File name:

EggsteranN]1.zip

Full analysis: https://app.any.run/tasks/b6835b7a-9a13-4f8e-a489-c0f3de0e04ef
Verdict: Malicious activity
Analysis date: January 29, 2025, 17:29:48
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
netreactor
confuser
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

D21F0987CD18BE4B3C1BF42A862A4D6D

SHA1:

403780412B9B8049317A1E4D2A32F893D2EF4649

SHA256:

157E8AA620EF2CCDA478B48A35C88CB61F122AD5A8BF1D0F890480ED18DFB732

SSDEEP:

98304:XIqASK7cXFbFg6wz5x3n7bS4Dr7UrYrGav9P6ZQ0ctcyhVkexY2HF8BnVML8rmEs:h/exI5m

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 6316)
    • Reads security settings of Internet Explorer

      • Eggsterant Deluxe Crack [By LOLSHAN].exe (PID: 6932)
    • Executable content was dropped or overwritten

      • Eggsterant Deluxe Crack [By LOLSHAN].exe (PID: 6932)
    • Drops a system driver (possible attempt to evade defenses)

      • Eggsterant Deluxe Crack [By LOLSHAN].exe (PID: 6932)
    • There is functionality for taking screenshot (YARA)

      • Eggsterant Deluxe Crack [By LOLSHAN].exe (PID: 6932)
    • Reads the date of Windows installation

      • Eggsterant Deluxe Crack [By LOLSHAN].exe (PID: 6932)
    • Starts CMD.EXE for commands execution

      • Eggsterant Deluxe Crack [By LOLSHAN].exe (PID: 6932)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 6316)
    • Manual execution by a user

      • Eggsterant Deluxe Crack [By LOLSHAN].exe (PID: 6932)
    • Checks supported languages

      • Eggsterant Deluxe Crack [By LOLSHAN].exe (PID: 6932)
    • The sample compiled with chinese language support

      • Eggsterant Deluxe Crack [By LOLSHAN].exe (PID: 6932)
    • Reads the machine GUID from the registry

      • Eggsterant Deluxe Crack [By LOLSHAN].exe (PID: 6932)
    • Reads the computer name

      • Eggsterant Deluxe Crack [By LOLSHAN].exe (PID: 6932)
    • .NET Reactor protector has been detected

      • Eggsterant Deluxe Crack [By LOLSHAN].exe (PID: 6932)
    • Create files in a temporary directory

      • Eggsterant Deluxe Crack [By LOLSHAN].exe (PID: 6932)
    • Confuser has been detected (YARA)

      • Eggsterant Deluxe Crack [By LOLSHAN].exe (PID: 6932)
    • Process checks computer location settings

      • Eggsterant Deluxe Crack [By LOLSHAN].exe (PID: 6932)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2023:09:28 06:07:22
ZipCRC: 0x65898b23
ZipCompressedSize: 2272497
ZipUncompressedSize: 5831168
ZipFileName: Eggsterant Deluxe Crack [By LOLSHAN].exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
134
Monitored processes
5
Malicious processes
0
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe eggsterant deluxe crack [by lolshan].exe cmd.exe no specs conhost.exe no specs choice.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
648choice /C Y /N /D Y /T 3 C:\Windows\System32\choice.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Offers the user a choice
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\choice.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
6316"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\EggsteranN]1.zipC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
6448\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6460"C:\Windows\System32\cmd.exe" /C choice /C Y /N /D Y /T 3 & Del "C:\Users\admin\AppData\Local\Temp\\security.dll"C:\Windows\System32\cmd.exeEggsterant Deluxe Crack [By LOLSHAN].exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
6932"C:\Users\admin\Desktop\Eggsterant Deluxe Crack [By LOLSHAN].exe" C:\Users\admin\Desktop\Eggsterant Deluxe Crack [By LOLSHAN].exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
4294967295
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\eggsterant deluxe crack [by lolshan].exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
2 264
Read events
2 245
Write events
19
Delete events
0

Modification events

(PID) Process:(6316) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(6316) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(6316) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(6316) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\EggsteranN]1.zip
(PID) Process:(6316) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(6316) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(6316) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(6316) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(6316) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF3D0000002D000000FD03000016020000
(PID) Process:(6316) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:name
Value:
256
Executable files
7
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
6316WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6316.11374\System.Numerics.Vectors.dllexecutable
MD5:AAA2CBF14E06E9D3586D8A4ED455DB33
SHA256:1D3EF8698281E7CF7371D1554AFEF5872B39F96C26DA772210A33DA041BA1183
6932Eggsterant Deluxe Crack [By LOLSHAN].exeC:\Users\admin\AppData\Local\Temp\security.dllexecutable
MD5:975ACD1E886C23ED34F897E4DD689CF3
SHA256:1FB11D1DFC74C785FF48E03B39F9641A6C8D2968B822AAD89FBA1D88E6B54156
6316WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6316.11374\SharpConfig.dllexecutable
MD5:E59D5EB684367B8B5E3F93A2696AAB53
SHA256:6776B7526824E62CEC9F00A13D1C1EC9DF38F84A9B04A0862E7B03D24E6D0CC9
6932Eggsterant Deluxe Crack [By LOLSHAN].exeC:\Users\admin\AppData\Local\Temp\dd202x.8.sysexecutable
MD5:739AE6B347CC74414D21DF6E925439BC
SHA256:25CD02AA7465BE65E8726361AE08CAF3C2E71DF4AE2444700EAA6AE7D51BAF08
6932Eggsterant Deluxe Crack [By LOLSHAN].exeC:\Users\admin\Desktop\config.cfgtext
MD5:51E74C574CD7E0FE531C71FB41724BD2
SHA256:8AE140A82B6A42CF7EC031C60424987273393125CAD73E165B6B3FFDA50AC5C0
6316WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6316.11374\Siticone.Desktop.UI.dllexecutable
MD5:1582AA45D981E0E569C6E05698642B30
SHA256:21EECAF504B7FE787A45F4AA8F8F36DACFC3AB1D75624DFB41827CDEF2A9A589
6316WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6316.11374\Eggsterant Deluxe Crack [By LOLSHAN].exeexecutable
MD5:B9283D8AF6BD2CD8DD9E5AF541D126F1
SHA256:092ABCC4F2B99F31260E958998E5D8E817A71DDA0ED0B0924C2097180774E44B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
29
DNS requests
13
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5064
SearchApp.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
5000
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
5000
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
1176
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2796
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2.19.122.16:443
Akamai International B.V.
DE
unknown
4
System
192.168.100.255:138
whitelisted
5064
SearchApp.exe
2.19.122.16:443
Akamai International B.V.
DE
unknown
716
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5064
SearchApp.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
1176
svchost.exe
40.126.32.133:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1176
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 40.127.240.158
  • 4.231.128.59
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
login.live.com
  • 40.126.32.133
  • 20.190.160.17
  • 40.126.32.68
  • 40.126.32.74
  • 20.190.160.14
  • 40.126.32.76
  • 40.126.32.136
  • 20.190.160.22
whitelisted
go.microsoft.com
  • 2.18.97.227
whitelisted
slscr.update.microsoft.com
  • 52.149.20.212
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 52.165.164.15
whitelisted
nexusrules.officeapps.live.com
  • 52.111.243.31
whitelisted
self.events.data.microsoft.com
  • 20.189.173.25
whitelisted

Threats

No threats detected
No debug info