File name:

Trojan-Ransom.Win32.SageCrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.7z

Full analysis: https://app.any.run/tasks/79496e97-b477-4fb0-92c6-18ffeb81d9fb
Verdict: Malicious activity
Threats:

WarZone RAT is a remote access trojan, which is written in C++ and offered as a malware-as-a-service. It packs a wide range of capabilities, from stealing victims’ files and passwords to capturing desktop activities. WarZone RAT is primarily distributed via phishing emails and receives regular updates from its C2.

Analysis date: April 29, 2025, 15:11:38
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-exec
avemaria
warzone
rat
Indicators:
MIME: application/x-7z-compressed
File info: 7-zip archive data, version 0.4
MD5:

08B8D8526C8B2EBB0F94F303752FEF0B

SHA1:

375DCC3D4F73FF33464520E5895AB42E7A60CEF5

SHA256:

225D1954FE297F6A70C767295DDA951827D19C21C68CEE70AA2ECD0CF39411A9

SSDEEP:

1536:6wS9E/Wv+B8eBaYkH8WxWb2CwRZ7FBZptcBMmTj3Rhnu0A/SYwL27QxTAmX:6p+y+B8ekYk9xW6Z7FBZk/bj27ATAS

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 4996)
    • AVEMARIA mutex has been found

      • Trojan-Ransom.Win32.SageCrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe (PID: 5064)
  • SUSPICIOUS

    • Creates file in the systems drive root

      • Trojan-Ransom.Win32.SageCrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe (PID: 5064)
    • Application launched itself

      • Trojan-Ransom.Win32.SageCrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe (PID: 5064)
  • INFO

    • Checks supported languages

      • Trojan-Ransom.Win32.SageCrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe (PID: 5064)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 4996)
    • Manual execution by a user

      • Trojan-Ransom.Win32.SageCrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe (PID: 5064)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.7z | 7-Zip compressed archive (v0.4) (57.1)
.7z | 7-Zip compressed archive (gen) (42.8)

EXIF

ZIP

FileVersion: 7z v0.04
ModifyDate: 2017:11:29 06:48:16+00:00
ArchivedFileName: Trojan-Ransom.Win32.SageCrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
330
Monitored processes
204
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe sppextcomobj.exe no specs slui.exe no specs #AVEMARIA trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
632C:\Users\admin\Desktop\Trojan-Ransom.Win32.SageCrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exeC:\Users\admin\Desktop\Trojan-Ransom.Win32.SageCrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exeTrojan-Ransom.Win32.SageCrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
664C:\Users\admin\Desktop\Trojan-Ransom.Win32.SageCrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exeC:\Users\admin\Desktop\Trojan-Ransom.Win32.SageCrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exeTrojan-Ransom.Win32.SageCrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
728C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
736C:\Users\admin\Desktop\Trojan-Ransom.Win32.SageCrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exeC:\Users\admin\Desktop\Trojan-Ransom.Win32.SageCrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exeTrojan-Ransom.Win32.SageCrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
744C:\Users\admin\Desktop\Trojan-Ransom.Win32.SageCrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exeC:\Users\admin\Desktop\Trojan-Ransom.Win32.SageCrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exeTrojan-Ransom.Win32.SageCrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
864C:\Users\admin\Desktop\Trojan-Ransom.Win32.SageCrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exeC:\Users\admin\Desktop\Trojan-Ransom.Win32.SageCrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exeTrojan-Ransom.Win32.SageCrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
900C:\Users\admin\Desktop\Trojan-Ransom.Win32.SageCrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exeC:\Users\admin\Desktop\Trojan-Ransom.Win32.SageCrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exeTrojan-Ransom.Win32.SageCrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
904C:\Users\admin\Desktop\Trojan-Ransom.Win32.SageCrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exeC:\Users\admin\Desktop\Trojan-Ransom.Win32.SageCrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exeTrojan-Ransom.Win32.SageCrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
960C:\Users\admin\Desktop\Trojan-Ransom.Win32.SageCrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exeC:\Users\admin\Desktop\Trojan-Ransom.Win32.SageCrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exeTrojan-Ransom.Win32.SageCrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
1012C:\Users\admin\Desktop\Trojan-Ransom.Win32.SageCrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exeC:\Users\admin\Desktop\Trojan-Ransom.Win32.SageCrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exeTrojan-Ransom.Win32.SageCrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\trojan-ransom.win32.sagecrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
Total events
2 032
Read events
2 013
Write events
19
Delete events
0

Modification events

(PID) Process:(4996) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(4996) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(4996) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(4996) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\Trojan-Ransom.Win32.SageCrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.7z
(PID) Process:(4996) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(4996) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(4996) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(4996) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(4996) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
(PID) Process:(4996) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF3D0000002D000000FD03000016020000
Executable files
1
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
4996WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb4996.31982\Trojan-Ransom.Win32.SageCrypt.ahg-54671e0df5427cc112e1f65c653bc2abba07b2c48766cdc13fd8ee98b0a3a8ec.exeexecutable
MD5:AF600B0B81FB51E83BCFB1B89AA27FC1
SHA256:54671E0DF5427CC112E1F65C653BC2ABBA07B2C48766CDC13FD8EE98B0A3A8EC
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
13
DNS requests
8
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
23.48.23.143:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6544
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
23.48.23.143:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:137
whitelisted
3216
svchost.exe
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
20.190.160.17:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
2104
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 40.127.240.158
whitelisted
crl.microsoft.com
  • 23.48.23.143
  • 23.48.23.156
whitelisted
www.microsoft.com
  • 23.35.229.160
whitelisted
google.com
  • 142.250.185.110
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
login.live.com
  • 20.190.160.17
  • 40.126.32.138
  • 40.126.32.76
  • 20.190.160.131
  • 20.190.160.128
  • 40.126.32.140
  • 40.126.32.68
  • 20.190.160.4
whitelisted
ocsp.digicert.com
  • 184.30.131.245
whitelisted

Threats

No threats detected
No debug info