File name:

Warzone 2.70 Cracked.rar

Full analysis: https://app.any.run/tasks/e6dd6761-9b31-4ee6-82ef-6bae7213f43b
Verdict: Malicious activity
Analysis date: April 28, 2021, 22:48:15
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

84A22B8D1783F4B749653D19CD7E7B41

SHA1:

16D28AA15979686EF6A06B914D4ABDB1323514B0

SHA256:

446E31274C87C71C7C0EFE0F975389BD64F389A806291219211F113968059AD1

SSDEEP:

393216:3eIgTZds5s6bbdAedvqEt470nZACUBpQregs83x2zQ3tnPYzI5:Bls6bBAedCEt/Wp3wvPIS

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • WARZONE RAT 2.70.exe (PID: 2724)
      • Inject.exe (PID: 3772)
      • Inject.exe (PID: 844)
      • WARZONE RAT 2.70.exe (PID: 2976)
    • Application was dropped or rewritten from another process

      • Warzone Cracked.exe (PID: 1344)
      • Inject.exe (PID: 844)
      • Inject.exe (PID: 3772)
      • WARZONE RAT 2.70.exe (PID: 2724)
      • WARZONE RAT 2.70.exe (PID: 2976)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2276)
    • Drops a file that was compiled in debug mode

      • WinRAR.exe (PID: 2276)
    • Drops a file with too old compile date

      • WinRAR.exe (PID: 2276)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
47
Monitored processes
6
Malicious processes
4
Suspicious processes
2

Behavior graph

Click at the process to see the details
drop and start drop and start start winrar.exe warzone cracked.exe no specs warzone rat 2.70.exe inject.exe no specs inject.exe no specs warzone rat 2.70.exe

Process information

PID
CMD
Path
Indicators
Parent process
844"Injector\Inject.exe" -m Main -i "Injector\Warzone.Loader.dll" -l Cortex.Loader -a "hello inject" -n "WARZONE RAT 2.70.exe"C:\Users\admin\AppData\Local\Temp\Rar$EXa2276.45807\Warzone 2.70 Cracked\Warzone 2.70 Cracked\Warzone 2.70 Cracked\Injector\Inject.exeWarzone Cracked.exe
User:
admin
Company:
Plan A Software
Integrity Level:
MEDIUM
Description:
An unmanaged command line application for injecting the .net runtime and .net assemblies into x86 or x64 unmanaged or managed remote processes.
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2276.45807\warzone 2.70 cracked\warzone 2.70 cracked\warzone 2.70 cracked\injector\inject.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
1344"C:\Users\admin\AppData\Local\Temp\Rar$EXa2276.45807\Warzone 2.70 Cracked\Warzone 2.70 Cracked\Warzone 2.70 Cracked\Warzone Cracked.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2276.45807\Warzone 2.70 Cracked\Warzone 2.70 Cracked\Warzone 2.70 Cracked\Warzone Cracked.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Warzone Cracked
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2276.45807\warzone 2.70 cracked\warzone 2.70 cracked\warzone 2.70 cracked\warzone cracked.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2276"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Warzone 2.70 Cracked.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2724"C:\Users\admin\AppData\Local\Temp\Rar$EXa2276.3823\Warzone 2.70 Cracked\Warzone 2.70 Cracked\Warzone 2.70 Cracked\WARZONE RAT 2.70.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2276.3823\Warzone 2.70 Cracked\Warzone 2.70 Cracked\Warzone 2.70 Cracked\WARZONE RAT 2.70.exe
WinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Description:
WARZONE RAT 2.70
Exit code:
0
Version:
2.7.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2276.3823\warzone 2.70 cracked\warzone 2.70 cracked\warzone 2.70 cracked\warzone rat 2.70.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2976"C:\Users\admin\AppData\Local\Temp\Rar$EXa2276.45807\Warzone 2.70 Cracked\Warzone 2.70 Cracked\Warzone 2.70 Cracked\WARZONE RAT 2.70.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2276.45807\Warzone 2.70 Cracked\Warzone 2.70 Cracked\Warzone 2.70 Cracked\WARZONE RAT 2.70.exe
Warzone Cracked.exe
User:
admin
Integrity Level:
MEDIUM
Description:
WARZONE RAT 2.70
Exit code:
0
Version:
2.7.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2276.45807\warzone 2.70 cracked\warzone 2.70 cracked\warzone 2.70 cracked\warzone rat 2.70.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3772"Injector\Inject.exe" -m Main -i "Injector\Warzone.Loader.dll" -l Cortex.Loader -a "hello inject" -n "WARZONE RAT 2.70.exe"C:\Users\admin\AppData\Local\Temp\Rar$EXa2276.45807\Warzone 2.70 Cracked\Warzone 2.70 Cracked\Warzone 2.70 Cracked\Injector\Inject.exeWarzone Cracked.exe
User:
admin
Company:
Plan A Software
Integrity Level:
MEDIUM
Description:
An unmanaged command line application for injecting the .net runtime and .net assemblies into x86 or x64 unmanaged or managed remote processes.
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2276.45807\warzone 2.70 cracked\warzone 2.70 cracked\warzone 2.70 cracked\injector\inject.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
Total events
873
Read events
856
Write events
17
Delete events
0

