Edit tour

Windows Analysis Report
8-Jira-05.04.2025.txt-515127.zip

Overview

General Information

Sample name:8-Jira-05.04.2025.txt-515127.zip
Analysis ID:1658091
MD5:b2ce79ed0490cb6562bea9e8da14d7aa
SHA1:79a77844cac8db7fdc543a2478194453b39547da
SHA256:7c77a74f0c867ca46aa8a2766919533240789f7ec1c30beee0485a8d660313e2
Infos:

Detection

Score:1
Range:0 - 100
Confidence:60%

Signatures

Drops PE files
Found dropped PE file which has not been started or loaded

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64_ra
  • rundll32.exe (PID: 7016 cmdline: C:\Windows\System32\rundll32.exe C:\Windows\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding MD5: EF3179D498793BF4234F708D3BE28633)
  • Setup_102024.exe (PID: 7132 cmdline: "C:\Users\user\AppData\Local\Temp\Temp1_8-Jira-05.04.2025.txt-515127.zip\Setup_102024.exe" MD5: 2A4C46E9A88035D53CC73B0535D823C5)
  • Setup_102024.exe (PID: 5932 cmdline: "C:\Users\user\AppData\Local\Temp\Temp1_8-Jira-05.04.2025.txt-515127.zip\Setup_102024.exe" MD5: 2A4C46E9A88035D53CC73B0535D823C5)
  • Setup_102024.exe (PID: 6300 cmdline: "C:\Users\user\Desktop\8-Jira-05.04.2025.txt-515127\Setup_102024.exe" MD5: 2A4C46E9A88035D53CC73B0535D823C5)
  • ChordPro-6-1-0-1-msw-x64.exe (PID: 740 cmdline: "C:\Users\user\Desktop\8-Jira-05.04.2025.txt-515127\ChordPro-6-1-0-1-msw-x64.exe" MD5: 42E5907F3D63B01B7206AC38B8E1B907)
    • ChordPro-6-1-0-1-msw-x64.tmp (PID: 980 cmdline: "C:\Users\user\AppData\Local\Temp\is-LMS41.tmp\ChordPro-6-1-0-1-msw-x64.tmp" /SL5="$204FC,12228257,780800,C:\Users\user\Desktop\8-Jira-05.04.2025.txt-515127\ChordPro-6-1-0-1-msw-x64.exe" MD5: 58E0E5E9460F8DFC3E3CD56CB4CCC4F0)
      • ChordPro-6-1-0-1-msw-x64.exe (PID: 6916 cmdline: "C:\Users\user\Desktop\8-Jira-05.04.2025.txt-515127\ChordPro-6-1-0-1-msw-x64.exe" /SPAWNWND=$20510 /NOTIFYWND=$204FC MD5: 42E5907F3D63B01B7206AC38B8E1B907)
        • ChordPro-6-1-0-1-msw-x64.tmp (PID: 1220 cmdline: "C:\Users\user\AppData\Local\Temp\is-MN1C4.tmp\ChordPro-6-1-0-1-msw-x64.tmp" /SL5="$30500,12228257,780800,C:\Users\user\Desktop\8-Jira-05.04.2025.txt-515127\ChordPro-6-1-0-1-msw-x64.exe" /SPAWNWND=$20510 /NOTIFYWND=$204FC MD5: 58E0E5E9460F8DFC3E3CD56CB4CCC4F0)
  • cleanup
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownHTTPS traffic detected: 104.18.9.197:443 -> 192.168.2.16:49697 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.18.9.197:443 -> 192.168.2.16:49706 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.18.9.197:443 -> 192.168.2.16:49715 version: TLS 1.2
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /2B16F48B05C1BDF4/20551578661/4E04F49AE3D25C46/74401410274?3EA4955EC37390351744014102 HTTP/1.1Host: postquantumgroup.comUser-Agent: NSIS_InetLoad (Mozilla)Accept: */*
Source: global trafficHTTP traffic detected: GET /2B16F48B05C1BDF4/21429241721/4E04F49AE3D25C46/74401411871?0A1ED13F59F052EB1744014118 HTTP/1.1Host: postquantumgroup.comUser-Agent: NSIS_InetLoad (Mozilla)Accept: */*
Source: global trafficHTTP traffic detected: GET /2B16F48B05C1BDF4/70662167461/4E04F49AE3D25C46/74401415481?F16C5F415B0BBF4E1744014154 HTTP/1.1Host: postquantumgroup.comUser-Agent: NSIS_InetLoad (Mozilla)Accept: */*
Source: global trafficDNS traffic detected: DNS query: postquantumgroup.com
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49697
Source: unknownNetwork traffic detected: HTTP traffic on port 49706 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49697 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49706
Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
Source: unknownHTTPS traffic detected: 104.18.9.197:443 -> 192.168.2.16:49697 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.18.9.197:443 -> 192.168.2.16:49706 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.18.9.197:443 -> 192.168.2.16:49715 version: TLS 1.2
Source: classification engineClassification label: clean1.winZIP@10/4@1/24
Source: C:\Users\user\Desktop\8-Jira-05.04.2025.txt-515127\Setup_102024.exeFile created: C:\Users\user\Desktop\8-Jira-05.04.2025.txt-515127\ChordPro-6-1-0-1-msw-x64.exe
Source: C:\Users\user\AppData\Local\Temp\Temp1_8-Jira-05.04.2025.txt-515127.zip\Setup_102024.exeFile created: C:\Users\user\AppData\Local\Temp\CBD8.tmp\
Source: C:\Users\user\Desktop\8-Jira-05.04.2025.txt-515127\ChordPro-6-1-0-1-msw-x64.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
Source: C:\Users\user\Desktop\8-Jira-05.04.2025.txt-515127\ChordPro-6-1-0-1-msw-x64.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
Source: C:\Users\user\AppData\Local\Temp\is-LMS41.tmp\ChordPro-6-1-0-1-msw-x64.tmpKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
