| File name: | New folder.rar |
| Full analysis: | https://app.any.run/tasks/361a2718-b405-41d3-8e53-f3dbeb9fdc36 |
| Verdict: | Malicious activity |
| Analysis date: | December 04, 2023, 18:58:59 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v5 |
| MD5: | EB37670E8F8D6399FF0923B4DE5BBE20 |
| SHA1: | 39DC59786C188978BB838238E62A88E8D2A2E8E1 |
| SHA256: | 4E7E1432E320848F9A61F4FE4353A9AD6D34F25F05F799FCCDC8C2AFC81EA6E5 |
| SSDEEP: | 98304:wBMuLqLssgQ2wczTOaXFJlwSRGIS+aoeHofNP1+Pav1KnyUpD9AMBTaSXkNBgq51:Kvqfst |
| .rar | | | RAR compressed archive (v5.0) (61.5) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 120 | "C:\Users\admin\Desktop\bin\中国黑客组织VIP远程协助V2011.exe" | C:\Users\admin\Desktop\bin\中国黑客组织VIP远程协助V2011.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 2147483652 Modules
| |||||||||||||||
| 644 | "C:\Users\admin\Desktop\中国黑客组织VIP专版远程控制\中国黑客组织.exe" | C:\Users\admin\Desktop\中国黑客组织VIP专版远程控制\中国黑客组织.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: 中国黑客组织 改进版 Exit code: 3221225477 Version: 2.1 Modules
| |||||||||||||||
| 1452 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1460 | "C:\Users\admin\Desktop\bin\中国黑客组织VIP远程协助V2011.exe" | C:\Users\admin\Desktop\bin\中国黑客组织VIP远程协助V2011.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 2147483652 Modules
| |||||||||||||||
| 1840 | "C:\Users\admin\Desktop\Black World DDOSV1.3日月神教专版\Server.exe" | C:\Users\admin\Desktop\Black World DDOSV1.3日月神教专版\Server.exe | explorer.exe | ||||||||||||
User: admin Company: 360.cn Integrity Level: HIGH Description: 360手机助手 Exit code: 0 Version: 1, 6, 0, 1610 Modules
| |||||||||||||||
| 2144 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\New folder.rar" | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 2224 | "C:\Users\admin\Desktop\中国黑客组织第五版\中国黑客组织第五版\中国黑客组织第五版.exe" | C:\Users\admin\Desktop\中国黑客组织第五版\中国黑客组织第五版\中国黑客组织第五版.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: 中国黑客组织第五版 Exit code: 0 Version: 5, 0, 0, 0 Modules
| |||||||||||||||
| 2348 | "C:\Users\admin\Desktop\Black World DDOSV1.3日月神教专版\Black World.exe" | C:\Users\admin\Desktop\Black World DDOSV1.3日月神教专版\Black World.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Blck Wrold DDOS V1.3 Exit code: 0 Version: 1, 0, 0, 0 Modules
| |||||||||||||||
| 3028 | "C:\Users\admin\Desktop\Black World DDOSV1.3日月神教专版\Server.exe" | C:\Users\admin\Desktop\Black World DDOSV1.3日月神教专版\Server.exe | — | explorer.exe | |||||||||||
User: admin Company: 360.cn Integrity Level: MEDIUM Description: 360手机助手 Exit code: 3221226540 Version: 1, 6, 0, 1610 Modules
| |||||||||||||||
| 3144 | "C:\Users\admin\Desktop\Sword beta 3.0\日月神教.exe" | C:\Users\admin\Desktop\Sword beta 3.0\日月神教.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| (PID) Process: | (2144) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\17F\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2144) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (2144) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (2144) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (2144) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2144) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2144) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2144) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (3264) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3264) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2144 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2144.34036\论坛专版免杀.rar | compressed | |
MD5:9B8B625D73F60BB66628F852A6CDA8E0 | SHA256:A06D40CBA186D1FAF28DAD922E9D047F7877AE0DCA0ED20B2B4D22F537D25EC1 | |||
| 2144 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2144.34036\中国黑客组织VIP专版远程控制.rar | compressed | |
MD5:F579D4BC1D892EE7CED9BBC45126EF5E | SHA256:4640650BF5A53AC9EBFB6DB63E07923A2A14D868C46278AA1E8B77BC43713DAC | |||
| 2144 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2144.34036\Black World DDOSV1.3日月神教专版.rar | compressed | |
MD5:A1F08BBE3A571FEBBCD06AA36AD1924C | SHA256:73C0D29BDA4644922F5B3AF482DA01CBAE4F7D0E8383488B232F8DC6EB1EB36B | |||
| 2144 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2144.34036\中国黑客组织第六版.rar | compressed | |
MD5:718CB9E80BDD4755317CE10F9AFEA0DD | SHA256:E8964A5E99B45EC3D52C7F579B3E10FEA7207E206F8DCB58D885AA38C5AC47AF | |||
| 2144 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2144.34036\Sword beta 3.0.rar | compressed | |
MD5:8EFEA927552F00AB1D438C30BC7B2807 | SHA256:D162E5EF706C5B4640CF196BAFB4AE68AB41A62B2596AFC063C164493C850CC7 | |||
| 3264 | WinRAR.exe | C:\Users\admin\Desktop\Black World DDOSV1.3日月神教专版\Black World.exe | executable | |
MD5:B8678094AF229486DEB00D682CCC3DAC | SHA256:224E121154EBD7D37B868BDD44D35B2DC9E68F5A5CA904764818CB6E229045C3 | |||
| 3264 | WinRAR.exe | C:\Users\admin\Desktop\Black World DDOSV1.3日月神教专版\Black World.ini | text | |
MD5:1B39DEBA33CA8A0C4236EECE9C8BEB04 | SHA256:0A81395AB235EEB3CE1F4F48BADBF051E7A0C4D493A9264AE270AEE55E32EFD9 | |||
| 3264 | WinRAR.exe | C:\Users\admin\Desktop\Black World DDOSV1.3日月神教专版\hzdg.dat | executable | |
MD5:398D9F89AC61AA7C540B3FDE70731947 | SHA256:A816535085D90D5D352653D5D2ECB06E4CA70C352042B514F179B1E14D0EC4B9 | |||
| 2144 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2144.34036\bin.rar | compressed | |
MD5:B0F25F491EBB3D3EC12A6A7DA20494C9 | SHA256:62C9322D3A72CE94AA4E6070CBE7F3D01D815BF1EC99BD7E3E3912F071FB96FE | |||
| 2144 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2144.34036\中国黑客组织第五版.rar | compressed | |
MD5:BC41641A2BF454266E3701827176D4BB | SHA256:345A2134F59530035922FABA52D8030B22FB25BE364BFFD32B783C52AC610F3B | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |