| File name: | Indetectables Rat v.0.9.5 [AutoIt] Beta By M3.rar |
| Full analysis: | https://app.any.run/tasks/c2d1992e-5539-42ba-9e77-5b3b1cff2193 |
| Verdict: | Malicious activity |
| Analysis date: | September 06, 2018, 13:21:38 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v4, os: Win32 |
| MD5: | 09BB5777247D06469AF5EEA4D9AB2982 |
| SHA1: | 4D1C8F9F2FF027FF1B8F818DF3C58F8FC712EEA0 |
| SHA256: | 1E2F183C1DE1D89E67EEE889A2A9D6F96919C6DEC469AB32A60D6D6123BA460D |
| SSDEEP: | 393216:+fKf1lZImbUAGjlCCIh5BYPDtPJxImCN6up:+fGZImAZCph5Bbp |
| .rar | | | RAR compressed archive (v-4.x) (58.3) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (41.6) |
| CompressedSize: | 129962 |
|---|---|
| UncompressedSize: | 139360 |
| OperatingSystem: | Win32 |
| ModifyDate: | 2014:01:17 11:30:12 |
| PackingMethod: | Normal |
| ArchivedFileName: | IndRat v.9.5\Bandeiras\ad.png |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 380 | "C:\Users\admin\Desktop\IndRat v.9.5\Compilador\Aut2exe.exe" | C:\Users\admin\Desktop\IndRat v.9.5\Compilador\Aut2exe.exe | explorer.exe | ||||||||||||
User: admin Company: AutoIt Team Integrity Level: MEDIUM Description: Aut2Exe Exit code: 0 Version: 3, 3, 8, 1 Modules
| |||||||||||||||
| 584 | "C:\Windows\system32\dllhost.exe" | C:\Windows\system32\dllhost.exe | — | Microsoft.ApplicationId.Framework.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: COM Surrogate Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 768 | "C:\Users\admin\Desktop\111.exe" | C:\Users\admin\Desktop\111.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 1 Version: 3, 3, 8, 1 Modules
| |||||||||||||||
| 868 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\Indetectables Rat v.0.9.5 [AutoIt] Beta By M3.rar" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 1504 | "C:\Users\admin\Desktop\IndRat v.9.5\IndRat.exe" | C:\Users\admin\Desktop\IndRat v.9.5\IndRat.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Version: 3, 3, 8, 1 Modules
| |||||||||||||||
| 2124 | "C:\Users\admin\Desktop\IndRat v.9.5\Compilador\upx.exe" --best --compress-icons=0 "C:\Users\admin\Desktop\111.exe" | C:\Users\admin\Desktop\IndRat v.9.5\Compilador\upx.exe | Aut2exe.exe | ||||||||||||
User: admin Company: The UPX Team http://upx.sf.net Integrity Level: MEDIUM Description: UPX executable packer Exit code: 0 Version: 3.07 (2010-09-08) Modules
| |||||||||||||||
| 2472 | "C:\Users\admin\AppData\Local\Temp\Ind\Microsoft.ApplicationId.Framework.exe" C:\Users\admin\AppData\Local\Temp\Ind\Microsoft.ApplicationId.Framework.exe | C:\Users\admin\AppData\Local\Temp\Ind\Microsoft.ApplicationId.Framework.exe | CompMgmtLauncher.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Version: 3, 3, 8, 1 Modules
| |||||||||||||||
| 2656 | "C:\Windows\System32\CompMgmtLauncher.exe" | C:\Windows\System32\CompMgmtLauncher.exe | — | Microsoft.ApplicationId.Framework.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Computer Management Snapin Launcher Exit code: 3221226540 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2688 | "C:\Users\admin\AppData\Local\Temp\Ind\Microsoft.ApplicationId.Framework.exe" | C:\Users\admin\AppData\Local\Temp\Ind\Microsoft.ApplicationId.Framework.exe | — | 111.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Version: 3, 3, 8, 1 Modules
| |||||||||||||||
| 2804 | "C:\Windows\system32\taskmgr.exe" /4 | C:\Windows\system32\taskmgr.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Task Manager Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (868) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (868) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (868) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\59\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (868) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\Indetectables Rat v.0.9.5 [AutoIt] Beta By M3.rar | |||
| (PID) Process: | (868) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (868) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (868) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (868) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (868) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface |
| Operation: | write | Name: | ShowPassword |
Value: 0 | |||
| (PID) Process: | (868) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin |
| Operation: | write | Name: | Placement |
Value: 2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF2C0000002C000000EC03000021020000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 868 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb868.30737\IndRat v.9.5\Bandeiras\af.png | image | |
MD5:E5D92DB7336D1DC8B4BE5425FF751325 | SHA256:2BF77EE6997D42C789F6BDF02806F66F6615D6AB033353C3246D69020DD92B52 | |||
| 868 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb868.30737\IndRat v.9.5\Bandeiras\am.png | image | |
MD5:0F82690416FF12366A67B9402735C1DE | SHA256:4AAB0BE2ACA936BD6DE310D5271509D517E9E6D3E74996B11D7EC2358040B4E9 | |||
| 868 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb868.30737\IndRat v.9.5\Bandeiras\au.png | image | |
MD5:2A1384DE781BF1374F8A96710ED5CD70 | SHA256:5D7C2318950FD8490EEA8C6C488917E386407D4D0C29FF2B71D10F73A9169162 | |||
| 868 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb868.30737\IndRat v.9.5\Bandeiras\ad.png | image | |
MD5:C22BA67A6B94164AD220C2064994ADD1 | SHA256:EEF9B90D0D988CC15B2AC5567852FACC7C0DE9B19A8C12BB96BDB7C64DD0D2C9 | |||
| 868 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb868.30737\IndRat v.9.5\Bandeiras\ao.png | image | |
MD5:5A020033C257E92D7613B278109CC404 | SHA256:B82F6BFF7F8772C7A663DDBFEA394695E0970162E7D0E18696CC386160597D1F | |||
| 868 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb868.30737\IndRat v.9.5\Bandeiras\at.png | image | |
MD5:018CB031396887BB748C95FF32FA6B6A | SHA256:F2488FB3A8A7D485E53050A00B6895408F6ADADAD7F68365DB274686CA26864A | |||
| 868 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb868.30737\IndRat v.9.5\Bandeiras\ba.png | image | |
MD5:1C320DD11E66B35DC1A2350F138181D5 | SHA256:115DC28A61F75D2799EEB0B17CC7C9EC8CDF082A60A3CED1E94292AF568FB0FB | |||
| 868 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb868.30737\IndRat v.9.5\Bandeiras\al.png | image | |
MD5:938F6D2AD6EB0754B4B1CE8D6EFE3D00 | SHA256:D3AD4F7C40CF88D3072EB158F6083053017D4B4F0537CFB8C0AAAD7CD79D768C | |||
| 868 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb868.30737\IndRat v.9.5\Bandeiras\ae.png | image | |
MD5:AA44839785B2EF1890987B6815791020 | SHA256:165A7FE36D6DABA17F36082CEBA573B107FF54293E8792C4FE2E186752210244 | |||
| 868 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb868.30737\IndRat v.9.5\Bandeiras\ag.png | image | |
MD5:1C0D859D89EA2FD426B5995629B48C02 | SHA256:DB673A779729744BD091322D388F31857B6E4B2F516C212317FB80BB6AE0660E | |||