Source: C:\Users\user\AppData\Local\Temp\is-LMS41.tmp\ChordPro-6-1-0-1-msw-x64.tmpKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
Source: C:\Users\user\Desktop\8-Jira-05.04.2025.txt-515127\ChordPro-6-1-0-1-msw-x64.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
Source: C:\Users\user\Desktop\8-Jira-05.04.2025.txt-515127\ChordPro-6-1-0-1-msw-x64.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
Source: C:\Users\user\AppData\Local\Temp\is-MN1C4.tmp\ChordPro-6-1-0-1-msw-x64.tmpKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
Source: C:\Users\user\AppData\Local\Temp\is-MN1C4.tmp\ChordPro-6-1-0-1-msw-x64.tmpKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
Source: C:\Users\user\AppData\Local\Temp\is-LMS41.tmp\ChordPro-6-1-0-1-msw-x64.tmpFile read: C:\Users\user\Desktop\desktop.ini
Source: C:\Windows\System32\rundll32.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Source: C:\Users\user\AppData\Local\Temp\is-MN1C4.tmp\ChordPro-6-1-0-1-msw-x64.tmpKey value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion RegisteredOrganization
Source: unknownProcess created: C:\Windows\System32\rundll32.exe C:\Windows\System32\rundll32.exe C:\Windows\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding
Source: C:\Users\user\AppData\Local\Temp\Temp1_8-Jira-05.04.2025.txt-515127.zip\Setup_102024.exeFile read: C:\Users\user\AppData\Local\Temp\Temp1_8-Jira-05.04.2025.txt-515127.zip\Setup_102024.exe
Source: unknownProcess created: C:\Windows\System32\rundll32.exe C:\Windows\System32\rundll32.exe C:\Windows\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding
Source: unknownProcess created: C:\Users\user\AppData\Local\Temp\Temp1_8-Jira-05.04.2025.txt-515127.zip\Setup_102024.exe "C:\Users\user\AppData\Local\Temp\Temp1_8-Jira-05.04.2025.txt-515127.zip\Setup_102024.exe"
Source: unknownProcess created: C:\Users\user\AppData\Local\Temp\Temp1_8-Jira-05.04.2025.txt-515127.zip\Setup_102024.exe "C:\Users\user\AppData\Local\Temp\Temp1_8-Jira-05.04.2025.txt-515127.zip\Setup_102024.exe"
Source: unknownProcess created: C:\Users\user\Desktop\8-Jira-05.04.2025.txt-515127\Setup_102024.exe "C:\Users\user\Desktop\8-Jira-05.04.2025.txt-515127\Setup_102024.exe"
Source: unknownProcess created: C:\Users\user\Desktop\8-Jira-05.04.2025.txt-515127\ChordPro-6-1-0-1-msw-x64.exe "C:\Users\user\Desktop\8-Jira-05.04.2025.txt-515127\ChordPro-6-1-0-1-msw-x64.exe"
Source: C:\Users\user\Desktop\8-Jira-05.04.2025.txt-515127\ChordPro-6-1-0-1-msw-x64.exeProcess created: C:\Users\user\AppData\Local\Temp\is-LMS41.tmp\ChordPro-6-1-0-1-msw-x64.tmp "C:\Users\user\AppData\Local\Temp\is-LMS41.tmp\ChordPro-6-1-0-1-msw-x64.tmp" /SL5="$204FC,12228257,780800,C:\Users\user\Desktop\8-Jira-05.04.2025.txt-515127\ChordPro-6-1-0-1-msw-x64.exe"
Source: C:\Users\user\AppData\Local\Temp\is-LMS41.tmp\ChordPro-6-1-0-1-msw-x64.tmpProcess created: C:\Users\user\Desktop\8-Jira-05.04.2025.txt-515127\ChordPro-6-1-0-1-msw-x64.exe "C:\Users\user\Desktop\8-Jira-05.04.2025.txt-515127\ChordPro-6-1-0-1-msw-x64.exe" /SPAWNWND=$20510 /NOTIFYWND=$204FC
Source: C:\Users\user\Desktop\8-Jira-05.04.2025.txt-515127\ChordPro-6-1-0-1-msw-x64.exeProcess created: C:\Users\user\AppData\Local\Temp\is-MN1C4.tmp\ChordPro-6-1-0-1-msw-x64.tmp "C:\Users\user\AppData\Local\Temp\is-MN1C4.tmp\ChordPro-6-1-0-1-msw-x64.tmp" /SL5="$30500,12228257,780800,C:\Users\user\Desktop\8-Jira-05.04.2025.txt-515127\ChordPro-6-1-0-1-msw-x64.exe" /SPAWNWND=$20510 /NOTIFYWND=$204FC
Source: C:\Users\user\Desktop\8-Jira-05.04.2025.txt-515127\ChordPro-6-1-0-1-msw-x64.exeProcess created: C:\Users\user\AppData\Local\Temp\is-LMS41.tmp\ChordPro-6-1-0-1-msw-x64.tmp "C:\Users\user\AppData\Local\Temp\is-LMS41.tmp\ChordPro-6-1-0-1-msw-x64.tmp" /SL5="$204FC,12228257,780800,C:\Users\user\Desktop\8-Jira-05.04.2025.txt-515127\ChordPro-6-1-0-1-msw-x64.exe"
Source: C:\Users\user\Desktop\8-Jira-05.04.2025.txt-515127\ChordPro-6-1-0-1-msw-x64.exeProcess created: C:\Users\user\AppData\Local\Temp\is-MN1C4.tmp\ChordPro-6-1-0-1-msw-x64.tmp "C:\Users\user\AppData\Local\Temp\is-MN1C4.tmp\ChordPro-6-1-0-1-msw-x64.tmp" /SL5="$30500,12228257,780800,C:\Users\user\Desktop\8-Jira-05.04.2025.txt-515127\ChordPro-6-1-0-1-msw-x64.exe" /SPAWNWND=$20510 /NOTIFYWND=$204FC
Source: C:\Users\user\AppData\Local\Temp\Temp1_8-Jira-05.04.2025.txt-515127.zip\Setup_102024.exeSection loaded: kernel.appcore.dll
Source: C:\Users\user\AppData\Local\Temp\Temp1_8-Jira-05.04.2025.txt-515127.zip\Setup_102024.exeSection loaded: uxtheme.dll
Source: C:\Users\user\AppData\Local\Temp\Temp1_8-Jira-05.04.2025.txt-515127.zip\Setup_102024.exeSection loaded: explorerframe.dll
Source: C:\Users\user\AppData\Local\Temp\Temp1_8-Jira-05.04.2025.txt-515127.zip\Setup_102024.exeSection loaded: textshaping.dll
