File name: | Monoxidex.zip |
Full analysis: | https://app.any.run/tasks/f6aa11b5-1ed1-44c6-900e-25357287dfd2 |
Verdict: | Malicious activity |
Analysis date: | July 06, 2021, 16:39:34 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/zip |
File info: | Zip archive data, at least v5.1 to extract |
MD5: | 006C81307C3221B3AADCA6AD035464AF |
SHA1: | 0876DE0C283C97341496CF0ADBF4A9D44C9BC160 |
SHA256: | F4C82D3AB92D57710F82E2DEAB430D40C1069F1272BBDECAC50873AF2FCF542A |
SSDEEP: | 6144:9F2chn30mcw7PwHoq4di/rINQDOBHL4ENt:Kc+DGIKQDOBUqt |
.zip | | | ZIP compressed archive (100) |
---|
ZipRequiredVersion: | 51 |
---|---|
ZipBitFlag: | 0x0001 |
ZipCompression: | Unknown (99) |
ZipModifyDate: | 2021:06:21 19:38:22 |
ZipCRC: | 0x00000000 |
ZipCompressedSize: | 109900 |
ZipUncompressedSize: | 337920 |
ZipFileName: | Monoxidex64.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
3800 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Monoxidex.zip" | C:\Program Files\WinRAR\WinRAR.exe | Explorer.EXE | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
3312 | "C:\Users\admin\Desktop\Monoxidex86.exe" | C:\Users\admin\Desktop\Monoxidex86.exe | — | Explorer.EXE | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
3832 | "C:\Users\admin\Desktop\Monoxidex86.exe" | C:\Users\admin\Desktop\Monoxidex86.exe | Explorer.EXE | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
1576 | "C:\Users\admin\AppData\Local\Temp\????????????????.exe" | C:\Users\admin\AppData\Local\Temp\????????????????.exe | — | Monoxidex86.exe | |||||||||||
User: admin Integrity Level: HIGH Modules
| |||||||||||||||
3168 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\MSOCache\All Users\{90140000-0016-0419-0000-0000000FF1CE}-C\ExcelLR.cab" | C:\Program Files\WinRAR\WinRAR.exe | — | ????????????????.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: HIGH Description: WinRAR archiver Version: 5.91.0 Modules
| |||||||||||||||
3616 | "C:\Windows\System32\msiexec.exe" /i "C:\MSOCache\All Users\{90140000-0017-0412-0000-0000000FF1CE}-C\SharePointDesignerMUI.msi" | C:\Windows\System32\msiexec.exe | — | ????????????????.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows� installer Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
4092 | "C:\Windows\System32\msiexec.exe" /i "C:\MSOCache\All Users\{90140000-0018-0407-0000-0000000FF1CE}-C\PowerPointMUI.msi" | C:\Windows\System32\msiexec.exe | — | ????????????????.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows� installer Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
1536 | "C:\Windows\System32\msiexec.exe" /i "C:\MSOCache\All Users\{90140000-0018-0411-0000-0000000FF1CE}-C\PowerPointMUI.msi" | C:\Windows\System32\msiexec.exe | — | ????????????????.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows� installer Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
2456 | "C:\Windows\System32\msiexec.exe" /i "C:\MSOCache\All Users\{90140000-0019-0C0A-0000-0000000FF1CE}-C\PublisherMUI.msi" | C:\Windows\System32\msiexec.exe | — | ????????????????.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows� installer Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
3808 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\MSOCache\All Users\{90140000-001A-0407-0000-0000000FF1CE}-C\OutlkLR.cab" | C:\Program Files\WinRAR\WinRAR.exe | — | ????????????????.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: HIGH Description: WinRAR archiver Version: 5.91.0 Modules
|
(PID) Process: | (3800) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtBMP |
Value: | |||
(PID) Process: | (3800) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtIcon |
Value: | |||
(PID) Process: | (3800) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\16D\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (3800) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
(PID) Process: | (3800) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Monoxidex.zip | |||
(PID) Process: | (3800) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | name |
Value: 120 | |||
(PID) Process: | (3800) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | size |
Value: 80 | |||
(PID) Process: | (3800) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | type |
Value: 120 | |||
(PID) Process: | (3800) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | mtime |
Value: 100 | |||
