File name:

Data.zip

Full analysis: https://app.any.run/tasks/fe5c81e9-0a0b-4a2e-a534-e5cad45004ed
Verdict: Malicious activity
Analysis date: July 21, 2021, 17:30:53
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

8F1ABF5CE2132FDDF129B4BC9D30CE75

SHA1:

8A469D3A1AD525982B9F2C1294BA23A3A70ACD89

SHA256:

0BCD7C5A1E0DE347667FCE50077A19CFB5C9BBFA23DEE7239348CACD53B4779C

SSDEEP:

24576:1nTUztSslH6w08p3sO7UO99MZeTlQXUADN20/P4N9e7nz48XE:sS4H7t7R90oIMqncQE

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Acrobat 8 keygen + Activation.exe (PID: 368)
      • Dreamweaver CS3 Keygen + Activation ZWT.exe (PID: 704)
      • Flash CS3 Keygen + Activation ZWT.exe (PID: 1700)
      • Photoshop CS3 Extended Keygen VLK.exe (PID: 3472)
      • Adobe Design Premium CS3 Keygen ZWT.exe (PID: 3336)
      • DreamWeaver CS3 Keygen + Activation.exe (PID: 3304)
      • Flash CS3 Keygen + Activation.exe (PID: 4008)
      • Adobe Premiere Pro 2.0 Keygen + Activation.exe (PID: 680)
      • Photoshop CS3 keygen + Activation ZWT.exe (PID: 3600)
      • Dreamweaver CS3 Keygen VLK.exe (PID: 2492)
      • Encore DVD 2.0 keygen.exe (PID: 1924)
      • InDesign CS3 Keygen VLK.exe (PID: 3676)
      • Adobe Web Premium CS3 Keygen + Activation.exe (PID: 2096)
      • Fireworks CS3 keygen + Activation ZWT.exe (PID: 3832)
      • Photoshop CS3 Activation Keygen.exe (PID: 2348)
      • InCopy CS3 Keygen VLK.exe (PID: 2928)
      • Adobe Web Premium CS3 Keygen + Activation ZWT.exe (PID: 1752)
      • Audition 2.0 keygen.exe (PID: 1044)
      • FireWorks CS3 Keygen + Activation.exe (PID: 1820)
      • Photoshop CS3 Extended Keygen + Activation ZWT.exe (PID: 2912)
      • Fireworks CS3 Keygen VLK.exe (PID: 4012)
      • Contribute CS3 Keygen VLK.exe (PID: 3656)
      • PhotoShop CS3 Extended Keygen + Activation.exe (PID: 4032)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2108)
    • Reads the computer name

      • WinRAR.exe (PID: 2108)
    • Checks supported languages

      • WinRAR.exe (PID: 2108)
      • Acrobat 8 keygen + Activation.exe (PID: 368)
      • Dreamweaver CS3 Keygen + Activation ZWT.exe (PID: 704)
      • Flash CS3 Keygen + Activation ZWT.exe (PID: 1700)
      • Photoshop CS3 Extended Keygen VLK.exe (PID: 3472)
      • DreamWeaver CS3 Keygen + Activation.exe (PID: 3304)
      • Photoshop CS3 keygen + Activation ZWT.exe (PID: 3600)
      • Flash CS3 Keygen + Activation.exe (PID: 4008)
      • Adobe Premiere Pro 2.0 Keygen + Activation.exe (PID: 680)
      • Dreamweaver CS3 Keygen VLK.exe (PID: 2492)
      • Adobe Design Premium CS3 Keygen ZWT.exe (PID: 3336)
      • Encore DVD 2.0 keygen.exe (PID: 1924)
      • InDesign CS3 Keygen VLK.exe (PID: 3676)
      • Fireworks CS3 keygen + Activation ZWT.exe (PID: 3832)
      • Photoshop CS3 Activation Keygen.exe (PID: 2348)
      • InCopy CS3 Keygen VLK.exe (PID: 2928)
      • Adobe Web Premium CS3 Keygen + Activation ZWT.exe (PID: 1752)
      • Adobe Web Premium CS3 Keygen + Activation.exe (PID: 2096)
      • Fireworks CS3 Keygen VLK.exe (PID: 4012)
      • FireWorks CS3 Keygen + Activation.exe (PID: 1820)
      • Contribute CS3 Keygen VLK.exe (PID: 3656)
      • Photoshop CS3 Extended Keygen + Activation ZWT.exe (PID: 2912)
      • Audition 2.0 keygen.exe (PID: 1044)
      • PhotoShop CS3 Extended Keygen + Activation.exe (PID: 4032)
    • Drops a file with too old compile date

