| File name: | AndroratZIP.zip |
| Full analysis: | https://app.any.run/tasks/289ea608-e2c1-447c-83b9-17916e1a675e |
| Verdict: | Malicious activity |
| Analysis date: | October 04, 2021, 12:37:54 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | AABD9FF3C08B4661709E6FB948779DC0 |
| SHA1: | 92D81BCF4808D6BC21DAA0B0B6319110323229C6 |
| SHA256: | 017904677BB82BB395255C45806AA9A7305E03662453759514612B71302827D7 |
| SSDEEP: | 196608:2R77Q7CCqyn/fhcjyeSoJ4NrA4MLru3x9w+QNYxJ:2xuL9GyeSoGhlMLM8uxJ |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipFileName: | Androrat/ |
|---|---|
| ZipUncompressedSize: | - |
| ZipCompressedSize: | - |
| ZipCRC: | 0x00000000 |
| ZipModifyDate: | 2015:06:29 21:49:19 |
| ZipCompression: | None |
| ZipBitFlag: | - |
| ZipRequiredVersion: | 20 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 184 | java -jar "C:\Program Files\Androrat\\apktool.jar" | C:\Program Files\Common Files\Oracle\Java\javapath\java.exe | — | cmd.exe | |||||||||||
User: admin Company: Oracle Corporation Integrity Level: MEDIUM Description: Java(TM) Platform SE binary Exit code: 1 Version: 8.0.2710.9 Modules
| |||||||||||||||
| 652 | C:\Windows\system32\cmd.exe /c ""C:\Program Files\Androrat\apktool.bat" " | C:\Windows\system32\cmd.exe | — | Explorer.EXE | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 1 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1108 | "C:\Program Files\Androrat\AndroRat Binder.exe" | C:\Program Files\Androrat\AndroRat Binder.exe | — | Explorer.EXE | |||||||||||
User: admin Integrity Level: MEDIUM Description: AndroRat Binder Exit code: 0 Version: 1.0.0.4 Modules
| |||||||||||||||
| 2160 | C:\Windows\system32\icacls.exe C:\ProgramData\Oracle\Java\.oracle_jre_usage /grant "everyone":(OI)(CI)M | C:\Windows\system32\icacls.exe | — | java.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2468 | "C:\Windows\explorer.exe" | C:\Windows\explorer.exe | — | Explorer.EXE | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2516 | "C:\Program Files\Androrat\AndroRat Binder.exe" | C:\Program Files\Androrat\AndroRat Binder.exe | — | Explorer.EXE | |||||||||||
User: admin Integrity Level: MEDIUM Description: AndroRat Binder Exit code: 0 Version: 1.0.0.4 Modules
| |||||||||||||||
| 2680 | "C:\Program Files\WinRAR\WinRAR.exe" -elevate4000 | C:\Program Files\WinRAR\WinRAR.exe | WinRAR.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: HIGH Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 2912 | "C:\Program Files\Androrat\aapt.exe" | C:\Program Files\Androrat\aapt.exe | — | Explorer.EXE | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 2 Modules
| |||||||||||||||
| 3356 | "C:\Windows\System32\cmd.exe" /C "C:\Program Files\Androrat\apktool.bat" | C:\Windows\System32\cmd.exe | Explorer.EXE | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 1 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 3452 | "C:\Program Files\Androrat\aapt.exe" | C:\Program Files\Androrat\aapt.exe | Explorer.EXE | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 2 Modules
| |||||||||||||||
| (PID) Process: | (4000) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (4000) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (4000) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\171\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (4000) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\AndroratZIP.zip | |||
| (PID) Process: | (4000) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (4000) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (4000) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (4000) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (4000) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath |
| Operation: | write | Name: | 0 |
Value: C:\Program Files | |||
| (PID) Process: | (4000) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2680 | WinRAR.exe | C:\Program Files\Androrat\32323\lib\mips\libblank_webserver_bin.so | o | |
MD5:B8C2CB14FD46C5C1651C8A2444D0BBD5 | SHA256:8415D1F9F1B1C79ACD19647DAFB9F839BFB6135B5683451360A9410C7E1259B3 | |||
| 2680 | WinRAR.exe | C:\Program Files\Androrat\32323\lib\armeabi\libblank_webserver_bin.so | o | |
MD5:59628BC3345D557A9831624F7BE3DBF8 | SHA256:4146C928600307E0B6542369F63464E48A77F698F0501836A625753BDE84639A | |||
| 2680 | WinRAR.exe | C:\Program Files\Androrat\32323\lib\mips\libtcpdump_bin.so | o | |
MD5:CEEC8823AFD863ABA3092324FF1D24EA | SHA256:348349AB83B16C9F5D3F0794A568416E840BD602A0D92DF534235ACE09AFF6F9 | |||
| 2680 | WinRAR.exe | C:\Program Files\Androrat\32323\lib\armeabi\libtcpdump_bin.so | o | |
MD5:791B88FA1BC2C6E30AF3EEC0A3311F16 | SHA256:9442D0ECAF9901CFF49BBDCE3FF0D3F1623DA45C13718583BA55B8D556980ADA | |||
| 2680 | WinRAR.exe | C:\Program Files\Androrat\32323\res\color\abs__primary_text_holo_light.xml | xml | |
MD5:1856059B2AD0243822C121DD21688E72 | SHA256:3A93C905E75042C62CC7F6502E58259DE0BEBB5D064861D000BE06956330DE73 | |||
| 2680 | WinRAR.exe | C:\Program Files\Androrat\32323\lib\x86\libtcpdump_bin.so | o | |
MD5:BA7AB1F5587E4E7D490DA898C686FE16 | SHA256:CD8C75F8F748906D5758032C3429CA02F1B57750A16FCDFE8688CA6BDFBAC9DC | |||
| 2680 | WinRAR.exe | C:\Program Files\Androrat\32323\AndroidManifest.xml | xml | |
MD5:5EC8ACEFAF79D6685578C101B51A2563 | SHA256:850D54F360E7E671F3842433E4E46D5352EBD5A057CA4347B3A7F4E5A64D8142 | |||
| 2680 | WinRAR.exe | C:\Program Files\Androrat\32323\res\color\abs__primary_text_disable_only_holo_dark.xml | xml | |
MD5:9AC4E697153A95248AC064A2136D7B7B | SHA256:65EF196FA18B51DBB163F70C4B70C85C3468FBA59B5F85BB8C0663BBE18E0B3B | |||
| 2680 | WinRAR.exe | C:\Program Files\Androrat\32323\lib\x86\libblank_webserver_bin.so | o | |
MD5:D692EF20C1C7529EFCE6378973DD935C | SHA256:78668E45E430C863AA1680F7851ADB6EDA8BBC0DAF2CDA463D468C199F687468 | |||
| 2680 | WinRAR.exe | C:\Program Files\Androrat\32323\res\drawable-hdpi\abs__ab_bottom_solid_light_holo.9.png | image | |
MD5:3303985D837A591398E4C9132F16A4ED | SHA256:2617EC6AC9E53BEBA74AAD393A5BBE36EC6B29266CCC4F8A7A06F11D66DE8A11 | |||