Source: C:\Users\user\AppData\Local\Temp\Temp1_8-Jira-05.04.2025.txt-515127.zip\Setup_102024.exeSection loaded: textinputframework.dll
Source: C:\Users\user\AppData\Local\Temp\Temp1_8-Jira-05.04.2025.txt-515127.zip\Setup_102024.exeSection loaded: coreuicomponents.dll
Source: C:\Users\user\AppData\Local\Temp\Temp1_8-Jira-05.04.2025.txt-515127.zip\Setup_102024.exeSection loaded: coremessaging.dll
Source: C:\Users\user\AppData\Local\Temp\Temp1_8-Jira-05.04.2025.txt-515127.zip\Setup_102024.exeSection loaded: ntmarta.dll
Source: C:\Users\user\AppData\Local\Temp\Temp1_8-Jira-05.04.2025.txt-515127.zip\Setup_102024.exeSection loaded: coremessaging.dll
Source: C:\Users\user\AppData\Local\Temp\Temp1_8-Jira-05.04.2025.txt-515127.zip\Setup_102024.exeSection loaded: wintypes.dll
Source: C:\Users\user\AppData\Local\Temp\Temp1_8-Jira-05.04.2025.txt-515127.zip\Setup_102024.exeSection loaded: wintypes.dll
Source: C:\Users\user\AppData\Local\Temp\Temp1_8-Jira-05.04.2025.txt-515127.zip\Setup_102024.exeSection loaded: wintypes.dll
Source: C:\Users\user\AppData\Local\Temp\Temp1_8-Jira-05.04.2025.txt-515127.zip\Setup_102024.exeSection loaded: sspicli.dll
Source: C:\Users\user\AppData\Local\Temp\Temp1_8-Jira-05.04.2025.txt-515127.zip\Setup_102024.exeSection loaded: secur32.dll
Source: C:\Users\user\AppData\Local\Temp\Temp1_8-Jira-05.04.2025.txt-515127.zip\Setup_102024.exeSection loaded: iphlpapi.dll
Source: C:\Users\user\AppData\Local\Temp\Temp1_8-Jira-05.04.2025.txt-515127.zip\Setup_102024.exeSection loaded: cryptbase.dll
Source: C:\Users\user\AppData\Local\Temp\Temp1_8-Jira-05.04.2025.txt-515127.zip\Setup_102024.exeSection loaded: mswsock.dll
Source: C:\Users\user\AppData\Local\Temp\Temp1_8-Jira-05.04.2025.txt-515127.zip\Setup_102024.exeSection loaded: dnsapi.dll
Source: C:\Users\user\AppData\Local\Temp\Temp1_8-Jira-05.04.2025.txt-515127.zip\Setup_102024.exeSection loaded: fwpuclnt.dll
Source: C:\Users\user\AppData\Local\Temp\Temp1_8-Jira-05.04.2025.txt-515127.zip\Setup_102024.exeSection loaded: rasadhlp.dll
Source: C:\Users\user\AppData\Local\Temp\Temp1_8-Jira-05.04.2025.txt-515127.zip\Setup_102024.exeSection loaded: schannel.dll
Source: C:\Users\user\AppData\Local\Temp\Temp1_8-Jira-05.04.2025.txt-515127.zip\Setup_102024.exeSection loaded: mskeyprotect.dll
Source: C:\Users\user\AppData\Local\Temp\Temp1_8-Jira-05.04.2025.txt-515127.zip\Setup_102024.exeSection loaded: ntasn1.dll
Source: C:\Users\user\AppData\Local\Temp\Temp1_8-Jira-05.04.2025.txt-515127.zip\Setup_102024.exeSection loaded: ncrypt.dll
Source: C:\Users\user\AppData\Local\Temp\Temp1_8-Jira-05.04.2025.txt-515127.zip\Setup_102024.exeSection loaded: ncryptsslp.dll
Source: C:\Users\user\AppData\Local\Temp\Temp1_8-Jira-05.04.2025.txt-515127.zip\Setup_102024.exeSection loaded: kernel.appcore.dll
Source: C:\Users\user\AppData\Local\Temp\Temp1_8-Jira-05.04.2025.txt-515127.zip\Setup_102024.exeSection loaded: uxtheme.dll
Source: C:\Users\user\AppData\Local\Temp\Temp1_8-Jira-05.04.2025.txt-515127.zip\Setup_102024.exeSection loaded: explorerframe.dll
Source: C:\Users\user\AppData\Local\Temp\Temp1_8-Jira-05.04.2025.txt-515127.zip\Setup_102024.exeSection loaded: textshaping.dll
Source: C:\Users\user\AppData\Local\Temp\Temp1_8-Jira-05.04.2025.txt-515127.zip\Setup_102024.exeSection loaded: textinputframework.dll
Source: C:\Users\user\AppData\Local\Temp\Temp1_8-Jira-05.04.2025.txt-515127.zip\Setup_102024.exeSection loaded: coreuicomponents.dll
Source: C:\Users\user\AppData\Local\Temp\Temp1_8-Jira-05.04.2025.txt-515127.zip\Setup_102024.exeSection loaded: coremessaging.dll
Source: C:\Users\user\AppData\Local\Temp\Temp1_8-Jira-05.04.2025.txt-515127.zip\Setup_102024.exeSection loaded: ntmarta.dll
Source: C:\Users\user\AppData\Local\Temp\Temp1_8-Jira-05.04.2025.txt-515127.zip\Setup_102024.exeSection loaded: coremessaging.dll
Source: C:\Users\user\AppData\Local\Temp\Temp1_8-Jira-05.04.2025.txt-515127.zip\Setup_102024.exeSection loaded: wintypes.dll
Source: C:\Users\user\AppData\Local\Temp\Temp1_8-Jira-05.04.2025.txt-515127.zip\Setup_102024.exeSection loaded: wintypes.dll
Source: C:\Users\user\AppData\Local\Temp\Temp1_8-Jira-05.04.2025.txt-515127.zip\Setup_102024.exeSection loaded: wintypes.dll
Source: C:\Users\user\AppData\Local\Temp\Temp1_8-Jira-05.04.2025.txt-515127.zip\Setup_102024.exeSection loaded: sspicli.dll
Source: C:\Users\user\AppData\Local\Temp\Temp1_8-Jira-05.04.2025.txt-515127.zip\Setup_102024.exeSection loaded: secur32.dll
Source: C:\Users\user\AppData\Local\Temp\Temp1_8-Jira-05.04.2025.txt-515127.zip\Setup_102024.exeSection loaded: iphlpapi.dll
Source: C:\Users\user\AppData\Local\Temp\Temp1_8-Jira-05.04.2025.txt-515127.zip\Setup_102024.exeSection loaded: cryptbase.dll
