File name:

Antidetect 8.01.36 CRACKED [Z3ROZ].rar

Full analysis: https://app.any.run/tasks/06cebeff-e3d9-4a03-b22e-01f9dd6750b7
Verdict: Malicious activity
Analysis date: August 12, 2020, 18:23:48
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

082081B4019F089358A3A79FD95F0600

SHA1:

6219CA759A00CC76FA8F92B7AD8ACA91F6D62753

SHA256:

41206ED48174E72D8D30B2F2B9939ABF598817AC725860D2078D297947AD3120

SSDEEP:

196608:beIKgsTtnYohRy3QATAx+Oxm+rtHlqL1zPps1gyC5mQESBwkD3:TKgKh43QAsVs+rtFqpPW1gLm9M3

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Antidetect8.exe (PID: 572)
      • Antidetect8.exe (PID: 3616)
      • Antidetect8.exe (PID: 3280)
      • Antidetect8.exe (PID: 1340)
    • Changes settings of System certificates

      • Antidetect8.exe (PID: 572)
      • Antidetect8.exe (PID: 3616)
  • SUSPICIOUS

    • Adds / modifies Windows certificates

      • Antidetect8.exe (PID: 572)
      • Antidetect8.exe (PID: 3616)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 612)
  • INFO

    • Manual execution by user

      • Antidetect8.exe (PID: 3616)
      • Antidetect8.exe (PID: 1340)
      • Antidetect8.exe (PID: 3280)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
54
Monitored processes
5
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
drop and start start winrar.exe antidetect8.exe antidetect8.exe antidetect8.exe antidetect8.exe

Process information

PID
CMD
Path
Indicators
Parent process
572"C:\Users\admin\AppData\Local\Temp\Rar$EXa612.49038\Antidetect 8.01.36 CRACKED [Z3ROZ]\Antidetect8.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa612.49038\Antidetect 8.01.36 CRACKED [Z3ROZ]\Antidetect8.exe
WinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa612.49038\antidetect 8.01.36 cracked [z3roz]\antidetect8.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
612"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Antidetect 8.01.36 CRACKED [Z3ROZ].rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
1340"C:\Users\admin\Desktop\Antidetect8.exe" C:\Users\admin\Desktop\Antidetect8.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\antidetect8.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3280"C:\Users\admin\Desktop\Antidetect8.exe" C:\Users\admin\Desktop\Antidetect8.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\antidetect8.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3616"C:\Users\admin\Desktop\Antidetect8.exe" C:\Users\admin\Desktop\Antidetect8.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\antidetect8.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
Total events
562
Read events
498
Write events
63
Delete events
1

Modification events

(PID) Process:(612) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(612) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(612) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\137\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(612) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\137\52C64B7E
Operation:writeName:@C:\Windows\system32\NetworkExplorer.dll,-1
Value:
Network
(PID) Process:(612) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Antidetect 8.01.36 CRACKED [Z3ROZ].rar
(PID) Process:(612) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(612) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(612) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(612) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(612) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\137\52C64B7E
Operation:writeName:@C:\Windows\system32\notepad.exe,-469
Value:
Text Document
Executable files
5
Suspicious files
2
Text files
18
Unknown types
2

