File name: | W32.Nimda.A.zip |
Full analysis: | https://app.any.run/tasks/f4f31f49-c90b-47c9-9dc0-c020f8e25788 |
Verdict: | Malicious activity |
Analysis date: | March 22, 2025, 21:37:14 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Tags: | |
Indicators: | |
MIME: | application/zip |
File info: | Zip archive data, at least v2.0 to extract, compression method=deflate |
MD5: | B62632C8E6AAFA05A07CAD52B2E25AA5 |
SHA1: | 35C626A3513F8866095F891F69C593DE6D87EBD2 |
SHA256: | E56E79F9DC8752E11B66C3DEA5282E835EF280A46A2B5D98AF19222D11B72767 |
SSDEEP: | 6144:F5+YTd3QOMgyjGyrQb+MU5opgJcvd7JEZ:F5+YhogyjGK4ZqWgZ |
.zip | | | ZIP compressed archive (100) |
---|
ZipRequiredVersion: | 788 |
---|---|
ZipBitFlag: | 0x0001 |
ZipCompression: | Deflated |
ZipModifyDate: | 2019:01:09 16:45:30 |
ZipCRC: | 0xda64013f |
ZipCompressedSize: | 284 |
ZipUncompressedSize: | 6148 |
ZipFileName: | .DS_Store |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
628 | "C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\AppData\Local\Temp\Rar$DIb2840.30555\readme_nimda.txt | C:\Windows\System32\notepad.exe | — | WinRAR.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Notepad Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
1404 | "C:\Users\admin\AppData\Local\Temp\Rar$EXb2840.25766\FIX_NIMDA.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXb2840.25766\FIX_NIMDA.exe | — | WinRAR.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221225786 Modules
| |||||||||||||||
2612 | "C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\Rar$DIb2840.33077\I-Worm.Nimda.zip | C:\Program Files\WinRAR\WinRAR.exe | WinRAR.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Version: 5.91.0 Modules
| |||||||||||||||
2832 | "C:\Users\admin\AppData\Local\Temp\Rar$EXb2612.35208\slide.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXb2612.35208\slide.exe | — | WinRAR.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 4294967295 Modules
| |||||||||||||||
2840 | "C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\W32.Nimda.A.zip | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Version: 5.91.0 Modules
|
(PID) Process: | (2840) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
(PID) Process: | (2840) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
(PID) Process: | (2840) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\omni_23_10_2024_.zip | |||
(PID) Process: | (2840) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\W32.Nimda.A.zip | |||
(PID) Process: | (2840) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | name |
Value: 120 | |||
(PID) Process: | (2840) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | size |
Value: 80 | |||
(PID) Process: | (2840) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | type |
Value: 120 | |||
(PID) Process: | (2840) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | mtime |
Value: 100 | |||
(PID) Process: | (2840) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (2840) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtBMP |
Value: |
PID | Process | Filename | Type | |
---|---|---|---|---|
2840 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb2840.25766\i-Worm.Nimda.txt | text | |
MD5:A2B2A4DF2FE6A1D85E9032E3E50B365F | SHA256:B1FF29B2C351F1DB2AB0D4E388FAF2DD23E353F515709906C655F87D1C892D30 | |||
2840 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb2840.25766\I-Worm.Nimda.zip | compressed | |
MD5:844855B2EC58F20718CFF30D874AB43E | SHA256:70E37EA05B1D89E37E04B1C2CE98731E65B6C37CF718DC72A109D862CA36CC2A | |||
2840 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb2840.25766\FIX_NIMDA.exe | executable | |
MD5:36D433DC87FDBFFABABDE57EF3C3C130 | SHA256:3F5A6D8334F31ACD4D9E2811CA705E0BCF4A1C9F672D2FB4933A00ADF46B2F5A | |||
2840 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb2840.25766\SLIDE.DAT | binary | |
MD5:087B30CDDE1487F4F90ABD2659EDD19D | SHA256:62F699631A33D6C04B5C8041E55C6287151C1527394D958651BF14F05C4904CF | |||
2840 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb2840.25766\slide.exe | executable | |
MD5:06F46062E7D56457252A9A3E3A73405A | SHA256:8E2BDCAEE8DFEFCFE42740A43A0079EB1BABFC530200BCFB57B1B1A548852AF1 | |||
2612 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb2612.35208\FIX_NIMDA.exe | executable | |
MD5:36D433DC87FDBFFABABDE57EF3C3C130 | SHA256:3F5A6D8334F31ACD4D9E2811CA705E0BCF4A1C9F672D2FB4933A00ADF46B2F5A | |||
2840 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DIb2840.30555\readme_nimda.txt | text | |
MD5:79E362C5BA84AD7722D133C2A348C52B | SHA256:7F1A1F69D826594FF7429584CE2F3902F28EA1566D28EDA7E6227DA81A5E19BC | |||
2840 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DIb2840.33077\I-Worm.Nimda.zip | compressed | |
MD5:844855B2EC58F20718CFF30D874AB43E | SHA256:70E37EA05B1D89E37E04B1C2CE98731E65B6C37CF718DC72A109D862CA36CC2A | |||
2840 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb2840.25766\readme_nimda.txt | text | |
MD5:79E362C5BA84AD7722D133C2A348C52B | SHA256:7F1A1F69D826594FF7429584CE2F3902F28EA1566D28EDA7E6227DA81A5E19BC | |||
2612 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb2612.35208\i-Worm.Nimda.txt | text | |
MD5:A2B2A4DF2FE6A1D85E9032E3E50B365F | SHA256:B1FF29B2C351F1DB2AB0D4E388FAF2DD23E353F515709906C655F87D1C892D30 |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
Domain | IP | Reputation |
---|---|---|
google.com |
| whitelisted |