| File name: | Crack.rar |
| Full analysis: | https://app.any.run/tasks/73d172b6-935e-46a8-a191-de23164a6d1b |
| Verdict: | Malicious activity |
| Analysis date: | August 16, 2018, 16:05:55 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v4, os: Win32, flags: Locked |
| MD5: | 153F2C4215531BC80E7141913ABDE172 |
| SHA1: | 7D7628BA0ED705F0EEC09D36A9C21A7D07C7F0C2 |
| SHA256: | 32BF0593DA42136D71C60F53EF2EB95ACC2F799263475F4BBBF67AA7C282BBAB |
| SSDEEP: | 49152:qeygreBGo+WSJONPp3HkZaA40Wi6foc47c83zAt/eVvSN8cC7gchJghbaedtIfA1:qkreBcfSuEAgNocYMUhcCkG60q1 |
| .rar | | | RAR compressed archive (v-4.x) (58.3) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (41.6) |
| CompressedSize: | 605852 |
|---|---|
| UncompressedSize: | 631808 |
| OperatingSystem: | Win32 |
| ModifyDate: | 2016:02:09 09:22:04 |
| PackingMethod: | Best Compression |
| ArchivedFileName: | Crack\Adobe CC 2015 Universal Patcher 1.5\adobe.snr.patch-painter.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 580 | "C:\Users\admin\Desktop\Crack\Adobe CC 2015 Universal Patcher 1.5\adobe.snr.patch-painter.exe" | C:\Users\admin\Desktop\Crack\Adobe CC 2015 Universal Patcher 1.5\adobe.snr.patch-painter.exe | explorer.exe | ||||||||||||
User: admin Company: PainteR Integrity Level: HIGH Description: Universal Adobe Patcher Exit code: 0 Version: 1.5.0.0 Modules
| |||||||||||||||
| 956 | "C:\Users\admin\Desktop\Crack\Adobe CC 2015.5 XFORCE Activation\Keygen_XF-adobecc2015.exe" | C:\Users\admin\Desktop\Crack\Adobe CC 2015.5 XFORCE Activation\Keygen_XF-adobecc2015.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 1680 | "C:\Users\admin\Desktop\Crack\Adobe CC 2015 Universal Patcher 1.5\adobe.snr.patch-painter.exe" | C:\Users\admin\Desktop\Crack\Adobe CC 2015 Universal Patcher 1.5\adobe.snr.patch-painter.exe | — | explorer.exe | |||||||||||
User: admin Company: PainteR Integrity Level: MEDIUM Description: Universal Adobe Patcher Exit code: 3221226540 Version: 1.5.0.0 Modules
| |||||||||||||||
| 2148 | "C:\Users\admin\Desktop\Crack\AMT Emulator v0.9 by PainteR\amtemu.v0.9-painter.exe" | C:\Users\admin\Desktop\Crack\AMT Emulator v0.9 by PainteR\amtemu.v0.9-painter.exe | explorer.exe | ||||||||||||
User: admin Company: PainteR Integrity Level: HIGH Description: ProxyEmu Exit code: 0 Version: 0.9.0.0 Modules
| |||||||||||||||
| 3360 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Crack.rar" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 3748 | "C:\Users\admin\Desktop\Crack\AMT Emulator v0.9 by PainteR\amtemu.v0.9-painter.exe" | C:\Users\admin\Desktop\Crack\AMT Emulator v0.9 by PainteR\amtemu.v0.9-painter.exe | — | explorer.exe | |||||||||||
User: admin Company: PainteR Integrity Level: MEDIUM Description: ProxyEmu Exit code: 3221226540 Version: 0.9.0.0 Modules
| |||||||||||||||
| (PID) Process: | (3360) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3360) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3360) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\59\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3360) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Crack.rar | |||
| (PID) Process: | (3360) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3360) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3360) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3360) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (3360) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop | |||
| (PID) Process: | (3360) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin |
| Operation: | write | Name: | Placement |
Value: 2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF2C0000002C000000EC03000021020000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3360 | WinRAR.exe | C:\Users\admin\Desktop\Crack\AMT Emulator v0.9 by PainteR\changelog.txt | text | |
MD5:— | SHA256:— | |||
| 3360 | WinRAR.exe | C:\Users\admin\Desktop\Crack\AMT Emulator v0.9 by PainteR\file_id.diz | text | |
MD5:— | SHA256:— | |||
| 3360 | WinRAR.exe | C:\Users\admin\Desktop\Crack\Adobe CC 2015 Universal Patcher 1.5\How Use Patch Not Listed Adobe Product In Patch.png | image | |
MD5:3CADB21B44C5F8B6A999B714A22E85A3 | SHA256:EB695210B07F0C92B79FDE2901E8A69EDEB43FDA296E336F5CDB5FD8A7E855DD | |||
| 3360 | WinRAR.exe | C:\Users\admin\Desktop\Crack\Adobe CC 2015 Universal Patcher 1.5\adobe.snr.patch-painter.exe | executable | |
MD5:0D9B7ABE952D6C1DC24750BF47969132 | SHA256:9EC96E0FACF95D1A08D4761AFF436DAC8318ABD008C7284A4A22347069E8284D | |||
| 3360 | WinRAR.exe | C:\Users\admin\Desktop\Crack\Adobe CC 2015.5 XFORCE Activation\How To Use Keygen.txt | text | |
MD5:838378A47EF1A272ECE0B8E3D3BB6159 | SHA256:73CD69136BCF4AB8336C303A4492F9044ABC811747B210967B27CB4BC892FD24 | |||
| 3360 | WinRAR.exe | C:\Users\admin\Desktop\Crack\Adobe CC 2015 Universal Patcher 1.5\SadeemAPK.com.URL | text | |
MD5:146F5C01B4A4989BC2CBED9D9C322BB2 | SHA256:FC5B36947E7151704AE339614D4AD15A2BBA155F883D0A6F8AB3F3AD0818BD0D | |||
| 3360 | WinRAR.exe | C:\Users\admin\Desktop\Crack\Adobe CC 2015.5 XFORCE Activation\SadeemPC.com - Download Latest Software Free.URL | text | |
MD5:2599DAF1CB8128BC8B09969C4AC51091 | SHA256:8924634DC43332D8289BEE28389A7B0F96D085BC5CD6C945D90D6099FDEBCDD3 | |||
| 3360 | WinRAR.exe | C:\Users\admin\Desktop\Crack\Adobe CC 2015.5 XFORCE Activation\CC2016_Offline_Activation Method With Screenshots.pdf | ||
MD5:285897308A633CA88826A01A03DA43D7 | SHA256:254F67DD6796850FE855624E56EED792B93317658F4E3DC7085694DC2A75791E | |||
| 3360 | WinRAR.exe | C:\Users\admin\Desktop\Crack\Adobe CC 2015.5 XFORCE Activation\disable_activation.cmd | text | |
MD5:18B92AB0F40B83DB461A064995F58E7E | SHA256:817D26B5C664BD6514203335BEA528DF42879473EC7CFC495D3D3E03054CA861 | |||
| 3360 | WinRAR.exe | C:\Users\admin\Desktop\Crack\Adobe CC 2015.5 XFORCE Activation\Keygen_XF-adobecc2015.exe | executable | |
MD5:8C03FBBEF9DB991BB02AB35BF0D2718E | SHA256:C5D9C52583EEFD03728BA877BAF21725F9E2DA4435E9433B87DC82B77B695EDD | |||