File name:

Crack.rar

Full analysis: https://app.any.run/tasks/73d172b6-935e-46a8-a191-de23164a6d1b
Verdict: Malicious activity
Analysis date: August 16, 2018, 16:05:55
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v4, os: Win32, flags: Locked
MD5:

153F2C4215531BC80E7141913ABDE172

SHA1:

7D7628BA0ED705F0EEC09D36A9C21A7D07C7F0C2

SHA256:

32BF0593DA42136D71C60F53EF2EB95ACC2F799263475F4BBBF67AA7C282BBAB

SSDEEP:

49152:qeygreBGo+WSJONPp3HkZaA40Wi6foc47c83zAt/eVvSN8cC7gchJghbaedtIfA1:qkreBcfSuEAgNocYMUhcCkG60q1

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • amtemu.v0.9-painter.exe (PID: 3748)
      • Keygen_XF-adobecc2015.exe (PID: 956)
      • adobe.snr.patch-painter.exe (PID: 580)
      • amtemu.v0.9-painter.exe (PID: 2148)
      • adobe.snr.patch-painter.exe (PID: 1680)
    • Loads dropped or rewritten executable

      • amtemu.v0.9-painter.exe (PID: 2148)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • amtemu.v0.9-painter.exe (PID: 2148)
      • WinRAR.exe (PID: 3360)
  • INFO

    • Dropped object may contain URL's

      • WinRAR.exe (PID: 3360)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

CompressedSize: 605852
UncompressedSize: 631808
OperatingSystem: Win32
ModifyDate: 2016:02:09 09:22:04
PackingMethod: Best Compression
ArchivedFileName: Crack\Adobe CC 2015 Universal Patcher 1.5\adobe.snr.patch-painter.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
46
Monitored processes
6
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe amtemu.v0.9-painter.exe no specs amtemu.v0.9-painter.exe keygen_xf-adobecc2015.exe no specs adobe.snr.patch-painter.exe no specs adobe.snr.patch-painter.exe

Process information

PID
CMD
Path
Indicators
Parent process
580"C:\Users\admin\Desktop\Crack\Adobe CC 2015 Universal Patcher 1.5\adobe.snr.patch-painter.exe" C:\Users\admin\Desktop\Crack\Adobe CC 2015 Universal Patcher 1.5\adobe.snr.patch-painter.exe
explorer.exe
User:
admin
Company:
PainteR
Integrity Level:
HIGH
Description:
Universal Adobe Patcher
Exit code:
0
Version:
1.5.0.0
Modules
Images
c:\users\admin\desktop\crack\adobe cc 2015 universal patcher 1.5\adobe.snr.patch-painter.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\gdi32.dll
956"C:\Users\admin\Desktop\Crack\Adobe CC 2015.5 XFORCE Activation\Keygen_XF-adobecc2015.exe" C:\Users\admin\Desktop\Crack\Adobe CC 2015.5 XFORCE Activation\Keygen_XF-adobecc2015.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\crack\adobe cc 2015.5 xforce activation\keygen_xf-adobecc2015.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winmm.dll
1680"C:\Users\admin\Desktop\Crack\Adobe CC 2015 Universal Patcher 1.5\adobe.snr.patch-painter.exe" C:\Users\admin\Desktop\Crack\Adobe CC 2015 Universal Patcher 1.5\adobe.snr.patch-painter.exeexplorer.exe
User:
admin
Company:
PainteR
Integrity Level:
MEDIUM
Description:
Universal Adobe Patcher
Exit code:
3221226540
Version:
1.5.0.0
Modules
Images
c:\users\admin\desktop\crack\adobe cc 2015 universal patcher 1.5\adobe.snr.patch-painter.exe
c:\systemroot\system32\ntdll.dll
2148"C:\Users\admin\Desktop\Crack\AMT Emulator v0.9 by PainteR\amtemu.v0.9-painter.exe" C:\Users\admin\Desktop\Crack\AMT Emulator v0.9 by PainteR\amtemu.v0.9-painter.exe
explorer.exe
User:
admin
Company:
PainteR
Integrity Level:
HIGH
Description:
ProxyEmu
Exit code:
0
Version:
0.9.0.0
Modules
Images
c:\users\admin\desktop\crack\amt emulator v0.9 by painter\amtemu.v0.9-painter.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3360"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Crack.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3748"C:\Users\admin\Desktop\Crack\AMT Emulator v0.9 by PainteR\amtemu.v0.9-painter.exe" C:\Users\admin\Desktop\Crack\AMT Emulator v0.9 by PainteR\amtemu.v0.9-painter.exeexplorer.exe
User:
admin
Company:
PainteR
Integrity Level:
MEDIUM
Description:
ProxyEmu
Exit code:
3221226540
Version:
0.9.0.0
Modules
Images
c:\users\admin\desktop\crack\amt emulator v0.9 by painter\amtemu.v0.9-painter.exe
c:\systemroot\system32\ntdll.dll
Total events
1 468
Read events
1 382
Write events
84
Delete events
2

