| File name: | gazelbomb.zip |
| Full analysis: | https://app.any.run/tasks/3197d27b-1e49-4b9e-91e1-dc0647070157 |
| Verdict: | Malicious activity |
| Analysis date: | March 21, 2019, 10:12:05 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | FE148FDEA38B127AFB65BC81B46B6D71 |
| SHA1: | E95EE52816F5D4BB8738D4927805D82827450715 |
| SHA256: | 236D5D6B8A83C944D33FB620CB09C81A772477B29EB73AE6F55D82146E86389F |
| SSDEEP: | 3072:S17FI4XS92bIK9ADkKF/myanEG8A/+xkpQSZiju5+Tqrp:07d6KAYxEGL6jFW9 |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2019:03:21 13:11:25 |
| ZipCRC: | 0xecd8e27c |
| ZipCompressedSize: | 83 |
| ZipUncompressedSize: | 92 |
| ZipFileName: | bat.bat |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 128 | gazel.exe | C:\Users\admin\Desktop\gazel.exe | — | cmd.exe | |||||||||||
User: admin Company: от создателей сапер-пидорас Integrity Level: MEDIUM Exit code: 0 Version: 1.00 Modules
| |||||||||||||||
| 240 | gazel.exe | C:\Users\admin\Desktop\gazel.exe | — | cmd.exe | |||||||||||
User: admin Company: от создателей сапер-пидорас Integrity Level: MEDIUM Exit code: 0 Version: 1.00 Modules
| |||||||||||||||
| 260 | gazel.exe | C:\Users\admin\Desktop\gazel.exe | — | cmd.exe | |||||||||||
User: admin Company: от создателей сапер-пидорас Integrity Level: MEDIUM Exit code: 0 Version: 1.00 Modules
| |||||||||||||||
| 264 | gazel.exe | C:\Users\admin\Desktop\gazel.exe | — | cmd.exe | |||||||||||
User: admin Company: от создателей сапер-пидорас Integrity Level: MEDIUM Exit code: 0 Version: 1.00 Modules
| |||||||||||||||
| 304 | gazel.exe | C:\Users\admin\Desktop\gazel.exe | — | cmd.exe | |||||||||||
User: admin Company: от создателей сапер-пидорас Integrity Level: MEDIUM Exit code: 0 Version: 1.00 Modules
| |||||||||||||||
| 324 | gazel.exe | C:\Users\admin\Desktop\gazel.exe | — | cmd.exe | |||||||||||
User: admin Company: от создателей сапер-пидорас Integrity Level: MEDIUM Exit code: 0 Version: 1.00 Modules
| |||||||||||||||
| 332 | gazel.exe | C:\Users\admin\Desktop\gazel.exe | — | cmd.exe | |||||||||||
User: admin Company: от создателей сапер-пидорас Integrity Level: MEDIUM Exit code: 0 Version: 1.00 Modules
| |||||||||||||||
| 340 | gazel.exe | C:\Users\admin\Desktop\gazel.exe | — | cmd.exe | |||||||||||
User: admin Company: от создателей сапер-пидорас Integrity Level: MEDIUM Exit code: 0 Version: 1.00 | |||||||||||||||
| 516 | gazel.exe | C:\Users\admin\Desktop\gazel.exe | — | cmd.exe | |||||||||||
User: admin Company: от создателей сапер-пидорас Integrity Level: MEDIUM Exit code: 0 Version: 1.00 Modules
| |||||||||||||||
| 580 | gazel.exe | C:\Users\admin\Desktop\gazel.exe | — | cmd.exe | |||||||||||
User: admin Company: от создателей сапер-пидорас Integrity Level: MEDIUM Exit code: 0 Version: 1.00 Modules
| |||||||||||||||
| (PID) Process: | (660) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (660) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (660) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (660) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\gazelbomb.zip | |||
| (PID) Process: | (660) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (660) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (660) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (660) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (660) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E |
| Operation: | write | Name: | @C:\Windows\System32\acppage.dll,-6002 |
Value: Windows Batch File | |||
| (PID) Process: | (3568) gazel.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AudioCompressionManager\DriverCache\msacm.imaadpcm |
| Operation: | write | Name: | fdwSupport |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 660 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa660.15602\bat.bat | — | |
MD5:— | SHA256:— | |||
| 660 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa660.15602\gazel.exe | — | |
MD5:— | SHA256:— | |||