| File name: | invoice 30422678.zip |
| Full analysis: | https://app.any.run/tasks/8216e7db-246c-4f79-bb05-a6a04695e213 |
| Verdict: | Malicious activity |
| Analysis date: | May 17, 2018, 19:12:34 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | 436DAF137D6294209163670BE88C0F85 |
| SHA1: | 7F0CFE6402C2CDE47C0233CC3FE25E673477D1C3 |
| SHA256: | EA1E873D574B82111C1A17E8DF31FAC0F31A5487264CB398243D8674A2B3F3F8 |
| SSDEEP: | 6:5jHQtzZ8/s2D/QMTCwVxaHs3vV25WUHRXj5T1p9/o7I97AJQB7ZnzbMyP+l0:5jv/s2D7aM0oq5Bbo7wzoUa0 |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2018:03:05 15:10:15 |
| ZipCRC: | 0x2a9a40f5 |
| ZipCompressedSize: | 188 |
| ZipUncompressedSize: | 220 |
| ZipFileName: | I918798443058.url |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 688 | "C:\Windows\system32\rundll32.exe" ndfapi.dll,NdfRunDllDiagnoseWithAnswerFile NetworkDiagnosticsSharing C:\Users\admin\AppData\Local\Temp\NDF4225.tmp | C:\Windows\system32\rundll32.exe | — | 7zFM.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1352 | -skip TRUE -path C:\Windows\diagnostics\system\networking -af C:\Users\admin\AppData\Local\Temp\NDF8FD6.tmp -ep NetworkDiagnosticsSharing | C:\Windows\system32\msdt.exe | rundll32.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Diagnostics Troubleshooting Wizard Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1516 | C:\Windows\System32\sdiagnhost.exe -Embedding | C:\Windows\System32\sdiagnhost.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Scripted Diagnostics Native Host Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2780 | "C:\Windows\system32\msdt.exe" -path "C:\Windows\diagnostics\system\networking" -skip force -af "C:\Users\admin\AppData\Local\Temp\NDF8FD6.tmp" -ep NetworkDiagnosticsSharing -elevated yes | C:\Windows\system32\msdt.exe | msdt.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Diagnostics Troubleshooting Wizard Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2916 | "C:\Windows\explorer.exe" | C:\Windows\explorer.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2952 | C:\Windows\System32\sdiagnhost.exe -Embedding | C:\Windows\System32\sdiagnhost.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Scripted Diagnostics Native Host Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3204 | C:\Windows\System32\sdiagnhost.exe -Embedding | C:\Windows\System32\sdiagnhost.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Scripted Diagnostics Native Host Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3404 | C:\Windows\System32\sdiagnhost.exe -Embedding | C:\Windows\System32\sdiagnhost.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Scripted Diagnostics Native Host Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3412 | "C:\Program Files\7-Zip\7zFM.exe" "C:\Users\admin\AppData\Local\Temp\invoice 30422678.zip" | C:\Program Files\7-Zip\7zFM.exe | explorer.exe | ||||||||||||
User: admin Company: Igor Pavlov Integrity Level: MEDIUM Description: 7-Zip File Manager Exit code: 0 Version: 16.04 Modules
| |||||||||||||||
| 3612 | "C:\Windows\system32\rundll32.exe" ndfapi.dll,NdfRunDllDiagnoseWithAnswerFile NetworkDiagnosticsSharing C:\Users\admin\AppData\Local\Temp\NDF8FD6.tmp | C:\Windows\system32\rundll32.exe | — | 7zFM.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (3412) 7zFM.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached |
| Operation: | write | Name: | {FBF23B40-E3F0-101B-8488-00AA003E56F8} {000214E4-0000-0000-C000-000000000046} 0xFFFF |
Value: 0100000000000000A06E8A1C13EED301 | |||
| (PID) Process: | (1352) msdt.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\93\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3412) 7zFM.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (3412) 7zFM.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
| (PID) Process: | (3204) sdiagnhost.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (3204) sdiagnhost.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
| (PID) Process: | (1352) msdt.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (1352) msdt.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
| (PID) Process: | (2780) msdt.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\93\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3404) sdiagnhost.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1352 | msdt.exe | C:\Users\admin\AppData\Local\Temp\SDIAG_ff9a166f-694d-407b-85e3-a8e2797f00d9\result\DebugReport.xml | — | |
MD5:— | SHA256:— | |||
| 1352 | msdt.exe | C:\Users\admin\AppData\Local\Temp\SDIAG_ff9a166f-694d-407b-85e3-a8e2797f00d9\result\ResultReport.xml | — | |
MD5:— | SHA256:— | |||
| 1352 | msdt.exe | C:\Users\admin\AppData\Local\Diagnostics\460911090\2018051719.000\DebugReport.xml | — | |
MD5:— | SHA256:— | |||
| 3412 | 7zFM.exe | C:\Users\admin\AppData\Local\Temp\NDF8FD6.tmp | binary | |
MD5:— | SHA256:— | |||
| 3412 | 7zFM.exe | C:\Users\admin\AppData\Local\Temp\7zO45D90464\I918798443058.url | text | |
MD5:DA3C1A7466D3C84A284B90BF247F8961 | SHA256:2A3C4284B88D58BF93AEEC15A1F7F3EDC8EE23198279F9CE8899F97EB439DAF5 | |||
| 1352 | msdt.exe | C:\Users\admin\AppData\Local\Temp\SDIAG_ff9a166f-694d-407b-85e3-a8e2797f00d9\InteractiveRes.ps1 | text | |
MD5:25B8543DBF571F040118423BC3C7A75E | SHA256:D78E6291D6F27AC6FEBDCF0A4D5A34521E7F033AF8875E026DF21BA7513AB64A | |||
| 1352 | msdt.exe | C:\Users\admin\AppData\Local\Temp\PLA769B.tmp | — | |
MD5:— | SHA256:— | |||
| 1352 | msdt.exe | C:\Users\admin\AppData\Local\Temp\PLA6848.tmp | — | |
MD5:— | SHA256:— | |||
| 1352 | msdt.exe | C:\Users\admin\AppData\Local\Temp\SDIAG_ff9a166f-694d-407b-85e3-a8e2797f00d9\NetworkDiagnosticsVerify.ps1 | text | |
MD5:C0BB6343BD0F6F9B46B33E4B66106953 | SHA256:EB9BC61668A93759D0127A11CDFC03E924100D69C7E6457FEAA89330474C90C3 | |||
| 1352 | msdt.exe | C:\Users\admin\AppData\Local\Temp\PLA3F96.tmp | — | |
MD5:— | SHA256:— | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 91.102.153.90:445 | buyviagraoverthecounterusabb.net | Limited Liability Company NTCOM | RU | unknown |
4 | System | 91.102.153.90:139 | buyviagraoverthecounterusabb.net | Limited Liability Company NTCOM | RU | unknown |
3412 | 7zFM.exe | 91.102.153.90:80 | buyviagraoverthecounterusabb.net | Limited Liability Company NTCOM | RU | unknown |
Domain | IP | Reputation |
|---|---|---|
buyviagraoverthecounterusabb.net |
| unknown |
dns.msftncsi.com |
| shared |