| File name: | Kraken.bin.zip |
| Full analysis: | https://app.any.run/tasks/8a8d5cf5-ebb9-442f-880f-f96a9d0f6d6b |
| Verdict: | Malicious activity |
| Threats: | Kraken is a trojan malware with infostealing capabilities that was first spotted in May of 2023. The malware can perform a wide range of malicious activities, including logging users’ keystrokes. The data then can be sent to the attacker using several protocols. The operators behind the Kraken stealer usually distribute it via phishing emails. |
| Analysis date: | January 11, 2019, 13:16:34 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | 2A31FC84EBA675C8AA74673FD7EFFD9D |
| SHA1: | 40479BCBDB8D3791B7DFA38381923412BC988E20 |
| SHA256: | 094922019198988CA8554CDD1D9C29D72E1DD5A4FBF3F665AEBC454B7F02ECA9 |
| SSDEEP: | 768:nfQfXA9MPEXvLFYcVBm7Lu166D1NR/aJYvmsBx/zn+y8pSyc+4enfLWu6whg4:nIfX0MPaBkLufDnAJur/8cA4nc |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 788 |
|---|---|
| ZipBitFlag: | 0x0001 |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2018:10:04 13:36:26 |
| ZipCRC: | 0x03dca1fc |
| ZipCompressedSize: | 48561 |
| ZipUncompressedSize: | 100864 |
| ZipFileName: | 2018-10-04_19-37-40.bin |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2276 | C:\ProgramData\sdelete.exe -c -z C: | C:\ProgramData\sdelete.exe | — | cmd.exe | |||||||||||
User: admin Company: Sysinternals - www.sysinternals.com Integrity Level: HIGH Description: Secure file delete Exit code: 0 Version: 2.02 Modules
| |||||||||||||||
| 2572 | "C:\Windows\explorer.exe" | C:\Windows\explorer.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2656 | "C:\Users\admin\AppData\Local\Temp\krakentemp0000.exe" | C:\Users\admin\AppData\Local\Temp\krakentemp0000.exe | eventvwr.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Version: 1.1.7.9 Modules
| |||||||||||||||
| 2716 | "C:\Windows\System32\eventvwr.exe" | C:\Windows\System32\eventvwr.exe | — | x.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Event Viewer Snapin Launcher Exit code: 3221226540 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2728 | "tasklist" /V /FO CSV | C:\Windows\system32\tasklist.exe | — | krakentemp0000.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Lists the current running tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2816 | ping 127.0.0.1 -n 3 | C:\Windows\system32\PING.EXE | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: TCP/IP Ping Command Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2836 | "C:\Windows\System32\cmd.exe" /C ping 127.0.0.1 -n 3 > NUL&&del /Q /F /S "C:\Users\admin\AppData\Local\Temp\krakentemp0000.exe" | C:\Windows\System32\cmd.exe | — | krakentemp0000.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2860 | cmd.exe /c C:\ProgramData\sdelete.exe -c -z C: | C:\Windows\system32\cmd.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2920 | REG ADD "HKEY_CURRENT_USER\Software\Sysinternals\SDelete" | C:\Windows\system32\reg.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Registry Console Tool Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2932 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Kraken.bin.zip" | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| (PID) Process: | (2932) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (2932) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (2932) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2932) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Kraken.bin.zip | |||
| (PID) Process: | (2932) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2932) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2932) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2932) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (2932) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface |
| Operation: | write | Name: | ShowPassword |
