| File name: | CK - Multihack Control Panel 0.4.0.rar |
| Full analysis: | https://app.any.run/tasks/e64926e7-5986-4d7d-9f5e-ace5e2ff0483 |
| Verdict: | Malicious activity |
| Analysis date: | February 09, 2022, 11:11:54 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v5 |
| MD5: | BA846369D867E993DAF5B72B2D23ABC9 |
| SHA1: | 9A1A406FF9CEA6A34EAE0BC7994B93986B40EC74 |
| SHA256: | 3D312E4F21286BBA1FC2126FCD77DCE68032B22C4C4FBA375D458C6CE5E20F7C |
| SSDEEP: | 98304:Ic0jcpITDcXxhM76kYxcg9WM6RsawkA6JDIl:IEmkX99Zpa5A6Jm |
| .rar | | | RAR compressed archive (v5.0) (61.5) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1008 | "C:\Windows\system32\cmd.exe" /C timeout 22 | C:\Windows\system32\cmd.exe | — | powershell.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1652 | timeout 22 | C:\Windows\system32\timeout.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: timeout - pauses command processing Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2580 | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -enc YwBtAGQAIAAvAEMAIAB0AGkAbQBlAG8AdQB0ACAAMgAyAA== | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | Installer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows PowerShell Exit code: 0 Version: 10.0.14409.1005 (rs1_srvoob.161208-1155) Modules
| |||||||||||||||
| 2588 | "C:\Users\admin\Desktop\CK - Multihack Control Panel 0.4.0\Installer.exe" | C:\Users\admin\Desktop\CK - Multihack Control Panel 0.4.0\Installer.exe | Explorer.EXE | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 2876 | "C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\CK - Multihack Control Panel 0.4.0\How to use.txt | C:\Windows\system32\NOTEPAD.EXE | — | Explorer.EXE | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Notepad Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3140 | timeout 22 | C:\Windows\system32\timeout.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: timeout - pauses command processing Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3296 | "C:\Windows\system32\cmd.exe" /C timeout 22 | C:\Windows\system32\cmd.exe | — | powershell.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 3300 | "C:\Users\admin\Desktop\CK - Multihack Control Panel 0.4.0\Installer.exe" | C:\Users\admin\Desktop\CK - Multihack Control Panel 0.4.0\Installer.exe | Explorer.EXE | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3762504530 Version: 1.0.0.0 Modules
| |||||||||||||||
| 3624 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\CK - Multihack Control Panel 0.4.0.rar" | C:\Program Files\WinRAR\WinRAR.exe | Explorer.EXE | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 3636 | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -enc YwBtAGQAIAAvAEMAIAB0AGkAbQBlAG8AdQB0ACAAMgAyAA== | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | Installer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 10.0.14409.1005 (rs1_srvoob.161208-1155) Modules
| |||||||||||||||
| (PID) Process: | (3624) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3624) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3624) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3624) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface |
| Operation: | write | Name: | ShowPassword |
Value: 0 | |||
| (PID) Process: | (3624) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (3624) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (3624) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\CK - Multihack Control Panel 0.4.0.rar | |||
| (PID) Process: | (3624) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3624) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3624) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3624 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb3624.29890\CK - Multihack Control Panel 0.4.0\Cheats\CS GO.dll | executable | |
MD5:AABBB38C4110CC0BF7203A567734A7E7 | SHA256:24B07028C1E38B9CA2F197750654A0DFB7D33C2E52C9DD67100609499E8028DB | |||
| 3624 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb3624.29890\CK - Multihack Control Panel 0.4.0\Cheats\Battlefield 4.dll | executable | |
MD5:D91BF81CF5178D47D1A588B0DF98EB24 | SHA256:F8E3B45FD3E22866006F16A9E73E28B5E357F31F3C275B517692A5F16918B492 | |||
| 3624 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb3624.29890\CK - Multihack Control Panel 0.4.0\Cheats\Apex.dll | executable | |
MD5:3F224766FE9B090333FDB43D5A22F9EA | SHA256:AE5E73416EB64BC18249ACE99F6847024ECEEA7CE9C343696C84196460F3A357 | |||
| 3624 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb3624.29890\CK - Multihack Control Panel 0.4.0\Cheats\Anarea.dll | executable | |
MD5:CFE87D58F973DAEDA4EE7D2CF4AE521D | SHA256:4997FDA5D0E90B8A0AB7DA314CB56F25D1450B366701C45C294D8DD3254DE483 | |||
| 3624 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb3624.29890\CK - Multihack Control Panel 0.4.0\Cheats\COD.dll | executable | |
MD5:8894176AF3EA65A09AE5CF4C0E6FF50F | SHA256:C64B7C6400E9BACC1A4F1BAED6374BFBCE9A3F8CF20C2D03F81EF18262F89C60 | |||
| 3624 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb3624.29890\CK - Multihack Control Panel 0.4.0\Cheats\Battlefield 2042.dll | executable | |
MD5:EEFE86B5A3AB256BEED8621A05210DF2 | SHA256:1D1C11FC1AD1FEBF9308225C4CCF0431606A4AB08680BA04494D276CB310BF15 | |||
| 3624 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb3624.29890\CK - Multihack Control Panel 0.4.0\Cheats\CoD Vanguard.dll | executable | |
MD5:0C48220A4485F36FEED84EF5DD0A5E9C | SHA256:2DD4EBAA12CBBA142B5D61A0EBF84A14D0D1BB8826BA42B63E303FE6721408DF | |||
| 3624 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb3624.29890\CK - Multihack Control Panel 0.4.0\Cheats\Battlefield 5.dll | executable | |
MD5:18FD51821D0A6F3E94E3FA71DB6DE3AF | SHA256:DBA84E704FFE5FCD42548856258109DC77C6A46FD0B784119A3548EC47E5644B | |||
| 3624 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb3624.29890\CK - Multihack Control Panel 0.4.0\Cheats\Dota 2.dll | executable | |
MD5:AABBB38C4110CC0BF7203A567734A7E7 | SHA256:24B07028C1E38B9CA2F197750654A0DFB7D33C2E52C9DD67100609499E8028DB | |||
| 3624 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb3624.29890\CK - Multihack Control Panel 0.4.0\Cheats\Escape from Tarkov.dll | executable | |
MD5:FF8026DAB5D3DABCA8F72B6FA7D258FA | SHA256:535E9D20F00A2F1A62F843A4A26CFB763138D5DFE358B0126D33996FBA9CA4D1 | |||