File name:

Monoxidex.zip

Full analysis: https://app.any.run/tasks/f6aa11b5-1ed1-44c6-900e-25357287dfd2
Verdict: Malicious activity
Analysis date: July 06, 2021, 16:39:34
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v5.1 to extract
MD5:

006C81307C3221B3AADCA6AD035464AF

SHA1:

0876DE0C283C97341496CF0ADBF4A9D44C9BC160

SHA256:

F4C82D3AB92D57710F82E2DEAB430D40C1069F1272BBDECAC50873AF2FCF542A

SSDEEP:

6144:9F2chn30mcw7PwHoq4di/rINQDOBHL4ENt:Kc+DGIKQDOBUqt

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Monoxidex86.exe (PID: 3312)
      • ????????????????.exe (PID: 1576)
      • Monoxidex86.exe (PID: 3832)
    • Drops executable file immediately after starts

      • Monoxidex86.exe (PID: 3832)
  • SUSPICIOUS

    • Checks supported languages

      • WinRAR.exe (PID: 3800)
      • ????????????????.exe (PID: 1576)
      • Monoxidex86.exe (PID: 3832)
      • WinRAR.exe (PID: 3808)
      • WinRAR.exe (PID: 3168)
    • Reads the computer name

      • WinRAR.exe (PID: 3800)
      • ????????????????.exe (PID: 1576)
      • WinRAR.exe (PID: 3168)
      • WinRAR.exe (PID: 3808)
    • Drops a file with a compile date too recent

      • WinRAR.exe (PID: 3800)
      • Monoxidex86.exe (PID: 3832)
    • Executable content was dropped or overwritten

      • Monoxidex86.exe (PID: 3832)
      • WinRAR.exe (PID: 3800)
    • Starts itself from another location

      • Monoxidex86.exe (PID: 3832)
    • Starts Microsoft Installer

      • ????????????????.exe (PID: 1576)
  • INFO

    • Manual execution by user

      • Monoxidex86.exe (PID: 3832)
      • Monoxidex86.exe (PID: 3312)
      • opera.exe (PID: 3548)
    • Checks supported languages

      • msiexec.exe (PID: 4092)
      • msiexec.exe (PID: 1536)
      • msiexec.exe (PID: 2884)
      • MSOXMLED.EXE (PID: 1812)
      • msiexec.exe (PID: 3144)
      • msiexec.exe (PID: 3176)
      • MSOXMLED.EXE (PID: 2260)
      • msiexec.exe (PID: 2456)
      • msiexec.exe (PID: 3616)
      • msiexec.exe (PID: 4068)
    • Reads the computer name

      • MSOXMLED.EXE (PID: 1812)
      • MSOXMLED.EXE (PID: 2260)
      • msiexec.exe (PID: 3616)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 51
ZipBitFlag: 0x0001
ZipCompression: Unknown (99)
ZipModifyDate: 2021:06:21 19:38:22
ZipCRC: 0x00000000
ZipCompressedSize: 109900
ZipUncompressedSize: 337920
ZipFileName: Monoxidex64.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
60
Monitored processes
23
Malicious processes
1
Suspicious processes
2

