File name:

AndroratZIP.zip

Full analysis: https://app.any.run/tasks/289ea608-e2c1-447c-83b9-17916e1a675e
Verdict: Malicious activity
Analysis date: October 04, 2021, 12:37:54
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

AABD9FF3C08B4661709E6FB948779DC0

SHA1:

92D81BCF4808D6BC21DAA0B0B6319110323229C6

SHA256:

017904677BB82BB395255C45806AA9A7305E03662453759514612B71302827D7

SSDEEP:

196608:2R77Q7CCqyn/fhcjyeSoJ4NrA4MLru3x9w+QNYxJ:2xuL9GyeSoGhlMLM8uxJ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • AndroRat Binder.exe (PID: 1108)
      • aapt.exe (PID: 2912)
      • aapt.exe (PID: 3452)
      • AndroRat Binder.exe (PID: 2516)
  • SUSPICIOUS

    • Checks supported languages

      • WinRAR.exe (PID: 4000)
      • WinRAR.exe (PID: 2680)
      • AndroRat Binder.exe (PID: 1108)
      • aapt.exe (PID: 2912)
      • java.exe (PID: 3536)
      • AndroRat Binder.exe (PID: 2516)
      • cmd.exe (PID: 3356)
      • aapt.exe (PID: 3452)
      • cmd.exe (PID: 652)
      • java.exe (PID: 184)
    • Application launched itself

      • WinRAR.exe (PID: 4000)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2680)
    • Reads the computer name

      • WinRAR.exe (PID: 2680)
      • AndroRat Binder.exe (PID: 2516)
      • WinRAR.exe (PID: 4000)
    • Creates files in the program directory

      • java.exe (PID: 184)
      • WinRAR.exe (PID: 2680)
    • Uses ICACLS.EXE to modify access control list

      • java.exe (PID: 184)
    • Check for Java to be installed

      • java.exe (PID: 184)
      • java.exe (PID: 3536)
    • Creates a directory in Program Files

      • WinRAR.exe (PID: 2680)
  • INFO

    • Reads the computer name

      • explorer.exe (PID: 2468)
      • icacls.exe (PID: 2160)
    • Manual execution by user

      • aapt.exe (PID: 2912)
      • explorer.exe (PID: 2468)
      • cmd.exe (PID: 652)
      • AndroRat Binder.exe (PID: 1108)
      • cmd.exe (PID: 3356)
      • AndroRat Binder.exe (PID: 2516)
      • aapt.exe (PID: 3452)
    • Checks supported languages

      • explorer.exe (PID: 2468)
      • icacls.exe (PID: 2160)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: Androrat/
ZipUncompressedSize: -
ZipCompressedSize: -
ZipCRC: 0x00000000
ZipModifyDate: 2015:06:29 21:49:19
ZipCompression: None
ZipBitFlag: -
ZipRequiredVersion: 20
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
63
Monitored processes
12
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs winrar.exe explorer.exe no specs androrat binder.exe no specs aapt.exe no specs cmd.exe no specs java.exe no specs icacls.exe no specs cmd.exe java.exe no specs aapt.exe androrat binder.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
184java -jar "C:\Program Files\Androrat\\apktool.jar" C:\Program Files\Common Files\Oracle\Java\javapath\java.execmd.exe
User:
admin
Company:
Oracle Corporation
Integrity Level:
MEDIUM
Description:
Java(TM) Platform SE binary
Exit code:
1
Version:
8.0.2710.9
Modules
Images
c:\program files\common files\oracle\java\javapath_target_52116515\java.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
652C:\Windows\system32\cmd.exe /c ""C:\Program Files\Androrat\apktool.bat" "C:\Windows\system32\cmd.exeExplorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
1108"C:\Program Files\Androrat\AndroRat Binder.exe" C:\Program Files\Androrat\AndroRat Binder.exeExplorer.EXE
User:
admin
Integrity Level:
MEDIUM
Description:
AndroRat Binder
Exit code:
0
Version:
1.0.0.4
Modules
Images
c:\program files\androrat\androrat binder.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2160C:\Windows\system32\icacls.exe C:\ProgramData\Oracle\Java\.oracle_jre_usage /grant "everyone":(OI)(CI)MC:\Windows\system32\icacls.exejava.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\icacls.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\ntmarta.dll
2468"C:\Windows\explorer.exe" C:\Windows\explorer.exeExplorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\user32.dll
2516"C:\Program Files\Androrat\AndroRat Binder.exe" C:\Program Files\Androrat\AndroRat Binder.exeExplorer.EXE
User:
admin
Integrity Level:
MEDIUM
Description:
AndroRat Binder
Exit code:
0
Version:
1.0.0.4
Modules
Images
c:\program files\androrat\androrat binder.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2680"C:\Program Files\WinRAR\WinRAR.exe" -elevate4000C:\Program Files\WinRAR\WinRAR.exe
WinRAR.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
HIGH
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
2912"C:\Program Files\Androrat\aapt.exe" C:\Program Files\Androrat\aapt.exeExplorer.EXE
User:
admin
Integrity Level:
MEDIUM
Exit code:
2
Modules
Images
c:\program files\androrat\aapt.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
3356"C:\Windows\System32\cmd.exe" /C "C:\Program Files\Androrat\apktool.bat" C:\Windows\System32\cmd.exe
Explorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\gdi32.dll
3452"C:\Program Files\Androrat\aapt.exe" C:\Program Files\Androrat\aapt.exe
Explorer.EXE
User:
admin
Integrity Level:
HIGH
Exit code:
2
Modules
Images
c:\program files\androrat\aapt.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
Total events
2 137
Read events
2 100
Write events
37
Delete events
0

