| File name: | Trojan.Shylock.Skype.zip |
| Full analysis: | https://app.any.run/tasks/f0b46e8f-5664-4e1a-a9eb-fefe82f4fceb |
| Verdict: | Malicious activity |
| Analysis date: | July 16, 2018, 15:07:37 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | 1DBEE013E7788A749F9E55A2B1BD20D5 |
| SHA1: | 132A2DB10EEECD91E91D4438409783B83879E341 |
| SHA256: | EF131AC51A972CE3CC14C33D858AD3E7346F3B705C54500A5081F110B24D9681 |
| SSDEEP: | 3072:xq8jl/+LJ7RlIOYjaVtgNQ1E9x7opG0jFrPpY6xVRuDmnZFZQ8kFzrrPIeY:pR/OdiOYjmgNZDopTJFYE8mnvZQrP5Y |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | 0x0009 |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2013:02:17 04:21:21 |
| ZipCRC: | 0x12856ea3 |
| ZipCompressedSize: | 181087 |
| ZipUncompressedSize: | 284672 |
| ZipFileName: | Shylock-skype_8FBEB78B06985C3188562E2F1B82D57D |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 876 | C:\Windows\system32\svchost.exe -k netsvcs | C:\Windows\System32\svchost.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1012 | "C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe3_ Global\UsGthrCtrlFltPipeMssGthrPipe3 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" | C:\Windows\System32\SearchProtocolHost.exe | — | SearchIndexer.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft Windows Search Protocol Host Exit code: 0 Version: 7.00.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1436 | C:\Windows\Explorer.EXE | C:\Windows\explorer.exe | — | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3008 | "C:\Program Files\7-Zip\7zFM.exe" "C:\Users\admin\AppData\Local\Temp\Trojan.Shylock.Skype.zip" | C:\Program Files\7-Zip\7zFM.exe | — | explorer.exe | |||||||||||
User: admin Company: Igor Pavlov Integrity Level: MEDIUM Description: 7-Zip File Manager Exit code: 0 Version: 18.01 Modules
| |||||||||||||||
| (PID) Process: | (1436) explorer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count |
| Operation: | write | Name: | {7P5N40RS-N0SO-4OSP-874N-P0S2R0O9SN8R}\7-Mvc\7mSZ.rkr |
Value: 00000000010000000000000002050000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF9098F22EEB1CD40100000000 | |||
| (PID) Process: | (1436) explorer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count |
| Operation: | write | Name: | HRZR_PGYFRFFVBA |
Value: 000000002A0000005500000036BF0A00050000002A0000001BD103007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E0065007800650000000000000040E8EA01FFFFFFFF18E32E00FFFFFFFF90499F750000000000000000DCE7EA01D5749B75000400000000000040E8EA01FFFFFFFF18E32E00FFFFFFFFB8972E00D0982E0010E32E000CE8EA012FB1E77580B01A764CF5EA01381EE8751463E875A0162D0040E8EA010000000070000000EFDA326E20E8EA01BE6AE875A0162D0040E8EA01000000004CEAEA016F62E875A0162D0040E8EA0100000400000000807C62E875A0162D0063003A005C00750073006500720073005C00610064006D00040000007EE9EA01F0E8EA017DA772777EE9EA01F270727799A77277D88D90767EE9EA0111000000A0452D0098452D0018E9EA017DA77277A6E9EA0104E900007FDA326EB4E8EA018291E87504E9EA01E4E7000053DA326EC8E8EA01B69CE875E8E7F2024C060000E0E8EA0158E3F202ECE8EA0111000000A0452D0098452D00E0E8EA018CE9EA0188E9EA0178E3F20258E9000013DA326E08E9EA018291E87558E9EA010CE9EA012795E87500000000E4E7F20234E9EA01CD94E875E4E7F202E0E9EA0158E3F202E194E8750000000058E3F202E0E9EA013CE9EA01050000002A0000001BD103007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E0065007800650000000000000040E8EA01FFFFFFFF18E32E00FFFFFFFF90499F750000000000000000DCE7EA01D5749B75000400000000000040E8EA01FFFFFFFF18E32E00FFFFFFFFB8972E00D0982E0010E32E000CE8EA012FB1E77580B01A764CF5EA01381EE8751463E875A0162D0040E8EA010000000070000000EFDA326E20E8EA01BE6AE875A0162D0040E8EA01000000004CEAEA016F62E875A0162D0040E8EA0100000400000000807C62E875A0162D0063003A005C00750073006500720073005C00610064006D00040000007EE9EA01F0E8EA017DA772777EE9EA01F270727799A77277D88D90767EE9EA0111000000A0452D0098452D0018E9EA017DA77277A6E9EA0104E900007FDA326EB4E8EA018291E87504E9EA01E4E7000