Source: C:\Users\user\AppData\Local\Temp\Temp1_8-Jira-05.04.2025.txt-515127.zip\Setup_102024.exeSection loaded: mswsock.dll
Source: C:\Users\user\AppData\Local\Temp\Temp1_8-Jira-05.04.2025.txt-515127.zip\Setup_102024.exeSection loaded: dnsapi.dll
Source: C:\Users\user\AppData\Local\Temp\Temp1_8-Jira-05.04.2025.txt-515127.zip\Setup_102024.exeSection loaded: fwpuclnt.dll
Source: C:\Users\user\AppData\Local\Temp\Temp1_8-Jira-05.04.2025.txt-515127.zip\Setup_102024.exeSection loaded: rasadhlp.dll
Source: C:\Users\user\AppData\Local\Temp\Temp1_8-Jira-05.04.2025.txt-515127.zip\Setup_102024.exeSection loaded: schannel.dll
Source: C:\Users\user\AppData\Local\Temp\Temp1_8-Jira-05.04.2025.txt-515127.zip\Setup_102024.exeSection loaded: mskeyprotect.dll
Source: C:\Users\user\AppData\Local\Temp\Temp1_8-Jira-05.04.2025.txt-515127.zip\Setup_102024.exeSection loaded: ntasn1.dll
Source: C:\Users\user\AppData\Local\Temp\Temp1_8-Jira-05.04.2025.txt-515127.zip\Setup_102024.exeSection loaded: ncrypt.dll
Source: C:\Users\user\AppData\Local\Temp\Temp1_8-Jira-05.04.2025.txt-515127.zip\Setup_102024.exeSection loaded: ncryptsslp.dll
Source: C:\Users\user\Desktop\8-Jira-05.04.2025.txt-515127\Setup_102024.exeSection loaded: kernel.appcore.dll
Source: C:\Users\user\Desktop\8-Jira-05.04.2025.txt-515127\Setup_102024.exeSection loaded: uxtheme.dll
Source: C:\Users\user\Desktop\8-Jira-05.04.2025.txt-515127\Setup_102024.exeSection loaded: explorerframe.dll
Source: C:\Users\user\Desktop\8-Jira-05.04.2025.txt-515127\Setup_102024.exeSection loaded: textshaping.dll
Source: C:\Users\user\Desktop\8-Jira-05.04.2025.txt-515127\Setup_102024.exeSection loaded: textinputframework.dll
Source: C:\Users\user\Desktop\8-Jira-05.04.2025.txt-515127\Setup_102024.exeSection loaded: coreuicomponents.dll
Source: C:\Users\user\Desktop\8-Jira-05.04.2025.txt-515127\Setup_102024.exeSection loaded: coremessaging.dll
Source: C:\Users\user\Desktop\8-Jira-05.04.2025.txt-515127\Setup_102024.exeSection loaded: ntmarta.dll
Source: C:\Users\user\Desktop\8-Jira-05.04.2025.txt-515127\Setup_102024.exeSection loaded: coremessaging.dll
Source: C:\Users\user\Desktop\8-Jira-05.04.2025.txt-515127\Setup_102024.exeSection loaded: wintypes.dll
Source: C:\Users\user\Desktop\8-Jira-05.04.2025.txt-515127\Setup_102024.exeSection loaded: wintypes.dll
Source: C:\Users\user\Desktop\8-Jira-05.04.2025.txt-515127\Setup_102024.exeSection loaded: wintypes.dll
Source: C:\Users\user\Desktop\8-Jira-05.04.2025.txt-515127\Setup_102024.exeSection loaded: sspicli.dll
Source: C:\Users\user\Desktop\8-Jira-05.04.2025.txt-515127\Setup_102024.exeSection loaded: secur32.dll
Source: C:\Users\user\Desktop\8-Jira-05.04.2025.txt-515127\Setup_102024.exeSection loaded: iphlpapi.dll
Source: C:\Users\user\Desktop\8-Jira-05.04.2025.txt-515127\Setup_102024.exeSection loaded: cryptbase.dll
Source: C:\Users\user\Desktop\8-Jira-05.04.2025.txt-515127\Setup_102024.exeSection loaded: mswsock.dll
Source: C:\Users\user\Desktop\8-Jira-05.04.2025.txt-515127\Setup_102024.exeSection loaded: dnsapi.dll
Source: C:\Users\user\Desktop\8-Jira-05.04.2025.txt-515127\Setup_102024.exeSection loaded: fwpuclnt.dll
Source: C:\Users\user\Desktop\8-Jira-05.04.2025.txt-515127\Setup_102024.exeSection loaded: rasadhlp.dll
Source: C:\Users\user\Desktop\8-Jira-05.04.2025.txt-515127\Setup_102024.exeSection loaded: schannel.dll
Source: C:\Users\user\Desktop\8-Jira-05.04.2025.txt-515127\Setup_102024.exeSection loaded: mskeyprotect.dll
Source: C:\Users\user\Desktop\8-Jira-05.04.2025.txt-515127\Setup_102024.exeSection loaded: ntasn1.dll
Source: C:\Users\user\Desktop\8-Jira-05.04.2025.txt-515127\Setup_102024.exeSection loaded: ncrypt.dll
Source: C:\Users\user\Desktop\8-Jira-05.04.2025.txt-515127\Setup_102024.exeSection loaded: ncryptsslp.dll
Source: C:\Users\user\Desktop\8-Jira-05.04.2025.txt-515127\ChordPro-6-1-0-1-msw-x64.exeSection loaded: version.dll
Source: C:\Users\user\Desktop\8-Jira-05.04.2025.txt-515127\ChordPro-6-1-0-1-msw-x64.exeSection loaded: netapi32.dll
Source: C:\Users\user\Desktop\8-Jira-05.04.2025.txt-515127\ChordPro-6-1-0-1-msw-x64.exeSection loaded: netutils.dll
Source: C:\Users\user\Desktop\8-Jira-05.04.2025.txt-515127\ChordPro-6-1-0-1-msw-x64.exeSection loaded: uxtheme.dll
Source: C:\Users\user\Desktop\8-Jira-05.04.2025.txt-515127\ChordPro-6-1-0-1-msw-x64.exeSection loaded: apphelp.dll
Source: C:\Users\user\AppData\Local\Temp\is-LMS41.tmp\ChordPro-6-1-0-1-msw-x64.tmpSection loaded: mpr.dll
Source: C:\Users\user\AppData\Local\Temp\is-LMS41.tmp\ChordPro-6-1-0-1-msw-x64.tmpSection loaded: version.dll
Source: C:\Users\user\AppData\Local\Temp\is-LMS41.tmp\ChordPro-6-1-0-1-msw-x64.tmpSection loaded: netapi32.dll
