Windows Analysis Report
7z2301-x64.exe

Overview

General Information

Sample name: 7z2301-x64.exe
Analysis ID: 1428447
MD5: e5788b13546156281bf0a4b38bdd0901
SHA1: 7df28d340d7084647921cc25a8c2068bb192bdbb
SHA256: 26cb6e9f56333682122fafe79dbcdfd51e9f47cc7217dccd29ac6fc33b5598cd
Infos:

Detection

Score: 19
Range: 0 - 100
Whitelisted: false
Confidence: 60%

Signatures

Infects executable files (exe, dll, sys, html)
Contains functionality to dynamically determine API calls
Contains functionality to shutdown / reboot the system
Detected potential crypto function
Dropped file seen in connection with other malware
Drops PE files
Drops files with a non-matching file extension (content does not match file extension)
Found dropped PE file which has not been started or loaded
PE file contains sections with non-standard names
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)

Classification

Source: 7z2301-x64.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, LARGE_ADDRESS_AWARE, 32BIT_MACHINE

Spreading

barindex
Source: C:\Users\user\Desktop\7z2301-x64.exe System file written: C:\Program Files\7-Zip\7-zip.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe System file written: C:\Program Files\7-Zip\7z.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe System file written: C:\Program Files\7-Zip\7z.exe Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe System file written: C:\Program Files\7-Zip\7-zip32.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe System file written: C:\Program Files\7-Zip\Uninstall.exe Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe System file written: C:\Program Files\7-Zip\7zG.exe Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe System file written: C:\Program Files\7-Zip\7zFM.exe Jump to behavior
Source: 7z2301-x64.exe, 00000000.00000003.1688177644.0000000002734000.00000004.00000020.00020000.00000000.sdmp, License.txt.0.dr String found in binary or memory: http://www.gnu.org/
Source: 7z2301-x64.exe, 00000000.00000003.1691781092.0000000004577000.00000004.00000020.00020000.00000000.sdmp, 7zFM.exe.0.dr String found in binary or memory: https://www.7-zip.org/
Source: C:\Users\user\Desktop\7z2301-x64.exe Code function: 0_2_004017DE GetModuleFileNameW,GetDlgItemTextW,lstrlenW,ShowWindow,ShowWindow,ShowWindow,SendMessageW,PeekMessageW,PeekMessageW,IsDialogMessageW,TranslateMessage,DispatchMessageW,SendMessageW,PeekMessageW,PeekMessageW,SetWindowTextW,lstrcpyW,lstrcpyW,lstrlenW,GetFileAttributesW,SetFileAttributesW,lstrcatW,lstrlenW,MessageBoxW,SetFileTime,SetFileAttributesW,MoveFileExW,GetLastError,SendMessageW,SetWindowTextW,MessageBoxW,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,GetLastError,ExitWindowsEx, 0_2_004017DE
Source: C:\Users\user\Desktop\7z2301-x64.exe Code function: 0_2_00404067 0_2_00404067
Source: C:\Users\user\Desktop\7z2301-x64.exe Code function: 0_2_0040580A 0_2_0040580A
Source: C:\Users\user\Desktop\7z2301-x64.exe Code function: 0_2_00404CC3 0_2_00404CC3
Source: C:\Users\user\Desktop\7z2301-x64.exe Code function: 0_2_00406BFD 0_2_00406BFD
Source: C:\Users\user\Desktop\7z2301-x64.exe Code function: 0_2_004060B8 0_2_004060B8
Source: Joe Sandbox View Dropped File: C:\Program Files\7-Zip\7-zip.dll F9B4944D3A5536A6F8B4D5DB17D903988A3518B22FBEE6E3F6019AAF44189B3D
Source: Joe Sandbox View Dropped File: C:\Program Files\7-Zip\7-zip32.dll 62EF98B00232F9D63A647E201ABFB354582D3FBC342EC63DF15B2A0CE514B5A6
Source: Joe Sandbox View Dropped File: C:\Program Files\7-Zip\7z.dll 77222E81CB7004E8C3E077AADA02B555A3D38FB05B50C64AFD36CA230A8FD5B9
Source: 7z2301-x64.exe, 00000000.00000000.1634981117.000000000040D000.00000002.00000001.01000000.00000003.sdmp Binary or memory string: OriginalFilename7zipInstall.exe, vs 7z2301-x64.exe
Source: 7z2301-x64.exe, 00000000.00000003.1691781092.0000000004577000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilename7-zip.dll, vs 7z2301-x64.exe
Source: 7z2301-x64.exe, 00000000.00000003.1691781092.0000000004577000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilename vs 7z2301-x64.exe
Source: 7z2301-x64.exe, 00000000.00000003.1691781092.0000000004577000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: FileVersionFileDescriptionOriginalFilename_winzip_.rsrcCOFF_SYMBOLSCERTIFICATE vs 7z2301-x64.exe
Source: 7z2301-x64.exe, 00000000.00000003.1691781092.0000000004577000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilename7z.dll, vs 7z2301-x64.exe
Source: 7z2301-x64.exe, 00000000.00000003.1691781092.0000000004577000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilename7z.exe, vs 7z2301-x64.exe
Source: 7z2301-x64.exe, 00000000.00000003.1691781092.0000000004577000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilename7z.sfx.exe, vs 7z2301-x64.exe
