File name: | [email protected] |
Full analysis: | https://app.any.run/tasks/28426d5c-14ee-4c5c-a40d-eba4174b0508 |
Verdict: | Malicious activity |
Analysis date: | November 30, 2024, 13:24:09 |
OS: | Windows 10 Professional (build: 19045, 64 bit) |
Tags: | |
Indicators: | |
MIME: | application/zip |
File info: | Zip archive data, at least v2.0 to extract, compression method=deflate |
MD5: | 2ED39478EFF85447F64CDAB8032196C2 |
SHA1: | D2B3E87AD2F8133DCD77F4AACB17EBD63237657C |
SHA256: | EC5B90DEB8F740CB1C6813F17DAFF72C7E1340070B705904C5B87C8DECD41B37 |
SSDEEP: | 96:JRWiITrnAqEBQtBVb/eRDWD7AdpT0VFgMIF2d:GUqwWBVb/eRG7AdpoF7IF2d |
.zip | | | ZIP compressed archive (100) |
---|
ZipRequiredVersion: | 788 |
---|---|
ZipBitFlag: | 0x0001 |
ZipCompression: | Deflated |
ZipModifyDate: | 2024:11:30 01:21:04 |
ZipCRC: | 0x901569e7 |
ZipCompressedSize: | 2648 |
ZipUncompressedSize: | 5052 |
ZipFileName: | 3deb7f7b1422af460a54f47b562d2e7a |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
204 | "C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\[email protected] | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Version: 5.91.0 Modules
| |||||||||||||||
2192 | C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s Dnscache | C:\Windows\System32\svchost.exe | services.exe | ||||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
2292 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5256 -childID 5 -isForBrowser -prefsHandle 5288 -prefMapHandle 5292 -prefsLen 31243 -prefMapSize 244583 -jsInitHandle 1500 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {8e103ede-f991-4160-90e8-f06ab47ba95c} 5872 "\\.\pipe\gecko-crash-server-pipe.5872" 1fcdd6a1310 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 123.0 Modules
| |||||||||||||||
3836 | "C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\ai.exe" "3317D408-1D86-409C-8779-206310B5CDAB" "B10DC8A6-9FC4-4A0B-9B45-19FB8735D5F6" "6924" | C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\ai.exe | — | OUTLOOK.EXE | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Artificial Intelligence (AI) Host for the Microsoft® Windows® Operating System and Platform x64. Version: 0.12.2.0 Modules
| |||||||||||||||
4328 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=4224 -childID 2 -isForBrowser -prefsHandle 4216 -prefMapHandle 4212 -prefsLen 36588 -prefMapSize 244583 -jsInitHandle 1500 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {d6077356-9c7d-427c-8f3e-31005fe021e6} 5872 "\\.\pipe\gecko-crash-server-pipe.5872" 1fce1498a10 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 123.0 Modules
| |||||||||||||||
4444 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=4948 -parentBuildID 20240213221259 -sandboxingKind 0 -prefsHandle 4932 -prefMapHandle 4744 -prefsLen 36588 -prefMapSize 244583 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {7dea0cc0-05ac-4a81-8c96-31feb4f3a10e} 5872 "\\.\pipe\gecko-crash-server-pipe.5872" 1fce252bd10 utility | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 123.0 Modules
| |||||||||||||||
5544 | "C:\Program Files\Mozilla Firefox\firefox.exe" | C:\Program Files\Mozilla Firefox\firefox.exe | — | explorer.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
5872 | "C:\Program Files\Mozilla Firefox\firefox.exe" | C:\Program Files\Mozilla Firefox\firefox.exe | firefox.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 123.0 Modules
| |||||||||||||||
6176 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=1912 -parentBuildID 20240213221259 -prefsHandle 1840 -prefMapHandle 1832 -prefsLen 31031 -prefMapSize 244583 -appDir "C:\Program Files\Mozilla Firefox\browser" - {20e31516-0ea9-4397-8d72-cc7ebf6d7cab} 5872 "\\.\pipe\gecko-crash-server-pipe.5872" 1fcd9ff1b10 gpu | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 123.0 Modules
| |||||||||||||||
6336 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5244 -childID 4 -isForBrowser -prefsHandle 5236 -prefMapHandle 5232 -prefsLen 31251 -prefMapSize 244583 -jsInitHandle 1500 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {903a7a2b-83ad-41f8-8b57-20dcdb92ec03} 5872 "\\.\pipe\gecko-crash-server-pipe.5872" 1fce48d7f50 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 123.0 Modules
|
(PID) Process: | (204) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\preferences.zip | |||
(PID) Process: | (204) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\chromium_ext.zip | |||
(PID) Process: | (204) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\omni_23_10_2024_.zip | |||
(PID) Process: | (204) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\[email protected] | |||
(PID) Process: | (204) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | name |
Value: 120 | |||
(PID) Process: | (204) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | size |
Value: 80 | |||
(PID) Process: | (204) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | type |
Value: 120 | |||
(PID) Process: | (204) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | mtime |
Value: 100 | |||
(PID) Process: | (204) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface |
Operation: | write | Name: | ShowPassword |
Value: 0 | |||
(PID) Process: | (6924) OUTLOOK.EXE | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Outlook\Resiliency\StartupItems |
Operation: | write | Name: | 4,. |