Modification events

(PID) Process:(3360) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3360) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3360) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\59\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3360) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Crack.rar
(PID) Process:(3360) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3360) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3360) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3360) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3360) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath
Operation:writeName:0
Value:
C:\Users\admin\Desktop
(PID) Process:(3360) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF2C0000002C000000EC03000021020000
Executable files
4
Suspicious files
1
Text files
17
Unknown types
0

Dropped files

PID
Process
Filename
Type
3360WinRAR.exeC:\Users\admin\Desktop\Crack\Adobe CC 2015 Universal Patcher 1.5\adobe.snr.patch-painter.exeexecutable
MD5:0D9B7ABE952D6C1DC24750BF47969132
SHA256:9EC96E0FACF95D1A08D4761AFF436DAC8318ABD008C7284A4A22347069E8284D
3360WinRAR.exeC:\Users\admin\Desktop\Crack\Adobe CC 2015 Universal Patcher 1.5\SadeemPC.com.URLtext
MD5:2599DAF1CB8128BC8B09969C4AC51091
SHA256:8924634DC43332D8289BEE28389A7B0F96D085BC5CD6C945D90D6099FDEBCDD3
3360WinRAR.exeC:\Users\admin\Desktop\Crack\Adobe CC 2015.5 XFORCE Activation\Keygen_XF-adobecc2015.exeexecutable
MD5:8C03FBBEF9DB991BB02AB35BF0D2718E
SHA256:C5D9C52583EEFD03728BA877BAF21725F9E2DA4435E9433B87DC82B77B695EDD
3360WinRAR.exeC:\Users\admin\Desktop\Crack\Adobe CC 2015.5 XFORCE Activation\How To Use Keygen.txttext
MD5:838378A47EF1A272ECE0B8E3D3BB6159
SHA256:73CD69136BCF4AB8336C303A4492F9044ABC811747B210967B27CB4BC892FD24
3360WinRAR.exeC:\Users\admin\Desktop\Crack\AMT Emulator v0.9 by PainteR\file_id.diztext
MD5:
SHA256:
3360WinRAR.exeC:\Users\admin\Desktop\Crack\AMT Emulator v0.9 by PainteR\painter.nfotext
MD5:
SHA256:
3360WinRAR.exeC:\Users\admin\Desktop\Crack\AMT Emulator v0.9 by PainteR\changelog.txttext
MD5:
SHA256:
3360WinRAR.exeC:\Users\admin\Desktop\Crack\Adobe CC 2015 Universal Patcher 1.5\SadeemAPK.com.URLtext
MD5:146F5C01B4A4989BC2CBED9D9C322BB2
SHA256:FC5B36947E7151704AE339614D4AD15A2BBA155F883D0A6F8AB3F3AD0818BD0D
3360WinRAR.exeC:\Users\admin\Desktop\Crack\AMT Emulator v0.9 by PainteR\SadeemAPK.com.URLtext
MD5:146F5C01B4A4989BC2CBED9D9C322BB2
SHA256:FC5B36947E7151704AE339614D4AD15A2BBA155F883D0A6F8AB3F3AD0818BD0D
3360WinRAR.exeC:\Users\admin\Desktop\Crack\Adobe CC 2015 Universal Patcher 1.5\How Use Patch Not Listed Adobe Product In Patch.pngimage
MD5:3CADB21B44C5F8B6A999B714A22E85A3
SHA256:EB695210B07F0C92B79FDE2901E8A69EDEB43FDA296E336F5CDB5FD8A7E855DD
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info