(PID) Process: | (3800) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath |
Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop |
PID | Process | Filename | Type | |
---|---|---|---|---|
3548 | opera.exe | C:\Users\admin\AppData\Roaming\Opera\Opera\operaprefs.ini | text | |
MD5:ED253764C673B079E87F0D1412B2EA1A | SHA256:8FC4C049E0C3CA644DC04FF86E6E1FB53911ADCE9D8996A8EC64845E739EB709 | |||
3548 | opera.exe | C:\Users\admin\AppData\Roaming\Opera\Opera\opssl6.dat | binary | |
MD5:828F49A04F36A937AE3AD5019E56EA2B | SHA256:ACEA58817D6F7D413AF156575783EEB28692A2AFC05EEC19AB234C1F8BA9CA9C | |||
3548 | opera.exe | C:\Users\admin\AppData\Roaming\Opera\Opera\tasks.xml | xml | |
MD5:BC6E07F5D1D09D838A38533F6A684E48 | SHA256:61684D74A897506A1EC691CD2E79474EEE4671CD6D982955EF0B01CA86A67030 | |||
3548 | opera.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\J64C209WSTE26R0UJYCN.temp | binary | |
MD5:D8096D817B85E069223A4878A44170F9 | SHA256:E156E891F7E8912D483F3BDB261E1C7C97B3824251991911A1DF7FB71F9F887A | |||
3548 | opera.exe | C:\Users\admin\AppData\Roaming\Opera\Opera\opr64A3.tmp | text | |
MD5:ED253764C673B079E87F0D1412B2EA1A | SHA256:8FC4C049E0C3CA644DC04FF86E6E1FB53911ADCE9D8996A8EC64845E739EB709 | |||
3548 | opera.exe | C:\Users\admin\AppData\Roaming\Opera\Opera\opr6B2B.tmp | xml | |
MD5:BC6E07F5D1D09D838A38533F6A684E48 | SHA256:61684D74A897506A1EC691CD2E79474EEE4671CD6D982955EF0B01CA86A67030 | |||
3548 | opera.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\16ec093b8f51508f.customDestinations-ms | binary | |
MD5:D8096D817B85E069223A4878A44170F9 | SHA256:E156E891F7E8912D483F3BDB261E1C7C97B3824251991911A1DF7FB71F9F887A | |||
3616 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\MSI147c4.LOG | text | |
MD5:F3B25701FE362EC84616A93A45CE9998 | SHA256:B3D510EF04275CA8E698E5B3CBB0ECE3949EF9252F0CDC839E9EE347409A2209 | |||
3548 | opera.exe | C:\Users\admin\AppData\Roaming\Opera\Opera\opicacrt6.dat | binary | |
MD5:82F1A2B1176A5ECC457D32301E2AD833 | SHA256:A783052804DD4C232BE2ED3DC00C430CB67A20370890E235562ED2B27B5A602E | |||
3548 | opera.exe | C:\Users\admin\AppData\Roaming\Opera\Opera\opuntrust.dat | binary | |
MD5:1AA8644C9261DC10F7247F6A145C1DD2 | SHA256:58A8933F65361633C6AB194000D312DC9D566F717B1A16814A0DBEE24A60EBE3 |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA8Ull8gIGmZT9XHrHiJQeI%3D | US | der | 1.47 Kb | whitelisted |
— | — | GET | 200 | 93.184.220.29:80 | http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl | US | der | 592 b | whitelisted |
— | — | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | US | der | 471 b | whitelisted |
— | — | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAxq6XzO1ZmDhpCgCp6lMhQ%3D | US | der | 471 b | whitelisted |
— | — | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA%2BnRyLFPYjID1ie%2Bx%2BdSjo%3D | US | der | 1.47 Kb | whitelisted |
— | — | GET | 200 | 8.253.207.120:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?072f70ecf3039a9d | US | compressed | 4.70 Kb | whitelisted |
— | — | GET | 200 | 8.253.207.120:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?e2802ac4512bcdb0 | US | compressed | 4.70 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
— | — | 185.26.182.93:443 | certs.opera.com | Opera Software AS | — | whitelisted |
— | — | 93.184.220.29:80 | crl3.digicert.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
— | — | 13.107.21.200:443 | www.bing.com | Microsoft Corporation | US | whitelisted |
— | — | 8.253.207.120:80 | ctldl.windowsupdate.com | Level 3 Communications, Inc. | US | malicious |
— | — | 152.199.19.161:443 | r20swj13mr.microsoft.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
— | — | 204.79.197.200:443 | www.bing.com | Microsoft Corporation | US | whitelisted |
— | — | 204.79.197.203:443 | www.msn.com | Microsoft Corporation | US | whitelisted |
— | — | 2.18.105.186:443 | go.microsoft.com | Deutsche Telekom AG | — | suspicious |
— | — | 13.92.246.37:443 | query.prod.cms.msn.com | Microsoft Corporation | US | whitelisted |
Domain | IP | Reputation |
---|---|---|
certs.opera.com |
| whitelisted |
crl3.digicert.com |
| whitelisted |
api.bing.com |
| whitelisted |
www.bing.com |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
r20swj13mr.microsoft.com |
| whitelisted |
iecvlist.microsoft.com |
| whitelisted |
ieonline.microsoft.com |
| whitelisted |
go.microsoft.com |
| whitelisted |