File name:

AndroratZIP.zip

Full analysis: https://app.any.run/tasks/289ea608-e2c1-447c-83b9-17916e1a675e
Verdict: Malicious activity
Analysis date: October 04, 2021, 12:37:54
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

AABD9FF3C08B4661709E6FB948779DC0

SHA1:

92D81BCF4808D6BC21DAA0B0B6319110323229C6

SHA256:

017904677BB82BB395255C45806AA9A7305E03662453759514612B71302827D7

SSDEEP:

196608:2R77Q7CCqyn/fhcjyeSoJ4NrA4MLru3x9w+QNYxJ:2xuL9GyeSoGhlMLM8uxJ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • AndroRat Binder.exe (PID: 1108)
      • aapt.exe (PID: 2912)
      • AndroRat Binder.exe (PID: 2516)
      • aapt.exe (PID: 3452)
  • SUSPICIOUS

    • Reads the computer name

      • WinRAR.exe (PID: 4000)
      • WinRAR.exe (PID: 2680)
      • AndroRat Binder.exe (PID: 2516)
    • Checks supported languages

      • WinRAR.exe (PID: 4000)
      • WinRAR.exe (PID: 2680)
      • AndroRat Binder.exe (PID: 1108)
      • java.exe (PID: 3536)
      • cmd.exe (PID: 3356)
      • aapt.exe (PID: 2912)
      • java.exe (PID: 184)
      • cmd.exe (PID: 652)
      • AndroRat Binder.exe (PID: 2516)
      • aapt.exe (PID: 3452)
    • Application launched itself

      • WinRAR.exe (PID: 4000)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2680)
    • Check for Java to be installed

      • java.exe (PID: 184)
      • java.exe (PID: 3536)
    • Uses ICACLS.EXE to modify access control list

      • java.exe (PID: 184)
    • Creates files in the program directory

      • java.exe (PID: 184)
      • WinRAR.exe (PID: 2680)
    • Creates a directory in Program Files

      • WinRAR.exe (PID: 2680)
  • INFO

    • Reads the computer name

      • explorer.exe (PID: 2468)
      • icacls.exe (PID: 2160)
    • Checks supported languages

      • explorer.exe (PID: 2468)
      • icacls.exe (PID: 2160)
    • Manual execution by user

      • explorer.exe (PID: 2468)
      • AndroRat Binder.exe (PID: 1108)
      • aapt.exe (PID: 2912)
      • cmd.exe (PID: 652)
      • cmd.exe (PID: 3356)
      • aapt.exe (PID: 3452)
      • AndroRat Binder.exe (PID: 2516)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: Androrat/
ZipUncompressedSize: -
ZipCompressedSize: -
ZipCRC: 0x00000000
ZipModifyDate: 2015:06:29 21:49:19
ZipCompression: None
ZipBitFlag: -
ZipRequiredVersion: 20
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
63
Monitored processes
12
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs winrar.exe explorer.exe no specs androrat binder.exe no specs aapt.exe no specs cmd.exe no specs java.exe no specs icacls.exe no specs cmd.exe java.exe no specs aapt.exe androrat binder.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
184java -jar "C:\Program Files\Androrat\\apktool.jar" C:\Program Files\Common Files\Oracle\Java\javapath\java.execmd.exe
User:
admin
Company:
Oracle Corporation
Integrity Level:
MEDIUM
Description:
Java(TM) Platform SE binary
Exit code:
1
Version:
8.0.2710.9
Modules
Images
c:\program files\common files\oracle\java\javapath_target_52116515\java.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
652C:\Windows\system32\cmd.exe /c ""C:\Program Files\Androrat\apktool.bat" "C:\Windows\system32\cmd.exeExplorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
1108"C:\Program Files\Androrat\AndroRat Binder.exe" C:\Program Files\Androrat\AndroRat Binder.exeExplorer.EXE
User:
admin
Integrity Level:
MEDIUM
Description:
AndroRat Binder
Exit code:
0
Version:
1.0.0.4
Modules
Images
c:\program files\androrat\androrat binder.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2160C:\Windows\system32\icacls.exe C:\ProgramData\Oracle\Java\.oracle_jre_usage /grant "everyone":(OI)(CI)MC:\Windows\system32\icacls.exejava.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\icacls.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\ntmarta.dll
2468"C:\Windows\explorer.exe" C:\Windows\explorer.exeExplorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\user32.dll
2516"C:\Program Files\Androrat\AndroRat Binder.exe" C:\Program Files\Androrat\AndroRat Binder.exeExplorer.EXE
User:
admin
Integrity Level:
MEDIUM
Description:
AndroRat Binder
Exit code:
0
Version:
1.0.0.4
Modules
Images
c:\program files\androrat\androrat binder.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2680"C:\Program Files\WinRAR\WinRAR.exe" -elevate4000C:\Program Files\WinRAR\WinRAR.exe
WinRAR.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
HIGH
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
2912"C:\Program Files\Androrat\aapt.exe" C:\Program Files\Androrat\aapt.exeExplorer.EXE
User:
admin
Integrity Level:
MEDIUM
Exit code:
2
Modules
Images
c:\program files\androrat\aapt.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
3356"C:\Windows\System32\cmd.exe" /C "C:\Program Files\Androrat\apktool.bat" C:\Windows\System32\cmd.exe
Explorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\gdi32.dll
3452"C:\Program Files\Androrat\aapt.exe" C:\Program Files\Androrat\aapt.exe
Explorer.EXE
User:
admin
Integrity Level:
HIGH
Exit code:
2
Modules
Images
c:\program files\androrat\aapt.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
Total events
2 137
Read events
2 100
Write events
37
Delete events
0