Source: C:\Users\user\AppData\Local\Temp\is-LMS41.tmp\ChordPro-6-1-0-1-msw-x64.tmpSection loaded: netutils.dll
Source: C:\Users\user\AppData\Local\Temp\is-LMS41.tmp\ChordPro-6-1-0-1-msw-x64.tmpSection loaded: uxtheme.dll
Source: C:\Users\user\AppData\Local\Temp\is-LMS41.tmp\ChordPro-6-1-0-1-msw-x64.tmpSection loaded: kernel.appcore.dll
Source: C:\Users\user\AppData\Local\Temp\is-LMS41.tmp\ChordPro-6-1-0-1-msw-x64.tmpSection loaded: wtsapi32.dll
Source: C:\Users\user\AppData\Local\Temp\is-LMS41.tmp\ChordPro-6-1-0-1-msw-x64.tmpSection loaded: winsta.dll
Source: C:\Users\user\AppData\Local\Temp\is-LMS41.tmp\ChordPro-6-1-0-1-msw-x64.tmpSection loaded: textinputframework.dll
Source: C:\Users\user\AppData\Local\Temp\is-LMS41.tmp\ChordPro-6-1-0-1-msw-x64.tmpSection loaded: coreuicomponents.dll
Source: C:\Users\user\AppData\Local\Temp\is-LMS41.tmp\ChordPro-6-1-0-1-msw-x64.tmpSection loaded: coremessaging.dll
Source: C:\Users\user\AppData\Local\Temp\is-LMS41.tmp\ChordPro-6-1-0-1-msw-x64.tmpSection loaded: ntmarta.dll
Source: C:\Users\user\AppData\Local\Temp\is-LMS41.tmp\ChordPro-6-1-0-1-msw-x64.tmpSection loaded: wintypes.dll
Source: C:\Users\user\AppData\Local\Temp\is-LMS41.tmp\ChordPro-6-1-0-1-msw-x64.tmpSection loaded: wintypes.dll
Source: C:\Users\user\AppData\Local\Temp\is-LMS41.tmp\ChordPro-6-1-0-1-msw-x64.tmpSection loaded: wintypes.dll
Source: C:\Users\user\AppData\Local\Temp\is-LMS41.tmp\ChordPro-6-1-0-1-msw-x64.tmpSection loaded: windows.storage.dll
Source: C:\Users\user\AppData\Local\Temp\is-LMS41.tmp\ChordPro-6-1-0-1-msw-x64.tmpSection loaded: wldp.dll
Source: C:\Users\user\AppData\Local\Temp\is-LMS41.tmp\ChordPro-6-1-0-1-msw-x64.tmpSection loaded: propsys.dll
Source: C:\Users\user\AppData\Local\Temp\is-LMS41.tmp\ChordPro-6-1-0-1-msw-x64.tmpSection loaded: edputil.dll
Source: C:\Users\user\AppData\Local\Temp\is-LMS41.tmp\ChordPro-6-1-0-1-msw-x64.tmpSection loaded: urlmon.dll
Source: C:\Users\user\AppData\Local\Temp\is-LMS41.tmp\ChordPro-6-1-0-1-msw-x64.tmpSection loaded: iertutil.dll
Source: C:\Users\user\AppData\Local\Temp\is-LMS41.tmp\ChordPro-6-1-0-1-msw-x64.tmpSection loaded: srvcli.dll
Source: C:\Users\user\AppData\Local\Temp\is-LMS41.tmp\ChordPro-6-1-0-1-msw-x64.tmpSection loaded: windows.staterepositoryps.dll
Source: C:\Users\user\AppData\Local\Temp\is-LMS41.tmp\ChordPro-6-1-0-1-msw-x64.tmpSection loaded: appresolver.dll
Source: C:\Users\user\AppData\Local\Temp\is-LMS41.tmp\ChordPro-6-1-0-1-msw-x64.tmpSection loaded: bcp47langs.dll
Source: C:\Users\user\AppData\Local\Temp\is-LMS41.tmp\ChordPro-6-1-0-1-msw-x64.tmpSection loaded: slc.dll
Source: C:\Users\user\AppData\Local\Temp\is-LMS41.tmp\ChordPro-6-1-0-1-msw-x64.tmpSection loaded: userenv.dll
Source: C:\Users\user\AppData\Local\Temp\is-LMS41.tmp\ChordPro-6-1-0-1-msw-x64.tmpSection loaded: sppc.dll
Source: C:\Users\user\AppData\Local\Temp\is-LMS41.tmp\ChordPro-6-1-0-1-msw-x64.tmpSection loaded: onecorecommonproxystub.dll
Source: C:\Users\user\AppData\Local\Temp\is-LMS41.tmp\ChordPro-6-1-0-1-msw-x64.tmpSection loaded: onecoreuapcommonproxystub.dll
Source: C:\Users\user\AppData\Local\Temp\is-LMS41.tmp\ChordPro-6-1-0-1-msw-x64.tmpSection loaded: pcacli.dll
Source: C:\Users\user\AppData\Local\Temp\is-LMS41.tmp\ChordPro-6-1-0-1-msw-x64.tmpSection loaded: sfc_os.dll
Source: C:\Users\user\Desktop\8-Jira-05.04.2025.txt-515127\ChordPro-6-1-0-1-msw-x64.exeSection loaded: version.dll
Source: C:\Users\user\Desktop\8-Jira-05.04.2025.txt-515127\ChordPro-6-1-0-1-msw-x64.exeSection loaded: netapi32.dll
Source: C:\Users\user\Desktop\8-Jira-05.04.2025.txt-515127\ChordPro-6-1-0-1-msw-x64.exeSection loaded: netutils.dll
Source: C:\Users\user\Desktop\8-Jira-05.04.2025.txt-515127\ChordPro-6-1-0-1-msw-x64.exeSection loaded: uxtheme.dll
Source: C:\Users\user\Desktop\8-Jira-05.04.2025.txt-515127\ChordPro-6-1-0-1-msw-x64.exeSection loaded: apphelp.dll
Source: C:\Users\user\AppData\Local\Temp\is-MN1C4.tmp\ChordPro-6-1-0-1-msw-x64.tmpSection loaded: mpr.dll
Source: C:\Users\user\AppData\Local\Temp\is-MN1C4.tmp\ChordPro-6-1-0-1-msw-x64.tmpSection loaded: version.dll
Source: C:\Users\user\AppData\Local\Temp\is-MN1C4.tmp\ChordPro-6-1-0-1-msw-x64.tmpSection loaded: netapi32.dll
Source: C:\Users\user\AppData\Local\Temp\is-MN1C4.tmp\ChordPro-6-1-0-1-msw-x64.tmpSection loaded: netutils.dll
Source: C:\Users\user\AppData\Local\Temp\is-MN1C4.tmp\ChordPro-6-1-0-1-msw-x64.tmpSection loaded: uxtheme.dll
Source: C:\Users\user\AppData\Local\Temp\is-MN1C4.tmp\ChordPro-6-1-0-1-msw-x64.tmpSection loaded: kernel.appcore.dll
Source: C:\Users\user\AppData\Local\Temp\is-MN1C4.tmp\ChordPro-6-1-0-1-msw-x64.tmpSection loaded: wtsapi32.dll