Source: 7z2301-x64.exe, 00000000.00000003.1691781092.0000000004577000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilename7zFM.exe, vs 7z2301-x64.exe
Source: 7z2301-x64.exe, 00000000.00000003.1691781092.0000000004577000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilename7zg.exe, vs 7z2301-x64.exe
Source: 7z2301-x64.exe, 00000000.00000003.1691781092.0000000004577000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameUninstall.exe, vs 7z2301-x64.exe
Source: 7z2301-x64.exe, 00000000.00000002.2876503375.0000000000197000.00000004.00000010.00020000.00000000.sdmp Binary or memory string: OriginalFilename7zipInstall.exe, vs 7z2301-x64.exe
Source: 7z2301-x64.exe Binary or memory string: OriginalFilename7zipInstall.exe, vs 7z2301-x64.exe
Source: 7z2301-x64.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, LARGE_ADDRESS_AWARE, 32BIT_MACHINE
Source: classification engine Classification label: clean19.spre.winEXE@1/109@0/0
Source: C:\Users\user\Desktop\7z2301-x64.exe Code function: 0_2_004017DE GetModuleFileNameW,GetDlgItemTextW,lstrlenW,ShowWindow,ShowWindow,ShowWindow,SendMessageW,PeekMessageW,PeekMessageW,IsDialogMessageW,TranslateMessage,DispatchMessageW,SendMessageW,PeekMessageW,PeekMessageW,SetWindowTextW,lstrcpyW,lstrcpyW,lstrlenW,GetFileAttributesW,SetFileAttributesW,lstrcatW,lstrlenW,MessageBoxW,SetFileTime,SetFileAttributesW,MoveFileExW,GetLastError,SendMessageW,SetWindowTextW,MessageBoxW,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,GetLastError,ExitWindowsEx, 0_2_004017DE
Source: C:\Users\user\Desktop\7z2301-x64.exe Code function: 0_2_004025C5 CoCreateInstance, 0_2_004025C5
Source: 7z2301-x64.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\7z2301-x64.exe File read: C:\Program Files\desktop.ini Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe File read: C:\Users\user\Desktop\7z2301-x64.exe Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: textshaping.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: textinputframework.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: coreuicomponents.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: linkinfo.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: ntshrui.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: cscapi.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: explorerframe.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: windowscodecs.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: thumbcache.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: policymanager.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: msvcp110_win.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: dataexchange.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: d3d11.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: dcomp.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: dxgi.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: twinapi.appcore.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: secur32.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: samcli.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: samlib.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: drprov.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: winsta.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: ntlanman.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: davclnt.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: davhlpr.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: wkscli.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: dlnashext.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: playtodevice.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: devdispitemprovider.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: mmdevapi.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: devobj.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: wpdshext.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: portabledeviceapi.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: msasn1.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: audiodev.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: wmvcore.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: wmasf.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: mfperfhelper.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: audiodev.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: wmvcore.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: wmasf.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: mfperfhelper.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: audiodev.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: wmvcore.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: wmasf.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: mfperfhelper.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: audiodev.