| File name: | Data.zip |
| Full analysis: | https://app.any.run/tasks/fe5c81e9-0a0b-4a2e-a534-e5cad45004ed |
| Verdict: | Malicious activity |
| Analysis date: | July 21, 2021, 17:30:53 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | 8F1ABF5CE2132FDDF129B4BC9D30CE75 |
| SHA1: | 8A469D3A1AD525982B9F2C1294BA23A3A70ACD89 |
| SHA256: | 0BCD7C5A1E0DE347667FCE50077A19CFB5C9BBFA23DEE7239348CACD53B4779C |
| SSDEEP: | 24576:1nTUztSslH6w08p3sO7UO99MZeTlQXUADN20/P4N9e7nz48XE:sS4H7t7R90oIMqncQE |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipFileName: | Acrobat 8 keygen + Activation.exe |
|---|---|
| ZipUncompressedSize: | 89088 |
| ZipCompressedSize: | 71836 |
| ZipCRC: | 0x5a86a88c |
| ZipModifyDate: | 2021:07:21 10:29:16 |
| ZipCompression: | Deflated |
| ZipBitFlag: | 0x0001 |
| ZipRequiredVersion: | 20 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 368 | "C:\Users\admin\Desktop\Acrobat 8 keygen + Activation.exe" | C:\Users\admin\Desktop\Acrobat 8 keygen + Activation.exe | — | Explorer.EXE | |||||||||||
User: admin Integrity Level: MEDIUM Description: Adobe Acrobat 8 Keygen Exit code: 2 Version: 9, 1, 1, 0 Modules
| |||||||||||||||
| 680 | "C:\Users\admin\Desktop\Adobe Premiere Pro 2.0 Keygen + Activation.exe" | C:\Users\admin\Desktop\Adobe Premiere Pro 2.0 Keygen + Activation.exe | — | Explorer.EXE | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 704 | "C:\Users\admin\Desktop\Dreamweaver CS3 Keygen + Activation ZWT.exe" | C:\Users\admin\Desktop\Dreamweaver CS3 Keygen + Activation ZWT.exe | — | Explorer.EXE | |||||||||||
User: admin Integrity Level: MEDIUM Description: KGTemplate MFC Application Exit code: 2 Version: 1, 0, 0, 1 Modules
| |||||||||||||||
| 1044 | "C:\Users\admin\Desktop\Audition 2.0 keygen.exe" | C:\Users\admin\Desktop\Audition 2.0 keygen.exe | — | Explorer.EXE | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 1700 | "C:\Users\admin\Desktop\Flash CS3 Keygen + Activation ZWT.exe" | C:\Users\admin\Desktop\Flash CS3 Keygen + Activation ZWT.exe | — | Explorer.EXE | |||||||||||
User: admin Integrity Level: MEDIUM Description: KGTemplate MFC Application Exit code: 2 Version: 1, 0, 0, 1 Modules
| |||||||||||||||
| 1752 | "C:\Users\admin\Desktop\Adobe Web Premium CS3 Keygen + Activation ZWT.exe" | C:\Users\admin\Desktop\Adobe Web Premium CS3 Keygen + Activation ZWT.exe | — | Explorer.EXE | |||||||||||
User: admin Integrity Level: MEDIUM Description: KGTemplate MFC Application Exit code: 2 Version: 1, 0, 0, 1 Modules
| |||||||||||||||
| 1820 | "C:\Users\admin\Desktop\FireWorks CS3 Keygen + Activation.exe" | C:\Users\admin\Desktop\FireWorks CS3 Keygen + Activation.exe | — | Explorer.EXE | |||||||||||
User: admin Integrity Level: MEDIUM Description: Adobe FireWorks CS3 Keygen Exit code: 2 Version: 1, 0, 0, 1 Modules
| |||||||||||||||
| 1924 | "C:\Users\admin\Desktop\Encore DVD 2.0 keygen.exe" | C:\Users\admin\Desktop\Encore DVD 2.0 keygen.exe | — | Explorer.EXE | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 2096 | "C:\Users\admin\Desktop\Adobe Web Premium CS3 Keygen + Activation.exe" | C:\Users\admin\Desktop\Adobe Web Premium CS3 Keygen + Activation.exe | — | Explorer.EXE | |||||||||||
