File name:

Torjan.Sinowal.zip

Full analysis: https://app.any.run/tasks/16a8ea3c-34fa-48f2-b609-6afb429aa7d4
Verdict: Malicious activity
Analysis date: May 01, 2019, 15:06:39
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract
MD5:

9538A123B2E1489B39C5F86BE4C11010

SHA1:

E9018A9E6AC7B89564B9E758F18F11A249084F5A

SHA256:

E5D4C1D746C193E655C51FC2B07E6AEB1BC8DEB55EB894BC809FA5DB2F4C4388

SSDEEP:

24576:fRNm0+bjvMpaYucSPI/eJwl4P2wmT5ke12rqC7DoJo0jPHeRuvrd:fRNv+UYYuHP2uwOODT5ko2rxX90jHewh

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Torpig miniloader_0F82964CF39056402EE2DE9193635B34.exe (PID: 1720)
    • Loads dropped or rewritten executable

      • regsvr32.exe (PID: 3520)
    • Registers / Runs the DLL via REGSVR32.EXE

      • cmd.exe (PID: 2644)
  • SUSPICIOUS

    • Creates files in the program directory

      • Torpig miniloader_0F82964CF39056402EE2DE9193635B34.exe (PID: 1720)
    • Starts CMD.EXE for commands execution

      • Torpig miniloader_0F82964CF39056402EE2DE9193635B34.exe (PID: 1720)
    • Executable content was dropped or overwritten

      • Torpig miniloader_0F82964CF39056402EE2DE9193635B34.exe (PID: 1720)
    • Connects to server without host name

      • Torpig miniloader_0F82964CF39056402EE2DE9193635B34.exe (PID: 1720)
      • regsvr32.exe (PID: 3520)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2014:12:19 15:12:21
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: Torpig miniloader-samp/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
36
Monitored processes
4
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs torpig miniloader_0f82964cf39056402ee2de9193635b34.exe cmd.exe no specs regsvr32.exe

Process information

PID
CMD
Path
Indicators
Parent process
1720"C:\Users\admin\Desktop\Torpig miniloader_0F82964CF39056402EE2DE9193635B34.exe" C:\Users\admin\Desktop\Torpig miniloader_0F82964CF39056402EE2DE9193635B34.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\torpig miniloader_0f82964cf39056402ee2de9193635b34.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2644"C:\Windows\system32\cmd.exe" /c C:\Windows\system32\regsvr32.exe /s "C:\ProgramData\1785\wsse.dll"C:\Windows\system32\cmd.exeTorpig miniloader_0F82964CF39056402EE2DE9193635B34.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3520C:\Windows\system32\regsvr32.exe /s "C:\ProgramData\1785\wsse.dll"C:\Windows\system32\regsvr32.exe
cmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3904"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Torjan.Sinowal.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
529
Read events
488
Write events
41
Delete events
0

Modification events

(PID) Process:(3904) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3904) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3904) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3904) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Torjan.Sinowal.zip
(PID) Process:(3904) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3904) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3904) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3904) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3904) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
(PID) Process:(1720) Torpig miniloader_0F82964CF39056402EE2DE9193635B34.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
Executable files
1
Suspicious files
2
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
3904WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3904.23269\Torpig miniloader-samp\Torpig miniloader_0F82964CF39056402EE2DE9193635B34
MD5:
SHA256:
1720Torpig miniloader_0F82964CF39056402EE2DE9193635B34.exeC:\ProgramData\1785\1160953.datbinary
MD5:
SHA256:
1720Torpig miniloader_0F82964CF39056402EE2DE9193635B34.exeC:\ProgramData\1785\1160953.dllbinary
MD5:
SHA256:
1720Torpig miniloader_0F82964CF39056402EE2DE9193635B34.exeC:\ProgramData\1785\wsse.dllexecutable
MD5:9FEB86525915F41A840C392BE065B4B7
SHA256:CBEFB7DF1306A8C967A5AC67B0D728087684E655BDAB1A26E4D61A883FCFDE21
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
2
DNS requests
1
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1720
Torpig miniloader_0F82964CF39056402EE2DE9193635B34.exe
POST
108.59.6.39:80
http://108.59.6.39/searc?fr=altavista&itag=ody&q=3b3659f93b4b4ec055077ee6c9f96ebd%2C4f027b1a77adf442&kgs=1&kls=0&p=1000
US
malicious
3520
regsvr32.exe
POST
108.59.6.39:80
http://108.59.6.39/searc?fr=altavista&itag=ody&q=3b3659f93b4b4ec055077ee6c9f96ebd%2C4f027b1a77adf442&kgs=1&kls=0
US
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3520
regsvr32.exe
108.59.6.39:80
Leaseweb USA, Inc.
US
malicious
1720
Torpig miniloader_0F82964CF39056402EE2DE9193635B34.exe
108.59.6.39:80
Leaseweb USA, Inc.
US
malicious

DNS requests

Domain
IP
Reputation
annotatinggramma.info
malicious

Threats

No threats detected
No debug info