File name:

Product list.pdf.gz

Full analysis: https://app.any.run/tasks/7a27b3ff-c567-4046-be81-6c63eb23597a
Verdict: Malicious activity
Analysis date: March 31, 2020, 01:24:10
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

5476D7E612541522C4EBBC17654C169B

SHA1:

7C11B4E31721F2EF61E85C3E8291281DD8A5A7A3

SHA256:

F1CC7BCFCE852A007B51FBDFC19292619461715999C2C619ED91DBAAFA579D7B

SSDEEP:

384:zfczVl3LvPOJsSDgq/w48OJmKzaO3RfhqduY5m8hu02nepIXKtkIs4MUivV:zUV1vPusmnQO4eJh6mnv6tkIs4nivV

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Product list.pdf.exe (PID: 1488)
      • Product list.pdf.exe (PID: 608)
    • Actions looks like stealing of personal data

      • Product list.pdf.exe (PID: 608)
    • Changes settings of System certificates

      • Product list.pdf.exe (PID: 608)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1756)
    • Reads Internet Cache Settings

      • Product list.pdf.exe (PID: 608)
    • Application launched itself

      • Product list.pdf.exe (PID: 1488)
    • Creates files in the user directory

      • Product list.pdf.exe (PID: 608)
    • Adds / modifies Windows certificates

      • Product list.pdf.exe (PID: 608)
  • INFO

    • Manual execution by user

      • Product list.pdf.exe (PID: 1488)
    • Reads settings of System Certificates

      • Product list.pdf.exe (PID: 608)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
39
Monitored processes
3
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe product list.pdf.exe no specs product list.pdf.exe

Process information

PID
CMD
Path
Indicators
Parent process
608"C:\Users\admin\Desktop\Product list.pdf.exe" C:\Users\admin\Desktop\Product list.pdf.exe
Product list.pdf.exe
User:
admin
Company:
WONderware
Integrity Level:
MEDIUM
Description:
Stiklings
Exit code:
0
Version:
1.00
Modules
Images
c:\windows\system32\mfc40.dll
c:\users\admin\desktop\product list.pdf.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt40.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1488"C:\Users\admin\Desktop\Product list.pdf.exe" C:\Users\admin\Desktop\Product list.pdf.exeexplorer.exe
User:
admin
Company:
WONderware
Integrity Level:
MEDIUM
Description:
Stiklings
Exit code:
0
Version:
1.00
Modules
Images
c:\users\admin\desktop\product list.pdf.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
1756"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Product list.pdf.gz"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
4 451
Read events
481
Write events
2 654
Delete events
1 316

Modification events

(PID) Process:(1756) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1756) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1756) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1756) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Product list.pdf.gz
(PID) Process:(1756) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1756) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1756) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1756) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1756) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath
Operation:writeName:0
Value:
C:\Users\admin\Desktop
(PID) Process:(1756) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
Executable files
1
Suspicious files
4
Text files
1
Unknown types
2

Dropped files

PID
Process
Filename
Type
608Product list.pdf.exeC:\Users\admin\AppData\Local\Temp\CabFF1.tmp
MD5:
SHA256:
608Product list.pdf.exeC:\Users\admin\AppData\Local\Temp\TarFF2.tmp
MD5:
SHA256:
608Product list.pdf.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6BADA8974A10C4BD62CC921D13E43B18_D9817BD5013875AD517DA73475345203der
MD5:
SHA256:
1756WinRAR.exeC:\Users\admin\Desktop\Product list.pdf.exeexecutable
MD5:
SHA256:
608Product list.pdf.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6BADA8974A10C4BD62CC921D13E43B18_D9817BD5013875AD517DA73475345203binary
MD5:
SHA256:
608Product list.pdf.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\0OOJWKXC.txttext
MD5:
SHA256:
608Product list.pdf.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6BADA8974A10C4BD62CC921D13E43B18_C9FB72B5AE80778A08024D8B0FDECC6Fbinary
MD5:
SHA256:
608Product list.pdf.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6BADA8974A10C4BD62CC921D13E43B18_C9FB72B5AE80778A08024D8B0FDECC6Fder
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
4
DNS requests
4
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
608
Product list.pdf.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA8sEMlbBsCTf7jUSfg%2BhWk%3D
US
der
1.47 Kb
whitelisted
608
Product list.pdf.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEAtqs7A%2Bsan2xGCSaqjN%2FrM%3D
US
der
1.47 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
608
Product list.pdf.exe
13.107.42.13:443
onedrive.live.com
Microsoft Corporation
US
malicious
608
Product list.pdf.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
608
Product list.pdf.exe
13.107.42.12:443
4apotw.bn.files.1drv.com
Microsoft Corporation
US
suspicious
608
Product list.pdf.exe
212.227.15.142:587
smtp.1and1.es
1&1 Internet SE
DE
suspicious

DNS requests

Domain
IP
Reputation
onedrive.live.com
  • 13.107.42.13
shared
ocsp.digicert.com
  • 93.184.220.29
whitelisted
4apotw.bn.files.1drv.com
  • 13.107.42.12
whitelisted
smtp.1and1.es
  • 212.227.15.142
  • 212.227.15.158
malicious

Threats

PID
Process
Class
Message
608
Product list.pdf.exe
Generic Protocol Command Decode
SURICATA Applayer Detect protocol only one direction
No debug info