File name:

Red Dead Redemption 2-Cracked.zip

Full analysis: https://app.any.run/tasks/dde20c45-54ef-4ac5-a2a8-883fbd0518ef
Verdict: Malicious activity
Analysis date: August 26, 2020, 03:46:10
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract
MD5:

64C30223D738BE993E23CC3835ACEBBA

SHA1:

ED9E645DFF3B97F09BD236D4D722996512FDAC8B

SHA256:

3AF37359C8E69D574202DD61D7C0829D0403ACBBFEF7F7E32BEA11B8B04D3571

SSDEEP:

768:e58NnxPrGybwcY1Y0S7nIlOiVQX+WNvHjcqcvvxuE0w9WU:e58N5iyhCVhllVQOuDckE//

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Red Dead Redemption 2 Installer.exe (PID: 2912)
      • Red Dead Redemption 2 Crack.exe (PID: 2508)
  • SUSPICIOUS

    • Creates files in the user directory

      • Red Dead Redemption 2 Installer.exe (PID: 2912)
    • Application launched itself

      • WinRAR.exe (PID: 2524)
  • INFO

    • Reads settings of System Certificates

      • Red Dead Redemption 2 Crack.exe (PID: 2508)
    • Manual execution by user

      • Red Dead Redemption 2 Crack.exe (PID: 2508)
      • Red Dead Redemption 2 Installer.exe (PID: 2912)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: 0x0009
ZipCompression: None
ZipModifyDate: 2020:08:25 23:45:18
ZipCRC: 0x3f703ac5
ZipCompressedSize: 33530
ZipUncompressedSize: 33530
ZipFileName: Red Dead Redemption 2-Cracked_PROTECTED.zip
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
43
Monitored processes
4
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs winrar.exe no specs red dead redemption 2 installer.exe red dead redemption 2 crack.exe

Process information

PID
CMD
Path
Indicators
Parent process
2508"C:\Users\admin\Desktop\Red Dead Redemption 2 Crack.exe" C:\Users\admin\Desktop\Red Dead Redemption 2 Crack.exe
explorer.exe
User:
admin
Company:
Skidrow Cracked
Integrity Level:
MEDIUM
Description:
Skidrow Crack
Exit code:
0
Version:
1.0.0.2
Modules
Images
c:\users\admin\desktop\red dead redemption 2 crack.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2524"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Red Dead Redemption 2-Cracked.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2912"C:\Users\admin\Desktop\Red Dead Redemption 2 Installer.exe" C:\Users\admin\Desktop\Red Dead Redemption 2 Installer.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Game Installer
Exit code:
0
Version:
2.2.0.2
Modules
Images
c:\users\admin\desktop\red dead redemption 2 installer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
4088"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Rar$DIb2524.42196\Red Dead Redemption 2-Cracked_PROTECTED.zip"C:\Program Files\WinRAR\WinRAR.exeWinRAR.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
1 020
Read events
946
Write events
74
Delete events
0

Modification events

(PID) Process:(2524) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2524) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2524) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\137\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2524) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\137\52C64B7E
Operation:writeName:@C:\Windows\system32\NetworkExplorer.dll,-1
Value:
Network
(PID) Process:(2524) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Red Dead Redemption 2-Cracked.zip
(PID) Process:(2524) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2524) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2524) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2524) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2524) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\137\52C64B7E
Operation:writeName:@C:\Windows\system32\notepad.exe,-469
Value:
Text Document
Executable files
0
Suspicious files
1
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
4088WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa4088.44595\Red Dead Redemption 2 Installer.exe
MD5:
SHA256:
4088WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa4088.44595\CRACK\Red Dead Redemption 2 Crack.exe
MD5:
SHA256:
2912Red Dead Redemption 2 Installer.exeC:\Users\admin\AppData\Roaming\Red Dead Redemption 2 Installer\Red Dead Redemption 2.jpgimage
MD5:
SHA256:
2524WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DIb2524.42196\Red Dead Redemption 2-Cracked_PROTECTED.zipcompressed
MD5:
SHA256:
2508Red Dead Redemption 2 Crack.exeC:\Users\admin\Desktop\logo.pngimage
MD5:2ADF1D04481BF05BB72851371793150F
SHA256:6AB7A9D0DF61A2EC40743D5C11DEC335A504AE200D3794247CD67C983B0DC980
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
9
DNS requests
6
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2912
Red Dead Redemption 2 Installer.exe
GET
301
5.182.210.152:80
http://skidrowcracked.com/post-thumbnail/?password=eo8kcu%3EMk0hN&title=Red%20Dead%20Redemption%202
unknown
html
312 b
suspicious
2912
Red Dead Redemption 2 Installer.exe
GET
301
5.182.210.152:80
http://sc-contentlocker.com/installer.php?step=Default&game=Red%20Dead%20Redemption%202
unknown
html
300 b
malicious
2912
Red Dead Redemption 2 Installer.exe
GET
301
5.182.210.152:80
http://sc-contentlocker.com/installer.php?step=Start&game=Red%20Dead%20Redemption%202
unknown
html
298 b
malicious
2912
Red Dead Redemption 2 Installer.exe
GET
301
5.182.210.152:80
http://sc-contentlocker.com/installer.php?step=Agreement&game=Red%20Dead%20Redemption%202
unknown
html
302 b
malicious
2912
Red Dead Redemption 2 Installer.exe
GET
301
5.182.210.152:80
http://sc-contentlocker.com/installer.php?step=Install&game=Red%20Dead%20Redemption%202
unknown
html
300 b
malicious
2508
Red Dead Redemption 2 Crack.exe
GET
301
5.182.210.152:80
http://skidrowcracked.com/wp-content/themes/skidrow/logo.png
unknown
html
269 b
suspicious
2912
Red Dead Redemption 2 Installer.exe
GET
301
5.182.210.152:80
http://sc-contentlocker.com/installer.php?step=InstallProgression&game=Red%20Dead%20Redemption%202
unknown
html
311 b
malicious
2508
Red Dead Redemption 2 Crack.exe
GET
301
5.182.210.152:80
http://skidrowcracked.com/post-thumbnail/?password=eo8kcu%3EMk0hN&title=Red%20Dead%20Redemption%202
unknown
html
312 b
suspicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2912
Red Dead Redemption 2 Installer.exe
5.182.210.152:80
sc-contentlocker.com
unknown
2912
Red Dead Redemption 2 Installer.exe
5.182.210.152:443
sc-contentlocker.com
unknown
2508
Red Dead Redemption 2 Crack.exe
5.182.210.152:80
sc-contentlocker.com
unknown
2508
Red Dead Redemption 2 Crack.exe
5.182.210.152:443
sc-contentlocker.com
unknown

DNS requests

Domain
IP
Reputation
sc-contentlocker.com
  • 5.182.210.152
malicious
skidrowcracked.com
  • 5.182.210.152
suspicious
dns.msftncsi.com
  • 131.107.255.255
shared

Threats

No threats detected
No debug info