File name:

SPRX INJECTOR.zip

Full analysis: https://app.any.run/tasks/63d16258-9000-461f-9100-0cf3018b1923
Verdict: Malicious activity
Analysis date: June 27, 2019, 22:42:26
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract
MD5:

62486A0F511A5C19741F063FFB29C8DB

SHA1:

7C069C6A9D69691D412EA1F4B2DBB48CBE9CE0ED

SHA256:

2B66BFA24005E7EB8E6F050B0029EFFBF966874E3B1A1FB7BAC1965FA1A6673C

SSDEEP:

49152:S4TlhgV3YQLRPr8bFmJnUzXL43cZtJvnZ:l34IePARm8LVZnnZ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • [HFW] Tool Non Host Paradise SPRX Injector By Botan MoDz.exe (PID: 3808)
      • [HFW] Tool Non Host Paradise SPRX Injector By Botan MoDz.exe (PID: 2320)
    • Loads dropped or rewritten executable

      • [HFW] Tool Non Host Paradise SPRX Injector By Botan MoDz.exe (PID: 2320)
      • [HFW] Tool Non Host Paradise SPRX Injector By Botan MoDz.exe (PID: 3808)
  • SUSPICIOUS

    • Reads the BIOS version

      • [HFW] Tool Non Host Paradise SPRX Injector By Botan MoDz.exe (PID: 3808)
      • [HFW] Tool Non Host Paradise SPRX Injector By Botan MoDz.exe (PID: 2320)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2856)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2019:05:09 22:01:03
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: SPRX INJECTOR/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
37
Monitored processes
3
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start drop and start start winrar.exe [hfw] tool non host paradise sprx injector by botan modz.exe [hfw] tool non host paradise sprx injector by botan modz.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2320"C:\Users\admin\AppData\Local\Temp\Rar$EXa2856.37074\SPRX INJECTOR\[HFW] Tool Non Host Paradise SPRX Injector By Botan MoDz.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2856.37074\SPRX INJECTOR\[HFW] Tool Non Host Paradise SPRX Injector By Botan MoDz.exe
WinRAR.exe
User:
admin
Company:
Microsoft
Integrity Level:
MEDIUM
Description:
Déstiny Cracked By Botan MoDz Taca MoDz
Exit code:
3489660927
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2856.37074\sprx injector\[hfw] tool non host paradise sprx injector by botan modz.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2856"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\SPRX INJECTOR.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3808"C:\Users\admin\AppData\Local\Temp\Rar$EXa2856.39097\SPRX INJECTOR\[HFW] Tool Non Host Paradise SPRX Injector By Botan MoDz.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2856.39097\SPRX INJECTOR\[HFW] Tool Non Host Paradise SPRX Injector By Botan MoDz.exeWinRAR.exe
User:
admin
Company:
Microsoft
Integrity Level:
MEDIUM
Description:
Déstiny Cracked By Botan MoDz Taca MoDz
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2856.39097\sprx injector\[hfw] tool non host paradise sprx injector by botan modz.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
482
Read events
468
Write events
14
Delete events
0

Modification events

(PID) Process:(2856) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2856) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2856) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2856) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\SPRX INJECTOR.zip
(PID) Process:(2856) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2856) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2856) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2856) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2856) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
Operation:writeName:@C:\Windows\system32\notepad.exe,-469
Value:
Text Document
(PID) Process:(2856) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
Executable files
12
Suspicious files
1
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
2856WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2856.37074\SPRX INJECTOR\MonoFlat.dllexecutable
MD5:
SHA256:
2856WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2856.37074\SPRX INJECTOR\Read Me.txttext
MD5:
SHA256:
2856WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2856.37074\SPRX INJECTOR\MetroFramework.dllexecutable
MD5:34EA7F7D66563F724318E322FF08F4DB
SHA256:C2C12D31B4844E29DE31594FC9632A372A553631DE0A0A04C8AF91668E37CF49
2856WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2856.39097\SPRX INJECTOR\MonoFlat.dllexecutable
MD5:
SHA256:
2856WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2856.39097\SPRX INJECTOR\Read Me.txttext
MD5:
SHA256:
3808[HFW] Tool Non Host Paradise SPRX Injector By Botan MoDz.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2856.39097\SPRX INJECTOR\Paradise.sprxbinary
MD5:
SHA256:
2856WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2856.37074\SPRX INJECTOR\[HFW] Tool Non Host Paradise SPRX Injector By Botan MoDz.exeexecutable
MD5:
SHA256:
2856WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2856.39097\SPRX INJECTOR\LogIn Theme Dll By xVenoxi.dllexecutable
MD5:F3A5FD717A0782C88641CDEC9E66EA64
SHA256:04D7E61F6102A9CFB7E262211880D1A2AC89AD5EDF30CF4D28AC5E1444EE4C97
2856WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2856.39097\SPRX INJECTOR\MetroFramework.dllexecutable
MD5:34EA7F7D66563F724318E322FF08F4DB
SHA256:C2C12D31B4844E29DE31594FC9632A372A553631DE0A0A04C8AF91668E37CF49
2856WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2856.39097\SPRX INJECTOR\[HFW] Tool Non Host Paradise SPRX Injector By Botan MoDz.exeexecutable
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info