Value: 0 | |||
| (PID) Process: | (3060) x.exe | Key: | HKEY_CLASSES_ROOT\mscfile\shell\open\command |
| Operation: | write | Name: | |
Value: C:\Users\admin\AppData\Local\Temp\krakentemp0000.exe | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2932 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb2932.12625\2018-10-04_19-37-40.bin | — | |
MD5:— | SHA256:— | |||
| 2656 | krakentemp0000.exe | C:\Users\admin\Contacts\admin.contact | — | |
MD5:— | SHA256:— | |||
| 2656 | krakentemp0000.exe | C:\Users\admin\Desktop\advicepopulation.jpg | — | |
MD5:— | SHA256:— | |||
| 2656 | krakentemp0000.exe | C:\Users\admin\Desktop\eventcoffee.jpg | — | |
MD5:— | SHA256:— | |||
| 2656 | krakentemp0000.exe | C:\Users\admin\Desktop\groupsthan.rtf | — | |
MD5:— | SHA256:— | |||
| 2656 | krakentemp0000.exe | C:\Users\admin\Desktop\independentfavorite.rtf | — | |
MD5:— | SHA256:— | |||
| 2656 | krakentemp0000.exe | C:\Users\admin\Desktop\jewelryexecutive.png | — | |
MD5:— | SHA256:— | |||
| 2656 | krakentemp0000.exe | C:\Users\admin\Desktop\ladetail.png | — | |
MD5:— | SHA256:— | |||
| 2656 | krakentemp0000.exe | C:\Users\admin\Desktop\mediashort.png | — | |
MD5:— | SHA256:— | |||
| 2656 | krakentemp0000.exe | C:\Users\admin\Desktop\paymentitaly.png | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2656 | krakentemp0000.exe | GET | 302 | 104.28.12.103:80 | http://blasze.tk/CN18R3 | US | text | 51 b | malicious |
2656 | krakentemp0000.exe | GET | 302 | 104.28.12.103:80 | http://blasze.tk/CN18R3 | US | text | 51 b | malicious |
2656 | krakentemp0000.exe | GET | 200 | 172.217.16.132:80 | http://www.google.com/ | US | html | 12.1 Kb | malicious |
2656 | krakentemp0000.exe | GET | 200 | 172.217.16.132:80 | http://www.google.com/ | US | html | 12.1 Kb | malicious |
2656 | krakentemp0000.exe | GET | 301 | 172.217.22.46:80 | http://google.com/ | US | html | 219 b | whitelisted |
2656 | krakentemp0000.exe | GET | 301 | 172.217.22.46:80 | http://google.com/ | US | html | 219 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2656 | krakentemp0000.exe | 216.239.38.21:443 | ipinfo.io | Google Inc. | US | whitelisted |
2656 | krakentemp0000.exe | 104.28.12.103:80 | blasze.tk | Cloudflare Inc | US | shared |
2656 | krakentemp0000.exe | 172.217.22.46:80 | — | Google Inc. | US | whitelisted |
2656 | krakentemp0000.exe | 172.217.16.132:80 | www.google.com | Google Inc. | US | whitelisted |
2656 | krakentemp0000.exe | 152.199.19.160:443 | download.sysinternals.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
ipinfo.io |
| shared |
blasze.tk |
| malicious |
www.google.com |
| malicious |
download.sysinternals.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2656 | krakentemp0000.exe | A Network Trojan was detected | ET POLICY Possible External IP Lookup Domain Observed in SNI (ipinfo. io) |
2656 | krakentemp0000.exe | Potential Corporate Privacy Violation | ET POLICY Possible External IP Lookup SSL Cert Observed (ipinfo.io) |
2656 | krakentemp0000.exe | A Network Trojan was detected | ET TROJAN [PTsecurity] Kraken Ransomware Start Activity 2 |
2656 | krakentemp0000.exe | A Network Trojan was detected | SC RANSOMWARE Ransomware Kraken Win32 |
2656 | krakentemp0000.exe | A Network Trojan was detected | MALWARE [PTsecurity] Kraken Cryptor |
2656 | krakentemp0000.exe | A Network Trojan was detected | MALWARE [PTsecurity] Ransomware.Kraken_Cryptor UA |
2656 | krakentemp0000.exe | A Network Trojan was detected | MALWARE [PTsecurity] Ransomware.Kraken_Cryptor URL |
2656 | krakentemp0000.exe | Potentially Bad Traffic | ET POLICY HTTP Request to a *.tk domain |
2656 | krakentemp0000.exe | A Network Trojan was detected | ET TROJAN [PTsecurity] Kraken Ransomware Start Activity 2 |
2656 | krakentemp0000.exe | A Network Trojan was detected | SC RANSOMWARE Ransomware Kraken Win32 |