Source: C:\Users\user\AppData\Local\Temp\is-MN1C4.tmp\ChordPro-6-1-0-1-msw-x64.tmpSection loaded: winsta.dll
Source: C:\Users\user\AppData\Local\Temp\is-MN1C4.tmp\ChordPro-6-1-0-1-msw-x64.tmpSection loaded: textinputframework.dll
Source: C:\Users\user\AppData\Local\Temp\is-MN1C4.tmp\ChordPro-6-1-0-1-msw-x64.tmpSection loaded: coreuicomponents.dll
Source: C:\Users\user\AppData\Local\Temp\is-MN1C4.tmp\ChordPro-6-1-0-1-msw-x64.tmpSection loaded: coremessaging.dll
Source: C:\Users\user\AppData\Local\Temp\is-MN1C4.tmp\ChordPro-6-1-0-1-msw-x64.tmpSection loaded: ntmarta.dll
Source: C:\Users\user\AppData\Local\Temp\is-MN1C4.tmp\ChordPro-6-1-0-1-msw-x64.tmpSection loaded: wintypes.dll
Source: C:\Users\user\AppData\Local\Temp\is-MN1C4.tmp\ChordPro-6-1-0-1-msw-x64.tmpSection loaded: wintypes.dll
Source: C:\Users\user\AppData\Local\Temp\is-MN1C4.tmp\ChordPro-6-1-0-1-msw-x64.tmpSection loaded: wintypes.dll
Source: C:\Users\user\AppData\Local\Temp\is-MN1C4.tmp\ChordPro-6-1-0-1-msw-x64.tmpSection loaded: windows.storage.dll
Source: C:\Users\user\AppData\Local\Temp\is-MN1C4.tmp\ChordPro-6-1-0-1-msw-x64.tmpSection loaded: wldp.dll
Source: C:\Users\user\AppData\Local\Temp\is-MN1C4.tmp\ChordPro-6-1-0-1-msw-x64.tmpSection loaded: profapi.dll
Source: C:\Users\user\AppData\Local\Temp\is-MN1C4.tmp\ChordPro-6-1-0-1-msw-x64.tmpSection loaded: shfolder.dll
Source: C:\Users\user\AppData\Local\Temp\is-MN1C4.tmp\ChordPro-6-1-0-1-msw-x64.tmpSection loaded: rstrtmgr.dll
Source: C:\Users\user\AppData\Local\Temp\is-MN1C4.tmp\ChordPro-6-1-0-1-msw-x64.tmpSection loaded: ncrypt.dll
Source: C:\Users\user\AppData\Local\Temp\is-MN1C4.tmp\ChordPro-6-1-0-1-msw-x64.tmpSection loaded: ntasn1.dll
Source: C:\Users\user\AppData\Local\Temp\is-MN1C4.tmp\ChordPro-6-1-0-1-msw-x64.tmpSection loaded: textshaping.dll
Source: C:\Users\user\AppData\Local\Temp\is-MN1C4.tmp\ChordPro-6-1-0-1-msw-x64.tmpSection loaded: msftedit.dll
Source: C:\Users\user\AppData\Local\Temp\is-MN1C4.tmp\ChordPro-6-1-0-1-msw-x64.tmpSection loaded: windows.globalization.dll
Source: C:\Users\user\AppData\Local\Temp\is-MN1C4.tmp\ChordPro-6-1-0-1-msw-x64.tmpSection loaded: bcp47langs.dll
Source: C:\Users\user\AppData\Local\Temp\is-MN1C4.tmp\ChordPro-6-1-0-1-msw-x64.tmpSection loaded: bcp47mrm.dll
Source: C:\Users\user\AppData\Local\Temp\is-MN1C4.tmp\ChordPro-6-1-0-1-msw-x64.tmpSection loaded: globinputhost.dll
Source: C:\Users\user\AppData\Local\Temp\is-MN1C4.tmp\ChordPro-6-1-0-1-msw-x64.tmpSection loaded: dwmapi.dll
Source: C:\Users\user\AppData\Local\Temp\Temp1_8-Jira-05.04.2025.txt-515127.zip\Setup_102024.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{56FDF344-FD6D-11d0-958A-006097C9A090}\InProcServer32
Source: C:\Users\user\AppData\Local\Temp\is-MN1C4.tmp\ChordPro-6-1-0-1-msw-x64.tmpKey value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion RegisteredOwner
Source: C:\Users\user\AppData\Local\Temp\is-MN1C4.tmp\ChordPro-6-1-0-1-msw-x64.tmpWindow found: window name: TMainForm
Source: C:\Users\user\AppData\Local\Temp\is-MN1C4.tmp\ChordPro-6-1-0-1-msw-x64.tmpFile opened: C:\Windows\SysWOW64\MSFTEDIT.DLL
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: 8-Jira-05.04.2025.txt-515127.zipStatic file information: File size 23098071 > 1048576
Source: C:\Users\user\Desktop\8-Jira-05.04.2025.txt-515127\ChordPro-6-1-0-1-msw-x64.exeFile created: C:\Users\user\AppData\Local\Temp\is-LMS41.tmp\ChordPro-6-1-0-1-msw-x64.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-MN1C4.tmp\ChordPro-6-1-0-1-msw-x64.tmpFile created: C:\Users\user\AppData\Local\Temp\is-S0TJD.tmp\_isetup\_setup64.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\Temp1_8-Jira-05.04.2025.txt-515127.zip\Setup_102024.exeFile created: C:\Users\user\AppData\Local\Temp\Temp1_8-Jira-05.04.2025.txt-515127.zip\ChordPro-6-1-0-1-msw-x64.exeJump to dropped file
Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\8-Jira-05.04.2025.txt-515127\ChordPro-6-1-0-1-msw-x64.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-LMS41.tmp\ChordPro-6-1-0-1-msw-x64.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-LMS41.tmp\ChordPro-6-1-0-1-msw-x64.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-LMS41.tmp\ChordPro-6-1-0-1-msw-x64.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-LMS41.tmp\ChordPro-6-1-0-1-msw-x64.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-LMS41.tmp\ChordPro-6-1-0-1-msw-x64.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\8-Jira-05.04.2025.txt-515127\ChordPro-6-1-0-1-msw-x64.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-MN1C4.tmp\ChordPro-6-1-0-1-msw-x64.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-MN1C4.tmp\ChordPro-6-1-0-1-msw-x64.