File name:

Antidetect 8.01.36 CRACKED [Z3ROZ].rar

Full analysis: https://app.any.run/tasks/06cebeff-e3d9-4a03-b22e-01f9dd6750b7
Verdict: Malicious activity
Analysis date: August 12, 2020, 18:23:48
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

082081B4019F089358A3A79FD95F0600

SHA1:

6219CA759A00CC76FA8F92B7AD8ACA91F6D62753

SHA256:

41206ED48174E72D8D30B2F2B9939ABF598817AC725860D2078D297947AD3120

SSDEEP:

196608:beIKgsTtnYohRy3QATAx+Oxm+rtHlqL1zPps1gyC5mQESBwkD3:TKgKh43QAsVs+rtFqpPW1gLm9M3

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Antidetect8.exe (PID: 572)
      • Antidetect8.exe (PID: 3616)
      • Antidetect8.exe (PID: 1340)
      • Antidetect8.exe (PID: 3280)
    • Changes settings of System certificates

      • Antidetect8.exe (PID: 572)
      • Antidetect8.exe (PID: 3616)
  • SUSPICIOUS

    • Adds / modifies Windows certificates

      • Antidetect8.exe (PID: 572)
      • Antidetect8.exe (PID: 3616)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 612)
  • INFO

    • Manual execution by user

      • Antidetect8.exe (PID: 3616)
      • Antidetect8.exe (PID: 1340)
      • Antidetect8.exe (PID: 3280)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
54
Monitored processes
5
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
drop and start start winrar.exe antidetect8.exe antidetect8.exe antidetect8.exe antidetect8.exe

Process information

PID
CMD
Path
Indicators
Parent process
572"C:\Users\admin\AppData\Local\Temp\Rar$EXa612.49038\Antidetect 8.01.36 CRACKED [Z3ROZ]\Antidetect8.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa612.49038\Antidetect 8.01.36 CRACKED [Z3ROZ]\Antidetect8.exe
WinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa612.49038\antidetect 8.01.36 cracked [z3roz]\antidetect8.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
612"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Antidetect 8.01.36 CRACKED [Z3ROZ].rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
1340"C:\Users\admin\Desktop\Antidetect8.exe" C:\Users\admin\Desktop\Antidetect8.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\antidetect8.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3280"C:\Users\admin\Desktop\Antidetect8.exe" C:\Users\admin\Desktop\Antidetect8.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\antidetect8.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3616"C:\Users\admin\Desktop\Antidetect8.exe" C:\Users\admin\Desktop\Antidetect8.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\antidetect8.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
Total events
562
Read events
498
Write events
63
Delete events
1

Modification events

(PID) Process:(612) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(612) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(612) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\137\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(612) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\137\52C64B7E
Operation:writeName:@C:\Windows\system32\NetworkExplorer.dll,-1
Value:
Network
(PID) Process:(612) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Antidetect 8.01.36 CRACKED [Z3ROZ].rar
(PID) Process:(612) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(612) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(612) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(612) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(612) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\137\52C64B7E
Operation:writeName:@C:\Windows\system32\notepad.exe,-469
Value:
Text Document
Executable files
5
Suspicious files
2
Text files
18
Unknown types
2