Value: 342C2E000C1B00000100000000000000243916312B43DB0100000000 |
PID | Process | Filename | Type | |
---|---|---|---|---|
6924 | OUTLOOK.EXE | C:\Users\admin\Documents\Outlook Files\Outlook1.pst | — | |
MD5:— | SHA256:— | |||
5872 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\scriptCache-current.bin | — | |
MD5:— | SHA256:— | |||
204 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb204.36710\3deb7f7b1422af460a54f47b562d2e7a | binary | |
MD5:3DEB7F7B1422AF460A54F47B562D2E7A | SHA256:AACA6C208925A6CBAC619A05BC980E84E2D29FAD4652D276FBAFEF887A2E4693 | |||
6924 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\02C1909A-3D77-4FBA-81B9-92E7F7717061 | xml | |
MD5:0E15E25D784AC75BF6827CEFA3EEE887 | SHA256:F31DBBC6004D4125BE1D25F27B1EE4DB3BF6213B5A8F2D2453D2F5D4D983D0FD | |||
6924 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Microsoft\TokenBroker\Cache\56a61aeb75d8f5be186c26607f4bb213abe7c5ec.tbres | binary | |
MD5:7E64838D9FE18D4FD752F376A932704A | SHA256:B8B0C35C0E4E59AF00A844BAAB84CBE507EE8FC5B0DF05C1952312F0D667976D | |||
6924 | OUTLOOK.EXE | C:\Users\admin\AppData\Roaming\Microsoft\Templates\~$rmalEmail.dotm | binary | |
MD5:D9DFB74B1995947987A86F1074F6D89B | SHA256:6333EF7F2454A7FB6885BFCEFBA90848DFC53BDE0E5923E081D9189C7C776E0C | |||
6924 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Microsoft\Office\16.0\AddInClassifierCache\OfficeSharedEntities.bin | text | |
MD5:CC90D669144261B198DEAD45AA266572 | SHA256:89C701EEFF939A44F28921FD85365ECD87041935DCD0FE0BAF04957DA12C9899 | |||
6924 | OUTLOOK.EXE | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_CBDCCBFE4F7A916411C1E69BDD97BB04 | binary | |
MD5:39218A086BBB6FFA3CC92345D04F6270 | SHA256:BBA6D03432C3E71F236BF3277715A06C4820822DD4542B265A10F4ED61C3A891 | |||
6924 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Microsoft\TokenBroker\Cache\089d66ba04a8cec4bdc5267f42f39cf84278bb67.tbres | binary | |
MD5:D252D3AE31E6DF8178B158816CFF27CB | SHA256:553693D9BF729F180F8DAEF38ED70183B05BEA681E7673C9EEFFA2FB85394EB8 | |||
6924 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Microsoft\Office\16.0\AddInClassifierCache\OfficeSharedEntitiesUpdated.bin | text | |
MD5:FFC51DFE023018C18EC3C31AFB1EB82E | SHA256:BD8D4A887A2FA5363D66CF0B76169EDDCF99D227E3CFBB625DFE34CA904EB419 |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
4712 | MoUsoCoreWorker.exe | GET | 200 | 23.48.23.143:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
5872 | firefox.exe | POST | 200 | 95.101.54.114:80 | http://r11.o.lencr.org/ | unknown | — | — | whitelisted |
5872 | firefox.exe | POST | 200 | 142.250.186.67:80 | http://o.pki.goog/s/wr3/yvU | unknown | — | — | whitelisted |
5872 | firefox.exe | POST | 200 | 95.101.54.195:80 | http://r10.o.lencr.org/ | unknown | — | — | whitelisted |
5872 | firefox.exe | POST | 200 | 95.101.54.114:80 | http://r11.o.lencr.org/ | unknown | — | — | whitelisted |
5872 | firefox.exe | POST | 200 | 95.101.54.195:80 | http://r10.o.lencr.org/ | unknown | — | — | whitelisted |
— | — | POST | 200 | 142.250.186.67:80 | http://o.pki.goog/wr2 | unknown | — | — | whitelisted |
5872 | firefox.exe | POST | 200 | 95.101.54.195:80 | http://r10.o.lencr.org/ | unknown | — | — | whitelisted |
— | — | GET | 200 | 23.48.23.143:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
4712 | MoUsoCoreWorker.exe | GET | 200 | 2.19.217.218:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
— | — | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 192.168.100.255:137 | — | — | — | whitelisted |
4712 | MoUsoCoreWorker.exe | 23.48.23.143:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
— | — | 23.48.23.143:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
4712 | MoUsoCoreWorker.exe | 2.19.217.218:80 | www.microsoft.com | Akamai International B.V. | NL | whitelisted |
— | — | 2.19.217.218:80 | www.microsoft.com | Akamai International B.V. | NL | whitelisted |
— | — | 23.212.110.169:443 | www.bing.com | Akamai International B.V. | CZ | whitelisted |
— | — | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 20.190.159.68:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
Domain | IP | Reputation |
---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
www.bing.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
login.live.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
officeclient.microsoft.com |
| whitelisted |
ecs.office.com |
| whitelisted |
PID | Process | Class | Message |
---|---|---|---|
2192 | svchost.exe | Potentially Bad Traffic | ET INFO Peer-to-Peer File Sharing Service Domain in DNS Lookup (ipfs .io) |
2192 | svchost.exe | Potentially Bad Traffic | ET INFO Peer-to-Peer File Sharing Service Domain in DNS Lookup (ipfs .io) |
2192 | svchost.exe | Potentially Bad Traffic | ET INFO Peer-to-Peer File Sharing Service Domain in DNS Lookup (ipfs .io) |
5872 | firefox.exe | Potential Corporate Privacy Violation | POLICY [ANY.RUN] InterPlanetary File System IPFS Service |
5872 | firefox.exe | Potentially Bad Traffic | ET INFO Observed Peer-to-Peer File Sharing Service Domain (ipfs .io in TLS SNI) |
5872 | firefox.exe | Potentially Bad Traffic | ET INFO Observed Peer-to-Peer File Sharing Service Domain (ipfs .io in TLS SNI) |
5872 | firefox.exe | Potential Corporate Privacy Violation | POLICY [ANY.RUN] InterPlanetary File System IPFS Service |