File name:

BleachBit-4.6.0-portable.zip

Full analysis: https://app.any.run/tasks/a2d9cce1-75ad-40a0-b8a2-275574233553
Verdict: Malicious activity
Analysis date: February 12, 2024, 18:52:28
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
python
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=store
MD5:

86B543EBFD356501F8246D5FAF1CA608

SHA1:

DD0D5521757EFC94718424AA1173F24E4F74B03E

SHA256:

EE9C06251E56695119B8184979F9BB17FB8BE44C2A0A46B34A8FDFA97CBCA502

SSDEEP:

98304:dYLEELqBrvNgfAi2gNHJEJfCoiKFzks/gnn7bGpd2JV/4Fjrlzo9RznhlIFDigov:J5HN5UwrXAHXWcWQ62FCGD

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Actions looks like stealing of personal data

      • WinRAR.exe (PID: 3668)
      • bleachbit.exe (PID: 2648)
      • bleachbit_console.exe (PID: 2980)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 3668)
    • Steals credentials from Web Browsers

      • bleachbit.exe (PID: 2648)
      • bleachbit_console.exe (PID: 2980)
  • SUSPICIOUS

    • Process drops SQLite DLL files

      • WinRAR.exe (PID: 3668)
    • Reads security settings of Internet Explorer

      • bleachbit.exe (PID: 2852)
      • bleachbit_console.exe (PID: 2916)
    • Application launched itself

      • bleachbit.exe (PID: 2852)
      • bleachbit_console.exe (PID: 2916)
    • Reads the Internet Settings

      • bleachbit.exe (PID: 2852)
      • bleachbit.exe (PID: 2648)
      • bleachbit_console.exe (PID: 2916)
      • bleachbit_console.exe (PID: 2980)
    • Uses RUNDLL32.EXE to load library

      • bleachbit.exe (PID: 2648)
      • bleachbit_console.exe (PID: 2980)
    • Reads settings of System Certificates

      • bleachbit.exe (PID: 2648)
      • bleachbit_console.exe (PID: 2980)
    • Loads Python modules

      • bleachbit_console.exe (PID: 2980)
  • INFO

    • Checks supported languages

      • bleachbit.exe (PID: 2852)
      • bleachbit.exe (PID: 2648)
      • bleachbit_console.exe (PID: 2916)
      • bleachbit_console.exe (PID: 2980)
    • Reads the computer name

      • bleachbit.exe (PID: 2852)
      • bleachbit.exe (PID: 2648)
      • bleachbit_console.exe (PID: 2980)
      • bleachbit_console.exe (PID: 2916)
    • Manual execution by a user

      • bleachbit.exe (PID: 2852)
      • explorer.exe (PID: 1576)
      • bleachbit_console.exe (PID: 2916)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3668)
    • Create files in a temporary directory

      • rundll32.exe (PID: 3964)
      • bleachbit.exe (PID: 2648)
      • rundll32.exe (PID: 1880)
    • Reads the machine GUID from the registry

      • bleachbit.exe (PID: 2648)
      • bleachbit.exe (PID: 2852)
      • bleachbit_console.exe (PID: 2980)
      • bleachbit_console.exe (PID: 2916)
    • Drops the executable file immediately after the start

      • rundll32.exe (PID: 3964)
    • Creates files or folders in the user directory

      • bleachbit.exe (PID: 2648)
    • Checks proxy server information

      • bleachbit.exe (PID: 2648)
      • bleachbit_console.exe (PID: 2980)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (36.3)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2023:11:05 15:37:28
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: BleachBit-Portable/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
58
Monitored processes
8
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe bleachbit.exe no specs bleachbit.exe rundll32.exe no specs explorer.exe no specs bleachbit_console.exe no specs bleachbit_console.exe rundll32.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1576"C:\Windows\explorer.exe" C:\Windows\explorer.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1880"C:\Windows\system32\rundll32.exe" C:\Users\admin\Desktop\BLEACH~1\LIBGIO~1.DLL,g_win32_run_session_bus@16C:\Windows\System32\rundll32.exebleachbit_console.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
2648"C:\Users\admin\Desktop\BleachBit-Portable\bleachbit.exe" --gui --no-uac C:\Users\admin\Desktop\BleachBit-Portable\bleachbit.exe
bleachbit.exe
User:
admin
Integrity Level:
HIGH
Description:
BleachBit frees space and maintains privacy by quickly wiping files you don't need and didn't know you had. Supported applications include Edge, Firefox, Google Chrome, VLC, and many others.
Exit code:
0
Version:
4.6.0
Modules
Images
c:\users\admin\desktop\bleachbit-portable\bleachbit.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
2852"C:\Users\admin\Desktop\BleachBit-Portable\bleachbit.exe" C:\Users\admin\Desktop\BleachBit-Portable\bleachbit.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
BleachBit frees space and maintains privacy by quickly wiping files you don't need and didn't know you had. Supported applications include Edge, Firefox, Google Chrome, VLC, and many others.
Exit code:
0
Version:
4.6.0
Modules
Images
c:\users\admin\desktop\bleachbit-portable\bleachbit.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
2916"C:\Users\admin\Desktop\BleachBit-Portable\bleachbit_console.exe" C:\Users\admin\Desktop\BleachBit-Portable\bleachbit_console.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
BleachBit frees space and maintains privacy by quickly wiping files you don't need and didn't know you had. Supported applications include Edge, Firefox, Google Chrome, VLC, and many others.
Exit code:
0
Version:
4.6.0
Modules
Images
c:\users\admin\desktop\bleachbit-portable\bleachbit_console.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
2980"C:\Users\admin\Desktop\BleachBit-Portable\bleachbit_console.exe" --gui --no-uac C:\Users\admin\Desktop\BleachBit-Portable\bleachbit_console.exe
bleachbit_console.exe
User:
admin
Integrity Level:
HIGH
Description:
BleachBit frees space and maintains privacy by quickly wiping files you don't need and didn't know you had. Supported applications include Edge, Firefox, Google Chrome, VLC, and many others.
Exit code:
0
Version:
4.6.0
Modules
Images
c:\users\admin\desktop\bleachbit-portable\bleachbit_console.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
3668"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\BleachBit-4.6.0-portable.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3964"C:\Windows\system32\rundll32.exe" C:\Users\admin\Desktop\BLEACH~1\LIBGIO~1.DLL,g_win32_run_session_bus@16C:\Windows\System32\rundll32.exebleachbit.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
Total events
11 878
Read events
11 799
Write events
45
Delete events
34

