| File name: | GoldenEyeRAT1.6.6RELEASE.zip |
| Full analysis: | https://app.any.run/tasks/a858c3e8-a6ee-4de9-b84a-757f14e44d8b |
| Verdict: | Malicious activity |
| Threats: | njRAT is a remote access trojan. It is one of the most widely accessible RATs on the market that features an abundance of educational information. Interested attackers can even find tutorials on YouTube. This allows it to become one of the most popular RATs in the world. |
| Analysis date: | December 06, 2018, 07:09:18 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | F7670BB96A27A041E10E3BA84DF0D011 |
| SHA1: | 37C08B7F6A8E38B62DA83A680B412BD5AA4B5864 |
| SHA256: | 05F30945508D84B63809CC8EA7630FD5BBA2750CA21CB734E08D5E993EA5C01F |
| SSDEEP: | 24576:xYEYAIG/xvmk2GYNu5nPmoaEMwV4FC15o:OlAIGxBYNupPmoaEdVy |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | None |
| ZipModifyDate: | 2018:12:05 13:13:14 |
| ZipCRC: | 0x00000000 |
| ZipCompressedSize: | - |
| ZipUncompressedSize: | - |
| ZipFileName: | GoldenEyeRAT1.6.6RELEASE/Golden Eye RAT Client/ |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 128 | "C:\Users\admin\Desktop\GoldenEyeRAT1.6.6RELEASE\Golden Eye RAT Client\GoldenEye Remote Administration Tool.exe" 0 | C:\Users\admin\Desktop\GoldenEyeRAT1.6.6RELEASE\Golden Eye RAT Client\GoldenEye Remote Administration Tool.exe | — | GoldenEye Remote Administration Tool.exe | |||||||||||
User: admin Company: BreakingSecurity.net Integrity Level: HIGH Exit code: 0 Version: 1.01.0001 Modules
| |||||||||||||||
| 312 | "C:\Users\admin\Desktop\GoldenEyeRAT1.6.6RELEASE\Golden Eye RAT Client\GoldenEye Remote Administration Tool.exe" 0 | C:\Users\admin\Desktop\GoldenEyeRAT1.6.6RELEASE\Golden Eye RAT Client\GoldenEye Remote Administration Tool.exe | — | GoldenEye Remote Administration Tool.exe | |||||||||||
User: admin Company: BreakingSecurity.net Integrity Level: HIGH Exit code: 0 Version: 1.01.0001 Modules
| |||||||||||||||
| 312 | "C:\Users\admin\Desktop\GoldenEyeRAT1.6.6RELEASE\Golden Eye RAT Client\GoldenEye Remote Administration Tool.exe" 0 | C:\Users\admin\Desktop\GoldenEyeRAT1.6.6RELEASE\Golden Eye RAT Client\GoldenEye Remote Administration Tool.exe | — | GoldenEye Remote Administration Tool.exe | |||||||||||
User: admin Company: BreakingSecurity.net Integrity Level: HIGH Exit code: 0 Version: 1.01.0001 Modules
| |||||||||||||||
| 316 | "C:\Users\admin\Desktop\GoldenEyeRAT1.6.6RELEASE\Golden Eye RAT Client\GoldenEye Remote Administration Tool.exe" 0 | C:\Users\admin\Desktop\GoldenEyeRAT1.6.6RELEASE\Golden Eye RAT Client\GoldenEye Remote Administration Tool.exe | — | GoldenEye Remote Administration Tool.exe | |||||||||||
User: admin Company: BreakingSecurity.net Integrity Level: HIGH Exit code: 0 Version: 1.01.0001 Modules
| |||||||||||||||
| 340 | "C:\Windows\InitSetup.exe" 0 | C:\Windows\InitSetup.exe | GoldenEye Remote Administration Tool.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 564 | "C:\Users\admin\Desktop\GoldenEyeRAT1.6.6RELEASE\Golden Eye RAT Client\GoldenEye Remote Administration Tool.exe" 0 | C:\Users\admin\Desktop\GoldenEyeRAT1.6.6RELEASE\Golden Eye RAT Client\GoldenEye Remote Administration Tool.exe | — | GoldenEye Remote Administration Tool.exe | |||||||||||
User: admin Company: BreakingSecurity.net Integrity Level: HIGH Exit code: 0 Version: 1.01.0001 Modules
| |||||||||||||||