Modification events

(PID) Process:(2276) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2276) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2276) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2276) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E
Operation:writeName:@C:\Windows\system32\NetworkExplorer.dll,-1
Value:
Network
(PID) Process:(2276) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Warzone 2.70 Cracked.rar
(PID) Process:(2276) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2276) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2276) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2276) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2276) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
Executable files
40
Suspicious files
4
Text files
10
Unknown types
4

Dropped files

PID
Process
Filename
Type
2276WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2276.45807\Warzone 2.70 Cracked\Warzone 2.70 Cracked\Warzone 2.70 Cracked\Datas\geoip\GeoIP.datbinary
MD5:B64EA0C3E9617CCD2F22D8568676A325
SHA256:432E12E688449C2CF1B184C94E2E964F9E09398C194888A7FE1A5B1F8CF3059B
2276WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2276.45807\Warzone 2.70 Cracked\Warzone 2.70 Cracked\Warzone 2.70 Cracked\Datas\rdpwrap.initext
MD5:6BC395161B04AA555D5A4E8EB8320020
SHA256:23390DFCDA60F292BA1E52ABB5BA2F829335351F4F9B1D33A9A6AD7A9BF5E2BE
2276WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2276.45807\Warzone 2.70 Cracked\Warzone 2.70 Cracked\Warzone 2.70 Cracked\Datas\rV.bsp1binary
MD5:A23A6C143732E1C83BF09FE71C78AA93
SHA256:E48D338DD5FC668888EB89E6C35E8F4B4F61B4D4BC35574C548A1BC9DBF52054
2276WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2276.45807\Warzone 2.70 Cracked\Warzone 2.70 Cracked\Warzone 2.70 Cracked\Datas\rdpwrap64.dllexecutable
MD5:C4063372AFE486D5E9A11C5B68E0524F
SHA256:FC1F3FC182CEF9BCEF5192E4FA4569697E27852CBFFB7A55EA6118C603DDC420
2276WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2276.45807\Warzone 2.70 Cracked\Warzone 2.70 Cracked\Warzone 2.70 Cracked\cratclientd.binexecutable
MD5:AC1144C81318C155A8A24C8FD7FC1CA5
SHA256:10BB6F5F2EEF11DE437C41E7CAA1713D4644345F17C601745445D26E8644717A
2276WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2276.45807\Warzone 2.70 Cracked\Warzone 2.70 Cracked\Warzone 2.70 Cracked\Datas\options.vnctext
MD5:6243B2004273137CB880196F4472268B
SHA256:11C79026B86D78DF113DD84848065175BC39EFADD48DF4C9768CA685E8FAFFC4
2276WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2276.45807\Warzone 2.70 Cracked\Warzone 2.70 Cracked\Warzone 2.70 Cracked\cratclient.binexecutable
MD5:2434C299FB99CB83F7D790B34DE2D6C2
SHA256:33512B63920B412F52067492D53756E706615348405379E5A27FE55A2D72F955
2276WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2276.45807\Warzone 2.70 Cracked\Warzone 2.70 Cracked\Warzone 2.70 Cracked\Datas\ServerManager.dllexecutable
MD5:CCC5BD0D95F504FCE814E6758D4953D6
SHA256:2B658436167826D3A1E44919A1113C6F1717515BD7EF0064D7152D7C3E050FC1
2276WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2276.45807\Warzone 2.70 Cracked\Warzone 2.70 Cracked\Warzone 2.70 Cracked\Datas\firefox.dllsexecutable
MD5:A26861558315278D5960FE1BF58B1950
SHA256:B52720863EC78E0F7BFF98E6C809FDF50AB2D0EA361E95EB5341E870AAFB0354
2276WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2276.45807\Warzone 2.70 Cracked\Warzone 2.70 Cracked\Warzone 2.70 Cracked\Injector\0Harmony.dllexecutable
MD5:49EB0F4AC96C709D82560B143F666BC8
SHA256:28011CDBC84E33B9CD5B1D3FAF5C9166ED825C4DB208B44AFAA2B44C5D64FAC0
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
2
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
95.216.3.180:80
wzlicense.ws
Hetzner Online GmbH
DE
unknown
2724
WARZONE RAT 2.70.exe
95.216.3.180:80
wzlicense.ws
Hetzner Online GmbH
DE
unknown

DNS requests

Domain
IP
Reputation
wzlicense.ws
  • 95.216.3.180
unknown

Threats

No threats detected
No debug info