| File name: | Data.zip |
| Full analysis: | https://app.any.run/tasks/fe5c81e9-0a0b-4a2e-a534-e5cad45004ed |
| Verdict: | Malicious activity |
| Analysis date: | July 21, 2021, 17:30:53 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | 8F1ABF5CE2132FDDF129B4BC9D30CE75 |
| SHA1: | 8A469D3A1AD525982B9F2C1294BA23A3A70ACD89 |
| SHA256: | 0BCD7C5A1E0DE347667FCE50077A19CFB5C9BBFA23DEE7239348CACD53B4779C |
| SSDEEP: | 24576:1nTUztSslH6w08p3sO7UO99MZeTlQXUADN20/P4N9e7nz48XE:sS4H7t7R90oIMqncQE |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipFileName: | Acrobat 8 keygen + Activation.exe |
|---|---|
| ZipUncompressedSize: | 89088 |
| ZipCompressedSize: | 71836 |
| ZipCRC: | 0x5a86a88c |
| ZipModifyDate: | 2021:07:21 10:29:16 |
| ZipCompression: | Deflated |
| ZipBitFlag: | 0x0001 |
| ZipRequiredVersion: | 20 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 368 | "C:\Users\admin\Desktop\Acrobat 8 keygen + Activation.exe" | C:\Users\admin\Desktop\Acrobat 8 keygen + Activation.exe | — | Explorer.EXE | |||||||||||
User: admin Integrity Level: MEDIUM Description: Adobe Acrobat 8 Keygen Exit code: 2 Version: 9, 1, 1, 0 Modules
| |||||||||||||||
| 680 | "C:\Users\admin\Desktop\Adobe Premiere Pro 2.0 Keygen + Activation.exe" | C:\Users\admin\Desktop\Adobe Premiere Pro 2.0 Keygen + Activation.exe | — | Explorer.EXE | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 704 | "C:\Users\admin\Desktop\Dreamweaver CS3 Keygen + Activation ZWT.exe" | C:\Users\admin\Desktop\Dreamweaver CS3 Keygen + Activation ZWT.exe | — | Explorer.EXE | |||||||||||
User: admin Integrity Level: MEDIUM Description: KGTemplate MFC Application Exit code: 2 Version: 1, 0, 0, 1 Modules
| |||||||||||||||
| 1044 | "C:\Users\admin\Desktop\Audition 2.0 keygen.exe" | C:\Users\admin\Desktop\Audition 2.0 keygen.exe | — | Explorer.EXE | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 1700 | "C:\Users\admin\Desktop\Flash CS3 Keygen + Activation ZWT.exe" | C:\Users\admin\Desktop\Flash CS3 Keygen + Activation ZWT.exe | — | Explorer.EXE | |||||||||||
User: admin Integrity Level: MEDIUM Description: KGTemplate MFC Application Exit code: 2 Version: 1, 0, 0, 1 Modules
| |||||||||||||||
| 1752 | "C:\Users\admin\Desktop\Adobe Web Premium CS3 Keygen + Activation ZWT.exe" | C:\Users\admin\Desktop\Adobe Web Premium CS3 Keygen + Activation ZWT.exe | — | Explorer.EXE | |||||||||||
User: admin Integrity Level: MEDIUM Description: KGTemplate MFC Application Exit code: 2 Version: 1, 0, 0, 1 Modules
| |||||||||||||||
| 1820 | "C:\Users\admin\Desktop\FireWorks CS3 Keygen + Activation.exe" | C:\Users\admin\Desktop\FireWorks CS3 Keygen + Activation.exe | — | Explorer.EXE | |||||||||||
User: admin Integrity Level: MEDIUM Description: Adobe FireWorks CS3 Keygen Exit code: 2 Version: 1, 0, 0, 1 Modules
| |||||||||||||||
| 1924 | "C:\Users\admin\Desktop\Encore DVD 2.0 keygen.exe" | C:\Users\admin\Desktop\Encore DVD 2.0 keygen.exe | — | Explorer.EXE | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 2096 | "C:\Users\admin\Desktop\Adobe Web Premium CS3 Keygen + Activation.exe" | C:\Users\admin\Desktop\Adobe Web Premium CS3 Keygen + Activation.exe | — | Explorer.EXE | |||||||||||
