003-2025..exe se notifica actuacion judicial; sentencia radicado 860003221-31-21-003-2025..exe #REMCOS se notifica actuacion judicial; sentencia radicado 860003221-31-21-003-2025..exe no specs #REMCOS se notifica actuacion judicial; sentencia radicado 860003221-31-21-003-2025..exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1536"C:\Users\admin\Desktop\SE NOTIFICA ACTUACION JUDICIAL; SENTENCIA Radicado 860003221-31-21-003-2025..exe"C:\Users\admin\Desktop\SE NOTIFICA ACTUACION JUDICIAL; SENTENCIA Radicado 860003221-31-21-003-2025..exe
SE NOTIFICA ACTUACION JUDICIAL; SENTENCIA Radicado 860003221-31-21-003-2025..exe
User:
admin
Company:
Zhorn Software
Integrity Level:
MEDIUM
Description:
Stickies 10.2a
Exit code:
2
Version:
10.2a
Modules
Images
c:\users\admin\desktop\se notifica actuacion judicial; sentencia radicado 860003221-31-21-003-2025..exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
1796"C:\Users\admin\Desktop\SE NOTIFICA ACTUACION JUDICIAL; SENTENCIA Radicado 860003221-31-21-003-2025..exe" C:\Users\admin\Desktop\SE NOTIFICA ACTUACION JUDICIAL; SENTENCIA Radicado 860003221-31-21-003-2025..exe
explorer.exe
User:
admin
Company:
Zhorn Software
Integrity Level:
MEDIUM
Description:
Stickies 10.2a
Version:
10.2a
Modules
Images
c:\users\admin\desktop\se notifica actuacion judicial; sentencia radicado 860003221-31-21-003-2025..exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\shell32.dll
c:\windows\syswow64\msvcp_win.dll
3608"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\SE NOTIFICA ACTUACION JUDICIAL; SENTENCIA Radicado 860003221-31-21-003-2025.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
3696"C:\Users\admin\AppData\Local\Temp\Rar$EXb3608.10878\SE NOTIFICA ACTUACION JUDICIAL; SENTENCIA Radicado 860003221-31-21-003-2025..exe"C:\Users\admin\AppData\Local\Temp\Rar$EXb3608.10878\SE NOTIFICA ACTUACION JUDICIAL; SENTENCIA Radicado 860003221-31-21-003-2025..exe
SE NOTIFICA ACTUACION JUDICIAL; SENTENCIA Radicado 860003221-31-21-003-2025..exe
User:
admin
Company:
Zhorn Software
Integrity Level:
MEDIUM
Description:
Stickies 10.2a
Version:
10.2a
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb3608.10878\se notifica actuacion judicial; sentencia radicado 860003221-31-21-003-2025..exe
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
c:\windows\syswow64\gdi32.dll
c:\windows\syswow64\gdi32full.dll
4320"C:\Users\admin\AppData\Local\Temp\Rar$EXb3608.10878\SE NOTIFICA ACTUACION JUDICIAL; SENTENCIA Radicado 860003221-31-21-003-2025..exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb3608.10878\SE NOTIFICA ACTUACION JUDICIAL; SENTENCIA Radicado 860003221-31-21-003-2025..exeWinRAR.exe
User:
admin
Company:
Zhorn Software
Integrity Level:
MEDIUM
Description:
Stickies 10.2a
Exit code:
1844206481
Version:
10.2a
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb3608.10878\se notifica actuacion judicial; sentencia radicado 860003221-31-21-003-2025..exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shell32.dll
4596"C:\Users\admin\Desktop\SE NOTIFICA ACTUACION JUDICIAL; SENTENCIA Radicado 860003221-31-21-003-2025..exe"C:\Users\admin\Desktop\SE NOTIFICA ACTUACION JUDICIAL; SENTENCIA Radicado 860003221-31-21-003-2025..exe
SE NOTIFICA ACTUACION JUDICIAL; SENTENCIA Radicado 860003221-31-21-003-2025..exe
User:
admin
Company:
Zhorn Software
Integrity Level:
MEDIUM
Description:
Stickies 10.2a
Exit code:
2
Version:
10.2a
Modules
Images
c:\users\admin\desktop\se notifica actuacion judicial; sentencia radicado 860003221-31-21-003-2025..exe
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
c:\windows\syswow64\gdi32.dll
5200"C:\Users\admin\Desktop\SE NOTIFICA ACTUACION JUDICIAL; SENTENCIA Radicado 860003221-31-21-003-2025..exe" C:\Users\admin\Desktop\SE NOTIFICA ACTUACION JUDICIAL; SENTENCIA Radicado 860003221-31-21-003-2025..exe
explorer.exe
User:
admin
Company:
Zhorn Software
Integrity Level:
MEDIUM
Description:
Stickies 10.2a
Version:
10.2a
Modules
Images
c:\users\admin\desktop\se notifica actuacion judicial; sentencia radicado 860003221-31-21-003-2025..exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shell32.dll
Total events
2 212
Read events
2 195
Write events
17
Delete events
0