Dropped files

PID
Process
Filename
Type
612WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa612.49038\Antidetect 8.01.36 CRACKED [Z3ROZ]\fla\Flash-24.0.0.189\FlashUtil32_24_0_0_189_Plugin.exeexecutable
MD5:19AC5C0AC0021899A696EEC9CE1E60AC
SHA256:514491086F315111960819E7DE4E9EA853133700D2459F18C22567242A50F29C
612WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa612.49038\Antidetect 8.01.36 CRACKED [Z3ROZ]\browsers.txttext
MD5:99550869C563C7A99BB9D826F63FEA50
SHA256:D13321ADFD3B9558B825FEE29F13C0FB7AC326B2DF3CF36071612249C8F0071E
612WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa612.49038\Antidetect 8.01.36 CRACKED [Z3ROZ]\fla\Flash-24.0.0.189\FlashPlayerPlugin_24_0_0_189.exeexecutable
MD5:B85FA92B2D9F27A629041BD511952ABF
SHA256:AFFE55B47C38325DD975B55C23687F1B0FAA1343D62393EE20F3C049F856FDD4
612WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa612.49038\Antidetect 8.01.36 CRACKED [Z3ROZ]\fla\Flash-24.0.0.189\plugin.vchcat
MD5:DC2DC0FE686F18833D2EA8C053746A13
SHA256:B94EE6C591053EB42A2F6228ACA85B11901165BB0302B0367886FE00E20F205D
612WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa612.49038\Antidetect 8.01.36 CRACKED [Z3ROZ]\GenFiles\DeviceList-Monitors.txttext
MD5:044D85ABFF2615F9E5FAA0F8A9E2964B
SHA256:D4EC06204D6B817C5B63F2EFCAFA0CC5837AE7772946881179A32604BF41DBD5
612WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa612.49038\Antidetect 8.01.36 CRACKED [Z3ROZ]\GenFiles\DeviceList-DiskDrive2.txttext
MD5:F2019FE9B931DEB8B420ABFB6F760B88
SHA256:9AC129595254F39A3C7552E04ABEA8C3C3B0C973AC102CFCBCCF021FB702059A
612WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa612.49038\Antidetect 8.01.36 CRACKED [Z3ROZ]\GenFiles\DevicesList-DiskDrive.txttext
MD5:BCFED5B275B6081C28B98567452C47A3
SHA256:412D6D18924A5D32C7644D5E706B21EFDED71D33CD3A6EEEA0D7BD8FAF7AC75E
612WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa612.49038\Antidetect 8.01.36 CRACKED [Z3ROZ]\GenFiles\DevicesList-Display.txttext
MD5:2F31D37A477D99A65E4D8C7C74ABE89B
SHA256:EC639F2B8FD13BC183B81BD37D8E063233303643F98EF406B11B0FDA8558C142
612WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa612.49819\Antidetect 8.01.36 CRACKED [Z3ROZ]\Antidetect8.exe
MD5:
SHA256:
612WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa612.49038\Antidetect 8.01.36 CRACKED [Z3ROZ]\GenFiles\macs.txttext
MD5:A94E2E8B8643EDB5601B26A98493FE6D
SHA256:48770AEA980C9CB5FCA7DD39BEC3B135B3FF1F8DB5690AE3F415C74F7A5A8AD3
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
5
DNS requests
2
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
636
WerFault.exe
GET
52.158.209.219:80
http://watson.microsoft.com/StageOne/Antidetect8_exe/28_0_0_0/5dcc1645/Antidetect8_exe/28_0_0_0/5dcc1645/40000015/0004d532.htm?LCID=1033&OS=6.1.7601.2.00010100.1.0.48.17514&SM=DELL&SPN=DELL&BV=DELL&MID=3ADE2C42-4AB9-49B7-B142-BE9AEEA69063
US
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
572
Antidetect8.exe
216.58.207.78:443
drive.google.com
Google Inc.
US
whitelisted
3616
Antidetect8.exe
216.58.207.78:443
drive.google.com
Google Inc.
US
whitelisted
3280
Antidetect8.exe
216.58.207.78:443
drive.google.com
Google Inc.
US
whitelisted
636
WerFault.exe
52.158.209.219:80
watson.microsoft.com
Microsoft Corporation
US
suspicious
1340
Antidetect8.exe
216.58.207.78:443
drive.google.com
Google Inc.
US
whitelisted

DNS requests

Domain
IP
Reputation
drive.google.com
  • 216.58.207.78
shared
watson.microsoft.com
  • 52.158.209.219
whitelisted

Threats

PID
Process
Class
Message
Potential Corporate Privacy Violation
ET POLICY Application Crash Report Sent to Microsoft
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
No debug info