Modification events

(PID) Process:(4000) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(4000) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(4000) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\171\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(4000) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\AndroratZIP.zip
(PID) Process:(4000) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(4000) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(4000) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(4000) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(4000) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath
Operation:writeName:0
Value:
C:\Program Files
(PID) Process:(4000) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
4
Suspicious files
6
Text files
2 224
Unknown types
132

Dropped files

PID
Process
Filename
Type
2680WinRAR.exeC:\Program Files\Androrat\32323\lib\mips\libblank_webserver_bin.soo
MD5:B8C2CB14FD46C5C1651C8A2444D0BBD5
SHA256:8415D1F9F1B1C79ACD19647DAFB9F839BFB6135B5683451360A9410C7E1259B3
2680WinRAR.exeC:\Program Files\Androrat\32323\lib\armeabi\libblank_webserver_bin.soo
MD5:59628BC3345D557A9831624F7BE3DBF8
SHA256:4146C928600307E0B6542369F63464E48A77F698F0501836A625753BDE84639A
2680WinRAR.exeC:\Program Files\Androrat\32323\lib\mips\libtcpdump_bin.soo
MD5:CEEC8823AFD863ABA3092324FF1D24EA
SHA256:348349AB83B16C9F5D3F0794A568416E840BD602A0D92DF534235ACE09AFF6F9
2680WinRAR.exeC:\Program Files\Androrat\32323\lib\armeabi\libtcpdump_bin.soo
MD5:791B88FA1BC2C6E30AF3EEC0A3311F16
SHA256:9442D0ECAF9901CFF49BBDCE3FF0D3F1623DA45C13718583BA55B8D556980ADA
2680WinRAR.exeC:\Program Files\Androrat\32323\res\color\abs__primary_text_holo_light.xmlxml
MD5:1856059B2AD0243822C121DD21688E72
SHA256:3A93C905E75042C62CC7F6502E58259DE0BEBB5D064861D000BE06956330DE73
2680WinRAR.exeC:\Program Files\Androrat\32323\lib\x86\libtcpdump_bin.soo
MD5:BA7AB1F5587E4E7D490DA898C686FE16
SHA256:CD8C75F8F748906D5758032C3429CA02F1B57750A16FCDFE8688CA6BDFBAC9DC
2680WinRAR.exeC:\Program Files\Androrat\32323\AndroidManifest.xmlxml
MD5:5EC8ACEFAF79D6685578C101B51A2563
SHA256:850D54F360E7E671F3842433E4E46D5352EBD5A057CA4347B3A7F4E5A64D8142
2680WinRAR.exeC:\Program Files\Androrat\32323\res\color\abs__primary_text_disable_only_holo_dark.xmlxml
MD5:9AC4E697153A95248AC064A2136D7B7B
SHA256:65EF196FA18B51DBB163F70C4B70C85C3468FBA59B5F85BB8C0663BBE18E0B3B
2680WinRAR.exeC:\Program Files\Androrat\32323\lib\x86\libblank_webserver_bin.soo
MD5:D692EF20C1C7529EFCE6378973DD935C
SHA256:78668E45E430C863AA1680F7851ADB6EDA8BBC0DAF2CDA463D468C199F687468
2680WinRAR.exeC:\Program Files\Androrat\32323\res\drawable-hdpi\abs__ab_bottom_solid_light_holo.9.pngimage
MD5:3303985D837A591398E4C9132F16A4ED
SHA256:2617EC6AC9E53BEBA74AAD393A5BBE36EC6B29266CCC4F8A7A06F11D66DE8A11
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info