| File name: | Downloads.zip |
| Full analysis: | https://app.any.run/tasks/56dbf239-a6e4-4b9f-b90d-04b1e570663d |
| Verdict: | Malicious activity |
| Analysis date: | February 26, 2023, 13:54:50 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | 9DBB1905F440548C82E78D4C6618DE64 |
| SHA1: | 0E9E837A434D7E59F794AF6C9EAE8003340383B6 |
| SHA256: | 287375907E26B9FC8C31E72EC23F320815C5EC6A1628494C02EDB7F30F1AB654 |
| SSDEEP: | 12288:gVb1w//9cRa4GSxQmP4kFsz8zZD6u6I7HSD9g/g6nuonqOKUViyxDg9EzCde+Npq:o1vRa4+pzd590TqOYY84NzYuZNmPnSl3 |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipFileName: | bulletspassview/ |
|---|---|
| ZipUncompressedSize: | - |
| ZipCompressedSize: | - |
| ZipCRC: | 0x00000000 |
| ZipModifyDate: | 2023:02:26 22:52:10 |
| ZipCompression: | None |
| ZipBitFlag: | - |
| ZipRequiredVersion: | 20 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 116 | "C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\Downloads\bulletspassview\readme.txt | C:\Windows\system32\NOTEPAD.EXE | — | Explorer.EXE | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Notepad Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 832 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\Downloads.zip" | C:\Program Files\WinRAR\WinRAR.exe | Explorer.EXE | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 1772 | "C:\Users\admin\Desktop\Downloads\dialupass\Dialupass.exe" | C:\Users\admin\Desktop\Downloads\dialupass\Dialupass.exe | Explorer.EXE | ||||||||||||
User: admin Company: NirSoft Integrity Level: HIGH Description: Dialup/VPN Password Recovery Exit code: 0 Version: 3.61 Modules
| |||||||||||||||
| 1836 | "C:\Users\admin\Desktop\Downloads\mailpv\mailpv.exe" | C:\Users\admin\Desktop\Downloads\mailpv\mailpv.exe | Explorer.EXE | ||||||||||||
User: admin Company: NirSoft Integrity Level: MEDIUM Description: Email Password-Recovery Exit code: 0 Version: 1.92 Modules
| |||||||||||||||
| 2184 | "C:\Users\admin\Desktop\Downloads\routerpassview\RouterPassView.exe" | C:\Users\admin\Desktop\Downloads\routerpassview\RouterPassView.exe | — | Explorer.EXE | |||||||||||
User: admin Company: NirSoft Integrity Level: MEDIUM Description: Decrypts Router files. Exit code: 0 Version: 1.90 Modules
| |||||||||||||||
| 2420 | "C:\Users\admin\Desktop\Downloads\dialupass\Dialupass.exe" | C:\Users\admin\Desktop\Downloads\dialupass\Dialupass.exe | — | Explorer.EXE | |||||||||||
User: admin Company: NirSoft Integrity Level: MEDIUM Description: Dialup/VPN Password Recovery Exit code: 3221226540 Version: 3.61 Modules
| |||||||||||||||
| 2492 | "C:\Users\admin\Desktop\Downloads\webbrowserpassview (1)\WebBrowserPassView.exe" | C:\Users\admin\Desktop\Downloads\webbrowserpassview (1)\WebBrowserPassView.exe | Explorer.EXE | ||||||||||||
User: admin Company: NirSoft Integrity Level: MEDIUM Description: Web Browser Password Viewer Exit code: 0 Version: 2.12 Modules
| |||||||||||||||
| 3380 | "C:\Users\admin\Desktop\Downloads\bulletspassview\BulletsPassView.exe" | C:\Users\admin\Desktop\Downloads\bulletspassview\BulletsPassView.exe | — | Explorer.EXE | |||||||||||
User: admin Company: NirSoft Integrity Level: MEDIUM Description: BulletsPassView Exit code: 0 Version: 1.32 Modules
| |||||||||||||||
