File name:

Data.zip

Full analysis: https://app.any.run/tasks/fe5c81e9-0a0b-4a2e-a534-e5cad45004ed
Verdict: Malicious activity
Analysis date: July 21, 2021, 17:30:53
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

8F1ABF5CE2132FDDF129B4BC9D30CE75

SHA1:

8A469D3A1AD525982B9F2C1294BA23A3A70ACD89

SHA256:

0BCD7C5A1E0DE347667FCE50077A19CFB5C9BBFA23DEE7239348CACD53B4779C

SSDEEP:

24576:1nTUztSslH6w08p3sO7UO99MZeTlQXUADN20/P4N9e7nz48XE:sS4H7t7R90oIMqncQE

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Flash CS3 Keygen + Activation ZWT.exe (PID: 1700)
      • Dreamweaver CS3 Keygen + Activation ZWT.exe (PID: 704)
      • Acrobat 8 keygen + Activation.exe (PID: 368)
      • Photoshop CS3 Extended Keygen VLK.exe (PID: 3472)
      • Adobe Design Premium CS3 Keygen ZWT.exe (PID: 3336)
      • DreamWeaver CS3 Keygen + Activation.exe (PID: 3304)
      • Adobe Premiere Pro 2.0 Keygen + Activation.exe (PID: 680)
      • Flash CS3 Keygen + Activation.exe (PID: 4008)
      • Photoshop CS3 keygen + Activation ZWT.exe (PID: 3600)
      • Dreamweaver CS3 Keygen VLK.exe (PID: 2492)
      • InCopy CS3 Keygen VLK.exe (PID: 2928)
      • Encore DVD 2.0 keygen.exe (PID: 1924)
      • InDesign CS3 Keygen VLK.exe (PID: 3676)
      • Adobe Web Premium CS3 Keygen + Activation.exe (PID: 2096)
      • Fireworks CS3 keygen + Activation ZWT.exe (PID: 3832)
      • Adobe Web Premium CS3 Keygen + Activation ZWT.exe (PID: 1752)
      • Audition 2.0 keygen.exe (PID: 1044)
      • FireWorks CS3 Keygen + Activation.exe (PID: 1820)
      • Photoshop CS3 Extended Keygen + Activation ZWT.exe (PID: 2912)
      • Contribute CS3 Keygen VLK.exe (PID: 3656)
      • Photoshop CS3 Activation Keygen.exe (PID: 2348)
      • Fireworks CS3 Keygen VLK.exe (PID: 4012)
      • PhotoShop CS3 Extended Keygen + Activation.exe (PID: 4032)
  • SUSPICIOUS

    • Checks supported languages

      • Dreamweaver CS3 Keygen + Activation ZWT.exe (PID: 704)
      • Acrobat 8 keygen + Activation.exe (PID: 368)
      • WinRAR.exe (PID: 2108)
      • Flash CS3 Keygen + Activation ZWT.exe (PID: 1700)
      • Photoshop CS3 Extended Keygen VLK.exe (PID: 3472)
      • Adobe Design Premium CS3 Keygen ZWT.exe (PID: 3336)
      • DreamWeaver CS3 Keygen + Activation.exe (PID: 3304)
      • Flash CS3 Keygen + Activation.exe (PID: 4008)
      • Photoshop CS3 keygen + Activation ZWT.exe (PID: 3600)
      • Dreamweaver CS3 Keygen VLK.exe (PID: 2492)
      • Adobe Premiere Pro 2.0 Keygen + Activation.exe (PID: 680)
      • Encore DVD 2.0 keygen.exe (PID: 1924)
      • InDesign CS3 Keygen VLK.exe (PID: 3676)
      • Adobe Web Premium CS3 Keygen + Activation.exe (PID: 2096)
      • Fireworks CS3 keygen + Activation ZWT.exe (PID: 3832)
      • InCopy CS3 Keygen VLK.exe (PID: 2928)
      • Adobe Web Premium CS3 Keygen + Activation ZWT.exe (PID: 1752)
      • Audition 2.0 keygen.exe (PID: 1044)
      • FireWorks CS3 Keygen + Activation.exe (PID: 1820)
      • Photoshop CS3 Extended Keygen + Activation ZWT.exe (PID: 2912)
      • Photoshop CS3 Activation Keygen.exe (PID: 2348)
      • Contribute CS3 Keygen VLK.exe (PID: 3656)
      • Fireworks CS3 Keygen VLK.exe (PID: 4012)
      • PhotoShop CS3 Extended Keygen + Activation.exe (PID: 4032)
    • Drops a file with too old compile date

      • WinRAR.exe (PID: 2108)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2108)
    • Reads the computer name

