File name: | CopyTrans Photo 4.403.zip |
Full analysis: | https://app.any.run/tasks/231d5ca2-3e39-40d9-aa3b-50a1f2f79ba6 |
Verdict: | Malicious activity |
Analysis date: | April 27, 2020, 04:29:21 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/zip |
File info: | Zip archive data, at least v2.0 to extract |
MD5: | 9D70DD15A6EADFBF14D19E55E56D3489 |
SHA1: | 2FA5F728832049A769D4761D2FA2544B777303E0 |
SHA256: | 2F29FC7D1A3A5F28A4429E8FFEEFE8C5B07555A13719BA255D73A3D43FCCBEC6 |
SSDEEP: | 12288:sycdKiUzzECPHaL+dOv12OiraGfeHPXu9YWVPYDk0zHKwbSYfX7+2R/ZpW707iGb:50uzwsHaLWOQXrpGvX6tiDBeSq2RBpWG |
.zip | | | ZIP compressed archive (100) |
---|
ZipRequiredVersion: | 20 |
---|---|
ZipBitFlag: | 0x0001 |
ZipCompression: | Deflated |
ZipModifyDate: | 2020:04:27 07:27:29 |
ZipCRC: | 0x643e0da0 |
ZipCompressedSize: | 684037 |
ZipUncompressedSize: | 757911 |
ZipFileName: | CopyTrans Photo 4.403.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
1136 | "C:\Users\admin\AppData\Local\Temp\is-U6R5U.tmp\CopyTrans Photo 4.403.tmp" /SL5="$801E0,367862,121344,C:\Users\admin\Desktop\CopyTrans Photo 4.403.exe" /SPAWNWND=$80194 /NOTIFYWND=$80130 | C:\Users\admin\AppData\Local\Temp\is-U6R5U.tmp\CopyTrans Photo 4.403.tmp | CopyTrans Photo 4.403.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
1784 | "C:\Windows\system32\schtasks.exe" /Delete /tn "Microsoft\Windows\Windows Error Reporting\SystemInfo" /f | C:\Windows\system32\schtasks.exe | — | sysinfo.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Manages scheduled tasks Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
2108 | C:\Windows\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -Embedding | C:\Windows\explorer.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
2360 | "C:\Users\admin\Desktop\CopyTrans Photo 4.403.exe" /SPAWNWND=$80194 /NOTIFYWND=$80130 | C:\Users\admin\Desktop\CopyTrans Photo 4.403.exe | CopyTrans Photo 4.403.tmp | ||||||||||||
User: admin Company: Integrity Level: HIGH Description: Exit code: 0 Version: 5.2 Modules
| |||||||||||||||
2740 | "explorer.exe" "C:\Users\admin\Desktop\CopyTrans Photo 4.403" | C:\Windows\explorer.exe | — | CopyTrans Photo 4.403.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Explorer Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
3164 | "C:\Windows\system32\schtasks.exe" /Create /f /XML "C:\Users\admin\AppData\Roaming\SystemDiag\data.xml" /tn "Microsoft\Windows\Windows Error Reporting\SystemInfo" | C:\Windows\system32\schtasks.exe | — | sysinfo.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
3388 | "C:\Users\admin\AppData\Local\Temp\is-4ILD9.tmp\CopyTrans Photo 4.403.tmp" /SL5="$80130,367862,121344,C:\Users\admin\Desktop\CopyTrans Photo 4.403.exe" | C:\Users\admin\AppData\Local\Temp\is-4ILD9.tmp\CopyTrans Photo 4.403.tmp | — | CopyTrans Photo 4.403.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
3420 | "C:\Users\admin\Desktop\CopyTrans Photo 4.403.exe" | C:\Users\admin\Desktop\CopyTrans Photo 4.403.exe | explorer.exe | ||||||||||||
User: admin Company: Integrity Level: MEDIUM Description: Exit code: 0 Version: 5.2 Modules
| |||||||||||||||
3544 | "C:\Users\admin\AppData\Local\Temp\is-V0CJU.tmp\7za.exe" x "C:\Users\admin\AppData\Local\Temp\is-V0CJU.tmp\sub.res" -p"b1lig@n_vl" | C:\Users\admin\AppData\Local\Temp\is-V0CJU.tmp\7za.exe | — | CopyTrans Photo 4.403.tmp | |||||||||||
User: admin Company: Igor Pavlov Integrity Level: HIGH Description: 7-Zip Standalone Console Exit code: 0 Version: 4.65 Modules
| |||||||||||||||
