| File name: | Bandicut Full Crack.rar |
| Full analysis: | https://app.any.run/tasks/571845c9-0c5a-4aaf-a1ca-669c8caf2b7d |
| Verdict: | Malicious activity |
| Analysis date: | May 10, 2024, 13:37:42 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v5 |
| MD5: | BD95FD7A845F24172710C3A6962F372C |
| SHA1: | 4CAA945F1FCBB03A0B0D281B7BC77D45ED5167B9 |
| SHA256: | 39313BE32226926A2147369BD9FE7C71539DFBF295F55E4721C44C4993A9DA5E |
| SSDEEP: | 98304:7UUks2Lgi1vEzaD90h/w1F6Ackco4+ZuvS4aSARVsPoPEvK2/2OVoGSV+0GWGc34:uQh4XB9AaKG21qWzmNTKrOXPmHp |
| .rar | | | RAR compressed archive (v5.0) (61.5) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 324 | c:\windows\resources\spoolsv.exe SE | C:\Windows\resources\spoolsv.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Version: 1.00 Modules
| |||||||||||||||
| 736 | c:\windows\resources\spoolsv.exe PR | C:\Windows\resources\spoolsv.exe | — | svchost.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Version: 1.00 Modules
| |||||||||||||||
| 860 | schtasks /create /tn "svchost" /tr "c:\windows\resources\svchost.exe" /sc daily /st 14:41 /f | C:\Windows\System32\schtasks.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 992 | c:\windows\resources\themes\explorer.exe | C:\Windows\resources\Themes\explorer.exe | spoolsv.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 1 Version: 1.00 Modules
| |||||||||||||||
| 1344 | c:\windows\resources\themes\explorer.exe | C:\Windows\resources\Themes\explorer.exe | spoolsv.exe | ||||||||||||
User: admin Integrity Level: HIGH Version: 1.00 Modules
| |||||||||||||||
| 1432 | "C:\Windows\system32\taskmgr.exe" | C:\Windows\System32\taskmgr.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Task Manager Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1596 | c:\windows\resources\svchost.exe | C:\Windows\resources\svchost.exe | spoolsv.exe | ||||||||||||
User: admin Integrity Level: HIGH Version: 1.00 Modules
| |||||||||||||||
| 1964 | c:\windows\resources\spoolsv.exe PR | C:\Windows\resources\spoolsv.exe | — | svchost.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Version: 1.00 Modules
| |||||||||||||||
| 1980 | c:\windows\resources\spoolsv.exe PR | C:\Windows\resources\spoolsv.exe | — | svchost.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Version: 1.00 Modules
| |||||||||||||||
| 2232 | C:\Windows\Resources\Themes\icsys.icn.exe | C:\Windows\Resources\Themes\icsys.icn.exe | bdcut.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Version: 1.00 Modules
| |||||||||||||||
| (PID) Process: | (3984) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3984) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3984) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3984) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface |
| Operation: | write | Name: | ShowPassword |
Value: 1 | |||
| (PID) Process: | (3984) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (3984) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (3984) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
| (PID) Process: | (3984) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Bandicut Full Crack.rar | |||
| (PID) Process: | (3984) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3984) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 736 | spoolsv.exe | C:\Users\admin\AppData\Local\Temp\~DF4A8E79AC1ACDF3EE.TMP | — | |
MD5:— | SHA256:— | |||
| 2232 | icsys.icn.exe | C:\windows\resources\themes\explorer.exe | executable | |
MD5:955AAA7C0635F41A7EB2C70F44151687 | SHA256:4316B180B8D3FDA376E8DEF586B20A545F76149C6B88788690A3CC14219141F7 | |||
| 3984 | WinRAR.exe | C:\Users\admin\Desktop\Bandicut Full + file kich hoat\file kich hoat\bdcut.exe | executable | |
MD5:F0B0D73B3E19FA5EA1331387BA9633BC | SHA256:DFE1C7A8D32298BF33DDEEA9F02EDDE052078A80A290EA3CF63DBEB03CA47DDE | |||
| 3984 | WinRAR.exe | C:\Users\admin\Desktop\Bandicut Full + file kich hoat\Bandicut 2021 new updated.exe | executable | |
MD5:9BD51E8573C57B37EEFB866570EF8568 | SHA256:5137D6F1AD631DB29752AD04E373AE0619C4EDDCF751F72FBFF3814355AFD5E7 | |||
| 2264 | explorer.exe | C:\windows\resources\spoolsv.exe | executable | |
MD5:C970F4A495502229943D90C7F67125C7 | SHA256:05C8452E2DEA7CFAE3668157A9CA9BBA9F258F385DD20195D28777965F913BEF | |||
| 2240 | bdcut.exe | C:\Users\admin\AppData\Local\Temp\~DF82F80B65FF79E284.TMP | binary | |
MD5:D047CD39186E445497E1E070A6B175DA | SHA256:5869A24450D383CAE56F75AA6A5A5489A26BDE6D8A51A46A631663F8AC19F960 | |||
| 2232 | icsys.icn.exe | C:\Users\admin\AppData\Local\Temp\~DFE7B5D8FC61A4D46E.TMP | binary | |
MD5:7EBDDE653172B22E0A2B65C29AE98CF4 | SHA256:9B6F0D09B1859AADB402CE2C9021429411F92AAB62B556B1C5E1921D7AC6ADED | |||
| 2240 | bdcut.exe | C:\users\admin\desktop\bandicut full + file kich hoat\file kich hoat\bdcut.exe | executable | |
MD5:D597126BFBB5B290A3900FF3BD6E1175 | SHA256:B3303F8484DA9D35B37CF961527447C90739B7A3BD60D46C6D41C65C278A657D | |||
| 2240 | bdcut.exe | C:\Windows\Resources\Themes\icsys.icn.exe | executable | |
MD5:2C21EA65F781634AFB3166404C5288E5 | SHA256:3ED207FDEEE295835A906244FCD58201BA32D3D0C07A6D06F21F4CD4559EC8A4 | |||
| 2256 | spoolsv.exe | C:\Users\admin\AppData\Local\Temp\~DFF7AC40E1CC6CB266.TMP | binary | |
MD5:7EBDDE653172B22E0A2B65C29AE98CF4 | SHA256:9B6F0D09B1859AADB402CE2C9021429411F92AAB62B556B1C5E1921D7AC6ADED | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | unknown |