      • WinRAR.exe (PID: 2108)
  • INFO

    • Manual execution by user

      • Flash CS3 Keygen + Activation ZWT.exe (PID: 1700)
      • Dreamweaver CS3 Keygen + Activation ZWT.exe (PID: 704)
      • Acrobat 8 keygen + Activation.exe (PID: 368)
      • Photoshop CS3 Extended Keygen VLK.exe (PID: 3472)
      • Adobe Design Premium CS3 Keygen ZWT.exe (PID: 3336)
      • DreamWeaver CS3 Keygen + Activation.exe (PID: 3304)
      • Flash CS3 Keygen + Activation.exe (PID: 4008)
      • Photoshop CS3 keygen + Activation ZWT.exe (PID: 3600)
      • Adobe Premiere Pro 2.0 Keygen + Activation.exe (PID: 680)
      • Dreamweaver CS3 Keygen VLK.exe (PID: 2492)
      • InDesign CS3 Keygen VLK.exe (PID: 3676)
      • Adobe Web Premium CS3 Keygen + Activation.exe (PID: 2096)
      • Fireworks CS3 keygen + Activation ZWT.exe (PID: 3832)
      • Photoshop CS3 Activation Keygen.exe (PID: 2348)
      • InCopy CS3 Keygen VLK.exe (PID: 2928)
      • Encore DVD 2.0 keygen.exe (PID: 1924)
      • Adobe Web Premium CS3 Keygen + Activation ZWT.exe (PID: 1752)
      • FireWorks CS3 Keygen + Activation.exe (PID: 1820)
      • Photoshop CS3 Extended Keygen + Activation ZWT.exe (PID: 2912)
      • Contribute CS3 Keygen VLK.exe (PID: 3656)
      • Fireworks CS3 Keygen VLK.exe (PID: 4012)
      • Audition 2.0 keygen.exe (PID: 1044)
      • PhotoShop CS3 Extended Keygen + Activation.exe (PID: 4032)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: Acrobat 8 keygen + Activation.exe
ZipUncompressedSize: 89088
ZipCompressedSize: 71836
ZipCRC: 0x5a86a88c
ZipModifyDate: 2021:07:21 10:29:16
ZipCompression: Deflated
ZipBitFlag: 0x0001
ZipRequiredVersion: 20
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
57
Monitored processes
24
Malicious processes
24
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe acrobat 8 keygen + activation.exe no specs dreamweaver cs3 keygen + activation zwt.exe no specs flash cs3 keygen + activation zwt.exe no specs photoshop cs3 extended keygen vlk.exe no specs adobe design premium cs3 keygen zwt.exe no specs dreamweaver cs3 keygen + activation.exe no specs flash cs3 keygen + activation.exe no specs photoshop cs3 keygen + activation zwt.exe no specs adobe premiere pro 2.0 keygen + activation.exe no specs dreamweaver cs3 keygen vlk.exe no specs incopy cs3 keygen vlk.exe no specs adobe web premium cs3 keygen + activation zwt.exe no specs encore dvd 2.0 keygen.exe no specs indesign cs3 keygen vlk.exe no specs adobe web premium cs3 keygen + activation.exe no specs fireworks cs3 keygen + activation zwt.exe no specs photoshop cs3 activation keygen.exe no specs audition 2.0 keygen.exe no specs fireworks cs3 keygen + activation.exe no specs photoshop cs3 extended keygen + activation zwt.exe no specs contribute cs3 keygen vlk.exe no specs fireworks cs3 keygen vlk.exe no specs photoshop cs3 extended keygen + activation.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
368"C:\Users\admin\Desktop\Acrobat 8 keygen + Activation.exe" C:\Users\admin\Desktop\Acrobat 8 keygen + Activation.exeExplorer.EXE
User:
admin
Integrity Level:
MEDIUM
Description:
Adobe Acrobat 8 Keygen
Exit code:
2
Version:
9, 1, 1, 0
Modules
Images
c:\users\admin\desktop\acrobat 8 keygen + activation.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\user32.dll
680"C:\Users\admin\Desktop\Adobe Premiere Pro 2.0 Keygen + Activation.exe" C:\Users\admin\Desktop\Adobe Premiere Pro 2.0 Keygen + Activation.exeExplorer.EXE
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\desktop\adobe premiere pro 2.0 keygen + activation.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imm32.dll
704"C:\Users\admin\Desktop\Dreamweaver CS3 Keygen + Activation ZWT.exe" C:\Users\admin\Desktop\Dreamweaver CS3 Keygen + Activation ZWT.exeExplorer.EXE
User:
admin
Integrity Level:
MEDIUM
Description:
KGTemplate MFC Application
Exit code:
2
Version:
1, 0, 0, 1
Modules
Images
c:\users\admin\desktop\dreamweaver cs3 keygen + activation zwt.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
1044"C:\Users\admin\Desktop\Audition 2.0 keygen.exe" C:\Users\admin\Desktop\Audition 2.0 keygen.exeExplorer.EXE
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\audition 2.0 keygen.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1700"C:\Users\admin\Desktop\Flash CS3 Keygen + Activation ZWT.exe" C:\Users\admin\Desktop\Flash CS3 Keygen + Activation ZWT.exeExplorer.EXE
User:
admin
Integrity Level:
MEDIUM
Description:
KGTemplate MFC Application
Exit code:
2
Version:
1, 0, 0, 1
Modules
Images
c:\users\admin\desktop\flash cs3 keygen + activation zwt.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\shlwapi.dll
1752"C:\Users\admin\Desktop\Adobe Web Premium CS3 Keygen + Activation ZWT.exe" C:\Users\admin\Desktop\Adobe Web Premium CS3 Keygen + Activation ZWT.exeExplorer.EXE
User:
admin
Integrity Level:
MEDIUM
Description:
KGTemplate MFC Application
Exit code:
2
Version:
1, 0, 0, 1
Modules
Images
c:\users\admin\desktop\adobe web premium cs3 keygen + activation zwt.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1820"C:\Users\admin\Desktop\FireWorks CS3 Keygen + Activation.exe" C:\Users\admin\Desktop\FireWorks CS3 Keygen + Activation.exeExplorer.EXE
User:
admin
Integrity Level:
MEDIUM
Description:
Adobe FireWorks CS3 Keygen
Exit code:
2
Version:
1, 0, 0, 1
Modules
Images
c:\users\admin\desktop\fireworks cs3 keygen + activation.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1924"C:\Users\admin\Desktop\Encore DVD 2.0 keygen.exe" C:\Users\admin\Desktop\Encore DVD 2.0 keygen.exeExplorer.EXE
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\desktop\encore dvd 2.0 keygen.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2096"C:\Users\admin\Desktop\Adobe Web Premium CS3 Keygen + Activation.exe" C:\Users\admin\Desktop\Adobe Web Premium CS3 Keygen + Activation.exeExplorer.EXE
User:
admin
Integrity Level:
MEDIUM
Description:
Adobe CS3 Web Premium Keygen
Exit code:
2
Version:
9, 9, 1, 0
Modules
Images
c:\users\admin\desktop\adobe web premium cs3 keygen + activation.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2108"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Data.zip"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
1 341
Read events
1 318
Write events
23
Delete events
0

