| File name: | Desinfecta Usb LC.zip |
| Full analysis: | https://app.any.run/tasks/45e3ce02-2a1d-4e75-af44-4a6b938f8e67 |
| Verdict: | Malicious activity |
| Analysis date: | August 22, 2018, 18:01:15 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | 205AA091F7E9AC92538C4D6E34A109C3 |
| SHA1: | 22F4179D826CB450113105CA14592A69BE329188 |
| SHA256: | E98ED3A7D00C5B836D33C489B77AFF4AB018758BB11022AD4307330415A401BC |
| SSDEEP: | 24576:OMFdlJt7MF71kWAAuqaZXQGcR9kFjUBT3NGkesOWea:1blrw7eXQTRuFjUBTdjesJP |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | 0x0808 |
| ZipCompression: | None |
| ZipModifyDate: | 2014:11:18 13:47:27 |
| ZipCRC: | 0x64526b55 |
| ZipCompressedSize: | 8656896 |
| ZipUncompressedSize: | 8656896 |
| ZipFileName: | Desinfecta Usb LC/Desinfecta_USB_LC_2.2.0.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 304 | "C:\Program Files\Java\jre1.8.0_92\bin\javaw.exe" -jar "C:\Users\admin\AppData\Local\Temp\RarSFX1\Desinfecta_Usb_LC.jar" | C:\Program Files\Java\jre1.8.0_92\bin\javaw.exe | — | Desinfecta_Usb_LC_3.0.0_VersiónOficial.exe | |||||||||||
User: admin Company: Oracle Corporation Integrity Level: HIGH Description: Java(TM) Platform SE binary Exit code: 0 Version: 8.0.920.14 Modules
| |||||||||||||||
| 476 | find /I /N ".js" pol_hklm.reg | C:\Windows\system32\find.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Find String (grep) Utility Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 916 | cmd /C echo %systemdrive% | C:\Windows\system32\cmd.exe | — | javaw.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 928 | find /I /N "\Roaming\" run_hkcu.reg | C:\Windows\system32\find.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Find String (grep) Utility Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 972 | find /I /N "\temp\" pol_hkcu.reg | C:\Windows\system32\find.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Find String (grep) Utility Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 992 | C:\Users\admin\AppData\Local\Temp\RarSFX1\SL.exe PC | C:\Users\admin\AppData\Local\Temp\RarSFX1\SL.exe | — | cmd.exe | |||||||||||
User: admin Company: LuisColmenarez Integrity Level: HIGH Description: Desactiva/Elimina Malwares - Desinfecta Usb LC Exit code: 255 Version: 3. 0. 0. 0 Modules
| |||||||||||||||
| 1196 | cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\99291PSC.cmd" C:\Users\admin\AppData\Local\Temp\RarSFX1\SL.exe PC" | C:\Windows\system32\cmd.exe | — | SL.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 255 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1336 | cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\24927FKA.cmd" "C:\Users\admin\Desktop\Desinfecta Usb LC\Desinfecta_USB_LC_2.2.0.exe" " | C:\Windows\system32\cmd.exe | — | Desinfecta_USB_LC_2.2.0.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 3221225786 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1460 | find /I /N ".js" pol_hkcu.reg | C:\Windows\system32\find.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Find String (grep) Utility Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1464 | find /I /N "\temp\" run_hklm.reg | C:\Windows\system32\find.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Find String (grep) Utility Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (3936) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3936) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3936) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\59\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3936) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Desinfecta Usb LC.zip | |||
| (PID) Process: | (3936) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3936) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3936) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3936) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (3936) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin |
| Operation: | write | Name: | Placement |
Value: 2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF2C0000002C000000EC03000021020000 | |||
| (PID) Process: | (3936) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\General |
| Operation: | write | Name: | LastFolder |
Value: C:\Users\admin\AppData\Local\Temp | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3936 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3936.8745\Desinfecta Usb LC\Desinfecta_USB_LC_2.2.0.exe | — | |
MD5:— | SHA256:— | |||
| 3936 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3936.8745\Desinfecta Usb LC\Desinfecta_USB_LC_2.1.0.exe | — | |
MD5:— | SHA256:— | |||
| 3936 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3936.8745\Desinfecta Usb LC\Desinfecta_Usb_LC_3.0.0_VersiónOficial.exe | — | |
MD5:— | SHA256:— | |||
| 2492 | Desinfecta_USB_LC_2.2.0.exe | C:\Users\admin\AppData\Local\qb4D170B.AB\icono.ico | — | |
MD5:— | SHA256:— | |||
| 3756 | Desinfecta_USB_LC_2.1.0.exe | C:\Users\admin\AppData\Local\qb4CB321.10\icono.ico | image | |
MD5:— | SHA256:— | |||
| 3756 | Desinfecta_USB_LC_2.1.0.exe | C:\Users\admin\AppData\Local\Temp\3756SNT3.cmd | text | |
MD5:— | SHA256:— | |||
| 1196 | cmd.exe | C:\arch.txt | — | |
MD5:— | SHA256:— | |||
| 2492 | Desinfecta_USB_LC_2.2.0.exe | C:\Users\admin\AppData\Local\Temp\24927FKA.cmd | text | |
MD5:— | SHA256:— | |||
| 2204 | reg.exe | C:\Users\admin\AppData\Local\Temp\REGD8B6.tmp | — | |
MD5:— | SHA256:— | |||
| 2492 | Desinfecta_USB_LC_2.2.0.exe | C:\Users\admin\AppData\Local\qb4D170B.AB\leeme.txt | text | |
MD5:— | SHA256:— | |||