File name: | gazelbomb.zip |
Full analysis: | https://app.any.run/tasks/3197d27b-1e49-4b9e-91e1-dc0647070157 |
Verdict: | Malicious activity |
Analysis date: | March 21, 2019, 10:12:05 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/zip |
File info: | Zip archive data, at least v2.0 to extract |
MD5: | FE148FDEA38B127AFB65BC81B46B6D71 |
SHA1: | E95EE52816F5D4BB8738D4927805D82827450715 |
SHA256: | 236D5D6B8A83C944D33FB620CB09C81A772477B29EB73AE6F55D82146E86389F |
SSDEEP: | 3072:S17FI4XS92bIK9ADkKF/myanEG8A/+xkpQSZiju5+Tqrp:07d6KAYxEGL6jFW9 |
.zip | | | ZIP compressed archive (100) |
---|
ZipFileName: | bat.bat |
---|---|
ZipUncompressedSize: | 92 |
ZipCompressedSize: | 83 |
ZipCRC: | 0xecd8e27c |
ZipModifyDate: | 2019:03:21 13:11:25 |
ZipCompression: | Deflated |
ZipBitFlag: | - |
ZipRequiredVersion: | 20 |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
660 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\gazelbomb.zip" | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe |
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Version: 5.60.0 | ||||
2372 | cmd /c ""C:\Users\admin\Desktop\bat.bat" " | C:\Windows\system32\cmd.exe | — | explorer.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) | ||||
2764 | gazel.exe | C:\Users\admin\Desktop\gazel.exe | — | cmd.exe |
User: admin Company: от создателей сапер-пидорас Integrity Level: MEDIUM Version: 1.00 | ||||
2860 | gazel.exe | C:\Users\admin\Desktop\gazel.exe | — | cmd.exe |
User: admin Company: от создателей сапер-пидорас Integrity Level: MEDIUM Version: 1.00 | ||||
2788 | gazel.exe | C:\Users\admin\Desktop\gazel.exe | — | cmd.exe |
User: admin Company: от создателей сапер-пидорас Integrity Level: MEDIUM Version: 1.00 | ||||
3568 | gazel.exe | C:\Users\admin\Desktop\gazel.exe | — | cmd.exe |
User: admin Company: от создателей сапер-пидорас Integrity Level: MEDIUM Version: 1.00 | ||||
3280 | gazel.exe | C:\Users\admin\Desktop\gazel.exe | — | cmd.exe |
User: admin Company: от создателей сапер-пидорас Integrity Level: MEDIUM Version: 1.00 | ||||
4064 | gazel.exe | C:\Users\admin\Desktop\gazel.exe | — | cmd.exe |
User: admin Company: от создателей сапер-пидорас Integrity Level: MEDIUM Version: 1.00 | ||||
2132 | gazel.exe | C:\Users\admin\Desktop\gazel.exe | — | cmd.exe |
User: admin Company: от создателей сапер-пидорас Integrity Level: MEDIUM Version: 1.00 | ||||
1872 | gazel.exe | C:\Users\admin\Desktop\gazel.exe | — | cmd.exe |
User: admin Company: от создателей сапер-пидорас Integrity Level: MEDIUM Version: 1.00 |
(PID) Process: | (660) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtBMP |
Value: | |||
(PID) Process: | (660) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtIcon |
Value: | |||
(PID) Process: | (660) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (660) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\gazelbomb.zip | |||
(PID) Process: | (660) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | name |
Value: 120 | |||
(PID) Process: | (660) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | size |
Value: 80 | |||
(PID) Process: | (660) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | type |
Value: 120 | |||
(PID) Process: | (660) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | mtime |
Value: 100 | |||
(PID) Process: | (660) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E |
Operation: | write | Name: | @C:\Windows\System32\acppage.dll,-6002 |
Value: Windows Batch File | |||
(PID) Process: | (3568) gazel.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AudioCompressionManager\DriverCache\msacm.imaadpcm |
Operation: | write | Name: | fdwSupport |
Value: 1 |
PID | Process | Filename | Type | |
---|---|---|---|---|
660 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa660.15602\bat.bat | — | |
MD5:— | SHA256:— | |||
660 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa660.15602\gazel.exe | — | |
MD5:— | SHA256:— |