| File name: | PDF-39845782903853904 NOMINA DEL MES DE ENERO CANCELADA A PROVEEDORES.tar |
| Full analysis: | https://app.any.run/tasks/71436165-b0b1-4053-8178-9566df2b01bb |
| Verdict: | Malicious activity |
| Threats: | A keylogger is a type of spyware that infects a system and has the ability to record every keystroke made on the device. This lets attackers collect personal information of victims, which may include their online banking credentials, as well as personal conversations. The most widespread vector of attack leading to a keylogger infection begins with a phishing email or link. Keylogging is also often present in remote access trojans as part of an extended set of malicious tools. |
| Analysis date: | January 16, 2024, 21:39:37 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v4, os: Win32 |
| MD5: | C70E3F13C2B440E2613AE018158E49DD |
| SHA1: | 782D7261418C7CF19A72A1D16BD69CFD3C00EFC4 |
| SHA256: | F1BCA9B3D5A00905B740AB41DF9CF318E32ACA99F254273B84018DE2103DAE8B |
| SSDEEP: | 49152:wnX+Ee4L2U/B0edrS2Ttir4DuYc1sd2Bd4Q5CWRnms+oYAKL9Le+rukU01BIIqmF:kfVnZ0eYcK1swBiQr0sz0gCU0kuYKNgS |
| .rar | | | RAR compressed archive (v-4.x) (58.3) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (41.6) |
| CompressedSize: | 1450107 |
|---|---|
| UncompressedSize: | 1153433600 |
| OperatingSystem: | Win32 |
| ModifyDate: | 2024:01:15 13:34:38 |
| PackingMethod: | Normal |
| ArchivedFileName: | PDF-39845782903853904 NOMINA DEL MES DE ENERO CANCELADA A PROVEEDORES.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1392 | "cmd" /c copy "C:\Users\admin\AppData\Local\Temp\Rar$EXb2036.17781\PDF-39845782903853904 NOMINA DEL MES DE ENERO CANCELADA A PROVEEDORES.exe" "C:\Users\admin\AppData\Roaming\AppData\AppData.exe" | C:\Windows\System32\cmd.exe | — | PDF-39845782903853904 NOMINA DEL MES DE ENERO CANCELADA A PROVEEDORES.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1652 | schtasks /create /sc minute /mo 10 /tn "Nano" /tr "'C:\Users\admin\AppData\Roaming\AppData\AppData.exe'" /f | C:\Windows\System32\schtasks.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2020 | "cmd" /c schtasks /create /sc minute /mo 10 /tn "Nano" /tr "'C:\Users\admin\AppData\Roaming\AppData\AppData.exe'" /f | C:\Windows\System32\cmd.exe | — | PDF-39845782903853904 NOMINA DEL MES DE ENERO CANCELADA A PROVEEDORES.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2036 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\PDF-39845782903853904 NOMINA DEL MES DE ENERO CANCELADA A PROVEEDORES.tar.rar" | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 2084 | "C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe" | C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe | PDF-39845782903853904 NOMINA DEL MES DE ENERO CANCELADA A PROVEEDORES.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Visual C# Command Line Compiler Exit code: 0 Version: 4.8.3761.0 built by: NET48REL1 Modules
| |||||||||||||||
| 2088 | "C:\Users\admin\AppData\Local\Temp\Rar$EXb2036.17781\PDF-39845782903853904 NOMINA DEL MES DE ENERO CANCELADA A PROVEEDORES.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXb2036.17781\PDF-39845782903853904 NOMINA DEL MES DE ENERO CANCELADA A PROVEEDORES.exe | — | WinRAR.exe | |||||||||||
User: admin Company: Samsung Electronics Integrity Level: MEDIUM Description: Samsung Magician Exit code: 4294967295 Version: Samsung Magician ver Modules
| |||||||||||||||
| 2416 | "cmd" /c mkdir "C:\Users\admin\AppData\Roaming\AppData" | C:\Windows\System32\cmd.exe | — | PDF-39845782903853904 NOMINA DEL MES DE ENERO CANCELADA A PROVEEDORES.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| (PID) Process: | (2036) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2036) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (2036) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (2036) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (2036) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
| (PID) Process: | (2036) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2036) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2036) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2036) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (2036) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2036 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb2036.17781\PDF-39845782903853904 NOMINA DEL MES DE ENERO CANCELADA A PROVEEDORES.exe | — | |
MD5:— | SHA256:— | |||
| 1392 | cmd.exe | C:\Users\admin\AppData\Roaming\AppData\AppData.exe | — | |
MD5:— | SHA256:— | |||
| 2036 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb2036.23651\PDF-39845782903853904 NOMINA DEL MES DE ENERO CANCELADA A PROVEEDORES.exe | — | |
MD5:— | SHA256:— | |||
| 2084 | csc.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\json[1].json | binary | |
MD5:58119C08763D15F3A22E6994EF65E42A | SHA256:D4B9762F3548F72F3FC2514C751F8A1A2FA52B2C07284212A23716A24DD25C76 | |||
| 2084 | csc.exe | C:\ProgramData\remcos\logs.dat | binary | |
MD5:0211CE494F91214A293D62F3114276BB | SHA256:C179F03EED849481F016150E315677A165B9ED918E0C057AF00A1F20EC4860F2 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2084 | csc.exe | GET | 200 | 178.237.33.50:80 | http://geoplugin.net/json.gp | unknown | binary | 951 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2084 | csc.exe | 191.88.250.205:1995 | gerardocarreralora09.con-ip.com | Colombia Movil | CO | unknown |
2084 | csc.exe | 178.237.33.50:80 | geoplugin.net | Schuberg Philis B.V. | NL | malicious |
Domain | IP | Reputation |
|---|---|---|
gerardocarreralora09.con-ip.com |
| unknown |
geoplugin.net |
| malicious |
PID | Process | Class | Message |
|---|---|---|---|
1080 | svchost.exe | Potentially Bad Traffic | ET INFO DNS Redirection Service Domain in DNS Lookup (con-ip .com) |
1080 | svchost.exe | Potentially Bad Traffic | ET INFO DNS Redirection Service Domain in DNS Lookup (con-ip .com) |
2084 | csc.exe | Malware Command and Control Activity Detected | ET JA3 Hash - Remcos 3.x TLS Connection |
2084 | csc.exe | A Network Trojan was detected | REMOTE [ANY.RUN] REMCOS JA3 Hash |