File name:

Desinfecta Usb LC.zip

Full analysis: https://app.any.run/tasks/45e3ce02-2a1d-4e75-af44-4a6b938f8e67
Verdict: Malicious activity
Analysis date: August 22, 2018, 18:01:15
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

205AA091F7E9AC92538C4D6E34A109C3

SHA1:

22F4179D826CB450113105CA14592A69BE329188

SHA256:

E98ED3A7D00C5B836D33C489B77AFF4AB018758BB11022AD4307330415A401BC

SSDEEP:

24576:OMFdlJt7MF71kWAAuqaZXQGcR9kFjUBT3NGkesOWea:1blrw7eXQTRuFjUBTdjesJP

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • mata_procesos.exe (PID: 3020)
      • SL.exe (PID: 992)
      • bc.exe (PID: 2352)
      • dr.exe (PID: 1892)
  • SUSPICIOUS

    • Starts CMD.EXE for commands execution

      • Desinfecta_USB_LC_2.1.0.exe (PID: 3756)
      • mata_procesos.exe (PID: 3020)
      • Desinfecta_USB_LC_2.2.0.exe (PID: 2492)
      • javaw.exe (PID: 2448)
      • javaw.exe (PID: 304)
      • SL.exe (PID: 992)
      • bc.exe (PID: 2352)
      • dr.exe (PID: 1892)
    • Executable content was dropped or overwritten

      • Desinfecta_USB_LC_2.1.0.exe (PID: 3756)
      • Desinfecta_USB_LC_2.2.0.exe (PID: 2492)
      • Desinfecta_Usb_LC_3.0.0_VersiónOficial.exe (PID: 4076)
      • Desinfecta_Usb_LC_3.0.0_VersiónOficial.exe (PID: 2168)
    • Executes JAVA applets

      • Desinfecta_Usb_LC_3.0.0_VersiónOficial.exe (PID: 4076)
      • Desinfecta_Usb_LC_3.0.0_VersiónOficial.exe (PID: 2168)
    • Reads internet explorer settings

      • Desinfecta_Usb_LC_3.0.0_VersiónOficial.exe (PID: 4076)
      • Desinfecta_Usb_LC_3.0.0_VersiónOficial.exe (PID: 2168)
    • Uses TASKKILL.EXE to kill process

      • cmd.exe (PID: 2916)
    • Uses REG.EXE to modify Windows registry

      • cmd.exe (PID: 3036)
  • INFO

    • Dropped object may contain URL's

      • Desinfecta_USB_LC_2.2.0.exe (PID: 2492)
      • Desinfecta_Usb_LC_3.0.0_VersiónOficial.exe (PID: 4076)
      • Desinfecta_Usb_LC_3.0.0_VersiónOficial.exe (PID: 2168)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0808
ZipCompression: None
ZipModifyDate: 2014:11:18 13:47:27
ZipCRC: 0x64526b55
ZipCompressedSize: 8656896
ZipUncompressedSize: 8656896
ZipFileName: Desinfecta Usb LC/Desinfecta_USB_LC_2.2.0.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
115
Monitored processes
61
Malicious processes
1
Suspicious processes
7

