| File name: | Antidetect 8.01.36 CRACKED [Z3ROZ] (1).rar |
| Full analysis: | https://app.any.run/tasks/a6e23e45-d396-4f31-a299-526100752693 |
| Verdict: | Malicious activity |
| Threats: | WarZone RAT is a remote access trojan, which is written in C++ and offered as a malware-as-a-service. It packs a wide range of capabilities, from stealing victims’ files and passwords to capturing desktop activities. WarZone RAT is primarily distributed via phishing emails and receives regular updates from its C2. |
| Analysis date: | August 12, 2020, 18:13:37 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v5 |
| MD5: | 695B5D6EE1F194D0B5130D41C7BCA22E |
| SHA1: | 3C1B88BFCD951D8AA7C04C9540C5975DB87004D6 |
| SHA256: | 4EEBD67E3DE4411E67706B9C6CFA06F6A3479A505342B14199E04AF94D1A5303 |
| SSDEEP: | 196608:geUKgsDtnYohRy3QATAx+Oxm+rtHlqL1zPps1gyC5mrENBikDyEZ:cKgSh43QAsVs+rtFqpPW1gLmHMyQ |
| .rar | | | RAR compressed archive (v5.0) (61.5) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 352 | C:\Windows\Explorer.EXE | C:\Windows\explorer.exe | — | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 464 | "C:\Windows\system32\pkgmgr.exe" /n:%temp%\ellocnak.xml | C:\Windows\system32\pkgmgr.exe | cmd.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Package Manager Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 668 | powershell Add-MpPreference -ExclusionPath C:\ | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | SkyFender.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows PowerShell Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 780 | "C:\Windows\System32\cmd.exe" | C:\Windows\System32\cmd.exe | SkyFender.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 988 | "C:\Windows\system32\pkgmgr.exe" /n:%temp%\ellocnak.xml | C:\Windows\system32\pkgmgr.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Package Manager Exit code: 3221226540 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 996 | "C:\Windows\system32\pkgmgr.exe" /n:%temp%\ellocnak.xml | C:\Windows\system32\pkgmgr.exe | cmd.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Package Manager Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1504 | "C:\Windows\System32\cmd.exe" | C:\Windows\System32\cmd.exe | SkyFender.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1736 | "C:\Users\admin\AppData\Roaming\tmp.exe" | C:\Users\admin\AppData\Roaming\tmp.exe | Antidetect 8.01.36 CRACKED BY (Z3ROZ).exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 1772 | "C:\Users\admin\AppData\Roaming\SkyFender.exe" | C:\Users\admin\AppData\Roaming\SkyFender.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 1780 | "C:\Windows\system32\pkgmgr.exe" /n:%temp%\ellocnak.xml | C:\Windows\system32\pkgmgr.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Package Manager Exit code: 3221226540 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| (PID) Process: | (3352) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3352) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3352) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\137\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3352) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\137\52C64B7E |
| Operation: | write | Name: | @C:\Windows\system32\NetworkExplorer.dll,-1 |
Value: Network | |||
| (PID) Process: | (3352) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Antidetect 8.01.36 CRACKED [Z3ROZ] (1).rar | |||
| (PID) Process: | (3352) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3352) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3352) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3352) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (352) explorer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rar\OpenWithList |
| Operation: | write | Name: | a |
Value: WinRAR.exe | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3352 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3352.37848\Antidetect 8.01.36 CRACKED [Z3ROZ]\browsers.txt | text | |
MD5:99550869C563C7A99BB9D826F63FEA50 | SHA256:D13321ADFD3B9558B825FEE29F13C0FB7AC326B2DF3CF36071612249C8F0071E | |||
| 3352 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3352.37848\Antidetect 8.01.36 CRACKED [Z3ROZ]\fla\Flash-24.0.0.189\flashplayer.xpt | xpt | |
MD5:A81FD3B03B8C6D6E5A14298110718D3F | SHA256:946C2D7808B0F256E5F6B62655246DC9C247833FB2F578519E4354F91DEB6E1B | |||
| 3352 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3352.37848\Antidetect 8.01.36 CRACKED [Z3ROZ]\fla\Flash-24.0.0.189\mms.cfg | text | |
MD5:5246A94C265991426A0B8F9425CBEA42 | SHA256:2B5640814352DAD0B28FE962F1D4D4EFBDEB51EDA918AEEC8F1F3173F1145766 | |||
| 3352 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3352.37848\Antidetect 8.01.36 CRACKED [Z3ROZ]\Fonts.ini | text | |
MD5:28CDE1DDC49D4E74C45E1D1B35256F39 | SHA256:A4CBC68F5A9DC481A271054B9E7526816F2C5B73B2B7DC46DA0DCA979BCD8CBB | |||
| 3352 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3352.37848\Antidetect 8.01.36 CRACKED [Z3ROZ]\GenFiles\DeviceList-Monitors.txt | text | |
MD5:044D85ABFF2615F9E5FAA0F8A9E2964B | SHA256:D4EC06204D6B817C5B63F2EFCAFA0CC5837AE7772946881179A32604BF41DBD5 | |||
| 3352 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3352.37848\Antidetect 8.01.36 CRACKED [Z3ROZ]\fla\Flash-24.0.0.189\NPSWF32_24_0_0_189.dll | executable | |
MD5:01AF2375AE1D0F1E3CC0A3AB7BF935B0 | SHA256:99690DB7B65F70EC6EC413D237F99FBD476DE11F5D284764A5AFB09E72D3EFB8 | |||
| 3352 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3352.37848\Antidetect 8.01.36 CRACKED [Z3ROZ]\GenFiles\usernames.txt | text | |
MD5:BBBB7FE243F8EA240F5EFB196E87A290 | SHA256:CD51BFBCB29724579B49210D9AD1F009F6EE2F108A9E37B01E62D002930E1B1E | |||
| 3352 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3352.37848\Antidetect 8.01.36 CRACKED [Z3ROZ]\GenFiles\DevicesList-Display.txt | text | |
MD5:2F31D37A477D99A65E4D8C7C74ABE89B | SHA256:EC639F2B8FD13BC183B81BD37D8E063233303643F98EF406B11B0FDA8558C142 | |||
| 3352 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3352.37848\Antidetect 8.01.36 CRACKED [Z3ROZ]\GenFiles\DevicesList-DiskDrive.txt | text | |
MD5:BCFED5B275B6081C28B98567452C47A3 | SHA256:412D6D18924A5D32C7644D5E706B21EFDED71D33CD3A6EEEA0D7BD8FAF7AC75E | |||
| 3352 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3352.37848\Antidetect 8.01.36 CRACKED [Z3ROZ]\GenFiles\DevicesList-Processor.txt | text | |
MD5:2CDE9E426BB0C198677D6ED40EC461BE | SHA256:45659CE5DBA4F5A4295509621B643ECA7FD996CA7C3D943CF94CA15009C14903 | |||
Domain | IP | Reputation |
|---|---|---|
u868328.nvpn.so |
| unknown |