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: wmvcore.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: wmasf.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: mfperfhelper.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: audiodev.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: wmvcore.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: wmasf.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: mfperfhelper.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: networkexplorer.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: audiodev.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: wmvcore.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: wmasf.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: mfperfhelper.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: audiodev.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: wmvcore.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: wmasf.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: mfperfhelper.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: audiodev.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: wmvcore.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: wmasf.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: mfperfhelper.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: audiodev.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: wmvcore.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: wmasf.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: mfperfhelper.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: audiodev.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: wmvcore.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: wmasf.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: mfperfhelper.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: audiodev.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: wmvcore.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: wmasf.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: mfperfhelper.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: audiodev.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: wmvcore.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: wmasf.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: mfperfhelper.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: audiodev.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: wmvcore.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: wmasf.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: mfperfhelper.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: audiodev.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: wmvcore.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: wmasf.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Section loaded: mfperfhelper.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{00021401-0000-0000-C000-000000000046}\InProcServer32 Jump to behavior
Source: 7-Zip File Manager.lnk.0.dr LNK file: ..\..\..\..\..\..\Program Files\7-Zip\7zFM.exe
Source: 7-Zip Help.lnk.0.dr LNK file: ..\..\..\..\..\..\Program Files\7-Zip\7-zip.chm
Source: C:\Users\user\Desktop\7z2301-x64.exe Automated click: Install
Source: C:\Users\user\Desktop\7z2301-x64.exe Automated click: OK
Source: C:\Users\user\Desktop\7z2301-x64.exe Automated click: OK
Source: C:\Users\user\Desktop\7z2301-x64.exe Automated click: OK
Source: C:\Users\user\Desktop\7z2301-x64.exe Automated click: OK
Source: C:\Users\user\Desktop\7z2301-x64.exe Automated click: OK
Source: C:\Users\user\Desktop\7z2301-x64.exe Automated click: OK
Source: C:\Users\user\Desktop\7z2301-x64.exe Automated click: OK
Source: C:\Users\user\Desktop\7z2301-x64.exe Automated click: OK
Source: C:\Users\user\Desktop\7z2301-x64.exe Automated click: OK
Source: C:\Users\user\Desktop\7z2301-x64.exe Automated click: OK
Source: C:\Users\user\Desktop\7z2301-x64.exe Automated click: OK
Source: C:\Users\user\Desktop\7z2301-x64.exe Automated click: OK
Source: C:\Users\user\Desktop\7z2301-x64.exe Automated click: OK
Source: C:\Users\user\Desktop\7z2301-x64.exe Automated click: OK
Source: Window Recorder Window detected: More than 3 window changes detected
Source: 7z2301-x64.exe Static file information: File size 1589510 > 1048576
Source: C:\Users\user\Desktop\7z2301-x64.exe Code function: 0_2_00401FB1 GetSystemDirectoryW,lstrlenW,lstrcpyW,LoadLibraryW,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,malloc,free, 0_2_00401FB1
Source: 7-zip32.dll.0.dr Static PE information: section name: .sxdata
Source: 7z.sfx.0.dr Static PE information: section name: .sxdata
Source: 7zCon.sfx.0.dr Static PE information: section name: .sxdata
Source: C:\Users\user\Desktop\7z2301-x64.exe Code function: 0_2_004072E0 push eax; ret 0_2_0040730E