User: admin Integrity Level: MEDIUM Description: Adobe CS3 Web Premium Keygen Exit code: 2 Version: 9, 9, 1, 0 Modules
| |||||||||||||||
| 2108 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Data.zip" | C:\Program Files\WinRAR\WinRAR.exe | Explorer.EXE | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| (PID) Process: | (2108) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (2108) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (2108) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\16B\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2108) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (2108) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Data.zip | |||
| (PID) Process: | (2108) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2108) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2108) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2108) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (2108) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2108 | WinRAR.exe | C:\Users\admin\Desktop\Contribute CS3 Keygen VLK.exe | executable | |
MD5:BEFAFE82FFA951197DA4DC92A96A9BE9 | SHA256:BE8AEC9917E90ACEB36ECBB7FD39AC8E76078D823E34023CA9C68C815769049B | |||
| 2108 | WinRAR.exe | C:\Users\admin\Desktop\Dreamweaver CS3 Keygen + Activation ZWT.exe | executable | |
MD5:169D11DEC220EDC1831B01F3A733C8D1 | SHA256:CCF9C93B94DC86A9ECA7722559579A2B4208B7224336530F5DE9AD7FCDE2A4B5 | |||
| 2108 | WinRAR.exe | C:\Users\admin\Desktop\DreamWeaver CS3 Keygen + Activation.exe | executable | |
MD5:9D2A457CA634CD7DE847A73CF1DC46B9 | SHA256:42EC9D8838C1D6F60A035ADD58500D0C046F95BF3E02B6BF13D96CF4AE090FF6 | |||
| 2108 | WinRAR.exe | C:\Users\admin\Desktop\Adobe Premiere Pro 2.0 Keygen + Activation.exe | executable | |
MD5:768638EEEA558E09C67F7DE53E4BFC0A | SHA256:D045F3E086414B8132251F394A2CE668A0A651B65B2130EC201E0C90414E0036 | |||
| 2108 | WinRAR.exe | C:\Users\admin\Desktop\Adobe Web Premium CS3 Keygen + Activation.exe | executable | |
MD5:193F302361A18A0AF0D96C3178F565BE | SHA256:52D0BFF459413EC4255B2B11CFC21AAB5AB1EBA0C6C9CD49A1294E5F16898AAD | |||
| 2108 | WinRAR.exe | C:\Users\admin\Desktop\Audition 2.0 keygen.exe | executable | |
MD5:088E33EE7C527E9034F2C3DB58199CB4 | SHA256:490EF392BFFF5069E97A0CF688A0AF090C1BEB362969105D199BBFB8A41FE5F7 | |||
| 2108 | WinRAR.exe | C:\Users\admin\Desktop\Fireworks CS3 keygen + Activation ZWT.exe | executable | |
MD5:8829F6159C6ACA800F02E7DA39695766 | SHA256:CBDB9A4EC355726890CA48AB28EF1A0B7F3CBBC1F159C7E8BDD37893E175B777 | |||
| 2108 | WinRAR.exe | C:\Users\admin\Desktop\Dreamweaver CS3 Keygen VLK.exe | executable | |
MD5:4BB84D9F3DEAD6C81D1999AE3D24633C | SHA256:A4C11FF462722B1560269D3704B1E5ED2CCC799EDA2130E6F4FB73008CD0E3A5 | |||
| 2108 | WinRAR.exe | C:\Users\admin\Desktop\Encore DVD 2.0 keygen.exe | executable | |
MD5:A202852FBDA797041D958BFB11349A50 | SHA256:D2A6B39F155677A42EBA1E6B186934BEFAFD7D81102F97B8B4FBD349BB72C144 | |||
| 2108 | WinRAR.exe | C:\Users\admin\Desktop\FireWorks CS3 Keygen + Activation.exe | executable | |
MD5:C89B9BD61B8824A8F781839F59F507E0 | SHA256:785A601E6A087779702BCCA7D1D0C4A346644260FA274DB88B87731331356438 | |||