File name: | Re-Loader-Activator-2.2-Final-R1n.zip |
Full analysis: | https://app.any.run/tasks/a4c27a93-1f36-4231-a482-ab59e6d8a046 |
Verdict: | Malicious activity |
Analysis date: | June 05, 2018, 13:39:12 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/zip |
File info: | Zip archive data, at least v1.0 to extract |
MD5: | 116466AF9C99F2F37707CE6C3591D54B |
SHA1: | 9F1069EE8E84709A4B33E70DC7DAD9A0EB6BEF9D |
SHA256: | 44D8801C544E3B44B8B12D4F49CA33FC7C231B4975086DCAFE9CC3054AAE2B02 |
SSDEEP: | 24576:FgOJP3+zfuVsBo4CDTFrfRHWSTs5/AaQ1wOJFoBD6tPqh/Ziq/OPBsFyFRhh0:FgOJf+z2VsBo46TtfRH8SwOJ46pqlL/7 |
.zip | | | ZIP compressed archive (100) |
---|
ZipRequiredVersion: | 10 |
---|---|
ZipBitFlag: | - |
ZipCompression: | None |
ZipModifyDate: | 2016:04:13 18:17:03 |
ZipCRC: | 0x00000000 |
ZipCompressedSize: | - |
ZipUncompressedSize: | - |
ZipFileName: | Re-Loader Activator 2.2 Final R@1n/ |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
1744 | C:\Windows\system32\vssvc.exe | C:\Windows\system32\vssvc.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
2020 | "C:\Users\admin\AppData\Local\Temp\Re-Loader\OEM\bootsect.exe" /nt52 SYS /force | C:\Users\admin\AppData\Local\Temp\Re-Loader\OEM\bootsect.exe | — | [email protected] | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
2200 | "C:\Users\admin\Desktop\Re-Loader Activator 2.2 Final R@1n\[email protected]" /ActAuto /RestorePoint /Logo=AutoDetect | C:\Users\admin\Desktop\Re-Loader Activator 2.2 Final R@1n\[email protected] | cmd.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Activator Exit code: 0 Version: 2.2.3.0 Modules
| |||||||||||||||
2740 | "C:\Windows\System32\shutdown.exe" /r /t 1 | C:\Windows\System32\shutdown.exe | — | [email protected] | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Shutdown and Annotation Tool Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
3052 | "C:\Users\admin\AppData\Local\Temp\Re-Loader\OEM\brset.exe" /nt60 SYS /force | C:\Users\admin\AppData\Local\Temp\Re-Loader\OEM\brset.exe | — | [email protected] | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Boot Sector Manipulation Tool Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
3216 | C:\Windows\system32\DllHost.exe /Processid:{F32D97DF-E3E5-4CB9-9E3E-0EB5B4E49801} | C:\Windows\system32\DllHost.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: COM Surrogate Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
3228 | "C:\Program Files\7-Zip\7zFM.exe" "C:\Users\admin\AppData\Local\Temp\Re-Loader-Activator-2.2-Final-R1n.zip" | C:\Program Files\7-Zip\7zFM.exe | — | explorer.exe | |||||||||||
User: admin Company: Igor Pavlov Integrity Level: MEDIUM Description: 7-Zip File Manager Exit code: 1073807364 Version: 16.04 Modules
| |||||||||||||||
3252 | "C:\Users\admin\Desktop\Re-Loader Activator 2.2 Final R@1n\[email protected]" /ActAuto /RestorePoint /Logo=AutoDetect | C:\Users\admin\Desktop\Re-Loader Activator 2.2 Final R@1n\[email protected] | — | cmd.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Activator Exit code: 3221226540 Version: 2.2.3.0 Modules
| |||||||||||||||
3412 | cmd /c ""C:\Users\admin\Desktop\Re-Loader Activator 2.2 Final R@1n\SetupComplete.cmd" " | C:\Windows\system32\cmd.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
