File name:

Gamesense crack (skeet).zip

Full analysis: https://app.any.run/tasks/05e63e0f-c7af-4893-a16f-144a4b741cbf
Verdict: Malicious activity
Threats:

Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.

Analysis date: May 22, 2021, 23:03:32
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
stealer
evasion
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

C44933D1208444B16578AA4DAD284789

SHA1:

7F2388FEDB5863F6E5F236972C571EAFCBB8B929

SHA256:

0C33651FFFCCE2273D8DF11F80399E2B03C2C31ACC42059AAF4DAE4A2F491C4A

SSDEEP:

24576:So4fuVqbvbj3BOs898DX+3+O4WbQ65WW9QXZz7Vh6zmxE1:SFfDbvvROsvS3+/4QEKZXVhPxC

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Skeet.exe (PID: 2788)
    • Steals credentials from Web Browsers

      • Skeet.exe (PID: 2788)
    • Actions looks like stealing of personal data

      • Skeet.exe (PID: 2788)
    • Stealing of credential data

      • Skeet.exe (PID: 2788)
  • SUSPICIOUS

    • Reads the cookies of Mozilla Firefox

      • Skeet.exe (PID: 2788)
    • Drops a file with too old compile date

      • WinRAR.exe (PID: 1104)
    • Drops a file that was compiled in debug mode

      • WinRAR.exe (PID: 1104)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1104)
    • Checks for external IP

      • Skeet.exe (PID: 2788)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: Gamesense crack (skeet)/Skeet.exe
ZipUncompressedSize: 1334272
ZipCompressedSize: 1081739
ZipCRC: 0xdf911c6b
ZipModifyDate: 2021:05:23 02:03:07
ZipCompression: Deflated
ZipBitFlag: 0x0008
ZipRequiredVersion: 20
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
39
Monitored processes
4
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start winrar.exe skeet.exe notepad.exe no specs notepad.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1104"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Gamesense crack (skeet).zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2072"C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\AppData\Local\Temp\Rar$DIa1104.47859\start.txtC:\Windows\system32\NOTEPAD.EXEWinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2788"C:\Users\admin\AppData\Local\Temp\Rar$EXa1104.47112\Gamesense crack (skeet)\Skeet.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa1104.47112\Gamesense crack (skeet)\Skeet.exe
WinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa1104.47112\gamesense crack (skeet)\skeet.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2892"C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\AppData\Local\Temp\Rar$DIa1104.47892\start.txtC:\Windows\system32\NOTEPAD.EXEWinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
555
Read events
518
Write events
37
Delete events
0

Modification events

(PID) Process:(1104) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1104) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1104) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1104) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E
Operation:writeName:@C:\Windows\system32\NetworkExplorer.dll,-1
Value:
Network
(PID) Process:(1104) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Gamesense crack (skeet).zip
(PID) Process:(1104) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1104) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1104) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1104) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1104) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E
Operation:writeName:@C:\Windows\system32\notepad.exe,-469
Value:
Text Document
Executable files
1
Suspicious files
4
Text files
22
Unknown types
9

Dropped files

PID
Process
Filename
Type
1104WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1104.47112\Gamesense crack (skeet)\lua\AA.txt
MD5:
SHA256:
1104WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1104.47112\Gamesense crack (skeet)\lua\Killsay.txt
MD5:
SHA256:
1104WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1104.47112\Gamesense crack (skeet)\lua\Mindmg.txt
MD5:
SHA256:
1104WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1104.47112\Gamesense crack (skeet)\lua\Skeet.txt
MD5:
SHA256:
1104WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1104.47112\Gamesense crack (skeet)\start.txt
MD5:
SHA256:
1104WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DIa1104.47859\start.txt
MD5:
SHA256:
1104WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DIa1104.47892\start.txt
MD5:
SHA256:
1104WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1104.47112\Gamesense crack (skeet)\Skeet.exeexecutable
MD5:
SHA256:
1104WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1104.47112\Gamesense crack (skeet)\api.txttext
MD5:
SHA256:
2788Skeet.exeC:\Users\admin\AppData\Local\Temp\HTyHJ1F8BFBFF000506E3C4BA364715\DotNetZip-ch3aj3tp.tmp
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
4
DNS requests
3
Threats
7

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2788
Skeet.exe
GET
200
208.95.112.1:80
http://ip-api.com/xml
unknown
xml
457 b
malicious
2788
Skeet.exe
GET
200
208.95.112.1:80
http://ip-api.com/xml
unknown
xml
457 b
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2788
Skeet.exe
54.235.184.117:443
api.ipify.org
Amazon.com, Inc.
US
suspicious
2788
Skeet.exe
149.154.167.220:443
api.telegram.org
Telegram Messenger LLP
GB
malicious
149.154.167.220:443
api.telegram.org
Telegram Messenger LLP
GB
malicious
2788
Skeet.exe
208.95.112.1:80
ip-api.com
IBURST
malicious

DNS requests

Domain
IP
Reputation
api.ipify.org
  • 54.235.184.117
  • 54.235.83.248
  • 23.21.76.253
  • 50.19.242.215
  • 23.21.48.44
  • 54.243.154.178
  • 54.225.222.160
  • 50.16.192.84
shared
ip-api.com
  • 208.95.112.1
malicious
api.telegram.org
  • 149.154.167.220
shared

Threats

PID
Process
Class
Message
2788
Skeet.exe
Potentially Bad Traffic
ET INFO TLS Handshake Failure
2788
Skeet.exe
Potential Corporate Privacy Violation
ET POLICY External IP Lookup ip-api.com
2788
Skeet.exe
Potential Corporate Privacy Violation
AV POLICY Internal Host Retrieving External IP Address (ip-api. com)
Potentially Bad Traffic
ET INFO TLS Handshake Failure
2788
Skeet.exe
Potential Corporate Privacy Violation
ET POLICY External IP Lookup ip-api.com
2788
Skeet.exe
Potential Corporate Privacy Violation
AV POLICY Internal Host Retrieving External IP Address (ip-api. com)
1 ETPRO signatures available at the full report
No debug info