Modification events

(PID) Process:(4000) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(4000) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(4000) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\171\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(4000) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\AndroratZIP.zip
(PID) Process:(4000) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(4000) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(4000) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(4000) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(4000) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath
Operation:writeName:0
Value:
C:\Program Files
(PID) Process:(4000) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
4
Suspicious files
6
Text files
2 224
Unknown types
132

Dropped files

PID
Process
Filename
Type
2680WinRAR.exeC:\Program Files\Androrat\32323\lib\mips\libtcpdump_bin.soo
MD5:CEEC8823AFD863ABA3092324FF1D24EA
SHA256:348349AB83B16C9F5D3F0794A568416E840BD602A0D92DF534235ACE09AFF6F9
2680WinRAR.exeC:\Program Files\Androrat\32323\apktool.ymltext
MD5:566F30BC690072479E15A1ECBC0590A5
SHA256:4A4160B624DB21C7408AFC2A44FFF7DCB8780B92D7463C6073E62946A10410A4
2680WinRAR.exeC:\Program Files\Androrat\32323\res\drawable-hdpi\abs__ab_bottom_solid_inverse_holo.9.pngimage
MD5:4D8519E343ECAA264178D768349C04FC
SHA256:A9FCFA138AF3B1BBE69FE429A4CB028D2FEBDA9F732972753B2AF6021CE6F06B
2680WinRAR.exeC:\Program Files\Androrat\32323\res\drawable-hdpi\abs__ab_bottom_solid_light_holo.9.pngimage
MD5:3303985D837A591398E4C9132F16A4ED
SHA256:2617EC6AC9E53BEBA74AAD393A5BBE36EC6B29266CCC4F8A7A06F11D66DE8A11
2680WinRAR.exeC:\Program Files\Androrat\32323\res\drawable-hdpi\abs__ab_bottom_transparent_dark_holo.9.pngimage
MD5:0C944BC6FB7DED6DF6B7EB8F85166439
SHA256:7E1841EA7C414348799DC109CA72CDB06FBD9DC8F20B3825DB34E7D4F5FACE43
2680WinRAR.exeC:\Program Files\Androrat\32323\AndroidManifest.xmlxml
MD5:5EC8ACEFAF79D6685578C101B51A2563
SHA256:850D54F360E7E671F3842433E4E46D5352EBD5A057CA4347B3A7F4E5A64D8142
2680WinRAR.exeC:\Program Files\Androrat\32323\res\color\abs__primary_text_holo_dark.xmlxml
MD5:73C597A7BA4D6A957A5A2FD9349CDA8D
SHA256:31C863DBAB2FD7EBC4006B8A662B174ABE707811CBE451CBF292A50A67FA7A48
2680WinRAR.exeC:\Program Files\Androrat\32323\lib\x86\libtcpdump_bin.soo
MD5:BA7AB1F5587E4E7D490DA898C686FE16
SHA256:CD8C75F8F748906D5758032C3429CA02F1B57750A16FCDFE8688CA6BDFBAC9DC
2680WinRAR.exeC:\Program Files\Androrat\32323\res\drawable-hdpi\abs__ab_share_pack_holo_light.9.pngimage
MD5:31E3EE19CF63A051098A6A1C077086F0
SHA256:196C4528BF448BB1CD427E55FDBF060F0ECC69CD91FA8706CEDA193346D8E263
2680WinRAR.exeC:\Program Files\Androrat\32323\res\drawable-hdpi\abs__ab_bottom_transparent_light_holo.9.pngimage
MD5:F692E1F8E4E27599A57B034F56472784
SHA256:FEF77AD4E3857FADCCDF917E849FC02B61765E8D9506AD7C676A96FAE47C095A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info