Behavior graph

Click at the process to see the details
start winrar.exe no specs desinfecta_usb_lc_2.1.0.exe no specs desinfecta_usb_lc_2.1.0.exe cmd.exe no specs notepad.exe no specs desinfecta_usb_lc_2.2.0.exe no specs desinfecta_usb_lc_2.2.0.exe cmd.exe no specs mata_procesos.exe no specs cmd.exe no specs cmd.exe no specs notepad.exe no specs desinfecta_usb_lc_3.0.0_versiónoficial.exe no specs desinfecta_usb_lc_3.0.0_versiónoficial.exe javaw.exe no specs cmd.exe no specs desinfecta_usb_lc_3.0.0_versiónoficial.exe no specs desinfecta_usb_lc_3.0.0_versiónoficial.exe javaw.exe no specs cmd.exe no specs cmd.exe no specs taskkill.exe no specs cmd.exe no specs sl.exe no specs cmd.exe no specs bc.exe no specs cmd.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs dr.exe no specs cmd.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
304"C:\Program Files\Java\jre1.8.0_92\bin\javaw.exe" -jar "C:\Users\admin\AppData\Local\Temp\RarSFX1\Desinfecta_Usb_LC.jar" C:\Program Files\Java\jre1.8.0_92\bin\javaw.exeDesinfecta_Usb_LC_3.0.0_VersiónOficial.exe
User:
admin
Company:
Oracle Corporation
Integrity Level:
HIGH
Description:
Java(TM) Platform SE binary
Exit code:
0
Version:
8.0.920.14
Modules
Images
c:\program files\java\jre1.8.0_92\bin\javaw.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
476find /I /N ".js" pol_hklm.reg C:\Windows\system32\find.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Find String (grep) Utility
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\find.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
916cmd /C echo %systemdrive%C:\Windows\system32\cmd.exejavaw.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
928find /I /N "\Roaming\" run_hkcu.reg C:\Windows\system32\find.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Find String (grep) Utility
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\find.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
972find /I /N "\temp\" pol_hkcu.reg C:\Windows\system32\find.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Find String (grep) Utility
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\find.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
992C:\Users\admin\AppData\Local\Temp\RarSFX1\SL.exe PCC:\Users\admin\AppData\Local\Temp\RarSFX1\SL.execmd.exe
User:
admin
Company:
LuisColmenarez
Integrity Level:
HIGH
Description:
Desactiva/Elimina Malwares - Desinfecta Usb LC
Exit code:
255
Version:
3. 0. 0. 0
Modules
Images
c:\users\admin\appdata\local\temp\rarsfx1\sl.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1196cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\99291PSC.cmd" C:\Users\admin\AppData\Local\Temp\RarSFX1\SL.exe PC"C:\Windows\system32\cmd.exeSL.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
255
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1336cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\24927FKA.cmd" "C:\Users\admin\Desktop\Desinfecta Usb LC\Desinfecta_USB_LC_2.2.0.exe" "C:\Windows\system32\cmd.exeDesinfecta_USB_LC_2.2.0.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
3221225786
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1460find /I /N ".js" pol_hkcu.reg C:\Windows\system32\find.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Find String (grep) Utility
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\find.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1464find /I /N "\temp\" run_hklm.reg C:\Windows\system32\find.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Find String (grep) Utility
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\find.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
Total events
2 079
Read events
2 034
Write events
45
Delete events
0

Modification events

(PID) Process:(3936) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3936) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3936) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\59\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3936) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Desinfecta Usb LC.zip
(PID) Process:(3936) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3936) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3936) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3936) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3936) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF2C0000002C000000EC03000021020000
(PID) Process:(3936) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\General
Operation:writeName:LastFolder
Value:
C:\Users\admin\AppData\Local\Temp
Executable files
13
Suspicious files
0
Text files
41
Unknown types
0

Dropped files

PID
Process
Filename
Type
3936WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3936.8745\Desinfecta Usb LC\Desinfecta_USB_LC_2.2.0.exe
MD5:
SHA256:
3936WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3936.8745\Desinfecta Usb LC\Desinfecta_USB_LC_2.1.0.exe
MD5:
SHA256:
3936WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3936.8745\Desinfecta Usb LC\Desinfecta_Usb_LC_3.0.0_VersiónOficial.exe
MD5:
SHA256:
2492Desinfecta_USB_LC_2.2.0.exeC:\Users\admin\AppData\Local\qb4D170B.AB\icono.ico
MD5:
SHA256:
3756Desinfecta_USB_LC_2.1.0.exeC:\Users\admin\AppData\Local\qb4CB321.10\icono.icoimage
MD5:
SHA256:
3756Desinfecta_USB_LC_2.1.0.exeC:\Users\admin\AppData\Local\Temp\3756SNT3.cmdtext
MD5:
SHA256:
1196cmd.exeC:\arch.txt
MD5:
SHA256:
2492Desinfecta_USB_LC_2.2.0.exeC:\Users\admin\AppData\Local\Temp\24927FKA.cmdtext
MD5:
SHA256:
2204reg.exeC:\Users\admin\AppData\Local\Temp\REGD8B6.tmp
MD5:
SHA256:
2492Desinfecta_USB_LC_2.2.0.exeC:\Users\admin\AppData\Local\qb4D170B.AB\leeme.txttext
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info