File name:

Monoxidex.zip

Full analysis: https://app.any.run/tasks/f6aa11b5-1ed1-44c6-900e-25357287dfd2
Verdict: Malicious activity
Analysis date: July 06, 2021, 16:39:34
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v5.1 to extract
MD5:

006C81307C3221B3AADCA6AD035464AF

SHA1:

0876DE0C283C97341496CF0ADBF4A9D44C9BC160

SHA256:

F4C82D3AB92D57710F82E2DEAB430D40C1069F1272BBDECAC50873AF2FCF542A

SSDEEP:

6144:9F2chn30mcw7PwHoq4di/rINQDOBHL4ENt:Kc+DGIKQDOBUqt

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Monoxidex86.exe (PID: 3312)
      • Monoxidex86.exe (PID: 3832)
      • ????????????????.exe (PID: 1576)
    • Drops executable file immediately after starts

      • Monoxidex86.exe (PID: 3832)
  • SUSPICIOUS

    • Reads the computer name

      • WinRAR.exe (PID: 3800)
      • WinRAR.exe (PID: 3168)
      • ????????????????.exe (PID: 1576)
      • WinRAR.exe (PID: 3808)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3800)
      • Monoxidex86.exe (PID: 3832)
    • Drops a file with a compile date too recent

      • WinRAR.exe (PID: 3800)
      • Monoxidex86.exe (PID: 3832)
    • Checks supported languages

      • WinRAR.exe (PID: 3800)
      • WinRAR.exe (PID: 3168)
      • Monoxidex86.exe (PID: 3832)
      • ????????????????.exe (PID: 1576)
      • WinRAR.exe (PID: 3808)
    • Starts itself from another location

      • Monoxidex86.exe (PID: 3832)
    • Starts Microsoft Installer

      • ????????????????.exe (PID: 1576)
  • INFO

    • Manual execution by user

      • Monoxidex86.exe (PID: 3312)
      • Monoxidex86.exe (PID: 3832)
      • opera.exe (PID: 3548)
    • Checks supported languages

      • msiexec.exe (PID: 3616)
      • msiexec.exe (PID: 4092)
      • msiexec.exe (PID: 2456)
      • msiexec.exe (PID: 1536)
      • MSOXMLED.EXE (PID: 1812)
      • msiexec.exe (PID: 2884)
      • msiexec.exe (PID: 3144)
      • msiexec.exe (PID: 4068)
      • MSOXMLED.EXE (PID: 2260)
      • msiexec.exe (PID: 3176)
    • Reads the computer name

      • MSOXMLED.EXE (PID: 1812)
      • MSOXMLED.EXE (PID: 2260)
      • msiexec.exe (PID: 3616)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: Monoxidex64.exe
ZipUncompressedSize: 337920
ZipCompressedSize: 109900
ZipCRC: 0x00000000
ZipModifyDate: 2021:06:21 19:38:22
ZipCompression: Unknown (99)
ZipBitFlag: 0x0001
ZipRequiredVersion: 51
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
60
Monitored processes
23
Malicious processes
1
Suspicious processes
2

Behavior graph

Click at the process to see the details
start drop and start winrar.exe monoxidex86.exe no specs monoxidex86.exe ????????????????.exe no specs winrar.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs winrar.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs msoxmled.exe no specs msoxmled.exe no specs msiexec.exe no specs winrar.exe no specs msoxmled.exe no specs opera.exe no specs msoxmled.exe no specs winrar.exe no specs msoxmled.exe no specs msiexec.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
864"C:\Program Files\WinRAR\WinRAR.exe" "C:\MSOCache\All Users\{90140000-00BA-0411-0000-0000000FF1CE}-C\GrooveLR.cab"C:\Program Files\WinRAR\WinRAR.exe????????????????.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
HIGH
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
1536"C:\Windows\System32\msiexec.exe" /i "C:\MSOCache\All Users\{90140000-0018-0411-0000-0000000FF1CE}-C\PowerPointMUI.msi" C:\Windows\System32\msiexec.exe????????????????.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows� installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1576"C:\Users\admin\AppData\Local\Temp\????????????????.exe"C:\Users\admin\AppData\Local\Temp\????????????????.exeMonoxidex86.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\????????????????.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1812"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLED.EXE" /verb open "C:\MSOCache\All Users\{90140000-002C-041F-0000-0000000FF1CE}-C\Proof.tr\Proof.xml"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLED.EXE????????????????.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
XML Editor
Exit code:
0
Version:
14.0.4750.1000
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\program files\common files\microsoft shared\office14\msoxmled.exe
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1904"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLED.EXE" /verb open "C:\MSOCache\All Users\{90140000-0101-0410-0000-0000000FF1CE}-C\XMUI.xml"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLED.EXE????????????????.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
XML Editor
Exit code:
0
Version:
14.0.4750.1000
Modules
Images
c:\program files\common files\microsoft shared\office14\msoxmled.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2020"C:\Program Files\WinRAR\WinRAR.exe" "C:\MSOCache\All Users\{90140000-0100-0410-0000-0000000FF1CE}-C\OMUI.cab"C:\Program Files\WinRAR\WinRAR.exe????????????????.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
HIGH
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
2260"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLED.EXE" /verb open "C:\MSOCache\All Users\{90140000-002C-0C0A-0000-0000000FF1CE}-C\Proof.fr\Proof.xml"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLED.EXE????????????????.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
XML Editor
Exit code:
0
Version:
14.0.4750.1000
Modules
Images
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\program files\common files\microsoft shared\office14\msoxmled.exe
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
2456"C:\Windows\System32\msiexec.exe" /i "C:\MSOCache\All Users\{90140000-0019-0C0A-0000-0000000FF1CE}-C\PublisherMUI.msi" C:\Windows\System32\msiexec.exe????????????????.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows� installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2480"C:\Windows\System32\msiexec.exe" /i "C:\MSOCache\All Users\{90140000-0101-0C0A-0000-0000000FF1CE}-C\XMUI.msi" C:\Windows\System32\msiexec.exe????????????????.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows� installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\msiexec.exe
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2884"C:\Windows\System32\msiexec.exe" /i "C:\MSOCache\All Users\{90140000-001B-0410-0000-0000000FF1CE}-C\WordMUI.msi" C:\Windows\System32\msiexec.exe????????????????.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows� installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\msiexec.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
3 275
Read events
3 226
Write events
49
Delete events
0

