| download: | Trojan-Qt5-Windows.7z |
| Full analysis: | https://app.any.run/tasks/2e64b12b-3614-4d69-b26b-5fa683f35379 |
| Verdict: | Malicious activity |
| Analysis date: | September 10, 2020, 07:28:42 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-7z-compressed |
| File info: | 7-zip archive data, version 0.4 |
| MD5: | 54AEE2FB9A38EE0913FA00BEA143B49D |
| SHA1: | AB76E9FF54CE50BFB8E7DE37814FCB8F52311696 |
| SHA256: | 369D50BDE8985A01CA1D6C807E5098209ADF59540404D3D5584F0AB7F16523A0 |
| SSDEEP: | 393216:dyGykBica/DDy9PV2U2Gs32fjO/IOoYevoLhpCP5G13AILiZHoQHmxseAfxSWvRK:4GraqNsx2fjOQOoYkyhsP5GbLg4xse6E |
| .7z | | | 7-Zip compressed archive (v0.4) (57.1) |
|---|---|---|
| .7z | | | 7-Zip compressed archive (gen) (42.8) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 796 | "C:\Users\admin\Desktop\Trojan-Qt5-Windows\trojan-qt5.exe" | C:\Users\admin\Desktop\Trojan-Qt5-Windows\trojan-qt5.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Version: 0.0.0.0 Modules
| |||||||||||||||
| 2492 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\Trojan-Qt5-Windows.7z" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 3536 | "C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe5_ Global\UsGthrCtrlFltPipeMssGthrPipe5 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" | C:\Windows\System32\SearchProtocolHost.exe | — | SearchIndexer.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft Windows Search Protocol Host Exit code: 0 Version: 7.00.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3652 | "C:\Windows\system32\notepad.exe" | C:\Windows\system32\notepad.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Notepad Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (2492) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (2492) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (2492) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\139\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2492) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\139\52C64B7E |
| Operation: | write | Name: | @C:\Windows\system32\NetworkExplorer.dll,-1 |
Value: Network | |||
| (PID) Process: | (2492) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\Trojan-Qt5-Windows.7z | |||
| (PID) Process: | (2492) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2492) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2492) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2492) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (2492) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\Trojan-Qt5-Windows | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2492 | WinRAR.exe | C:\Users\admin\Desktop\Trojan-Qt5-Windows\translations\qt_bg.qm | qm | |
MD5:6BCB7BF161BBE019CFAEEE7D331E3E79 | SHA256:47F5749032C655F8399563728B8E5591B796AABABB631D0BCA9F18D74F4ED6F0 | |||
| 2492 | WinRAR.exe | C:\Users\admin\Desktop\Trojan-Qt5-Windows\translations\qt_cs.qm | qm | |
MD5:987E045E06AEBA29A8E05A074E6BDB91 | SHA256:86E174EFF79F096D81146860DD5CA9E946C643A3464C7DA8919C972747B8DF09 | |||
| 2492 | WinRAR.exe | C:\Users\admin\Desktop\Trojan-Qt5-Windows\translations\qt_de.qm | qm | |
MD5:73911D71DB30DE43F856D4EA9E911837 | SHA256:AE34D874BD5A6D11A2EEE605E07A7C6DB2FFDBC998CEB8CFB7C346DD914332BB | |||
| 2492 | WinRAR.exe | C:\Users\admin\Desktop\Trojan-Qt5-Windows\translations\qt_ca.qm | qm | |
MD5:D1D7AB4DA8BC6A6097AF2DB42C9BD14E | SHA256:44C6B11B0F7BF6B6423D03089BCB603DA37CB9B46BA7B10B7DC07F75FDF9708F | |||
| 2492 | WinRAR.exe | C:\Users\admin\Desktop\Trojan-Qt5-Windows\translations\qt_da.qm | qm | |
MD5:D541CC7F5EA2248E72D2E86CE6CBFA45 | SHA256:423E88732439997DEB776F45F1B808F446F8023AB25FA925E949EC27724AB7E0 | |||
| 2492 | WinRAR.exe | C:\Users\admin\Desktop\Trojan-Qt5-Windows\translations\qt_en.qm | qm | |
MD5:4AEF4415F2E976B2CC6F24B877804A57 | SHA256:307CEF95DD5B36FF215055D427E1885B7FC3650C9224CF76D63056545996FF60 | |||
| 2492 | WinRAR.exe | C:\Users\admin\Desktop\Trojan-Qt5-Windows\translations\qt_fi.qm | qm | |
MD5:FF556242E6061DAC90683223351ABD61 | SHA256:D04666A656680BE2756B58CE45DB175B846C5928EB6AF62DBA841444DD10E03A | |||
| 2492 | WinRAR.exe | C:\Users\admin\Desktop\Trojan-Qt5-Windows\translations\qt_ar.qm | qm | |
MD5:E7EC8B6E07D62634777DBCB47BD611D3 | SHA256:820EB8876A61022B371D557EEBD83A99A3872C6E93ACBF3E98026DFCB3CE8EFB | |||
| 2492 | WinRAR.exe | C:\Users\admin\Desktop\Trojan-Qt5-Windows\translations\qt_ko.qm | qm | |
MD5:D3EB25E0FFF5719E8840612727896B1D | SHA256:487755EB0841D47748CCBC2AB8D255CA12277DD0FB687D6DDC730982F8DA77BA | |||
| 2492 | WinRAR.exe | C:\Users\admin\Desktop\Trojan-Qt5-Windows\translations\qt_it.qm | qm | |
MD5:B183FE971035ADA2E95401263C79AA3B | SHA256:54BDD9856E6007B443F553F03B5B83BCA9F08595BF18D3293663517F04E89333 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
796 | trojan-qt5.exe | 37.58.57.238:123 | pool.ntp.org | Leaseweb Deutschland GmbH | DE | unknown |
Domain | IP | Reputation |
|---|---|---|
pool.ntp.org |
| malicious |