| File name: | AppNee.com.AMT.Emulator.v0.9.2.rar |
| Full analysis: | https://app.any.run/tasks/d6653980-fb82-4515-8561-e8180990d9c4 |
| Verdict: | Malicious activity |
| Analysis date: | September 02, 2018, 16:49:10 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v5 |
| MD5: | 16273D81025FE1CCB018E81BEAFA5C2C |
| SHA1: | 9FD5815D4CD354283D282B656641697BE4EA791F |
| SHA256: | 314258BB8A334CE2B727652037F461566C1DCCB347BE655AC1C0304C1363A2A8 |
| SSDEEP: | 49152:kKDpEzBmyJ5jhrHjqoiwEvUxkNXY20QjktPNlUR467QH:BDGAchCPikNXYr2kt1C4CQH |
| .rar | | | RAR compressed archive (v5.0) (61.5) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 996 | "C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe12_ Global\UsGthrCtrlFltPipeMssGthrPipe12 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" | C:\Windows\System32\SearchProtocolHost.exe | — | SearchIndexer.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft Windows Search Protocol Host Exit code: 0 Version: 7.00.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1548 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\AppNee.com.AMT.Emulator.v0.9.2.rar" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 3680 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa1548.15198\AppNee.com.AMT.Emulator.v0.9.2\amtemu.v0.9.2-painter.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa1548.15198\AppNee.com.AMT.Emulator.v0.9.2\amtemu.v0.9.2-painter.exe | — | WinRAR.exe | |||||||||||
User: admin Company: PainteR Integrity Level: MEDIUM Description: ProxyEmu Exit code: 3221226540 Version: 0.9.2.0 Modules
| |||||||||||||||
| 3952 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa1548.15198\AppNee.com.AMT.Emulator.v0.9.2\amtemu.v0.9.2-painter.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa1548.15198\AppNee.com.AMT.Emulator.v0.9.2\amtemu.v0.9.2-painter.exe | WinRAR.exe | ||||||||||||
User: admin Company: PainteR Integrity Level: HIGH Description: ProxyEmu Exit code: 0 Version: 0.9.2.0 Modules
| |||||||||||||||
| (PID) Process: | (1548) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (1548) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (1548) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\59\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (1548) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\AppNee.com.AMT.Emulator.v0.9.2.rar | |||
| (PID) Process: | (1548) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (1548) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (1548) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (1548) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (1548) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\59\52C64B7E |
| Operation: | write | Name: | @C:\Windows\System32\ieframe.dll,-10046 |
Value: Internet Shortcut | |||
| (PID) Process: | (1548) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1548 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1548.15627\AppNee.com.AMT.Emulator.v0.9.2\amtlib.dll | — | |
MD5:— | SHA256:— | |||
| 1548 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1548.15198\AppNee.com.AMT.Emulator.v0.9.2\Original source.url | text | |
MD5:— | SHA256:— | |||
| 1548 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1548.15198\AppNee.com.AMT.Emulator.v0.9.2\Latest version.url | text | |
MD5:— | SHA256:— | |||
| 1548 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1548.15198\AppNee.com.AMT.Emulator.v0.9.2\amtlib.dll | executable | |
MD5:— | SHA256:— | |||
| 3952 | amtemu.v0.9.2-painter.exe | C:\Users\admin\Desktop\amtlib.dll.DEL | executable | |
MD5:— | SHA256:— | |||
| 3952 | amtemu.v0.9.2-painter.exe | C:\Users\admin\AppData\Local\Temp\spc_player.dll | executable | |
MD5:41AFBF49BA7F6EE164F31FAA2CD38E15 | SHA256:50D30B7AA7B9858F91F33165314C7CF7F2ACC97157091676C7E7925E018FD387 | |||
| 1548 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1548.15198\AppNee.com.AMT.Emulator.v0.9.2\changelog.txt | text | |
MD5:24882987B223569D21F827A935E468B9 | SHA256:CF271FDA61A832897F6770F2ABAC23B49CCFBE667889AAF6BD39A3B913D5671E | |||
| 1548 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1548.15198\AppNee.com.AMT.Emulator.v0.9.2\amtemu.v0.9.2-painter.exe | executable | |
MD5:8ABDC20F619641E29AA9AD2B999A0DCC | SHA256:CDC95D0113A2AF05C2E70FAB23F6C218AE583EBCB47077DD5B705A476F9D6B96 | |||
| 3952 | amtemu.v0.9.2-painter.exe | C:\Users\admin\Desktop\amtlib.dll | executable | |
MD5:219218AE29B2F9DFC8F6B745C004B1E3 | SHA256:649F3B0148C4F8202B0C2D24A490A99523ACC0BD3245C08499162B94CA5D30A5 | |||
| 3952 | amtemu.v0.9.2-painter.exe | C:\Users\admin\Desktop\painter.ini | text | |
MD5:4BE40389409CA2312CFBEA5790046261 | SHA256:E1919072E9DA0C48F653571619FD0336CE5DC835624C739C10746581C675A54D | |||