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-MN1C4.tmp\ChordPro-6-1-0-1-msw-x64.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-MN1C4.tmp\ChordPro-6-1-0-1-msw-x64.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-MN1C4.tmp\ChordPro-6-1-0-1-msw-x64.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-MN1C4.tmp\ChordPro-6-1-0-1-msw-x64.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-MN1C4.tmp\ChordPro-6-1-0-1-msw-x64.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-MN1C4.tmp\ChordPro-6-1-0-1-msw-x64.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-MN1C4.tmp\ChordPro-6-1-0-1-msw-x64.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-MN1C4.tmp\ChordPro-6-1-0-1-msw-x64.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\is-S0TJD.tmp\_isetup\_setup64.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\Temp1_8-Jira-05.04.2025.txt-515127.zip\Setup_102024.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\Temp1_8-Jira-05.04.2025.txt-515127.zip\ChordPro-6-1-0-1-msw-x64.exe
Source: C:\Users\user\AppData\Local\Temp\Temp1_8-Jira-05.04.2025.txt-515127.zip\Setup_102024.exeProcess information queried: ProcessInformation
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
DLL Side-Loading
1
Process Injection
1
Masquerading
OS Credential Dumping1
Process Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
DLL Side-Loading
1
Rundll32
LSASS Memory2
System Owner/User Discovery
Remote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
Process Injection
Security Account Manager1
File and Directory Discovery
SMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
DLL Side-Loading
NTDS1
System Information Discovery
Distributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
SourceDetectionScannerLabelLink
C:\Users\user\AppData\Local\Temp\Temp1_8-Jira-05.04.2025.txt-515127.zip\ChordPro-6-1-0-1-msw-x64.exe4%ReversingLabs
C:\Users\user\AppData\Local\Temp\Temp1_8-Jira-05.04.2025.txt-515127.zip\ChordPro-6-1-0-1-msw-x64.exe3%ReversingLabs
C:\Users\user\AppData\Local\Temp\is-LMS41.tmp\ChordPro-6-1-0-1-msw-x64.tmp0%ReversingLabs
C:\Users\user\AppData\Local\Temp\is-S0TJD.tmp\_isetup\_setup64.tmp0%ReversingLabs
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://postquantumgroup.com/2B16F48B05C1BDF4/20551578661/4E04F49AE3D25C46/74401410274?3EA4955EC373903517440141020%Avira URL Cloudsafe
https://postquantumgroup.com/2B16F48B05C1BDF4/21429241721/4E04F49AE3D25C46/74401411871?0A1ED13F59F052EB17440141180%Avira URL Cloudsafe
https://postquantumgroup.com/2B16F48B05C1BDF4/70662167461/4E04F49AE3D25C46/74401415481?F16C5F415B0BBF4E17440141540%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
postquantumgroup.com
104.18.9.197
truefalse
    unknown
    NameMaliciousAntivirus DetectionReputation
    https://postquantumgroup.com/2B16F48B05C1BDF4/20551578661/4E04F49AE3D25C46/74401410274?3EA4955EC37390351744014102false
    • Avira URL Cloud: safe
    unknown
    https://postquantumgroup.com/2B16F48B05C1BDF4/70662167461/4E04F49AE3D25C46/74401415481?F16C5F415B0BBF4E1744014154false
    • Avira URL Cloud: safe
    unknown
    https://postquantumgroup.com/2B16F48B05C1BDF4/21429241721/4E04F49AE3D25C46/74401411871?0A1ED13F59F052EB1744014118false
    • Avira URL Cloud: safe
    unknown
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    104.18.9.197
    postquantumgroup.comUnited States
    13335CLOUDFLARENETUSfalse
    IP
    127.0.0.1
    Joe Sandbox version:42.0.0 Malachite
    Analysis ID:1658091
    Start date and time:2025-04-07 10:21:02 +02:00
    Joe Sandbox product:CloudBasic
    Overall analysis duration:
    Hypervisor based Inspection enabled:false
    Report type:full
    Cookbook file name:defaultwindowsinteractivecookbook.jbs
    Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
    Number of analysed new started processes analysed:22
    Number of new started drivers analysed:0
    Number of existing processes analysed:0
    Number of existing drivers analysed:0
    Number of injected processes analysed:1
    Technologies:
    • EGA enabled
    Analysis Mode:stream
    Analysis stop reason:Timeout
    Sample name:8-Jira-05.04.2025.txt-515127.zip
    Detection:CLEAN
    Classification:clean1.winZIP@10/4@1/24
    Cookbook Comments:
    • Found application associated with file extension: .zip
    • Exclude process from analysis (whitelisted): SIHClient.exe
    • Excluded IPs from analysis (whitelisted): 4.175.87.197
    • Excluded domains from analysis (whitelisted): slscr.update.microsoft.com
    • Not all processes where analyzed, report is missing behavior information
    • Report size getting too big, too many NtOpenKeyEx calls found.