User: admin Integrity Level: MEDIUM Description: Adobe CS3 Web Premium Keygen Exit code: 2 Version: 9, 9, 1, 0 Modules
| |||||||||||||||
| 2108 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Data.zip" | C:\Program Files\WinRAR\WinRAR.exe | Explorer.EXE | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| (PID) Process: | (2108) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (2108) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (2108) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\16B\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2108) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (2108) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Data.zip | |||
| (PID) Process: | (2108) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2108) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2108) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2108) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (2108) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2108 | WinRAR.exe | C:\Users\admin\Desktop\Adobe Premiere Pro 2.0 Keygen + Activation.exe | executable | |
MD5:768638EEEA558E09C67F7DE53E4BFC0A | SHA256:D045F3E086414B8132251F394A2CE668A0A651B65B2130EC201E0C90414E0036 | |||
| 2108 | WinRAR.exe | C:\Users\admin\Desktop\Adobe Design Premium CS3 Keygen ZWT.exe | executable | |
MD5:296F5E28714414230C3763CF1F9B0880 | SHA256:0DBD5B617CE2207BD05F3B8D084E35AEC782A834735EDE7DC07759A802DCC9D9 | |||
| 2108 | WinRAR.exe | C:\Users\admin\Desktop\Dreamweaver CS3 Keygen VLK.exe | executable | |
MD5:4BB84D9F3DEAD6C81D1999AE3D24633C | SHA256:A4C11FF462722B1560269D3704B1E5ED2CCC799EDA2130E6F4FB73008CD0E3A5 | |||
| 2108 | WinRAR.exe | C:\Users\admin\Desktop\Encore DVD 2.0 keygen.exe | executable | |
MD5:A202852FBDA797041D958BFB11349A50 | SHA256:D2A6B39F155677A42EBA1E6B186934BEFAFD7D81102F97B8B4FBD349BB72C144 | |||
| 2108 | WinRAR.exe | C:\Users\admin\Desktop\Fireworks CS3 keygen + Activation ZWT.exe | executable | |
MD5:8829F6159C6ACA800F02E7DA39695766 | SHA256:CBDB9A4EC355726890CA48AB28EF1A0B7F3CBBC1F159C7E8BDD37893E175B777 | |||
| 2108 | WinRAR.exe | C:\Users\admin\Desktop\FireWorks CS3 Keygen + Activation.exe | executable | |
MD5:C89B9BD61B8824A8F781839F59F507E0 | SHA256:785A601E6A087779702BCCA7D1D0C4A346644260FA274DB88B87731331356438 | |||
| 2108 | WinRAR.exe | C:\Users\admin\Desktop\Flash CS3 Keygen + Activation ZWT.exe | executable | |
MD5:E3C7D489013B51C671AA79C9068A2A00 | SHA256:5EA232AC5EBCA4584F8689D5A1ED466404272A5C5496F41934537504368B5DA2 | |||
| 2108 | WinRAR.exe | C:\Users\admin\Desktop\InCopy CS3 Keygen VLK.exe | executable | |
MD5:2FF3F7C609644B1C1175B010449A3DF2 | SHA256:20DD9EDA60114C292F00171063CB06B5157FD4E64A34F82F6C29865F219A1AD0 | |||
| 2108 | WinRAR.exe | C:\Users\admin\Desktop\Photoshop CS3 Extended Keygen + Activation ZWT.exe | executable | |
MD5:C2FD1FE04080C2969237F6E361002787 | SHA256:476150257BA1187892754A3CE31EE29DEAAA436EE522F6F514A9E284BF28BF1A | |||
| 2108 | WinRAR.exe | C:\Users\admin\Desktop\Flash CS3 Keygen + Activation.exe | executable | |
MD5:97009D04FB92911DC377315F6E04CC4D | SHA256:2EBE5BE779C70C381D8272CCC283477D17B87AC347A2FD8A5D659A4EBBA399C4 | |||