Modification events

(PID) Process:(2108) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2108) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2108) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2108) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(2108) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Data.zip
(PID) Process:(2108) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2108) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2108) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2108) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2108) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath
Operation:writeName:0
Value:
C:\Users\admin\Desktop
Executable files
23
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
2108WinRAR.exeC:\Users\admin\Desktop\Contribute CS3 Keygen VLK.exeexecutable
MD5:BEFAFE82FFA951197DA4DC92A96A9BE9
SHA256:BE8AEC9917E90ACEB36ECBB7FD39AC8E76078D823E34023CA9C68C815769049B
2108WinRAR.exeC:\Users\admin\Desktop\Dreamweaver CS3 Keygen + Activation ZWT.exeexecutable
MD5:169D11DEC220EDC1831B01F3A733C8D1
SHA256:CCF9C93B94DC86A9ECA7722559579A2B4208B7224336530F5DE9AD7FCDE2A4B5
2108WinRAR.exeC:\Users\admin\Desktop\DreamWeaver CS3 Keygen + Activation.exeexecutable
MD5:9D2A457CA634CD7DE847A73CF1DC46B9
SHA256:42EC9D8838C1D6F60A035ADD58500D0C046F95BF3E02B6BF13D96CF4AE090FF6
2108WinRAR.exeC:\Users\admin\Desktop\Adobe Premiere Pro 2.0 Keygen + Activation.exeexecutable
MD5:768638EEEA558E09C67F7DE53E4BFC0A
SHA256:D045F3E086414B8132251F394A2CE668A0A651B65B2130EC201E0C90414E0036
2108WinRAR.exeC:\Users\admin\Desktop\Adobe Web Premium CS3 Keygen + Activation.exeexecutable
MD5:193F302361A18A0AF0D96C3178F565BE
SHA256:52D0BFF459413EC4255B2B11CFC21AAB5AB1EBA0C6C9CD49A1294E5F16898AAD
2108WinRAR.exeC:\Users\admin\Desktop\Audition 2.0 keygen.exeexecutable
MD5:088E33EE7C527E9034F2C3DB58199CB4
SHA256:490EF392BFFF5069E97A0CF688A0AF090C1BEB362969105D199BBFB8A41FE5F7
2108WinRAR.exeC:\Users\admin\Desktop\Fireworks CS3 keygen + Activation ZWT.exeexecutable
MD5:8829F6159C6ACA800F02E7DA39695766
SHA256:CBDB9A4EC355726890CA48AB28EF1A0B7F3CBBC1F159C7E8BDD37893E175B777
2108WinRAR.exeC:\Users\admin\Desktop\Dreamweaver CS3 Keygen VLK.exeexecutable
MD5:4BB84D9F3DEAD6C81D1999AE3D24633C
SHA256:A4C11FF462722B1560269D3704B1E5ED2CCC799EDA2130E6F4FB73008CD0E3A5
2108WinRAR.exeC:\Users\admin\Desktop\Encore DVD 2.0 keygen.exeexecutable
MD5:A202852FBDA797041D958BFB11349A50
SHA256:D2A6B39F155677A42EBA1E6B186934BEFAFD7D81102F97B8B4FBD349BB72C144
2108WinRAR.exeC:\Users\admin\Desktop\FireWorks CS3 Keygen + Activation.exeexecutable
MD5:C89B9BD61B8824A8F781839F59F507E0
SHA256:785A601E6A087779702BCCA7D1D0C4A346644260FA274DB88B87731331356438
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info