File name:

Warzone 2.70 Cracked.rar

Full analysis: https://app.any.run/tasks/e6dd6761-9b31-4ee6-82ef-6bae7213f43b
Verdict: Malicious activity
Analysis date: April 28, 2021, 22:48:15
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

84A22B8D1783F4B749653D19CD7E7B41

SHA1:

16D28AA15979686EF6A06B914D4ABDB1323514B0

SHA256:

446E31274C87C71C7C0EFE0F975389BD64F389A806291219211F113968059AD1

SSDEEP:

393216:3eIgTZds5s6bbdAedvqEt470nZACUBpQregs83x2zQ3tnPYzI5:Bls6bBAedCEt/Wp3wvPIS

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • WARZONE RAT 2.70.exe (PID: 2976)
      • Warzone Cracked.exe (PID: 1344)
      • Inject.exe (PID: 844)
      • WARZONE RAT 2.70.exe (PID: 2724)
      • Inject.exe (PID: 3772)
    • Loads dropped or rewritten executable

      • Inject.exe (PID: 844)
      • WARZONE RAT 2.70.exe (PID: 2976)
      • WARZONE RAT 2.70.exe (PID: 2724)
      • Inject.exe (PID: 3772)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2276)
    • Drops a file with too old compile date

      • WinRAR.exe (PID: 2276)
    • Drops a file that was compiled in debug mode

      • WinRAR.exe (PID: 2276)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
47
Monitored processes
6
Malicious processes
4
Suspicious processes
2

Behavior graph

Click at the process to see the details
drop and start drop and start start winrar.exe warzone cracked.exe no specs warzone rat 2.70.exe inject.exe no specs inject.exe no specs warzone rat 2.70.exe

Process information

PID
CMD
Path
Indicators
Parent process
844"Injector\Inject.exe" -m Main -i "Injector\Warzone.Loader.dll" -l Cortex.Loader -a "hello inject" -n "WARZONE RAT 2.70.exe"C:\Users\admin\AppData\Local\Temp\Rar$EXa2276.45807\Warzone 2.70 Cracked\Warzone 2.70 Cracked\Warzone 2.70 Cracked\Injector\Inject.exeWarzone Cracked.exe
User:
admin
Company:
Plan A Software
Integrity Level:
MEDIUM
Description:
An unmanaged command line application for injecting the .net runtime and .net assemblies into x86 or x64 unmanaged or managed remote processes.
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2276.45807\warzone 2.70 cracked\warzone 2.70 cracked\warzone 2.70 cracked\injector\inject.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
1344"C:\Users\admin\AppData\Local\Temp\Rar$EXa2276.45807\Warzone 2.70 Cracked\Warzone 2.70 Cracked\Warzone 2.70 Cracked\Warzone Cracked.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2276.45807\Warzone 2.70 Cracked\Warzone 2.70 Cracked\Warzone 2.70 Cracked\Warzone Cracked.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Warzone Cracked
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2276.45807\warzone 2.70 cracked\warzone 2.70 cracked\warzone 2.70 cracked\warzone cracked.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2276"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Warzone 2.70 Cracked.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2724"C:\Users\admin\AppData\Local\Temp\Rar$EXa2276.3823\Warzone 2.70 Cracked\Warzone 2.70 Cracked\Warzone 2.70 Cracked\WARZONE RAT 2.70.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2276.3823\Warzone 2.70 Cracked\Warzone 2.70 Cracked\Warzone 2.70 Cracked\WARZONE RAT 2.70.exe
WinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Description:
WARZONE RAT 2.70
Exit code:
0
Version:
2.7.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2276.3823\warzone 2.70 cracked\warzone 2.70 cracked\warzone 2.70 cracked\warzone rat 2.70.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2976"C:\Users\admin\AppData\Local\Temp\Rar$EXa2276.45807\Warzone 2.70 Cracked\Warzone 2.70 Cracked\Warzone 2.70 Cracked\WARZONE RAT 2.70.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2276.45807\Warzone 2.70 Cracked\Warzone 2.70 Cracked\Warzone 2.70 Cracked\WARZONE RAT 2.70.exe
Warzone Cracked.exe
User:
admin
Integrity Level:
MEDIUM
Description:
WARZONE RAT 2.70
Exit code:
0
Version:
2.7.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2276.45807\warzone 2.70 cracked\warzone 2.70 cracked\warzone 2.70 cracked\warzone rat 2.70.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3772"Injector\Inject.exe" -m Main -i "Injector\Warzone.Loader.dll" -l Cortex.Loader -a "hello inject" -n "WARZONE RAT 2.70.exe"C:\Users\admin\AppData\Local\Temp\Rar$EXa2276.45807\Warzone 2.70 Cracked\Warzone 2.70 Cracked\Warzone 2.70 Cracked\Injector\Inject.exeWarzone Cracked.exe
User:
admin
Company:
Plan A Software
Integrity Level:
MEDIUM
Description:
An unmanaged command line application for injecting the .net runtime and .net assemblies into x86 or x64 unmanaged or managed remote processes.
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2276.45807\warzone 2.70 cracked\warzone 2.70 cracked\warzone 2.70 cracked\injector\inject.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
Total events
873
Read events
856
Write events
17
Delete events
0