      • WinRAR.exe (PID: 2108)
  • INFO

    • Manual execution by user

      • Acrobat 8 keygen + Activation.exe (PID: 368)
      • Flash CS3 Keygen + Activation ZWT.exe (PID: 1700)
      • Photoshop CS3 Extended Keygen VLK.exe (PID: 3472)
      • Dreamweaver CS3 Keygen + Activation ZWT.exe (PID: 704)
      • Adobe Design Premium CS3 Keygen ZWT.exe (PID: 3336)
      • DreamWeaver CS3 Keygen + Activation.exe (PID: 3304)
      • Flash CS3 Keygen + Activation.exe (PID: 4008)
      • Photoshop CS3 keygen + Activation ZWT.exe (PID: 3600)
      • Adobe Premiere Pro 2.0 Keygen + Activation.exe (PID: 680)
      • Dreamweaver CS3 Keygen VLK.exe (PID: 2492)
      • InCopy CS3 Keygen VLK.exe (PID: 2928)
      • InDesign CS3 Keygen VLK.exe (PID: 3676)
      • Encore DVD 2.0 keygen.exe (PID: 1924)
      • Adobe Web Premium CS3 Keygen + Activation.exe (PID: 2096)
      • Fireworks CS3 keygen + Activation ZWT.exe (PID: 3832)
      • Photoshop CS3 Activation Keygen.exe (PID: 2348)
      • Adobe Web Premium CS3 Keygen + Activation ZWT.exe (PID: 1752)
      • Audition 2.0 keygen.exe (PID: 1044)
      • Photoshop CS3 Extended Keygen + Activation ZWT.exe (PID: 2912)
      • Contribute CS3 Keygen VLK.exe (PID: 3656)
      • Fireworks CS3 Keygen VLK.exe (PID: 4012)
      • FireWorks CS3 Keygen + Activation.exe (PID: 1820)
      • PhotoShop CS3 Extended Keygen + Activation.exe (PID: 4032)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: Acrobat 8 keygen + Activation.exe
ZipUncompressedSize: 89088
ZipCompressedSize: 71836
ZipCRC: 0x5a86a88c
ZipModifyDate: 2021:07:21 10:29:16
ZipCompression: Deflated
ZipBitFlag: 0x0001
ZipRequiredVersion: 20
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
57
Monitored processes
24
Malicious processes
24
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe acrobat 8 keygen + activation.exe no specs dreamweaver cs3 keygen + activation zwt.exe no specs flash cs3 keygen + activation zwt.exe no specs photoshop cs3 extended keygen vlk.exe no specs adobe design premium cs3 keygen zwt.exe no specs dreamweaver cs3 keygen + activation.exe no specs flash cs3 keygen + activation.exe no specs photoshop cs3 keygen + activation zwt.exe no specs adobe premiere pro 2.0 keygen + activation.exe no specs dreamweaver cs3 keygen vlk.exe no specs incopy cs3 keygen vlk.exe no specs adobe web premium cs3 keygen + activation zwt.exe no specs encore dvd 2.0 keygen.exe no specs indesign cs3 keygen vlk.exe no specs adobe web premium cs3 keygen + activation.exe no specs fireworks cs3 keygen + activation zwt.exe no specs photoshop cs3 activation keygen.exe no specs audition 2.0 keygen.exe no specs fireworks cs3 keygen + activation.exe no specs photoshop cs3 extended keygen + activation zwt.exe no specs contribute cs3 keygen vlk.exe no specs fireworks cs3 keygen vlk.exe no specs photoshop cs3 extended keygen + activation.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
368"C:\Users\admin\Desktop\Acrobat 8 keygen + Activation.exe" C:\Users\admin\Desktop\Acrobat 8 keygen + Activation.exeExplorer.EXE
User:
admin
Integrity Level:
MEDIUM
Description:
Adobe Acrobat 8 Keygen
Exit code:
2
Version:
9, 1, 1, 0
Modules
Images
c:\users\admin\desktop\acrobat 8 keygen + activation.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\user32.dll
680"C:\Users\admin\Desktop\Adobe Premiere Pro 2.0 Keygen + Activation.exe" C:\Users\admin\Desktop\Adobe Premiere Pro 2.0 Keygen + Activation.exeExplorer.EXE
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\desktop\adobe premiere pro 2.0 keygen + activation.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imm32.dll
704"C:\Users\admin\Desktop\Dreamweaver CS3 Keygen + Activation ZWT.exe" C:\Users\admin\Desktop\Dreamweaver CS3 Keygen + Activation ZWT.exeExplorer.EXE
User:
admin
Integrity Level:
MEDIUM
Description:
KGTemplate MFC Application
Exit code:
2
Version:
1, 0, 0, 1
Modules
Images
c:\users\admin\desktop\dreamweaver cs3 keygen + activation zwt.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
1044"C:\Users\admin\Desktop\Audition 2.0 keygen.exe" C:\Users\admin\Desktop\Audition 2.0 keygen.exeExplorer.EXE
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\audition 2.0 keygen.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1700"C:\Users\admin\Desktop\Flash CS3 Keygen + Activation ZWT.exe" C:\Users\admin\Desktop\Flash CS3 Keygen + Activation ZWT.exeExplorer.EXE
User:
admin
Integrity Level:
MEDIUM
Description:
KGTemplate MFC Application
Exit code:
2
Version:
1, 0, 0, 1
Modules
Images
c:\users\admin\desktop\flash cs3 keygen + activation zwt.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\shlwapi.dll
1752"C:\Users\admin\Desktop\Adobe Web Premium CS3 Keygen + Activation ZWT.exe" C:\Users\admin\Desktop\Adobe Web Premium CS3 Keygen + Activation ZWT.exeExplorer.EXE
User:
admin
Integrity Level:
MEDIUM
Description:
KGTemplate MFC Application
Exit code:
2
Version:
1, 0, 0, 1
Modules
Images
c:\users\admin\desktop\adobe web premium cs3 keygen + activation zwt.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1820"C:\Users\admin\Desktop\FireWorks CS3 Keygen + Activation.exe" C:\Users\admin\Desktop\FireWorks CS3 Keygen + Activation.exeExplorer.EXE
User:
admin
Integrity Level:
MEDIUM
Description:
Adobe FireWorks CS3 Keygen
Exit code:
2
Version:
1, 0, 0, 1
Modules
Images
c:\users\admin\desktop\fireworks cs3 keygen + activation.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1924"C:\Users\admin\Desktop\Encore DVD 2.0 keygen.exe" C:\Users\admin\Desktop\Encore DVD 2.0 keygen.exeExplorer.EXE
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\desktop\encore dvd 2.0 keygen.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2096"C:\Users\admin\Desktop\Adobe Web Premium CS3 Keygen + Activation.exe" C:\Users\admin\Desktop\Adobe Web Premium CS3 Keygen + Activation.exeExplorer.EXE
User:
admin
Integrity Level:
MEDIUM
Description:
Adobe CS3 Web Premium Keygen
Exit code:
2
Version:
9, 9, 1, 0
Modules
Images
c:\users\admin\desktop\adobe web premium cs3 keygen + activation.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2108"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Data.zip"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
1 341
Read events
1 318
Write events
23
Delete events
0