| 3872 | "C:\Users\admin\Desktop\Downloads\netrouteview\NetRouteView.exe" | C:\Users\admin\Desktop\Downloads\netrouteview\NetRouteView.exe | — | Explorer.EXE | |||||||||||
User: admin Company: NirSoft Integrity Level: MEDIUM Description: NetRouteView Exit code: 0 Version: 1.40 Modules
| |||||||||||||||
| 4040 | "C:\Users\admin\Desktop\Downloads\vncpassview\VNCPassView.exe" | C:\Users\admin\Desktop\Downloads\vncpassview\VNCPassView.exe | — | Explorer.EXE | |||||||||||
User: admin Company: NirSoft Integrity Level: MEDIUM Description: VNCPassView Exit code: 0 Version: 1.05 Modules
| |||||||||||||||
| (PID) Process: | (832) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (832) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (832) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\16D\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (832) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (832) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (832) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (832) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\Downloads.zip | |||
| (PID) Process: | (832) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (832) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (832) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 832 | WinRAR.exe | C:\Users\admin\Desktop\Downloads\bulletspassview\readme.txt | text | |
MD5:57AEE80A94BAF45512C0B7BD598C9B35 | SHA256:4B1D52F644239A09BAF545CD54C7DDFC9D04CB5F65E73F63989F71ED1B99612B | |||
| 832 | WinRAR.exe | C:\Users\admin\Desktop\Downloads\bulletspassview\BulletsPassView.chm | chm | |
MD5:C957F7AB8D05FABAC84EF239FB36CB29 | SHA256:32F9F133832ADC8116F5A588D35CA4F036B7E435E9AEEADE48B3A823DA56372F | |||
| 832 | WinRAR.exe | C:\Users\admin\Desktop\Downloads\dialupass\Dialupass.chm | chm | |
MD5:287F794AA15CB93FA91B763B34FE3A3A | SHA256:1E3EC12FBE9825C1EB044994D27C6FB97E5B2CEE352D114B0AE6F8862E2A2DD5 | |||
| 832 | WinRAR.exe | C:\Users\admin\Desktop\Downloads\dialupass\readme.txt | text | |
MD5:4F4A1F874F73C9236B92C6BBD1F36E3B | SHA256:C136C24B40756F9CF4D5AD3C7F7F1AEA9CE13E82979918E70326262F801A8F4C | |||
| 832 | WinRAR.exe | C:\Users\admin\Desktop\Downloads\bulletspassview\BulletsPassView.exe | executable | |
MD5:E40C9293EA0B6D62A0F62F40212DF07B | SHA256:B19DFE440E515C39928B475A946656A12B1051E98E0DF36C016586B34A766D5C | |||
| 832 | WinRAR.exe | C:\Users\admin\Desktop\Downloads\vncpassview\VNCPassView.exe | executable | |
MD5:D28F0CFAE377553FCB85918C29F4889B | SHA256:816D7616238958DFE0BB811A063EB3102EFD82EFF14408F5CAB4CB5258BFD019 | |||
| 832 | WinRAR.exe | C:\Users\admin\Desktop\Downloads\webbrowserpassview (1)\readme.txt | text | |
MD5:DFF7CBF7A7A6FC115C45D8E384FFCA0F | SHA256:496794C2682DE2961E0D48EC79DB5511F9274AC06405A40F64BE927DE89E05FC | |||
| 832 | WinRAR.exe | C:\Users\admin\Desktop\Downloads\routerpassview\RouterPassView.exe | executable | |
MD5:10D1D830605DB00287A616674EF9154A | SHA256:3EE00A42A65D2DF9EE571875A11F53B56C8494E90E1E8E60E128AABDB56399C8 | |||
| 2492 | WebBrowserPassView.exe | C:\Users\admin\AppData\Local\Temp\bhv5156.tmp | — | |
MD5:— | SHA256:— | |||
| 832 | WinRAR.exe | C:\Users\admin\Desktop\Downloads\vncpassview\VNCPassView.chm | chm | |
MD5:4314DF5882277917E89357D7243A3CEC | SHA256:CBA64638575E382BAB065F43DC60B76943BCE77854A80AF38DEBEB803EDB96E4 | |||