| File name: | Instagram Social Tool [V3.0] By Cyber-Data [CRACKED].zip |
| Full analysis: | https://app.any.run/tasks/d271fdbf-0f3a-4810-bd89-817d22b613af |
| Verdict: | Malicious activity |
| Analysis date: | September 18, 2019, 14:26:50 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | 7419A374D2D87DA0CEDF98037194B933 |
| SHA1: | E0D69D4B83A14841A7E82C4153DAAB864EB9CE09 |
| SHA256: | 404E91F40A484CECD7C1BCCA45A6D0352B6F860BCABCEF7416A77D5864583215 |
| SSDEEP: | 49152:607/IiTinN/dJQ+kg0qDY7MUCnR8VOBtG2jjI2H3ezwd7O9YmJomG+0kcaO:H/IiTqrjkca3Cn+OBtG2jjIKuz8Oam1w |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2019:02:14 00:02:01 |
| ZipCRC: | 0x0fc3c5d4 |
| ZipCompressedSize: | 429 |
| ZipUncompressedSize: | 1468 |
| ZipFileName: | Fix ERROR.txt |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 752 | "C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" | C:\Windows\System32\SearchProtocolHost.exe | — | SearchIndexer.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft Windows Search Protocol Host Exit code: 0 Version: 7.00.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2076 | "C:\Users\admin\Desktop\Instagram Social Tool Cracked By Zhir.exe" | C:\Users\admin\Desktop\Instagram Social Tool Cracked By Zhir.exe | — | explorer.exe | |||||||||||
User: admin Company: eData Integrity Level: MEDIUM Description: Instagram Social Tool Exit code: 0 Version: 4.0.0.0 Modules
| |||||||||||||||
| 2908 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Instagram Social Tool [V3.0] By Cyber-Data [CRACKED].zip" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| (PID) Process: | (2908) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (2908) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (2908) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2908) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Instagram Social Tool [V3.0] By Cyber-Data [CRACKED].zip | |||
| (PID) Process: | (2908) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2908) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2908) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2908) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (752) SearchProtocolHost.exe | Key: | HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\72\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (752) SearchProtocolHost.exe | Key: | HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\72\52C64B7E |
| Operation: | write | Name: | @C:\Windows\system32\notepad.exe,-469 |
Value: Text Document | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2908 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2908.33466\Read This.txt | text | |
MD5:372B5DDB1C64A5B2AD583EB1D4140BB5 | SHA256:4B2EE356FD6FDA71146CD6F4EA2D148C0BD9607F13E5D2BE7194852829DC555E | |||
| 2908 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2908.33466\Instagram Social Tool Cracked By Zhir.exe | executable | |
MD5:E3BB83AFFBD2E4BABF48E1258E8D6198 | SHA256:A91636A3531AAA751C69BC6AB31F58EFB9339B125D29FB569CF1F29357C89611 | |||
| 2908 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2908.33466\Fix ERROR.txt | text | |
MD5:31C19129F675D356B91E14B29B6A60D2 | SHA256:713EA4BF5C318FC5CEAA4448D5CF32A9D2652E039DBC071CEFD7F3E935F378E9 | |||
| 2908 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2908.33466\Proxy.dll | executable | |
MD5:F8EDA354539081697A0D50BE72A41676 | SHA256:01AAAF93DEAEFD820D5C7A8859BBBD43657A7EC409D3D0DDC0D9CD1C809286C4 | |||
| 2908 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2908.33466\InstaAPI.dll | executable | |
MD5:B94983A2B43CB2D8D82C3861827C0BB3 | SHA256:F346D8BE7F01ACC3327F4E95AE4A345A4439447D0DC435A36E072EADE044C5EE | |||
| 2908 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2908.33466\Theme.dll | executable | |
MD5:5ECA94D909F1BA4C5F3E35AC65A49076 | SHA256:DE0E530D46C803D85B8AEB6D18816F1B09CB3DAFEFB5E19FDFA15C9F41E0F474 | |||