Modification events

(PID) Process:(2276) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2276) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2276) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2276) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E
Operation:writeName:@C:\Windows\system32\NetworkExplorer.dll,-1
Value:
Network
(PID) Process:(2276) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Warzone 2.70 Cracked.rar
(PID) Process:(2276) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2276) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2276) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2276) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2276) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
Executable files
40
Suspicious files
4
Text files
10
Unknown types
4

Dropped files

PID
Process
Filename
Type
2276WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2276.45807\Warzone 2.70 Cracked\Warzone 2.70 Cracked\Warzone 2.70 Cracked\Datas\firefox.dllsexecutable
MD5:A26861558315278D5960FE1BF58B1950
SHA256:B52720863EC78E0F7BFF98E6C809FDF50AB2D0EA361E95EB5341E870AAFB0354
2276WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2276.45807\Warzone 2.70 Cracked\Warzone 2.70 Cracked\Warzone 2.70 Cracked\Datas\geoip\GeoIP.datbinary
MD5:B64EA0C3E9617CCD2F22D8568676A325
SHA256:432E12E688449C2CF1B184C94E2E964F9E09398C194888A7FE1A5B1F8CF3059B
2276WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2276.45807\Warzone 2.70 Cracked\Warzone 2.70 Cracked\Warzone 2.70 Cracked\cratclientd.binexecutable
MD5:AC1144C81318C155A8A24C8FD7FC1CA5
SHA256:10BB6F5F2EEF11DE437C41E7CAA1713D4644345F17C601745445D26E8644717A
2276WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2276.45807\Warzone 2.70 Cracked\Warzone 2.70 Cracked\Warzone 2.70 Cracked\Injector\Bootstrap.libobj
MD5:60CEA0DAE5A157DE2F1563B5FB28CC31
SHA256:15249DB52C19992FC843C03CDBCC6FA1D20A618AD379B99FA242ED27809919B7
2276WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2276.45807\Warzone 2.70 Cracked\Warzone 2.70 Cracked\Warzone 2.70 Cracked\Datas\SocksManager.exeexecutable
MD5:E659818D6EFE1953E14C9ECE3B24A14C
SHA256:28195831F7E09DDF9BBE28EC957C1F380D27CF9CC3EBF538BEAADA0E4E74886A
2276WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2276.45807\Warzone 2.70 Cracked\Warzone 2.70 Cracked\Warzone 2.70 Cracked\Datas\ServerManager.dllexecutable
MD5:CCC5BD0D95F504FCE814E6758D4953D6
SHA256:2B658436167826D3A1E44919A1113C6F1717515BD7EF0064D7152D7C3E050FC1
2276WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2276.45807\Warzone 2.70 Cracked\Warzone 2.70 Cracked\Warzone 2.70 Cracked\Injector\Bootstrap.dllexecutable
MD5:68B1F2580254EE6B18E39B6ED9493CA6
SHA256:8CF696B44808A84A59C94B61BFA513007466546DA6C996540424B08E4BC0879A
2276WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2276.45807\Warzone 2.70 Cracked\Warzone 2.70 Cracked\Warzone 2.70 Cracked\Datas\sqlite3.dllexecutable
MD5:D3979DB259F55D59B4EDB327673C1905
SHA256:043E5570299C6099756C1809C5632EABEAB95ED3C1A55C86843C0EC218940E5A
2276WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2276.45807\Warzone 2.70 Cracked\Warzone 2.70 Cracked\Warzone 2.70 Cracked\Injector\0Harmony.dllexecutable
MD5:49EB0F4AC96C709D82560B143F666BC8
SHA256:28011CDBC84E33B9CD5B1D3FAF5C9166ED825C4DB208B44AFAA2B44C5D64FAC0
2276WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2276.45807\Warzone 2.70 Cracked\Warzone 2.70 Cracked\Warzone 2.70 Cracked\Datas\vncviewer.exeexecutable
MD5:17AE77C95C824BD71E9E3DA66068B1DF
SHA256:54B1E999D48059651E15685A860F655C37B70E241433335D01048CE65D237856
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
2
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
95.216.3.180:80
wzlicense.ws
Hetzner Online GmbH
DE
unknown
2724
WARZONE RAT 2.70.exe
95.216.3.180:80
wzlicense.ws
Hetzner Online GmbH
DE
unknown

DNS requests

Domain
IP
Reputation
wzlicense.ws
  • 95.216.3.180
unknown

Threats

No threats detected
No debug info