File name:

peace elite bypass.zip

Full analysis: https://app.any.run/tasks/4e9e9e32-4555-4da5-bb89-dd1f682e7e84
Verdict: Malicious activity
Analysis date: February 24, 2020, 04:19:12
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract
MD5:

4DA0D0D407DA49F90CD5A69A05AA07AC

SHA1:

4E41882F0894FB8B6EDA755D761941CD3B4D72F4

SHA256:

238222355C75EE64386116A0342EE628A91836E78FBA8F4594E5A0136BF01DF0

SSDEEP:

196608:u+X8WU5mqkkRc8ouYagUb5ia81ZE2CuolhJQFiYQY33xPb8UMRsla6nKNGRFAX/q:jXIk8cS/bYvZE2Cuo/Jqi2xPbrbla6n5

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • 拯救助手1.exe (PID: 3420)
      • 拯救国服过检测V2.0.v2破解版.exe (PID: 3484)
      • Õü¾È¹ú·þ¹ý¼ì²âV2.0.v2.exe (PID: 3928)
      • 拯救国服过检测V2.0.v2破解版.exe (PID: 2496)
      • Õü¾È¹ú·þ¹ý¼ì²âV2.0.v2.exe (PID: 1832)
    • Task Manager has been disabled (taskmgr)

      • Õü¾È¹ú·þ¹ý¼ì²âV2.0.v2.exe (PID: 3928)
      • Õü¾È¹ú·þ¹ý¼ì²âV2.0.v2.exe (PID: 1832)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1196)
      • 拯救国服过检测V2.0.v2破解版.exe (PID: 3484)
      • 拯救国服过检测V2.0.v2破解版.exe (PID: 2496)
  • INFO

    • Manual execution by user

      • 拯救国服过检测V2.0.v2破解版.exe (PID: 3484)
      • 拯救助手1.exe (PID: 3420)
      • WinRAR.exe (PID: 1196)
      • 拯救国服过检测V2.0.v2破解版.exe (PID: 2496)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2020:02:24 04:09:08
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: ??ƽ??Ӣ???ȹ????????⸨??һ???ƽ???/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
54
Monitored processes
7
Malicious processes
2
Suspicious processes
2

Behavior graph

Click at the process to see the details
start drop and start drop and start winrar.exe no specs winrar.exe 拯救助手1.exe 拯救国服过检测v2.0.v2破解版.exe õü¾è¹ú·þ¹ý¼ì²âv2.0.v2.exe 拯救国服过检测v2.0.v2破解版.exe õü¾è¹ú·þ¹ý¼ì²âv2.0.v2.exe

Process information

PID
CMD
Path
Indicators
Parent process
1196"C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Desktop\peace elite bypass.zip" C:\Users\admin\Desktop\C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
1832C:\KSDJF9\Õü¾È¹ú·þ¹ý¼ì²âV2.0.v2.exeC:\KSDJF9\Õü¾È¹ú·þ¹ý¼ì²âV2.0.v2.exe
拯救国服过检测V2.0.v2破解版.exe
User:
admin
Company:
腾讯应用
Integrity Level:
HIGH
Description:
腾讯应用
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\ksdjf9\õü¾è¹ú·þ¹ý¼ì²âv2.0.v2.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2496"C:\Users\admin\Desktop\和平精英拯救国服过检测辅助一体破解版\拯救国服过检测V2.0.v2破解版.exe" C:\Users\admin\Desktop\和平精英拯救国服过检测辅助一体破解版\拯救国服过检测V2.0.v2破解版.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
易语言程序
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\和平精英拯救国服过检测辅助一体破解版\拯救国服过检测v2.0.v2破解版.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2616"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\peace elite bypass.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3420"C:\Users\admin\Desktop\和平精英拯救国服过检测辅助一体破解版\拯救助手1.exe" C:\Users\admin\Desktop\和平精英拯救国服过检测辅助一体破解版\拯救助手1.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
拯救
Exit code:
3221225477
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\和平精英拯救国服过检测辅助一体破解版\拯救助手1.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3484"C:\Users\admin\Desktop\和平精英拯救国服过检测辅助一体破解版\拯救国服过检测V2.0.v2破解版.exe" C:\Users\admin\Desktop\和平精英拯救国服过检测辅助一体破解版\拯救国服过检测V2.0.v2破解版.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
易语言程序
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\和平精英拯救国服过检测辅助一体破解版\拯救国服过检测v2.0.v2破解版.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3928C:\KSDJF9\Õü¾È¹ú·þ¹ý¼ì²âV2.0.v2.exeC:\KSDJF9\Õü¾È¹ú·þ¹ý¼ì²âV2.0.v2.exe
拯救国服过检测V2.0.v2破解版.exe
User:
admin
Company:
腾讯应用
Integrity Level:
HIGH
Description:
腾讯应用
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\ksdjf9\õü¾è¹ú·þ¹ý¼ì²âv2.0.v2.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
384
Read events
355
Write events
29
Delete events
0

Modification events

(PID) Process:(2616) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2616) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2616) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2616) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\peace elite bypass.zip
(PID) Process:(2616) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2616) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2616) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2616) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2616) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
(PID) Process:(2616) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\General
Operation:writeName:LastFolder
Value:
C:\Users\admin\Desktop
Executable files
4
Suspicious files
0
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
1196WinRAR.exeC:\Users\admin\Desktop\和平精英拯救国服过检测辅助一体破解版\拯救国服过检测V2.0.v2破解版.exeexecutable
MD5:
SHA256:
1196WinRAR.exeC:\Users\admin\Desktop\和平精英拯救国服过检测辅助一体破解版\拯救助手1.exeexecutable
MD5:
SHA256:
3484拯救国服过检测V2.0.v2破解版.exeC:\KSDJF9\Õü¾È¹ú·þ¹ý¼ì²âV2.0.v2.exeexecutable
MD5:
SHA256:
1196WinRAR.exeC:\Users\admin\Desktop\和平精英拯救国服过检测辅助一体破解版\必看说明.txttext
MD5:
SHA256:
2496拯救国服过检测V2.0.v2破解版.exeC:\KSDJF9\Õü¾È¹ú·þ¹ý¼ì²âV2.0.v2.exeexecutable
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
2
DNS requests
2
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1832
Õü¾È¹ú·þ¹ý¼ì²âV2.0.v2.exe
43.226.64.41:9001
CN
unknown
3928
Õü¾È¹ú·þ¹ý¼ì²âV2.0.v2.exe
43.226.64.41:9001
CN
unknown

DNS requests

Domain
IP
Reputation
dns.msftncsi.com
  • 131.107.255.255
shared

Threats

No threats detected
No debug info