| File name: | analyze.zip |
| Full analysis: | https://app.any.run/tasks/61de7681-2dcb-441b-b763-f3f771ea63c5 |
| Verdict: | Malicious activity |
| Analysis date: | October 20, 2020, 02:40:09 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | 653BC28B0A9A3AD56DCCDDAAE143CCE7 |
| SHA1: | DE93859A6A3A6850CAB1EF11E3AA5491F3A18262 |
| SHA256: | F8DBD4F75EB3BF74F091F0AC2F7312FD15A15DF193B749FD8E73D3482AC62CCC |
| SSDEEP: | 98304:9meZpw3w9E/1YYz2HcXKQpovegI7A0EIcoFZunq9:9mew3w9EdYl8aQpNsvoFZuq |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2016:03:24 17:57:07 |
| ZipCRC: | 0x9217c55e |
| ZipCompressedSize: | 722 |
| ZipUncompressedSize: | 1594 |
| ZipFileName: | analyze/ArConfig.dat |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 316 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2792.49640\mbbServiceSetup.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2792.49640\mbbServiceSetup.exe | — | WinRAR.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| 576 | "C:\Program Files\MobileBrServ\mbbService.exe" | C:\Program Files\MobileBrServ\mbbService.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Version: 22.001.29.01.03 Modules
| |||||||||||||||
| 888 | "C:\Program Files\MobileBrServ\mbbService.exe" -install | C:\Program Files\MobileBrServ\mbbService.exe | — | mbbServiceSetup.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Version: 22.001.29.01.03 Modules
| |||||||||||||||
| 888 | "C:\Users\admin\Desktop\analyze\AutoRun.exe" | C:\Users\admin\Desktop\analyze\AutoRun.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: AutoRun Exit code: 0 Version: 22.001.29.01.03 Modules
| |||||||||||||||
| 1748 | "C:\Program Files\DeleteFile.exe" | C:\Program Files\DeleteFile.exe | — | Uninstall.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 1944 | "C:\Users\admin\AppData\Local\Temp\MobileBrServ\CompareVersion.exe " -22.001.29.01.03, | C:\Users\admin\AppData\Local\Temp\MobileBrServ\CompareVersion.exe | — | mbbServiceSetup.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 3 Modules
| |||||||||||||||
| 1968 | "C:\Program Files\MobileBrServ\mbbservice.exe" -service | C:\Program Files\MobileBrServ\mbbservice.exe | — | services.exe | |||||||||||
User: SYSTEM Integrity Level: SYSTEM Exit code: 0 Version: 22.001.29.01.03 Modules
| |||||||||||||||
| 2116 | "C:\Users\admin\AppData\Local\Temp\MobileBrServ\CompareVersion.exe " -22.001.29.01.03,22.001.29.01.03 | C:\Users\admin\AppData\Local\Temp\MobileBrServ\CompareVersion.exe | — | mbbServiceSetup.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2244 | "C:\Program Files\MobileBrServ\Uninstall.exe" | C:\Program Files\MobileBrServ\Uninstall.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| 2264 | "C:\Program Files\MobileBrServ\Uninstall.exe" | C:\Program Files\MobileBrServ\Uninstall.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 2 Modules
| |||||||||||||||
| (PID) Process: | (2740) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (2740) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (2740) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2740) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\analyze.zip | |||
| (PID) Process: | (2740) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2740) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2740) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2740) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (2792) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (2792) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2740 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2740.46858\analyze\HiLink.app\Contents\_CodeSignature\CodeResources | xml | |
MD5:— | SHA256:— | |||
| 2740 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2740.46858\analyze\HiLink.app\Contents\MacOS\HiLink | binary | |
MD5:— | SHA256:— | |||
| 2740 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2740.46858\analyze\HiLink.app\Contents\Resources\English.lproj\InfoPlist.strings | text | |
MD5:— | SHA256:— | |||
| 2740 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2740.46858\analyze\HiLink.app\Contents\Resources\English.lproj\Logo.icns | image | |
MD5:— | SHA256:— | |||
| 2740 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2740.46858\analyze\HiLink.app.zip | compressed | |
MD5:— | SHA256:— | |||
| 2740 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2740.46858\analyze\HiLink.app\Contents\Resources\mbbserviceopen.app\Contents\MacOS\mbbserviceopen | binary | |
MD5:— | SHA256:— | |||
| 2740 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2740.46858\analyze\HiLink.app\Contents\Info.plist | xml | |
MD5:15D2DED113F2F849808C4400C7698A1F | SHA256:51FF58328F0FBD7F10BCB057FA931684619EE473CAFB67BC62AC6EAC817C1339 | |||
| 2740 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2740.46858\analyze\HiLink.app\Contents\Resources\English.lproj\main.nib\objects.xib | xml | |
MD5:32311A779B180920778D1C82FB8E6803 | SHA256:8AA8251E9F40C0AEC5C1F2E6F44EE4B276F18746942D95D403DF2988E729E412 | |||
| 2740 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2740.46858\analyze\HiLink.app\Contents\Resources\Installer.png | image | |
MD5:0E9E279C003E7B59192C4096808A80F6 | SHA256:F6ABB05685BD9C61FABF63905E37471262D0729A78FCE52CFFACC6F38DC57958 | |||
| 2740 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2740.46858\analyze\HiLink.app\Contents\Resources\English.lproj\custom.strings | text | |
MD5:64FC9B3091DC6AC8070EE183583E0C54 | SHA256:51880423A36197B329673D2D9BABD05A0E359D920BB557DDE8DCCFD2CB96C69D | |||