| File name: | Antidetect 8.01.36 CRACKED [Z3ROZ] (1).rar |
| Full analysis: | https://app.any.run/tasks/a6e23e45-d396-4f31-a299-526100752693 |
| Verdict: | Malicious activity |
| Threats: | WarZone RAT is a remote access trojan, which is written in C++ and offered as a malware-as-a-service. It packs a wide range of capabilities, from stealing victims’ files and passwords to capturing desktop activities. WarZone RAT is primarily distributed via phishing emails and receives regular updates from its C2. |
| Analysis date: | August 12, 2020, 18:13:37 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v5 |
| MD5: | 695B5D6EE1F194D0B5130D41C7BCA22E |
| SHA1: | 3C1B88BFCD951D8AA7C04C9540C5975DB87004D6 |
| SHA256: | 4EEBD67E3DE4411E67706B9C6CFA06F6A3479A505342B14199E04AF94D1A5303 |
| SSDEEP: | 196608:geUKgsDtnYohRy3QATAx+Oxm+rtHlqL1zPps1gyC5mrENBikDyEZ:cKgSh43QAsVs+rtFqpPW1gLmHMyQ |
| .rar | | | RAR compressed archive (v5.0) (61.5) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 352 | C:\Windows\Explorer.EXE | C:\Windows\explorer.exe | — | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 464 | "C:\Windows\system32\pkgmgr.exe" /n:%temp%\ellocnak.xml | C:\Windows\system32\pkgmgr.exe | cmd.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Package Manager Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 668 | powershell Add-MpPreference -ExclusionPath C:\ | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | SkyFender.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows PowerShell Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 780 | "C:\Windows\System32\cmd.exe" | C:\Windows\System32\cmd.exe | SkyFender.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 988 | "C:\Windows\system32\pkgmgr.exe" /n:%temp%\ellocnak.xml | C:\Windows\system32\pkgmgr.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Package Manager Exit code: 3221226540 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 996 | "C:\Windows\system32\pkgmgr.exe" /n:%temp%\ellocnak.xml | C:\Windows\system32\pkgmgr.exe | cmd.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Package Manager Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1504 | "C:\Windows\System32\cmd.exe" | C:\Windows\System32\cmd.exe | SkyFender.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1736 | "C:\Users\admin\AppData\Roaming\tmp.exe" | C:\Users\admin\AppData\Roaming\tmp.exe | Antidetect 8.01.36 CRACKED BY (Z3ROZ).exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 1772 | "C:\Users\admin\AppData\Roaming\SkyFender.exe" | C:\Users\admin\AppData\Roaming\SkyFender.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 1780 | "C:\Windows\system32\pkgmgr.exe" /n:%temp%\ellocnak.xml | C:\Windows\system32\pkgmgr.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Package Manager Exit code: 3221226540 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| (PID) Process: | (3352) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3352) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3352) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\137\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3352) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\137\52C64B7E |
| Operation: | write | Name: | @C:\Windows\system32\NetworkExplorer.dll,-1 |
Value: Network | |||
| (PID) Process: | (3352) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Antidetect 8.01.36 CRACKED [Z3ROZ] (1).rar | |||
| (PID) Process: | (3352) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3352) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3352) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3352) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (352) explorer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rar\OpenWithList |
| Operation: | write | Name: | a |
Value: WinRAR.exe | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3352 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3352.37848\Antidetect 8.01.36 CRACKED [Z3ROZ]\browsers.txt | text | |
MD5:99550869C563C7A99BB9D826F63FEA50 | SHA256:D13321ADFD3B9558B825FEE29F13C0FB7AC326B2DF3CF36071612249C8F0071E | |||
| 3352 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3352.37848\Antidetect 8.01.36 CRACKED [Z3ROZ]\fla\Flash-24.0.0.189\mms.cfg | text | |
MD5:5246A94C265991426A0B8F9425CBEA42 | SHA256:2B5640814352DAD0B28FE962F1D4D4EFBDEB51EDA918AEEC8F1F3173F1145766 | |||
| 3352 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3352.37848\Antidetect 8.01.36 CRACKED [Z3ROZ]\chrome_parameters.txt | text | |
MD5:5FB9B885ED185A658B44300ECB22A30B | SHA256:9EE6DF8C3300C2E99DE1EA46300A4FE196CD4F2CFDB70364B8A095FCE0045B3E | |||
| 3352 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3352.37848\Antidetect 8.01.36 CRACKED [Z3ROZ]\fla\Flash-24.0.0.189\ktlh_ff.dll | executable | |
MD5:86722382CCAF8BA83238F59DCBC4FA73 | SHA256:8A90B1D65A480D302D29BE52B74CC02871DCC60CD1BA6E9924DFF2A7491357A7 | |||
| 3352 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3352.37848\Antidetect 8.01.36 CRACKED [Z3ROZ]\GenFiles\DeviceList-DiskDrive2.txt | text | |
MD5:F2019FE9B931DEB8B420ABFB6F760B88 | SHA256:9AC129595254F39A3C7552E04ABEA8C3C3B0C973AC102CFCBCCF021FB702059A | |||
| 3352 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3352.37848\Antidetect 8.01.36 CRACKED [Z3ROZ]\fla\Flash-24.0.0.189\plugin.vch | cat | |
MD5:DC2DC0FE686F18833D2EA8C053746A13 | SHA256:B94EE6C591053EB42A2F6228ACA85B11901165BB0302B0367886FE00E20F205D | |||
| 3352 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3352.37848\Antidetect 8.01.36 CRACKED [Z3ROZ]\fla\Flash-24.0.0.189\FlashPlayerPlugin_24_0_0_189.exe | executable | |
MD5:B85FA92B2D9F27A629041BD511952ABF | SHA256:AFFE55B47C38325DD975B55C23687F1B0FAA1343D62393EE20F3C049F856FDD4 | |||
| 3352 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3352.37848\Antidetect 8.01.36 CRACKED [Z3ROZ]\fla\Flash-24.0.0.189\flashplayer.xpt | xpt | |
MD5:A81FD3B03B8C6D6E5A14298110718D3F | SHA256:946C2D7808B0F256E5F6B62655246DC9C247833FB2F578519E4354F91DEB6E1B | |||
| 3352 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3352.37848\Antidetect 8.01.36 CRACKED [Z3ROZ]\fla\Flash-24.0.0.189\FlashUtil32_24_0_0_189_Plugin.exe | executable | |
MD5:19AC5C0AC0021899A696EEC9CE1E60AC | SHA256:514491086F315111960819E7DE4E9EA853133700D2459F18C22567242A50F29C | |||
| 3352 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3352.37848\Antidetect 8.01.36 CRACKED [Z3ROZ]\GenFiles\macs.txt | text | |
MD5:A94E2E8B8643EDB5601B26A98493FE6D | SHA256:48770AEA980C9CB5FCA7DD39BEC3B135B3FF1F8DB5690AE3F415C74F7A5A8AD3 | |||
Domain | IP | Reputation |
|---|---|---|
u868328.nvpn.so |
| unknown |