| 636 | "C:\Users\admin\WindowsGrfxSrvs\WindowsGrfxSrvs.exe" | C:\Users\admin\WindowsGrfxSrvs\WindowsGrfxSrvs.exe | — | InitSetup.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 684 | "C:\Windows\InitSetup.exe" 0 | C:\Windows\InitSetup.exe | — | GoldenEye Remote Administration Tool.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 788 | "C:\Users\admin\Desktop\GoldenEyeRAT1.6.6RELEASE\Golden Eye RAT Client\GoldenEye Remote Administration Tool.exe" 0 | C:\Users\admin\Desktop\GoldenEyeRAT1.6.6RELEASE\Golden Eye RAT Client\GoldenEye Remote Administration Tool.exe | — | GoldenEye Remote Administration Tool.exe | |||||||||||
User: admin Company: BreakingSecurity.net Integrity Level: HIGH Exit code: 0 Version: 1.01.0001 Modules
| |||||||||||||||
| 904 | "C:\Windows\InitSetup.exe" 0 | C:\Windows\InitSetup.exe | — | GoldenEye Remote Administration Tool.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| (PID) Process: | (2844) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (2844) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (2844) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2844) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\GoldenEyeRAT1.6.6RELEASE.zip | |||
| (PID) Process: | (2844) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2844) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2844) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2844) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (2844) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin |
| Operation: | write | Name: | Placement |
Value: 2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000 | |||
| (PID) Process: | (2844) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\General |
| Operation: | write | Name: | LastFolder |
Value: C:\Users\admin\AppData\Local\Temp | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2844 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2844.19658\GoldenEyeRAT1.6.6RELEASE\Golden Eye RAT Client\Configuration\FileSearcher.ini | — | |
MD5:— | SHA256:— | |||
| 2844 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2844.19658\GoldenEyeRAT1.6.6RELEASE\Golden Eye RAT Client\Configuration\networkcontrol.ini | — | |
MD5:— | SHA256:— | |||
| 2844 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2844.19658\GoldenEyeRAT1.6.6RELEASE\Golden Eye RAT Client\Configuration\On Join Commands.ini | — | |
MD5:— | SHA256:— | |||
| 2844 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2844.19658\GoldenEyeRAT1.6.6RELEASE\Golden Eye RAT Client\Configuration\settings.ini | — | |
MD5:— | SHA256:— | |||
| 2844 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2844.19658\GoldenEyeRAT1.6.6RELEASE\Golden Eye RAT Client\Data\GeoIP.dat | — | |
MD5:— | SHA256:— | |||
| 2844 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2844.19658\GoldenEyeRAT1.6.6RELEASE\Golden Eye RAT Client\GoldenEye Remote Administration Tool.exe | — | |
MD5:— | SHA256:— | |||
| 2844 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2844.19658\GoldenEyeRAT1.6.6RELEASE\Golden Eye RAT Client\VelyseTheme.dll | — | |
MD5:— | SHA256:— | |||
| 2844 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2844.19658\GoldenEyeRAT1.6.6RELEASE\Lic Server\Clients\Hostah\hwid.txt | — | |
MD5:— | SHA256:— | |||
| 2844 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2844.19658\GoldenEyeRAT1.6.6RELEASE\Lic Server\Clients\Hostah\password.txt | — | |
MD5:— | SHA256:— | |||
| 2844 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2844.19658\GoldenEyeRAT1.6.6RELEASE\Lic Server\GoldenEye Licensing Server.exe | — | |
MD5:— | SHA256:— | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2944 | WindowsGrfxSrvs.exe | 104.20.208.21:443 | pastebin.com | Cloudflare Inc | US | shared |
2944 | WindowsGrfxSrvs.exe | 70.46.121.187:9000 | citysinks.com | Windstream Communications Inc | US | malicious |
Domain | IP | Reputation |
|---|---|---|
pastebin.com |
| malicious |
citysinks.com |
| malicious |