053DA326EC8E8EA01B69CE875E8E7F2024C060000E0E8EA0158E3F202ECE8EA0111000000A0452D0098452D00E0E8EA018CE9EA0188E9EA0178E3F20258E9000013DA326E08E9EA018291E87558E9EA010CE9EA012795E87500000000E4E7F20234E9EA01CD94E875E4E7F202E0E9EA0158E3F202E194E8750000000058E3F202E0E9EA013CE9EA01050000002A0000001BD103007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E0065007800650000000000000040E8EA01FFFFFFFF18E32E00FFFFFFFF90499F750000000000000000DCE7EA01D5749B75000400000000000040E8EA01FFFFFFFF18E32E00FFFFFFFFB8972E00D0982E0010E32E000CE8EA012FB1E77580B01A764CF5EA01381EE8751463E875A0162D0040E8EA010000000070000000EFDA326E20E8EA01BE6AE875A0162D0040E8EA01000000004CEAEA016F62E875A0162D0040E8EA0100000400000000807C62E875A0162D0063003A005C00750073006500720073005C00610064006D00040000007EE9EA01F0E8EA017DA772777EE9EA01F270727799A77277D88D90767EE9EA0111000000A0452D0098452D0018E9EA017DA77277A6E9EA0104E900007FDA326EB4E8EA018291E87504E9EA01E4E7000053DA326EC8E8EA01B69CE875E8E7F2024C060000E0E8EA0158E3F202ECE8EA0111000000A0452D0098452D00E0E8EA018CE9EA0188E9EA0178E3F20258E9000013DA326E08E9EA018291E87558E9EA010CE9EA012795E87500000000E4E7F20234E9EA01CD94E875E4E7F202E0E9EA0158E3F202E194E8750000000058E3F202E0E9EA013CE9EA01 | |||
| (PID) Process: | (1436) explorer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts |
| Operation: | delete key | Name: | |
Value: | |||
| (PID) Process: | (1436) explorer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts |
| Operation: | write | Name: | C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Opera12.15 1748.lnk |
Value: 1 | |||
| (PID) Process: | (1436) explorer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts |
| Operation: | write | Name: | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam\Steam.lnk |
Value: 1 | |||
| (PID) Process: | (1436) explorer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts |
| Operation: | write | Name: | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam\Steam.lnk |
Value: 1 | |||
| (PID) Process: | (1436) explorer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts |
| Operation: | write | Name: | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk |
Value: 1 | |||
| (PID) Process: | (1436) explorer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts |
| Operation: | write | Name: | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk |
Value: 1 | |||
| (PID) Process: | (1436) explorer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts |
| Operation: | write | Name: | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Skype\Skype.lnk |
Value: 1 | |||
| (PID) Process: | (1436) explorer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts |
| Operation: | write | Name: | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype\Skype.lnk |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3008 | 7zFM.exe | C:\Users\admin\AppData\Local\Temp\7zE0CB8EFB3\Shylock-skype_8FBEB78B06985C3188562E2F1B82D57D | — | |
MD5:— | SHA256:— | |||
| 3008 | 7zFM.exe | C:\Users\admin\AppData\Local\Temp\7zE0CB8A593\Shylock-skype_8FBEB78B06985C3188562E2F1B82D57D | — | |
MD5:— | SHA256:— | |||
| 876 | svchost.exe | C:\Windows\appcompat\programs\RecentFileCache.bcf | txt | |
MD5:— | SHA256:— | |||
| 1436 | explorer.exe | C:\Users\admin\Desktop\Shylock-skype_8FBEB78B06985C3188562E2F1B82.exeD57D | executable | |
MD5:8FBEB78B06985C3188562E2F1B82D57D | SHA256:4BD97130A89C2F9080259D8E87D8D713A23FD0E4336EABB0BF47A44D700EC842 | |||
| 1436 | explorer.exe | C:\Users\admin\Desktop\Shylock-skype_8FBEB78B06985C3188562E2F1B82.exeD57D.exe | executable | |
MD5:8FBEB78B06985C3188562E2F1B82D57D | SHA256:4BD97130A89C2F9080259D8E87D8D713A23FD0E4336EABB0BF47A44D700EC842 | |||
| 1436 | explorer.exe | C:\Users\admin\Desktop\Shylock-skype_8FBEB78B06985C3188562E2F1B82D57D | executable | |
MD5:8FBEB78B06985C3188562E2F1B82D57D | SHA256:4BD97130A89C2F9080259D8E87D8D713A23FD0E4336EABB0BF47A44D700EC842 | |||