Modification events

(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3668) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\BleachBit-4.6.0-portable.zip
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
68
Suspicious files
169
Text files
215
Unknown types
42

Dropped files

PID
Process
Filename
Type
3668WinRAR.exeC:\Users\admin\Desktop\BleachBit-Portable\cacert.pemtext
MD5:EA4EE2AF66C4C57B8A275867E9DC07CD
SHA256:FA883829EBB8CD2A602F9B21C1F85DE24CF47949D520BCEB1828B4CD1CB6906C
3668WinRAR.exeC:\Users\admin\Desktop\BleachBit-Portable\etc\dbus-1\system.conftext
MD5:B03D0315F1346F423075CA3A33EA0739
SHA256:C9992C5D59FE38703B613383963E4417D23D96115D5EE8D08A214B81DF6A1B57
3668WinRAR.exeC:\Users\admin\Desktop\BleachBit-Portable\COPYINGtext
MD5:C678957B0C8E964AA6C70FD77641A71E
SHA256:E79E9C8A0C85D735FF98185918EC94ED7D175EFC377012787AEBCF3B80F0D90B
3668WinRAR.exeC:\Users\admin\Desktop\BleachBit-Portable\etc\fonts\conf.d\20-unhint-small-dejavu-sans-mono.confxml
MD5:0CBF30E4580C5A8570DA071AB12C5E4D
SHA256:3E90C9C36BEEF46F10D1529251F8683B9C4AC900695ADBB4A23A4B6036F938A5
3668WinRAR.exeC:\Users\admin\Desktop\BleachBit-Portable\etc\fonts\conf.d\20-unhint-small-dejavu-serif.confxml
MD5:E90C678D46F49BB9D6BA469B64E80C0C
SHA256:68777B1705EC7A05A86430DEF4BE093668E84E305CC7E11291DF52403A7318CC
3668WinRAR.exeC:\Users\admin\Desktop\BleachBit-Portable\etc\fonts\conf.d\10-scale-bitmap-fonts.confxml
MD5:C79833EF7E11FC58472AAE2D55E233B2
SHA256:9E8E338453028B8B6AD97A9103E799A1E338B51E8231C73D28B82A4C530927A0
3668WinRAR.exeC:\Users\admin\Desktop\BleachBit-Portable\etc\fonts\conf.d\20-unhint-small-dejavu-sans.confxml
MD5:F7DF7BBA810DD953DD78212900F4DCAD
SHA256:0D9C177B6A85DAA9957ED6750D4EB26122604DA18D340E7BA31E6F4D24F963ED
3668WinRAR.exeC:\Users\admin\Desktop\BleachBit-Portable\etc\fonts\conf.d\20-unhint-small-vera.confxml
MD5:6FB496D0BB963A54D5DB870955DDD771
SHA256:855E1F86A70170982CDA0E796E407173C81E4033537CCB6FA899F638A324EF60
3668WinRAR.exeC:\Users\admin\Desktop\BleachBit-Portable\etc\fonts\conf.d\28-user.confxml
MD5:A266C2A0043823CBF1D24299A8192DCA
SHA256:E7452C8AD25DD83C07C405B20DACFDD60D329933E666496E6D6D325B7962197B
3668WinRAR.exeC:\Users\admin\Desktop\BleachBit-Portable\BleachBit.initext
MD5:0FA0571B5329B8A2B4019589E97FE1F6
SHA256:CF864D8C3E89A789B57218413EB047F3F66537303BC0729013F4CFC887F956DB
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
6
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2648
bleachbit.exe
104.21.36.254:443
update.bleachbit.org
CLOUDFLARENET
unknown
2980
bleachbit_console.exe
104.21.36.254:443
update.bleachbit.org
CLOUDFLARENET
unknown

DNS requests

Domain
IP
Reputation
update.bleachbit.org
  • 104.21.36.254
  • 172.67.201.162
unknown

Threats

No threats detected
No debug info