Persistence and Installation Behavior

barindex
Source: C:\Users\user\Desktop\7z2301-x64.exe System file written: C:\Program Files\7-Zip\7-zip.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe System file written: C:\Program Files\7-Zip\7z.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe System file written: C:\Program Files\7-Zip\7z.exe Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe System file written: C:\Program Files\7-Zip\7-zip32.dll Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe System file written: C:\Program Files\7-Zip\Uninstall.exe Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe System file written: C:\Program Files\7-Zip\7zG.exe Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe System file written: C:\Program Files\7-Zip\7zFM.exe Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe File created: C:\Program Files\7-Zip\7-zip.dll Jump to dropped file
Source: C:\Users\user\Desktop\7z2301-x64.exe File created: C:\Program Files\7-Zip\7z.sfx Jump to dropped file
Source: C:\Users\user\Desktop\7z2301-x64.exe File created: C:\Program Files\7-Zip\7z.dll Jump to dropped file
Source: C:\Users\user\Desktop\7z2301-x64.exe File created: C:\Program Files\7-Zip\7z.exe Jump to dropped file
Source: C:\Users\user\Desktop\7z2301-x64.exe File created: C:\Program Files\7-Zip\7-zip32.dll Jump to dropped file
Source: C:\Users\user\Desktop\7z2301-x64.exe File created: C:\Program Files\7-Zip\Uninstall.exe Jump to dropped file
Source: C:\Users\user\Desktop\7z2301-x64.exe File created: C:\Program Files\7-Zip\7zCon.sfx Jump to dropped file
Source: C:\Users\user\Desktop\7z2301-x64.exe File created: C:\Program Files\7-Zip\7zG.exe Jump to dropped file
Source: C:\Users\user\Desktop\7z2301-x64.exe File created: C:\Program Files\7-Zip\7zFM.exe Jump to dropped file
Source: C:\Users\user\Desktop\7z2301-x64.exe File created: C:\Program Files\7-Zip\7z.sfx Jump to dropped file
Source: C:\Users\user\Desktop\7z2301-x64.exe File created: C:\Program Files\7-Zip\7zCon.sfx Jump to dropped file
Source: C:\Users\user\Desktop\7z2301-x64.exe Dropped PE file which has not been started: C:\Program Files\7-Zip\7-zip.dll Jump to dropped file
Source: C:\Users\user\Desktop\7z2301-x64.exe Dropped PE file which has not been started: C:\Program Files\7-Zip\7z.sfx Jump to dropped file
Source: C:\Users\user\Desktop\7z2301-x64.exe Dropped PE file which has not been started: C:\Program Files\7-Zip\7z.dll Jump to dropped file
Source: C:\Users\user\Desktop\7z2301-x64.exe Dropped PE file which has not been started: C:\Program Files\7-Zip\7z.exe Jump to dropped file
Source: C:\Users\user\Desktop\7z2301-x64.exe Dropped PE file which has not been started: C:\Program Files\7-Zip\Uninstall.exe Jump to dropped file
Source: C:\Users\user\Desktop\7z2301-x64.exe Dropped PE file which has not been started: C:\Program Files\7-Zip\7-zip32.dll Jump to dropped file
Source: C:\Users\user\Desktop\7z2301-x64.exe Dropped PE file which has not been started: C:\Program Files\7-Zip\7zCon.sfx Jump to dropped file
Source: C:\Users\user\Desktop\7z2301-x64.exe Dropped PE file which has not been started: C:\Program Files\7-Zip\7zG.exe Jump to dropped file
Source: C:\Users\user\Desktop\7z2301-x64.exe Dropped PE file which has not been started: C:\Program Files\7-Zip\7zFM.exe Jump to dropped file
Source: 7z2301-x64.exe, 00000000.00000002.2876920400.0000000000823000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: C:\Users\user\MusicsProd_VMware_SATA
Source: 7z2301-x64.exe, 00000000.00000003.1747576765.000000000083E000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: }\\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000007500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
Source: 7z2301-x64.exe, 00000000.00000003.2353941581.0000000000865000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: \\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000006500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000C5E500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000007500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}(
Source: 7z2301-x64.exe, 00000000.00000003.2353941581.0000000000865000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: \\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000006500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000C5E500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000007500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
Source: 7z2301-x64.exe, 00000000.00000003.2070595360.000000000083C000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\Device\CdRom0\??\Volume{a33c736e-61ca-11ee-8c18-806e6f6e6963}\DosDevices\D:x
Source: 7z2301-x64.exe, 00000000.00000002.2876920400.0000000000861000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD0hh
