| download: | Enigma%2BProtector%2Bv5.20%2Bx86.zip |
| Full analysis: | https://app.any.run/tasks/bc3eeabd-65ed-4c86-b7c0-84f5cf7f176b |
| Verdict: | Malicious activity |
| Analysis date: | August 19, 2018, 19:59:33 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | B51D5A53851F1C2F7FB8B42B1911581D |
| SHA1: | 76C5707EF608072AF518EE8618B653D554248A0C |
| SHA256: | 16201E9FDC0C00125D260C5F3F12AA5E531F383BDBE3241A81B93C4A50C95F5A |
| SSDEEP: | 393216:2M2HK30w32aD3/tV39V3q3k3X3I315gLl1NJLo4MTRK8KS/kfOn9AOOCByO:23ut65YNJLSox0kf89A8yO |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2008:04:23 04:00:00 |
| ZipCRC: | 0xa970fb24 |
| ZipCompressedSize: | 494281 |
| ZipUncompressedSize: | 1097728 |
| ZipFileName: | libeay32.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 372 | "C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe10_ Global\UsGthrCtrlFltPipeMssGthrPipe10 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" | C:\Windows\System32\SearchProtocolHost.exe | — | SearchIndexer.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft Windows Search Protocol Host Exit code: 0 Version: 7.00.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2200 | "C:\Users\admin\Desktop\Enigma32g.exe" | C:\Users\admin\Desktop\Enigma32g.exe | explorer.exe | ||||||||||||
User: admin Company: The Enigma Protector Integrity Level: MEDIUM Exit code: 0 Version: 5.0.0.2212 Modules
| |||||||||||||||
| 2492 | "C:\Users\admin\Desktop\123.exe" | C:\Users\admin\Desktop\123.exe | — | Enigma32g.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 3221225786 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2636 | "C:\Users\admin\Desktop\enigma32.exe" | C:\Users\admin\Desktop\enigma32.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 1 Modules
| |||||||||||||||
| 4044 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\b06d7a74-4c87-48f1-88f7-743697a28fa7.zip" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| (PID) Process: | (4044) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (4044) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (4044) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\59\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (4044) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\b06d7a74-4c87-48f1-88f7-743697a28fa7.zip | |||
| (PID) Process: | (4044) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (4044) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (4044) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (4044) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (4044) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\59\52C64B7E |
| Operation: | write | Name: | @C:\Windows\System32\hhctrl.ocx,-452 |
Value: Compiled HTML Help file | |||
| (PID) Process: | (4044) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\59\52C64B7E |
| Operation: | write | Name: | @C:\Windows\System32\ieframe.dll,-10046 |
Value: Internet Shortcut | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 4044 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa4044.5501\support.url | text | |
MD5:975CACF9CEE893BA4F1BE30936A1EF45 | SHA256:E228C154CC73045300EB9E0101A7C4815023AF47787A7C3C897A325A2B2ABA3A | |||
| 4044 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa4044.5501\libspv.dll | executable | |
MD5:CE77DD8834344A3A913B14AF4EA803AF | SHA256:58B4E4124BD41B2D24EA25BBBDB714D52E18642EFBC8C3A519B69EF04367FC3D | |||
| 4044 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa4044.5501\ssleay32.dll | executable | |
MD5:D522127B19938F0F9E127AF60D8E678E | SHA256:A28416A2107A454255B41B1AB61EA1FA3CE2298C01D6BF44C52F5098E3129912 | |||
| 4044 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa4044.5501\udis.dll | executable | |
MD5:88E01CF86D15BE0DF1209C5F0F76E4F5 | SHA256:4F21456111057CFAE3147C674573A3F72EDC2AB22D1EA2B1B07611BFE9678ECA | |||
| 4044 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa4044.5501\Email Patterns\Software News.xml | xml | |
MD5:492331E5C6B083290D2365EFC98398FE | SHA256:6CFAB4D81ACE3C9899D4715B05D2C0D238C8916D0B990D76C1323BC652568465 | |||
| 4044 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa4044.5501\EnigmaPluginsSDK\Bcb\plugin.bpf | text | |
MD5:4AF4DA1E9B04C1BF85C7E4E5A1B40563 | SHA256:2A8CB2CED3AB70DDA075EE5CC28EF4A98EF98C5B61F7DDAD5388AE81065D49EF | |||
| 4044 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa4044.5501\EnigmaPluginsSDK\Delphi\plugin.dof | text | |
MD5:DB322260F0523E6CF188BC423419CCBB | SHA256:E232278525CAF7933972916470C59027B8CA62777F3B2C40856885741F58AAB6 | |||
| 4044 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa4044.5501\Email Patterns\Registration Order.xml | xml | |
MD5:0BF414A1B2763C3AD5D8BB582E26FF04 | SHA256:6E2F96F4F70F752AE212DD4332FD29C679B4D3D3833BF90DA6E32D4081DF289D | |||
| 4044 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa4044.5501\EnigmaPluginsSDK\Bcb\plugin.bpr | xml | |
MD5:790616C935F9340C0A967D29ABD5FD8E | SHA256:CB4A1757E28B7E0E4BA80FD40E7C1472855E6D5B6E4B598B4B9CFFE13B0E74E9 | |||
| 4044 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa4044.5501\EnigmaPluginsSDK\Delphi\plugin.cfg | text | |
MD5:DFA10930F8938C3C41837CD1D96EF8D1 | SHA256:91502E94BD83B8803E91D20D1B231C112D65561F588B92E888982F7753374E8D | |||