    • Report size getting too big, too many NtQueryValueKey calls found.
    • VT rate limit hit for: postquantumgroup.com
    Process:C:\Users\user\AppData\Local\Temp\Temp1_8-Jira-05.04.2025.txt-515127.zip\Setup_102024.exe
    File Type:PE32 executable (GUI) Intel 80386, for MS Windows
    Category:dropped
    Size (bytes):12582912
    Entropy (8bit):7.9807225956109855
    Encrypted:false
    SSDEEP:
    MD5:2226F3FAB6B6F173EC1D87B5A9178D1C
    SHA1:182FC8FD0891594986D6D0FEBF46274E22D09A10
    SHA-256:80E373DB48E45C8C4A5AF4C6C045861430AD2045CA2382954024ACD940E0A3AA
    SHA-512:123D5E4C472ECD46E6A5FFC4F15B3E92AFF8A18FAC3BACEE6EA3977CF54D26B775EBF37ED0FD30FAFED9849FA1DF353138529FA7F90DE662F03B4DC12BFC7B98
    Malicious:false
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 4%
    • Antivirus: ReversingLabs, Detection: 3%
    Reputation:unknown
    Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L......^.................P...........^.......p....@.......................................@......@...................@....... ..6....p...H...................................................`......................."..D....0.......................text....6.......8.................. ..`.itext.......P.......<.............. ..`.data....7...p...8...T..............@....bss.....m...............................idata..6.... ......................@....didata......0......................@....edata.......@......................@..@.tls.........P...........................rdata..]....`......................@..@.rsrc....H...p...H..................@..@....................................@..@........................................................
    Process:C:\Users\user\Desktop\8-Jira-05.04.2025.txt-515127\ChordPro-6-1-0-1-msw-x64.exe
    File Type:PE32 executable (GUI) Intel 80386, for MS Windows
    Category:dropped
    Size (bytes):2571264
    Entropy (8bit):6.387757854734691
    Encrypted:false
    SSDEEP:
    MD5:58E0E5E9460F8DFC3E3CD56CB4CCC4F0
    SHA1:BE6781D0A5F969389CB8E69E1F5EBD48605F8438
    SHA-256:BC52B0EDA87186B995F5FAAF045812B52C8CD7765E76FA8D02E9833406625343
    SHA-512:BEBCDCE3282ED935ACB9E93A80802FE39FB465EF0E974013A85F4AD70D0D3BC52528AD1AFFF5C24BA7A2859E13C539CD63FEF27B2D21513F5C17C56099462259
    Malicious:false
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 0%
    Reputation:unknown
    Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L......^..................%...........%.......%...@.......................... (...........@......@....................'.......&..5...0'...................................................... '.....................L.&.H.....&......................text.....%.......%................. ..`.itext...&....%..(....%............. ..`.data...dZ....%..\....%.............@....bss.....x...0&..........................idata...5....&..6....&.............@....didata.......&......@&.............@....edata........'......J&.............@..@.tls....D.....'..........................rdata..].... '......L&.............@..@.rsrc........0'......N&.............@..@............. (......<'.............@..@........................................................
    Process:C:\Users\user\AppData\Local\Temp\is-MN1C4.tmp\ChordPro-6-1-0-1-msw-x64.tmp
    File Type:PE32+ executable (console) x86-64, for MS Windows
    Category:dropped
    Size (bytes):6144
    Entropy (8bit):4.720366600008286
    Encrypted:false
    SSDEEP:
    MD5:E4211D6D009757C078A9FAC7FF4F03D4
    SHA1:019CD56BA687D39D12D4B13991C9A42EA6BA03DA
    SHA-256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
    SHA-512:17257F15D843E88BB78ADCFB48184B8CE22109CC2C99E709432728A392AFAE7B808ED32289BA397207172DE990A354F15C2459B6797317DA8EA18B040C85787E
    Malicious:false
    Antivirus:
    • Antivirus: ReversingLabs, Detection: 0%
    Reputation:unknown
    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......^...............l...............=\......=\......=\......Rich............................PE..d.....R..........#............................@.............................`.......,......................................................<!.......P..H....@..0.................................................................... ...............................text............................... ..`.rdata..|.... ......................@..@.data...,....0......................@....pdata..0....@......................@..@.rsrc...H....P......................@..@................................................................................................................................................................................................................................................................................................................................
    File type:Zip archive data, at least v2.1 to extract, compression method=deflate64
    Entropy (8bit):7.999161689451689
    TrID:
    • ZIP compressed archive (8000/1) 100.00%
    File name:8-Jira-05.04.2025.txt-515127.zip
    File size:23'098'071 bytes
    MD5:b2ce79ed0490cb6562bea9e8da14d7aa
    SHA1:79a77844cac8db7fdc543a2478194453b39547da
    SHA256:7c77a74f0c867ca46aa8a2766919533240789f7ec1c30beee0485a8d660313e2
    SHA512:0d23a8347cb150a53b82f5d8b7c4ab2e791425b3ee96b4c86fe168c53918900ce1934c219c2e1168c60125a521769bd98c76d760a6067f9a2887d5c65b3c4cd8
    SSDEEP:393216:1cE42NyB9l6WSb5vV0fC2yzGJRaajAgUMhPwWlU3YMzmM4IncKgzeflJKY1DL6oR:6B9l6LbT0a2yGna/gDhPSoamoc5A2Ydv
    TLSH:8E3733CDA0BAF87185EF7D68B19370F17405B15F35A6B92B9BB44EB2D05FA08442B01B
    File Content Preview:PK.........!.Z.PV.1r`.........Setup_102024.exe.\{xTG...H.!.....Pb.......Q.7...&-.dC.&..."...d/A....@..V..T...O...5...l..........b..b.Z$.".......~......w...9s....3...].A.$#~..$uJ._....&.$%/z2Yz"...........o.O....g.>...O}...../...N.S>....iy%ei....O.~.u.lQ..
    Icon Hash:1c1c1e4e4ececedc