Modification events

(PID) Process:(2108) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2108) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2108) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2108) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(2108) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Data.zip
(PID) Process:(2108) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2108) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2108) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2108) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2108) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath
Operation:writeName:0
Value:
C:\Users\admin\Desktop
Executable files
23
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
2108WinRAR.exeC:\Users\admin\Desktop\Adobe Premiere Pro 2.0 Keygen + Activation.exeexecutable
MD5:768638EEEA558E09C67F7DE53E4BFC0A
SHA256:D045F3E086414B8132251F394A2CE668A0A651B65B2130EC201E0C90414E0036
2108WinRAR.exeC:\Users\admin\Desktop\Adobe Design Premium CS3 Keygen ZWT.exeexecutable
MD5:296F5E28714414230C3763CF1F9B0880
SHA256:0DBD5B617CE2207BD05F3B8D084E35AEC782A834735EDE7DC07759A802DCC9D9
2108WinRAR.exeC:\Users\admin\Desktop\Dreamweaver CS3 Keygen VLK.exeexecutable
MD5:4BB84D9F3DEAD6C81D1999AE3D24633C
SHA256:A4C11FF462722B1560269D3704B1E5ED2CCC799EDA2130E6F4FB73008CD0E3A5
2108WinRAR.exeC:\Users\admin\Desktop\Encore DVD 2.0 keygen.exeexecutable
MD5:A202852FBDA797041D958BFB11349A50
SHA256:D2A6B39F155677A42EBA1E6B186934BEFAFD7D81102F97B8B4FBD349BB72C144
2108WinRAR.exeC:\Users\admin\Desktop\Fireworks CS3 keygen + Activation ZWT.exeexecutable
MD5:8829F6159C6ACA800F02E7DA39695766
SHA256:CBDB9A4EC355726890CA48AB28EF1A0B7F3CBBC1F159C7E8BDD37893E175B777
2108WinRAR.exeC:\Users\admin\Desktop\FireWorks CS3 Keygen + Activation.exeexecutable
MD5:C89B9BD61B8824A8F781839F59F507E0
SHA256:785A601E6A087779702BCCA7D1D0C4A346644260FA274DB88B87731331356438
2108WinRAR.exeC:\Users\admin\Desktop\Flash CS3 Keygen + Activation ZWT.exeexecutable
MD5:E3C7D489013B51C671AA79C9068A2A00
SHA256:5EA232AC5EBCA4584F8689D5A1ED466404272A5C5496F41934537504368B5DA2
2108WinRAR.exeC:\Users\admin\Desktop\InCopy CS3 Keygen VLK.exeexecutable
MD5:2FF3F7C609644B1C1175B010449A3DF2
SHA256:20DD9EDA60114C292F00171063CB06B5157FD4E64A34F82F6C29865F219A1AD0
2108WinRAR.exeC:\Users\admin\Desktop\Photoshop CS3 Extended Keygen + Activation ZWT.exeexecutable
MD5:C2FD1FE04080C2969237F6E361002787
SHA256:476150257BA1187892754A3CE31EE29DEAAA436EE522F6F514A9E284BF28BF1A
2108WinRAR.exeC:\Users\admin\Desktop\Flash CS3 Keygen + Activation.exeexecutable
MD5:97009D04FB92911DC377315F6E04CC4D
SHA256:2EBE5BE779C70C381D8272CCC283477D17B87AC347A2FD8A5D659A4EBBA399C4
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info