Behavior graph

Click at the process to see the details
start drop and start winrar.exe monoxidex86.exe no specs monoxidex86.exe ????????????????.exe no specs winrar.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs winrar.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs msoxmled.exe no specs msoxmled.exe no specs msiexec.exe no specs winrar.exe no specs msoxmled.exe no specs opera.exe no specs msoxmled.exe no specs winrar.exe no specs msoxmled.exe no specs msiexec.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3800"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Monoxidex.zip"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
3312"C:\Users\admin\Desktop\Monoxidex86.exe" C:\Users\admin\Desktop\Monoxidex86.exeExplorer.EXE
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\monoxidex86.exe
c:\windows\system32\ntdll.dll
3832"C:\Users\admin\Desktop\Monoxidex86.exe" C:\Users\admin\Desktop\Monoxidex86.exe
Explorer.EXE
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\monoxidex86.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1576"C:\Users\admin\AppData\Local\Temp\????????????????.exe"C:\Users\admin\AppData\Local\Temp\????????????????.exeMonoxidex86.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\users\admin\appdata\local\temp\????????????????.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3168"C:\Program Files\WinRAR\WinRAR.exe" "C:\MSOCache\All Users\{90140000-0016-0419-0000-0000000FF1CE}-C\ExcelLR.cab"C:\Program Files\WinRAR\WinRAR.exe????????????????.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
HIGH
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3616"C:\Windows\System32\msiexec.exe" /i "C:\MSOCache\All Users\{90140000-0017-0412-0000-0000000FF1CE}-C\SharePointDesignerMUI.msi" C:\Windows\System32\msiexec.exe????????????????.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows� installer
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
4092"C:\Windows\System32\msiexec.exe" /i "C:\MSOCache\All Users\{90140000-0018-0407-0000-0000000FF1CE}-C\PowerPointMUI.msi" C:\Windows\System32\msiexec.exe????????????????.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows� installer
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1536"C:\Windows\System32\msiexec.exe" /i "C:\MSOCache\All Users\{90140000-0018-0411-0000-0000000FF1CE}-C\PowerPointMUI.msi" C:\Windows\System32\msiexec.exe????????????????.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows� installer
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2456"C:\Windows\System32\msiexec.exe" /i "C:\MSOCache\All Users\{90140000-0019-0C0A-0000-0000000FF1CE}-C\PublisherMUI.msi" C:\Windows\System32\msiexec.exe????????????????.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows� installer
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3808"C:\Program Files\WinRAR\WinRAR.exe" "C:\MSOCache\All Users\{90140000-001A-0407-0000-0000000FF1CE}-C\OutlkLR.cab"C:\Program Files\WinRAR\WinRAR.exe????????????????.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
HIGH
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
3 275
Read events
3 226
Write events
49
Delete events
0

Modification events

(PID) Process:(3800) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3800) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3800) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16D\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3800) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(3800) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Monoxidex.zip
(PID) Process:(3800) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3800) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3800) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3800) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3800) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath
Operation:writeName:0
Value:
C:\Users\admin\Desktop
Executable files
3
Suspicious files
9
Text files
5
Unknown types
0

