File name: | builder.zip |
Full analysis: | https://app.any.run/tasks/e169fe54-85a2-4bbe-b107-0e6ee7f7f929 |
Verdict: | Malicious activity |
Analysis date: | April 25, 2019, 12:34:35 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/zip |
File info: | Zip archive data, at least v1.0 to extract |
MD5: | CD2FFAC93E261D275C41AE00BAA6C1FD |
SHA1: | CE222F708FE439261AE7A2DCB33AF8D502815820 |
SHA256: | F6615AFCF67237316C46911D6373CACB190CEE5B5B4BF820CBE01DEAA932F1B4 |
SSDEEP: | 6144:bFgGXm6iCKG/H5nY85KqxSp1RGVKDpTWMdAmYtHVUbZa:esmBAHfCzKSAmuHea |
.zip | | | ZIP compressed archive (100) |
---|
ZipFileName: | builder/ |
---|---|
ZipUncompressedSize: | - |
ZipCompressedSize: | - |
ZipCRC: | 0x00000000 |
ZipModifyDate: | 2018:07:25 17:23:07 |
ZipCompression: | None |
ZipBitFlag: | - |
ZipRequiredVersion: | 10 |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
2668 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\builder.zip" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | |
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 | ||||
2404 | "C:\Users\admin\Desktop\builder\builder.exe" | C:\Users\admin\Desktop\builder\builder.exe | explorer.exe | |
User: admin Integrity Level: MEDIUM Description: bilder Version: 1.0.0.0 | ||||
2600 | "C:\Users\admin\Desktop\builder\builder.exe" | C:\Users\admin\Desktop\builder\builder.exe | explorer.exe | |
User: admin Integrity Level: MEDIUM Description: bilder Version: 1.0.0.0 |
PID | Process | Filename | Type | |
---|---|---|---|---|
2668 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2668.22287\builder\hash.idkey | text | |
MD5:81649F1B3283E2926B29827E6632C001 | SHA256:22373B7A6DEB560A5EC101B36E85E3D141A9E6C4C9C4EB6EB8A6333C0207D662 | |||
2668 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2668.22287\builder\builder.exe | executable | |
MD5:E0DE77AB592ED1858ED4F8D78B55EB16 | SHA256:05139AB2DB77973338F4FDBBB0D48C4E7E989DFE4F6508F6BFB8BBE3E6C92A3E |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
2600 | builder.exe | 18.196.177.5:1558 | — | Amazon.com, Inc. | DE | unknown |
2404 | builder.exe | 18.196.177.5:1558 | — | Amazon.com, Inc. | DE | unknown |
Domain | IP | Reputation |
---|---|---|
dns.msftncsi.com |
| shared |