| File name: | JetX Predict Bot v0.4 (ZarLeak crack).zip |
| Full analysis: | https://app.any.run/tasks/e3107831-91a0-411d-9e9c-5da892b808a0 |
| Verdict: | Malicious activity |
| Analysis date: | July 29, 2021, 17:09:41 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | F2B66506DD0FAF335884F4B7B2DD7789 |
| SHA1: | C8BC55484B6497F9F2C6D30D8661C0A7766D7BD5 |
| SHA256: | 0C1D3014DF5F3B283737F83856A6AB263E06D88A3F253DEC6D6EF84A38432919 |
| SSDEEP: | 196608:3WARd7Lu99MD7kkZFGZKUakd5H87viNcfoRdVeJQesHYy5xHOywTBlEuOYPRIeOA:GAD3uYkk7KKUag5HOiNwsYJQeOYg1wTd |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipFileName: | d3dcompiler_47.dll |
|---|---|
| ZipUncompressedSize: | 4410176 |
| ZipCompressedSize: | 1877164 |
| ZipCRC: | 0x48381f30 |
| ZipModifyDate: | 2021:02:22 21:27:02 |
| ZipCompression: | Deflated |
| ZipBitFlag: | - |
| ZipRequiredVersion: | 20 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2608 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\JetX Predict Bot v0.4 (ZarLeak crack).zip" | C:\Program Files\WinRAR\WinRAR.exe | Explorer.EXE | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 2856 | "C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\AppData\Local\Temp\Rar$DIa2608.29962\update-settings.ini | C:\Windows\system32\NOTEPAD.EXE | — | WinRAR.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Notepad Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3644 | "C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\AppData\Local\Temp\Rar$DIa2608.28220\FAQ & Donate.txt | C:\Windows\system32\NOTEPAD.EXE | — | WinRAR.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Notepad Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (2608) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (2608) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (2608) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\16B\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2608) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (2608) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\JetX Predict Bot v0.4 (ZarLeak crack).zip | |||
| (PID) Process: | (2608) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2608) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2608) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2608) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (2608) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\16B\52C64B7E |
| Operation: | write | Name: | @C:\Windows\system32\notepad.exe,-469 |
Value: Text Document | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2608 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DIa2608.29962\update-settings.ini | text | |
MD5:7FF86D56D064B4330AEECF4EC6FE6D23 | SHA256:C4276E71B4EAEF04CD5D3ECEFDA3A754C3B1B4079FFD69EB2C79773040F95B66 | |||
| 2608 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2608.30846\FAQ & Donate.txt | text | |
MD5:F86946A74C6BE4A975ECC0DCBAFA9E0D | SHA256:74E789137AC03F7E2C3BA6FD5FF8658B847FAFBD9F10F5F1E55745933CCD5110 | |||
| 2608 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2608.30846\JetX Predict v0.4.EXE | executable | |
MD5:3DC037801531363127F1934F1E09B23A | SHA256:62AA6AE9A8518352505997D234ACB2A7D3BD39ACEDCAA7386122BF30C0D220FF | |||
| 2608 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2608.26829\FAQ & Donate.txt | text | |
MD5:F86946A74C6BE4A975ECC0DCBAFA9E0D | SHA256:74E789137AC03F7E2C3BA6FD5FF8658B847FAFBD9F10F5F1E55745933CCD5110 | |||
| 2608 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DIa2608.28220\FAQ & Donate.txt | text | |
MD5:F86946A74C6BE4A975ECC0DCBAFA9E0D | SHA256:74E789137AC03F7E2C3BA6FD5FF8658B847FAFBD9F10F5F1E55745933CCD5110 | |||
| 2608 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2608.30846\update-settings.ini | text | |
MD5:7FF86D56D064B4330AEECF4EC6FE6D23 | SHA256:C4276E71B4EAEF04CD5D3ECEFDA3A754C3B1B4079FFD69EB2C79773040F95B66 | |||
| 2608 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2608.26829\d3dcompiler_47.dll | executable | |
MD5:387575BA5B0AE81A4EA8229C093B80E1 | SHA256:25EBDF571D4C8DBCA43C848A73CEA72473DA41927064D1399CE5A8C3DAA7D0EA | |||
| 2608 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2608.26829\update-settings.ini | text | |
MD5:7FF86D56D064B4330AEECF4EC6FE6D23 | SHA256:C4276E71B4EAEF04CD5D3ECEFDA3A754C3B1B4079FFD69EB2C79773040F95B66 | |||
| 2608 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2608.26829\JetX Predict v0.4.EXE | executable | |
MD5:3DC037801531363127F1934F1E09B23A | SHA256:62AA6AE9A8518352505997D234ACB2A7D3BD39ACEDCAA7386122BF30C0D220FF | |||
| 2608 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2608.30846\d3dcompiler_47.dll | executable | |
MD5:387575BA5B0AE81A4EA8229C093B80E1 | SHA256:25EBDF571D4C8DBCA43C848A73CEA72473DA41927064D1399CE5A8C3DAA7D0EA | |||