Dropped files

PID
Process
Filename
Type
3548opera.exeC:\Users\admin\AppData\Roaming\Opera\Opera\operaprefs.initext
MD5:ED253764C673B079E87F0D1412B2EA1A
SHA256:8FC4C049E0C3CA644DC04FF86E6E1FB53911ADCE9D8996A8EC64845E739EB709
3548opera.exeC:\Users\admin\AppData\Roaming\Opera\Opera\opssl6.datbinary
MD5:828F49A04F36A937AE3AD5019E56EA2B
SHA256:ACEA58817D6F7D413AF156575783EEB28692A2AFC05EEC19AB234C1F8BA9CA9C
3548opera.exeC:\Users\admin\AppData\Roaming\Opera\Opera\tasks.xmlxml
MD5:BC6E07F5D1D09D838A38533F6A684E48
SHA256:61684D74A897506A1EC691CD2E79474EEE4671CD6D982955EF0B01CA86A67030
3548opera.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\J64C209WSTE26R0UJYCN.tempbinary
MD5:D8096D817B85E069223A4878A44170F9
SHA256:E156E891F7E8912D483F3BDB261E1C7C97B3824251991911A1DF7FB71F9F887A
3548opera.exeC:\Users\admin\AppData\Roaming\Opera\Opera\opr64A3.tmptext
MD5:ED253764C673B079E87F0D1412B2EA1A
SHA256:8FC4C049E0C3CA644DC04FF86E6E1FB53911ADCE9D8996A8EC64845E739EB709
3548opera.exeC:\Users\admin\AppData\Roaming\Opera\Opera\opr6B2B.tmpxml
MD5:BC6E07F5D1D09D838A38533F6A684E48
SHA256:61684D74A897506A1EC691CD2E79474EEE4671CD6D982955EF0B01CA86A67030
3548opera.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\16ec093b8f51508f.customDestinations-msbinary
MD5:D8096D817B85E069223A4878A44170F9
SHA256:E156E891F7E8912D483F3BDB261E1C7C97B3824251991911A1DF7FB71F9F887A
3616msiexec.exeC:\Users\admin\AppData\Local\Temp\MSI147c4.LOGtext
MD5:F3B25701FE362EC84616A93A45CE9998
SHA256:B3D510EF04275CA8E698E5B3CBB0ECE3949EF9252F0CDC839E9EE347409A2209
3548opera.exeC:\Users\admin\AppData\Roaming\Opera\Opera\opicacrt6.datbinary
MD5:82F1A2B1176A5ECC457D32301E2AD833
SHA256:A783052804DD4C232BE2ED3DC00C430CB67A20370890E235562ED2B27B5A602E
3548opera.exeC:\Users\admin\AppData\Roaming\Opera\Opera\opuntrust.datbinary
MD5:1AA8644C9261DC10F7247F6A145C1DD2
SHA256:58A8933F65361633C6AB194000D312DC9D566F717B1A16814A0DBEE24A60EBE3
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
76
DNS requests
16
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA8Ull8gIGmZT9XHrHiJQeI%3D
US
der
1.47 Kb
whitelisted
GET
200
93.184.220.29:80
http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl
US
der
592 b
whitelisted
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
der
471 b
whitelisted
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAxq6XzO1ZmDhpCgCp6lMhQ%3D
US
der
471 b
whitelisted
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA%2BnRyLFPYjID1ie%2Bx%2BdSjo%3D
US
der
1.47 Kb
whitelisted
GET
200
8.253.207.120:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?072f70ecf3039a9d
US
compressed
4.70 Kb
whitelisted
GET
200
8.253.207.120:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?e2802ac4512bcdb0
US
compressed
4.70 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
185.26.182.93:443
certs.opera.com
Opera Software AS
whitelisted
93.184.220.29:80
crl3.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
13.107.21.200:443
www.bing.com
Microsoft Corporation
US
whitelisted
8.253.207.120:80
ctldl.windowsupdate.com
Level 3 Communications, Inc.
US
malicious
152.199.19.161:443
r20swj13mr.microsoft.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
204.79.197.200:443
www.bing.com
Microsoft Corporation
US
whitelisted
204.79.197.203:443
www.msn.com
Microsoft Corporation
US
whitelisted
2.18.105.186:443
go.microsoft.com
Deutsche Telekom AG
suspicious
13.92.246.37:443
query.prod.cms.msn.com
Microsoft Corporation
US
whitelisted

DNS requests

Domain
IP
Reputation
certs.opera.com
  • 185.26.182.93
  • 185.26.182.94
whitelisted
crl3.digicert.com
  • 93.184.220.29
whitelisted
api.bing.com
  • 13.107.13.80
whitelisted
www.bing.com
  • 13.107.21.200
  • 204.79.197.200
whitelisted
ctldl.windowsupdate.com
  • 8.253.207.120
  • 8.248.141.254
  • 67.26.83.254
  • 67.26.75.254
  • 8.248.115.254
whitelisted
ocsp.digicert.com
  • 93.184.220.29
whitelisted
r20swj13mr.microsoft.com
  • 152.199.19.161
whitelisted
iecvlist.microsoft.com
  • 152.199.19.161
whitelisted
ieonline.microsoft.com
  • 204.79.197.200
whitelisted
go.microsoft.com
  • 2.18.105.186
whitelisted

Threats

No threats detected
No debug info