Source: 7z2301-x64.exe, 00000000.00000003.1987033584.0000000005115000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: \\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000006500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000C5E500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000007500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}&&
Source: 7z2301-x64.exe, 00000000.00000003.2353941581.0000000000865000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: \\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000006500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000C5E500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000007500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}KK
Source: 7z2301-x64.exe, 00000000.00000002.2877690760.0000000005079000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: \\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000006500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000C5E500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000007500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}yz
Source: 7z2301-x64.exe, 00000000.00000002.2877690760.0000000005079000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: \\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000006500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000C5E500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000007500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}`
Source: 7z2301-x64.exe, 00000000.00000003.2101798092.0000000000870000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: War&Prod_VMware_SATA_CD00#4&224f==
Source: 7z2301-x64.exe, 00000000.00000003.2234627664.0000000000861000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Prod_VMware_SATA_CD0==
Source: 7z2301-x64.exe, 00000000.00000002.2876920400.00000000007CA000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\Device\CdRom0\??\Volume{a33c736e-61ca-11ee-8c18-806e6f6e6963}\DosDevices\D:o
Source: 7z2301-x64.exe, 00000000.00000003.1747032469.0000000000873000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: \\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000006500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000C5E500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000007500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}en
Source: 7z2301-x64.exe, 00000000.00000003.2353941581.0000000000865000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\Device\CdRom0\??\Volume{a33c736e-61ca-11ee-8c18-806e6f6e6963}\DosDevices\D:
Source: 7z2301-x64.exe, 00000000.00000003.2070595360.000000000083C000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000006500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000C5E500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000007500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
Source: 7z2301-x64.exe, 00000000.00000002.2876920400.00000000007CA000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\Device\CdRom0\??\Volume{a33c736e-61ca-11ee-8c18-806e6f6e6963}\DosDevices\D:<S
Source: 7z2301-x64.exe, 00000000.00000002.2876920400.00000000007CA000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: 0uWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\Device\CdRom0\??\Volume{a33c736e-61ca-11ee-8c18-806e6f6e6963}\DosDevices\D:
Source: 7z2301-x64.exe, 00000000.00000002.2877690760.0000000005079000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: \\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000006500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000C5E500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000007500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}``U
Source: 7z2301-x64.exe, 00000000.00000002.2876920400.00000000007CA000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\Device\CdRom0\??\Volume{a33c736e-61ca-11ee-8c18-806e6f6e6963}\DosDevices\D:&
Source: 7z2301-x64.exe, 00000000.00000003.2318928092.0000000000864000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: %1!ls! (%2!c!:) %3!ls!Prod_VMware_SATA_CD0==
Source: 7z2301-x64.exe, 00000000.00000003.1688177644.0000000002734000.00000004.00000020.00020000.00000000.sdmp, History.txt.0.dr Binary or memory string: - 7-Zip now can extract VHDX disk images (Microsoft Hyper-V Virtual Hard Disk v2 format).
Source: 7z2301-x64.exe, 00000000.00000003.2234627664.0000000000844000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: 1ca-11ee-8c18-806e6f6e6963}#0000000006500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000C5E500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000007500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}$$
Source: C:\Users\user\Desktop\7z2301-x64.exe Code function: 0_2_00401FB1 GetSystemDirectoryW,lstrlenW,lstrcpyW,LoadLibraryW,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,malloc,free, 0_2_00401FB1
Source: C:\Users\user\Desktop\7z2301-x64.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\7z2301-x64.exe Code function: 0_2_00405B75 GetVersion,GetModuleHandleW,GetProcAddress,GetSystemDirectoryW,LoadLibraryExW, 0_2_00405B75
No contacted IP infos