Modification events

(PID) Process:(3608) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(3608) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(3608) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(3608) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\SE NOTIFICA ACTUACION JUDICIAL; SENTENCIA Radicado 860003221-31-21-003-2025.zip
(PID) Process:(3608) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3608) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3608) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3608) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3608) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
(PID) Process:(3696) SE NOTIFICA ACTUACION JUDICIAL; SENTENCIA Radicado 860003221-31-21-003-2025..exeKey:HKEY_CURRENT_USER\SOFTWARE\Rmc-B1NSAB
Operation:writeName:exepath
Value:
EF858555103F82E81A4CAFB059E3A54A7D631FD67C428EA27772B2D53524793F23D30EAB0673D28A5F28191150519F8F5D1EEBE3EFA2D997DE7C5AC701EA7978EE16B2E3D2D6C078F6F2CBE104091F9E99B713C4337C843C914A92FA8ABA0AB5DCCC642D35299895A0E3B6E19AC42C9FBFCD138C0A78E1A520300F59F382E684EC00DB53BE00AA69CF8E637B9AC97FEFAD3120FFF522EB461C1F9B7A25CB8C3BEB2A83D047A7F073D7C034AF643D11B0231A0EF81BFC73BEEBA0981ED53EC7CC1A8AB02EFEE87995D79F09B85D5AFF63D016B575C30427CC327E88B6503CBA86FEE3102AF0450940797DA585CC377F681E8FB511F93AEBB0545A16EAE56D860E18C166A486B18CC89DC6
Executable files
2
Suspicious files
1
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
4320SE NOTIFICA ACTUACION JUDICIAL; SENTENCIA Radicado 860003221-31-21-003-2025..exeC:\Users\admin\Documents\KCSoftwares\sdk\mdb2db.exe
MD5:
SHA256:
3608WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb3608.10878\SE NOTIFICA ACTUACION JUDICIAL; SENTENCIA Radicado 860003221-31-21-003-2025..exeexecutable
MD5:B8C2AB4336434E87B5D27A9BB7DC723D
SHA256:848E8667A115761C6941AC9E1A99B682354FC158C170729F7C85E399DF0B500B
3608WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3608.12989\SE NOTIFICA ACTUACION JUDICIAL; SENTENCIA Radicado 860003221-31-21-003-2025..exeexecutable
MD5:B8C2AB4336434E87B5D27A9BB7DC723D
SHA256:848E8667A115761C6941AC9E1A99B682354FC158C170729F7C85E399DF0B500B
3696SE NOTIFICA ACTUACION JUDICIAL; SENTENCIA Radicado 860003221-31-21-003-2025..exeC:\ProgramData\remcos\logs.datbinary
MD5:5A7CF43F3EA262135CB797AAFB8FB0E0
SHA256:F555D44CFDCF8D0FB66B8A0C474AC8541B94F712DA5258E0F6D12B39BD397545
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
34
DNS requests
20
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
GET
200
23.48.23.176:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1176
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6072
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6072
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
644
svchost.exe
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5064
SearchApp.exe
92.123.104.47:443
www.bing.com
Akamai International B.V.
DE
whitelisted
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4712
MoUsoCoreWorker.exe
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
23.48.23.176:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:137
whitelisted
644
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.186.142
whitelisted
www.bing.com
  • 92.123.104.47
  • 92.123.104.62
  • 92.123.104.58
  • 92.123.104.52
  • 92.123.104.61
  • 92.123.104.56
  • 92.123.104.53
  • 92.123.104.51
  • 92.123.104.55
whitelisted
ocsp.digicert.com
  • 184.30.131.245
whitelisted
crl.microsoft.com
  • 23.48.23.176
  • 23.48.23.143
  • 23.48.23.156
  • 23.48.23.166
  • 23.48.23.173
whitelisted
www.microsoft.com
  • 23.35.229.160
whitelisted
settings-win.data.microsoft.com
  • 51.124.78.146
  • 40.127.240.158
whitelisted
login.live.com
  • 40.126.32.134
  • 40.126.32.76
  • 40.126.32.136
  • 40.126.32.72
  • 20.190.160.20
  • 40.126.32.133
  • 40.126.32.68
  • 20.190.160.17
  • 40.126.31.73
  • 20.190.159.2
  • 40.126.31.69
  • 20.190.159.64
  • 20.190.159.23
  • 20.190.159.4
  • 20.190.159.75
  • 40.126.31.67
whitelisted
go.microsoft.com
  • 23.213.166.81
whitelisted
slscr.update.microsoft.com
  • 52.149.20.212
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.242.39.171
whitelisted

Threats

No threats detected
No debug info