| File name: | AndroratZIP.zip |
| Full analysis: | https://app.any.run/tasks/289ea608-e2c1-447c-83b9-17916e1a675e |
| Verdict: | Malicious activity |
| Analysis date: | October 04, 2021, 12:37:54 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | AABD9FF3C08B4661709E6FB948779DC0 |
| SHA1: | 92D81BCF4808D6BC21DAA0B0B6319110323229C6 |
| SHA256: | 017904677BB82BB395255C45806AA9A7305E03662453759514612B71302827D7 |
| SSDEEP: | 196608:2R77Q7CCqyn/fhcjyeSoJ4NrA4MLru3x9w+QNYxJ:2xuL9GyeSoGhlMLM8uxJ |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipFileName: | Androrat/ |
|---|---|
| ZipUncompressedSize: | - |
| ZipCompressedSize: | - |
| ZipCRC: | 0x00000000 |
| ZipModifyDate: | 2015:06:29 21:49:19 |
| ZipCompression: | None |
| ZipBitFlag: | - |
| ZipRequiredVersion: | 20 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 184 | java -jar "C:\Program Files\Androrat\\apktool.jar" | C:\Program Files\Common Files\Oracle\Java\javapath\java.exe | — | cmd.exe | |||||||||||
User: admin Company: Oracle Corporation Integrity Level: MEDIUM Description: Java(TM) Platform SE binary Exit code: 1 Version: 8.0.2710.9 Modules
| |||||||||||||||
| 652 | C:\Windows\system32\cmd.exe /c ""C:\Program Files\Androrat\apktool.bat" " | C:\Windows\system32\cmd.exe | — | Explorer.EXE | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 1 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1108 | "C:\Program Files\Androrat\AndroRat Binder.exe" | C:\Program Files\Androrat\AndroRat Binder.exe | — | Explorer.EXE | |||||||||||
User: admin Integrity Level: MEDIUM Description: AndroRat Binder Exit code: 0 Version: 1.0.0.4 Modules
| |||||||||||||||
| 2160 | C:\Windows\system32\icacls.exe C:\ProgramData\Oracle\Java\.oracle_jre_usage /grant "everyone":(OI)(CI)M | C:\Windows\system32\icacls.exe | — | java.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2468 | "C:\Windows\explorer.exe" | C:\Windows\explorer.exe | — | Explorer.EXE | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2516 | "C:\Program Files\Androrat\AndroRat Binder.exe" | C:\Program Files\Androrat\AndroRat Binder.exe | — | Explorer.EXE | |||||||||||
User: admin Integrity Level: MEDIUM Description: AndroRat Binder Exit code: 0 Version: 1.0.0.4 Modules
| |||||||||||||||
| 2680 | "C:\Program Files\WinRAR\WinRAR.exe" -elevate4000 | C:\Program Files\WinRAR\WinRAR.exe | WinRAR.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: HIGH Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 2912 | "C:\Program Files\Androrat\aapt.exe" | C:\Program Files\Androrat\aapt.exe | — | Explorer.EXE | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 2 Modules
| |||||||||||||||
| 3356 | "C:\Windows\System32\cmd.exe" /C "C:\Program Files\Androrat\apktool.bat" | C:\Windows\System32\cmd.exe | Explorer.EXE | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 1 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 3452 | "C:\Program Files\Androrat\aapt.exe" | C:\Program Files\Androrat\aapt.exe | Explorer.EXE | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 2 Modules
| |||||||||||||||
| (PID) Process: | (4000) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (4000) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (4000) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\171\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (4000) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\AndroratZIP.zip | |||
| (PID) Process: | (4000) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (4000) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (4000) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (4000) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (4000) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath |
| Operation: | write | Name: | 0 |
Value: C:\Program Files | |||
| (PID) Process: | (4000) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2680 | WinRAR.exe | C:\Program Files\Androrat\32323\lib\mips\libtcpdump_bin.so | o | |
MD5:CEEC8823AFD863ABA3092324FF1D24EA | SHA256:348349AB83B16C9F5D3F0794A568416E840BD602A0D92DF534235ACE09AFF6F9 | |||
| 2680 | WinRAR.exe | C:\Program Files\Androrat\32323\apktool.yml | text | |
MD5:566F30BC690072479E15A1ECBC0590A5 | SHA256:4A4160B624DB21C7408AFC2A44FFF7DCB8780B92D7463C6073E62946A10410A4 | |||
| 2680 | WinRAR.exe | C:\Program Files\Androrat\32323\res\drawable-hdpi\abs__ab_bottom_solid_inverse_holo.9.png | image | |
MD5:4D8519E343ECAA264178D768349C04FC | SHA256:A9FCFA138AF3B1BBE69FE429A4CB028D2FEBDA9F732972753B2AF6021CE6F06B | |||
| 2680 | WinRAR.exe | C:\Program Files\Androrat\32323\res\drawable-hdpi\abs__ab_bottom_solid_light_holo.9.png | image | |
MD5:3303985D837A591398E4C9132F16A4ED | SHA256:2617EC6AC9E53BEBA74AAD393A5BBE36EC6B29266CCC4F8A7A06F11D66DE8A11 | |||
| 2680 | WinRAR.exe | C:\Program Files\Androrat\32323\res\drawable-hdpi\abs__ab_bottom_transparent_dark_holo.9.png | image | |
MD5:0C944BC6FB7DED6DF6B7EB8F85166439 | SHA256:7E1841EA7C414348799DC109CA72CDB06FBD9DC8F20B3825DB34E7D4F5FACE43 | |||
| 2680 | WinRAR.exe | C:\Program Files\Androrat\32323\AndroidManifest.xml | xml | |
MD5:5EC8ACEFAF79D6685578C101B51A2563 | SHA256:850D54F360E7E671F3842433E4E46D5352EBD5A057CA4347B3A7F4E5A64D8142 | |||
| 2680 | WinRAR.exe | C:\Program Files\Androrat\32323\res\color\abs__primary_text_holo_dark.xml | xml | |
MD5:73C597A7BA4D6A957A5A2FD9349CDA8D | SHA256:31C863DBAB2FD7EBC4006B8A662B174ABE707811CBE451CBF292A50A67FA7A48 | |||
| 2680 | WinRAR.exe | C:\Program Files\Androrat\32323\lib\x86\libtcpdump_bin.so | o | |
MD5:BA7AB1F5587E4E7D490DA898C686FE16 | SHA256:CD8C75F8F748906D5758032C3429CA02F1B57750A16FCDFE8688CA6BDFBAC9DC | |||
| 2680 | WinRAR.exe | C:\Program Files\Androrat\32323\res\drawable-hdpi\abs__ab_share_pack_holo_light.9.png | image | |
MD5:31E3EE19CF63A051098A6A1C077086F0 | SHA256:196C4528BF448BB1CD427E55FDBF060F0ECC69CD91FA8706CEDA193346D8E263 | |||
| 2680 | WinRAR.exe | C:\Program Files\Androrat\32323\res\drawable-hdpi\abs__ab_bottom_transparent_light_holo.9.png | image | |
MD5:F692E1F8E4E27599A57B034F56472784 | SHA256:FEF77AD4E3857FADCCDF917E849FC02B61765E8D9506AD7C676A96FAE47C095A | |||