| File name: | kf151.zip |
| Full analysis: | https://app.any.run/tasks/2c43b10f-add7-4ad2-845a-29601799a583 |
| Verdict: | Malicious activity |
| Analysis date: | November 28, 2019, 14:56:06 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | 9248012B83991E3FE6B6B424A9A3BB23 |
| SHA1: | 7FA4177A4B1E5DCC9D24762D374483D9CFDE7C18 |
| SHA256: | 121064CC16E06CA58B2FF58FC8E868C8175107D424CD7F19A23D992849E482AE |
| SSDEEP: | 6144:OQ8DTO+JLWnXJU2jD5h+fSzcRJmiCN0UEcJ3Dm22:OQ8DTNLWnXNJKRJmjNscJ3y22 |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | 0x0002 |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2006:08:06 19:54:03 |
| ZipCRC: | 0x7a553444 |
| ZipCompressedSize: | 266712 |
| ZipUncompressedSize: | 272357 |
| ZipFileName: | keyfinder.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1940 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\kf151.zip" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 2040 | "C:\Users\admin\AppData\Local\Temp\RarSFX0\findkey.exe" | C:\Users\admin\AppData\Local\Temp\RarSFX0\findkey.exe | — | keyfinder.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2480 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa1940.49779\keyfinder.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa1940.49779\keyfinder.exe | WinRAR.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 3332 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa1940.49779\keyfinder.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa1940.49779\keyfinder.exe | — | WinRAR.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| 3968 | "C:\Users\admin\AppData\Local\Temp\RarSFX0\xpkey.exe" | C:\Users\admin\AppData\Local\Temp\RarSFX0\xpkey.exe | — | findkey.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| (PID) Process: | (1940) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (1940) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (1940) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (1940) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\kf151.zip | |||
| (PID) Process: | (1940) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (1940) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (1940) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (1940) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (1940) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (1940) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2480 | keyfinder.exe | C:\Users\admin\AppData\Local\Temp\RarSFX0\xpkey.exe | executable | |
MD5:F5393A2616FDACD43D46B302CC723E84 | SHA256:CB603DA8A9CB1C8BBF922175D30E8F51DB867FA5DA3A4DDC3637805B7A6CCAE2 | |||
| 1940 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1940.49779\keyfinder.exe | executable | |
MD5:042F13CB1818A8B9FE026A250C4EEF93 | SHA256:47AB0544C45E7E745B2459018B4CA5AA1631602CD6977A2A0CE73A2F5F454831 | |||
| 3968 | xpkey.exe | C:\Users\admin\AppData\Local\Temp\RarSFX0\xpkey.txt | text | |
MD5:4EF283E7931D2FF21AC766BDC7EA4700 | SHA256:7273F70BBB22BE4418DC8AE35F4525A3335307522790C4FC7383E95BEF19C9ED | |||
| 2480 | keyfinder.exe | C:\Users\admin\AppData\Local\Temp\RarSFX0\officekey.exe | executable | |
MD5:BA47986812381F64938D22FC55D2C6E9 | SHA256:5B4FEC2EC25E488C8C377A7FE3AD90CF1AFFDA5A053A6A44EEA13CA6B98CAD9C | |||
| 2480 | keyfinder.exe | C:\Users\admin\AppData\Local\Temp\RarSFX0\findkey.exe | executable | |
MD5:D1EEE936774BC595DE3BBC9666723646 | SHA256:F8D3C74B6843436688DCE8E6F8AD44D9EB9B179B1E04AAC3F831CA2B663FC04F | |||
| 2480 | keyfinder.exe | C:\Users\admin\AppData\Local\Temp\RarSFX0\chgxp.vbs | text | |
MD5:DDD5148D88DB8298FA44A83ACE8B540F | SHA256:00A3B8A2E8E04522FFD6955639A8F706B8955A4640744C53D05DF517BBF147DC | |||