3668 | "C:\Users\admin\AppData\Local\Temp\is-V0CJU.tmp\7za.exe" x "C:\Users\admin\AppData\Local\Temp\is-V0CJU.tmp\misc.res" -p"b1lig@n_vl" | C:\Users\admin\AppData\Local\Temp\is-V0CJU.tmp\7za.exe | — | CopyTrans Photo 4.403.tmp | |||||||||||
User: admin Company: Igor Pavlov Integrity Level: HIGH Description: 7-Zip Standalone Console Exit code: 0 Version: 4.65 Modules
|
(PID) Process: | (3880) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtBMP |
Value: | |||
(PID) Process: | (3880) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtIcon |
Value: | |||
(PID) Process: | (3880) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (3880) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\CopyTrans Photo 4.403.zip | |||
(PID) Process: | (3880) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | name |
Value: 120 | |||
(PID) Process: | (3880) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | size |
Value: 80 | |||
(PID) Process: | (3880) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | type |
Value: 120 | |||
(PID) Process: | (3880) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | mtime |
Value: 100 | |||
(PID) Process: | (3880) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath |
Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop | |||
(PID) Process: | (3880) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface |
Operation: | write | Name: | ShowPassword |
Value: 0 |
PID | Process | Filename | Type | |
---|---|---|---|---|
1136 | CopyTrans Photo 4.403.tmp | C:\Users\admin\AppData\Local\Temp\{A116156A-F9BF-4318-95AB-3ADB8566D2A9}\is-M6JC6.tmp | — | |
MD5:— | SHA256:— | |||
1136 | CopyTrans Photo 4.403.tmp | C:\Users\admin\AppData\Local\Temp\{A116156A-F9BF-4318-95AB-3ADB8566D2A9}\license.txt | — | |
MD5:— | SHA256:— | |||
3880 | WinRAR.exe | C:\Users\admin\Desktop\CopyTrans Photo 4.403.exe | executable | |
MD5:— | SHA256:— | |||
1136 | CopyTrans Photo 4.403.tmp | C:\Users\admin\Desktop\CopyTrans Photo 4.403\license.txt | text | |
MD5:— | SHA256:— | |||
1136 | CopyTrans Photo 4.403.tmp | C:\Users\admin\AppData\Local\Temp\is-V0CJU.tmp\misc.res | compressed | |
MD5:— | SHA256:— | |||
1136 | CopyTrans Photo 4.403.tmp | C:\Users\admin\AppData\Local\Temp\is-V0CJU.tmp\form.res | compressed | |
MD5:— | SHA256:— | |||
3996 | 7za.exe | C:\Users\admin\AppData\Local\Temp\is-V0CJU.tmp\form.exe | executable | |
MD5:— | SHA256:— | |||
3668 | 7za.exe | C:\Users\admin\AppData\Local\Temp\is-V0CJU.tmp\misc.xml | xml | |
MD5:— | SHA256:— | |||
1136 | CopyTrans Photo 4.403.tmp | C:\Users\admin\AppData\Roaming\SystemDiag\sysinfo.exe | executable | |
MD5:— | SHA256:— | |||
1136 | CopyTrans Photo 4.403.tmp | C:\Users\admin\AppData\Roaming\SystemDiag\data | xml | |
MD5:— | SHA256:— |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
1136 | CopyTrans Photo 4.403.tmp | GET | 301 | 104.27.143.232:80 | http://crackpluskeygen.org/provider | US | — | — | malicious |
1136 | CopyTrans Photo 4.403.tmp | POST | 200 | 172.217.22.14:80 | http://www.google-analytics.com/collect | US | image | 35 b | whitelisted |
1136 | CopyTrans Photo 4.403.tmp | POST | 200 | 172.217.22.14:80 | http://www.google-analytics.com/collect | US | image | 35 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
1136 | CopyTrans Photo 4.403.tmp | 172.217.22.14:80 | www.google-analytics.com | Google Inc. | US | whitelisted |
1136 | CopyTrans Photo 4.403.tmp | 104.27.143.232:80 | crackpluskeygen.org | Cloudflare Inc | US | shared |
1136 | CopyTrans Photo 4.403.tmp | 104.27.143.232:443 | crackpluskeygen.org | Cloudflare Inc | US | shared |
Domain | IP | Reputation |
---|---|---|
www.google-analytics.com |
| whitelisted |
crackpluskeygen.org |
| malicious |