Modification events

(PID) Process:(3800) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3800) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3800) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16D\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3800) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(3800) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Monoxidex.zip
(PID) Process:(3800) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3800) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3800) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3800) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3800) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath
Operation:writeName:0
Value:
C:\Users\admin\Desktop
Executable files
3
Suspicious files
9
Text files
5
Unknown types
0

Dropped files

PID
Process
Filename
Type
3548opera.exeC:\Users\admin\AppData\Roaming\Opera\Opera\opr64A3.tmptext
MD5:
SHA256:
3616msiexec.exeC:\Users\admin\AppData\Local\Temp\MSI147c4.LOGtext
MD5:F3B25701FE362EC84616A93A45CE9998
SHA256:B3D510EF04275CA8E698E5B3CBB0ECE3949EF9252F0CDC839E9EE347409A2209
3832Monoxidex86.exeC:\Users\admin\AppData\Local\Temp\????????????????.exeexecutable
MD5:5C378B11848AC59704C2000B4E711C30
SHA256:BD764FE2F9734D5AC56933CE68DF0A175BFA98DC0266AE3CD3A5C963267EA77E
3548opera.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\16ec093b8f51508f.customDestinations-msbinary
MD5:
SHA256:
3548opera.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\J64C209WSTE26R0UJYCN.tempbinary
MD5:
SHA256:
3548opera.exeC:\Users\admin\AppData\Roaming\Opera\Opera\opr6B2B.tmpxml
MD5:
SHA256:
3548opera.exeC:\Users\admin\AppData\Roaming\Opera\Opera\tasks.xmlxml
MD5:
SHA256:
3548opera.exeC:\Users\admin\AppData\Roaming\Opera\Opera\operaprefs.initext
MD5:
SHA256:
3800WinRAR.exeC:\Users\admin\Desktop\Monoxidex64.exeexecutable
MD5:692361071BBBB3E9243D09DC190FEDEA
SHA256:AE9405B9556C24389EE359993F45926A895481C8D60D98B91A3065F5C026CFFE
3800WinRAR.exeC:\Users\admin\Desktop\Monoxidex86.exeexecutable
MD5:5C378B11848AC59704C2000B4E711C30
SHA256:BD764FE2F9734D5AC56933CE68DF0A175BFA98DC0266AE3CD3A5C963267EA77E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
76
DNS requests
16
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
der
471 b
whitelisted
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAxq6XzO1ZmDhpCgCp6lMhQ%3D
US
der
471 b
whitelisted
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA%2BnRyLFPYjID1ie%2Bx%2BdSjo%3D
US
der
1.47 Kb
whitelisted
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA8Ull8gIGmZT9XHrHiJQeI%3D
US
der
1.47 Kb
whitelisted
GET
200
93.184.220.29:80
http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl
US
der
592 b
whitelisted
GET
200
8.253.207.120:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?072f70ecf3039a9d
US
compressed
4.70 Kb
whitelisted
GET
200
8.253.207.120:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?e2802ac4512bcdb0
US
compressed
4.70 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
185.26.182.93:443
certs.opera.com
Opera Software AS
whitelisted
93.184.220.29:80
crl3.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
13.107.21.200:443
www.bing.com
Microsoft Corporation
US
whitelisted
152.199.19.161:443
r20swj13mr.microsoft.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
204.79.197.200:443
www.bing.com
Microsoft Corporation
US
whitelisted
204.79.197.203:443
www.msn.com
Microsoft Corporation
US
malicious
2.18.105.186:443
go.microsoft.com
Deutsche Telekom AG
suspicious
13.92.246.37:443
query.prod.cms.msn.com
Microsoft Corporation
US
whitelisted
8.253.207.120:80
ctldl.windowsupdate.com
Level 3 Communications, Inc.
US
malicious

DNS requests

Domain
IP
Reputation
certs.opera.com
  • 185.26.182.93
  • 185.26.182.94
whitelisted
crl3.digicert.com
  • 93.184.220.29
whitelisted
api.bing.com
  • 13.107.13.80
whitelisted
www.bing.com
  • 13.107.21.200
  • 204.79.197.200
whitelisted
ctldl.windowsupdate.com
  • 8.253.207.120
  • 8.248.141.254
  • 67.26.83.254
  • 67.26.75.254
  • 8.248.115.254
whitelisted
ocsp.digicert.com
  • 93.184.220.29
whitelisted
r20swj13mr.microsoft.com
  • 152.199.19.161
whitelisted
iecvlist.microsoft.com
  • 152.199.19.161
whitelisted
ieonline.microsoft.com
  • 204.79.197.200
whitelisted
go.microsoft.com
  • 2.18.105.186
whitelisted

Threats

No threats detected
No debug info