File name:

Instagram Social Tool [V3.0] By Cyber-Data [CRACKED].zip

Full analysis: https://app.any.run/tasks/d271fdbf-0f3a-4810-bd89-817d22b613af
Verdict: Malicious activity
Analysis date: September 18, 2019, 14:26:50
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

7419A374D2D87DA0CEDF98037194B933

SHA1:

E0D69D4B83A14841A7E82C4153DAAB864EB9CE09

SHA256:

404E91F40A484CECD7C1BCCA45A6D0352B6F860BCABCEF7416A77D5864583215

SSDEEP:

49152:607/IiTinN/dJQ+kg0qDY7MUCnR8VOBtG2jjI2H3ezwd7O9YmJomG+0kcaO:H/IiTqrjkca3Cn+OBtG2jjIKuz8Oam1w

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 752)
    • Application was dropped or rewritten from another process

      • Instagram Social Tool Cracked By Zhir.exe (PID: 2076)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2908)
    • Reads Internet Cache Settings

      • Instagram Social Tool Cracked By Zhir.exe (PID: 2076)
  • INFO

    • Manual execution by user

      • Instagram Social Tool Cracked By Zhir.exe (PID: 2076)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2019:02:14 00:02:01
ZipCRC: 0x0fc3c5d4
ZipCompressedSize: 429
ZipUncompressedSize: 1468
ZipFileName: Fix ERROR.txt
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
35
Monitored processes
3
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe searchprotocolhost.exe no specs instagram social tool cracked by zhir.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
752"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2076"C:\Users\admin\Desktop\Instagram Social Tool Cracked By Zhir.exe" C:\Users\admin\Desktop\Instagram Social Tool Cracked By Zhir.exeexplorer.exe
User:
admin
Company:
eData
Integrity Level:
MEDIUM
Description:
Instagram Social Tool
Exit code:
0
Version:
4.0.0.0
Modules
Images
c:\users\admin\desktop\instagram social tool cracked by zhir.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2908"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Instagram Social Tool [V3.0] By Cyber-Data [CRACKED].zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
939
Read events
890
Write events
48
Delete events
1

Modification events

(PID) Process:(2908) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2908) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2908) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2908) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Instagram Social Tool [V3.0] By Cyber-Data [CRACKED].zip
(PID) Process:(2908) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2908) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2908) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2908) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(752) SearchProtocolHost.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\72\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(752) SearchProtocolHost.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\72\52C64B7E
Operation:writeName:@C:\Windows\system32\notepad.exe,-469
Value:
Text Document
Executable files
4
Suspicious files
0
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
2908WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2908.33466\Read This.txttext
MD5:372B5DDB1C64A5B2AD583EB1D4140BB5
SHA256:4B2EE356FD6FDA71146CD6F4EA2D148C0BD9607F13E5D2BE7194852829DC555E
2908WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2908.33466\Instagram Social Tool Cracked By Zhir.exeexecutable
MD5:E3BB83AFFBD2E4BABF48E1258E8D6198
SHA256:A91636A3531AAA751C69BC6AB31F58EFB9339B125D29FB569CF1F29357C89611
2908WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2908.33466\Fix ERROR.txttext
MD5:31C19129F675D356B91E14B29B6A60D2
SHA256:713EA4BF5C318FC5CEAA4448D5CF32A9D2652E039DBC071CEFD7F3E935F378E9
2908WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2908.33466\Proxy.dllexecutable
MD5:F8EDA354539081697A0D50BE72A41676
SHA256:01AAAF93DEAEFD820D5C7A8859BBBD43657A7EC409D3D0DDC0D9CD1C809286C4
2908WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2908.33466\InstaAPI.dllexecutable
MD5:B94983A2B43CB2D8D82C3861827C0BB3
SHA256:F346D8BE7F01ACC3327F4E95AE4A345A4439447D0DC435A36E072EADE044C5EE
2908WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2908.33466\Theme.dllexecutable
MD5:5ECA94D909F1BA4C5F3E35AC65A49076
SHA256:DE0E530D46C803D85B8AEB6D18816F1B09CB3DAFEFB5E19FDFA15C9F41E0F474
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info