3460 | "C:\Users\admin\Desktop\Re-Loader Activator 2.2 Final R@1n\[email protected]" /ActAuto /RestorePoint /Logo=AutoDetect | C:\Users\admin\Desktop\Re-Loader Activator 2.2 Final R@1n\[email protected] | — | cmd.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Activator Exit code: 3221226540 Version: 2.2.3.0 Modules
|
(PID) Process: | (3228) 7zFM.exe | Key: | HKEY_CURRENT_USER\Software\7-Zip\Extraction |
Operation: | write | Name: | ShowPassword |
Value: 1 | |||
(PID) Process: | (3412) cmd.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
(PID) Process: | (3412) cmd.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | AutoDetect |
Value: 1 | |||
(PID) Process: | (2200) [email protected] | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
(PID) Process: | (2200) [email protected] | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | AutoDetect |
Value: 1 | |||
(PID) Process: | (3216) DllHost.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
Operation: | write | Name: | SppCreate (Enter) |
Value: 4000000000000000F8D3B1AFD2FCD301900C0000500F0000D0070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
(PID) Process: | (3216) DllHost.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP |
Operation: | write | Name: | LastIndex |
Value: 50 | |||
(PID) Process: | (3216) DllHost.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
Operation: | write | Name: | SppGatherWriterMetadata (Enter) |
Value: 400000000000000024801FB0D2FCD301900C0000500F0000D3070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
(PID) Process: | (3216) DllHost.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher |
Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000D84424B0D2FCD301900C0000B80F0000E8030000010000000000000000000000A6816D1492BA7F4886D2268B3D0FB9DA0000000000000000 | |||
(PID) Process: | (1744) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer |
Operation: | write | Name: | IDENTIFY (Enter) |
Value: 400000000000000010E140B0D2FCD301D0060000E00B0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 |
PID | Process | Filename | Type | |
---|---|---|---|---|
3228 | 7zFM.exe | C:\Users\admin\AppData\Local\Temp\7zEC9C51424\Re-Loader Activator 2.2 Final R@1n\A lire\Leggimi.txt | — | |
MD5:— | SHA256:— | |||
3228 | 7zFM.exe | C:\Users\admin\AppData\Local\Temp\7zEC9C51424\Re-Loader Activator 2.2 Final R@1n\A lire\Lisezmoi.txt | — | |
MD5:— | SHA256:— | |||
3228 | 7zFM.exe | C:\Users\admin\AppData\Local\Temp\7zEC9C51424\Re-Loader Activator 2.2 Final R@1n\A lire\Readme.txt | — | |
MD5:— | SHA256:— | |||
3228 | 7zFM.exe | C:\Users\admin\AppData\Local\Temp\7zEC9C51424\Re-Loader Activator 2.2 Final R@1n\A lire\自述.txt | — | |
MD5:— | SHA256:— | |||
3228 | 7zFM.exe | C:\Users\admin\AppData\Local\Temp\7zEC9C51424\Re-Loader Activator 2.2 Final R@1n\nfo.nfo | — | |
MD5:— | SHA256:— | |||
3228 | 7zFM.exe | C:\Users\admin\AppData\Local\Temp\7zEC9C51424\Re-Loader Activator 2.2 Final R@1n\[email protected] | — | |
MD5:— | SHA256:— | |||
3228 | 7zFM.exe | C:\Users\admin\AppData\Local\Temp\7zEC9C51424\Re-Loader Activator 2.2 Final R@1n\SetupComplete.cmd | — | |
MD5:— | SHA256:— | |||
3216 | DllHost.exe | C:\System Volume Information\SPP\metadata-2 | — | |
MD5:— | SHA256:— | |||
3052 | brset.exe | \\?\Volume{e1a82db3-a9f0-11e7-b142-806e6f6e6963} | — | |
MD5:— | SHA256:— | |||
2020 | bootsect.exe | \\?\Volume{e1a82db3-a9f0-11e7-b142-806e6f6e6963} | — | |
MD5:— | SHA256:— |