Dropped files

PID
Process
Filename
Type
612WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa612.49038\Antidetect 8.01.36 CRACKED [Z3ROZ]\GenFiles\DevicesList-DiskDrive.txttext
MD5:BCFED5B275B6081C28B98567452C47A3
SHA256:412D6D18924A5D32C7644D5E706B21EFDED71D33CD3A6EEEA0D7BD8FAF7AC75E
612WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa612.49038\Antidetect 8.01.36 CRACKED [Z3ROZ]\chrome_parameters.txttext
MD5:5FB9B885ED185A658B44300ECB22A30B
SHA256:9EE6DF8C3300C2E99DE1EA46300A4FE196CD4F2CFDB70364B8A095FCE0045B3E
612WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa612.49038\Antidetect 8.01.36 CRACKED [Z3ROZ]\Antidetect8.exeexecutable
MD5:F366EF0433BAC81A7384C355CC4E9739
SHA256:87687B8D40C73D5674229F192221B2173B62F4B989CF31AC85991314B988FEC0
612WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa612.49038\Antidetect 8.01.36 CRACKED [Z3ROZ]\fla\Flash-24.0.0.189\flashplayer.xptxpt
MD5:A81FD3B03B8C6D6E5A14298110718D3F
SHA256:946C2D7808B0F256E5F6B62655246DC9C247833FB2F578519E4354F91DEB6E1B
612WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa612.49038\Antidetect 8.01.36 CRACKED [Z3ROZ]\fla\Flash-24.0.0.189\FlashPlayerPlugin_24_0_0_189.exeexecutable
MD5:B85FA92B2D9F27A629041BD511952ABF
SHA256:AFFE55B47C38325DD975B55C23687F1B0FAA1343D62393EE20F3C049F856FDD4
612WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa612.49038\Antidetect 8.01.36 CRACKED [Z3ROZ]\fla\Flash-24.0.0.189\mms.cfgtext
MD5:5246A94C265991426A0B8F9425CBEA42
SHA256:2B5640814352DAD0B28FE962F1D4D4EFBDEB51EDA918AEEC8F1F3173F1145766
612WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa612.49038\Antidetect 8.01.36 CRACKED [Z3ROZ]\fla\Flash-24.0.0.189\plugin.vchcat
MD5:DC2DC0FE686F18833D2EA8C053746A13
SHA256:B94EE6C591053EB42A2F6228ACA85B11901165BB0302B0367886FE00E20F205D
612WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa612.49038\Antidetect 8.01.36 CRACKED [Z3ROZ]\fla\Flash-24.0.0.189\FlashUtil32_24_0_0_189_Plugin.exeexecutable
MD5:19AC5C0AC0021899A696EEC9CE1E60AC
SHA256:514491086F315111960819E7DE4E9EA853133700D2459F18C22567242A50F29C
612WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa612.49819\Antidetect 8.01.36 CRACKED [Z3ROZ]\Antidetect8.exe
MD5:
SHA256:
612WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa612.49038\Antidetect 8.01.36 CRACKED [Z3ROZ]\GenFiles\DeviceList-DiskDrive2.txttext
MD5:F2019FE9B931DEB8B420ABFB6F760B88
SHA256:9AC129595254F39A3C7552E04ABEA8C3C3B0C973AC102CFCBCCF021FB702059A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
5
DNS requests
2
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
636
WerFault.exe
GET
52.158.209.219:80
http://watson.microsoft.com/StageOne/Antidetect8_exe/28_0_0_0/5dcc1645/Antidetect8_exe/28_0_0_0/5dcc1645/40000015/0004d532.htm?LCID=1033&OS=6.1.7601.2.00010100.1.0.48.17514&SM=DELL&SPN=DELL&BV=DELL&MID=3ADE2C42-4AB9-49B7-B142-BE9AEEA69063
US
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
572
Antidetect8.exe
216.58.207.78:443
drive.google.com
Google Inc.
US
whitelisted
3280
Antidetect8.exe
216.58.207.78:443
drive.google.com
Google Inc.
US
whitelisted
636
WerFault.exe
52.158.209.219:80
watson.microsoft.com
Microsoft Corporation
US
suspicious
3616
Antidetect8.exe
216.58.207.78:443
drive.google.com
Google Inc.
US
whitelisted
1340
Antidetect8.exe
216.58.207.78:443
drive.google.com
Google Inc.
US
whitelisted

DNS requests

Domain
IP
Reputation
drive.google.com
  • 216.58.207.78
shared
watson.microsoft.com
  • 52.158.209.219
whitelisted

Threats

PID
Process
Class
Message
636
WerFault.exe
Potential Corporate Privacy Violation
ET POLICY Application Crash Report Sent to Microsoft
636
WerFault.exe
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
No debug info