| File name: | Ulitmate_Virus_Maker_Tool_Pack_2.zip |
| Full analysis: | https://app.any.run/tasks/99650214-d0a8-4adb-bb95-a66e9b1de532 |
| Verdict: | Suspicious activity |
| Analysis date: | June 22, 2020, 07:32:24 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | D1F8E210D8551A0C62283559AB511BF9 |
| SHA1: | B8BD1C3AF74987054A43E79EFA407584D7A35143 |
| SHA256: | 51F2C46E67961B61AD524782823EFCCCA3E31729A4106023A9C41EFCFF74ED79 |
| SSDEEP: | 49152:IWq8MpcDXnEpGHd5hEa32413n1eyDe9NZ5yK:Ix1pcDXEEHd5GgL1ljy9F |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2013:08:12 09:42:07 |
| ZipCRC: | 0xd8e830cc |
| ZipCompressedSize: | 80176 |
| ZipUncompressedSize: | 165376 |
| ZipFileName: | Ultimate Virus Builder.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2668 | dw20.exe -x -s 368 | C:\Windows\Microsoft.NET\Framework\v2.0.50727\dw20.exe | — | Ultimate Virus Builder.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft .NET Error Reporting Shim Exit code: 0 Version: 2.0.50727.4927 (NetFXspW7.050727-4900) Modules
| |||||||||||||||
| 2676 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2972.1450\HICHKAS.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2972.1450\HICHKAS.exe | — | WinRAR.exe | |||||||||||
User: admin Company: Virus Maker Software . Integrity Level: MEDIUM Description: Programmer : Mehran Rasa Exit code: 0 Version: 1.00 Modules
| |||||||||||||||
| 2680 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2972.389\virus maker .exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2972.389\virus maker .exe | — | WinRAR.exe | |||||||||||
User: admin Company: www.realhackings.com Integrity Level: MEDIUM Description: can be used to make simple batch virus Exit code: 0 Version: 01.00.00.00 Modules
| |||||||||||||||
| 2832 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2972.099\Virus_Maker.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2972.099\Virus_Maker.exe | — | WinRAR.exe | |||||||||||
User: admin Company: andreinick05 Integrity Level: MEDIUM Description: Batch Virus Maker Exit code: 0 Version: 0.0.0.2 Modules
| |||||||||||||||
| 2956 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2972.975\SonicBat.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2972.975\SonicBat.exe | — | WinRAR.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Batch File Virus Maker Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 2972 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Ulitmate_Virus_Maker_Tool_Pack_2.zip" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 3292 | msg * Command Added to your virus ! | C:\Windows\system32\msg.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Message Utility Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3372 | cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\2680KBP9.cmd" "C:\Users\admin\AppData\Local\Temp\Rar$EXa2972.389\virus maker .exe" " | C:\Windows\system32\cmd.exe | — | virus maker .exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 3900 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2972.1766\$MOOTHiE's Macro Virus Creator Ver. 1.0.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2972.1766\$MOOTHiE's Macro Virus Creator Ver. 1.0.exe | — | WinRAR.exe | |||||||||||
User: admin Company: Zero Gravity Integrity Level: MEDIUM Description: Costom Macro Virus Creator Exit code: 0 Version: 1.00 Modules
| |||||||||||||||
| 3968 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2972.541\Ultimate Virus Builder.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2972.541\Ultimate Virus Builder.exe | WinRAR.exe | ||||||||||||
User: admin Company: HackApps Integrity Level: MEDIUM Description: Ultimate Virus Builder Exit code: 3762507597 Version: 1.0.0.9 Modules
| |||||||||||||||
| (PID) Process: | (2972) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (2972) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (2972) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12F\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2972) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12F\52C64B7E |
| Operation: | write | Name: | @C:\Windows\system32\NetworkExplorer.dll,-1 |
Value: Network | |||
| (PID) Process: | (2972) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Ulitmate_Virus_Maker_Tool_Pack_2.zip | |||
| (PID) Process: | (2972) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2972) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2972) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2972) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (2972) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2972 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2972.099\$MOOTHiE's Macro Virus Creator Ver. 1.0.exe | executable | |
MD5:BA8E425C41DB31AC3517095283121DAE | SHA256:DF7744898ED8617ACFF8A9CFCBEB07221B51D9747D296A7CB2172312ACA56005 | |||
| 2972 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2972.099\virus maker .exe | executable | |
MD5:1D38ED88BCDD11E0F5D657AB3542C918 | SHA256:75773722494446DFA60651A2B93D568B8C6CC18AA78E8E0D03F0C8514FEBEBD9 | |||
| 2972 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2972.099\SonicBat.exe | executable | |
MD5:15BEB2A9E80F559C4C65B84C513EB42D | SHA256:9F57E8D0544A05DC0799A91342CF5D2C07BC8EB308DA6BBBC2AD354C1FA70CE8 | |||
| 2972 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2972.099\dark horse trojan virus maker\COMCTL32.OCX | executable | |
MD5:EB5F811C1F78005B3C147599A0CCCF51 | SHA256:BF4147F8A12BEC3D54E3EF941475E29D852A1876117C6CE88F47B882EF6D4A03 | |||
| 2972 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2972.099\HICHKAS.exe | executable | |
MD5:B191AD6DB9B7AF9BA384DAE487386736 | SHA256:3DAB4DC1BFAEFE2FE8317778D17D8C7E9DEAE6228818BF7CFB87074C3F8288FC | |||
| 2972 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2972.099\Virus_Maker.exe | executable | |
MD5:83A5B7BC2F149EA64755EFAA332FB18D | SHA256:53CCD7DFB40E152FA560050403A67E2BF8912B012518D5230394B3357D085D65 | |||
| 2972 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2972.099\dark horse trojan virus maker\DarkHorseTrojanVirusMaker.exe | executable | |
MD5:C8C538CC07718D0ADABFA0AFEC212B8C | SHA256:A1366F71067BA4E4CE55078CE257F3656A6A02926A3D50652EB55575A3582950 | |||
| 2972 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2972.389\Ultimate Virus Builder.exe | executable | |
MD5:82D82F90205F0EDF2071F8B72C570278 | SHA256:3609CC9DF65CDBC4145074756A2B47D316255317EB07957238644349EA162CE1 | |||
| 2972 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2972.389\$MOOTHiE's Macro Virus Creator Ver. 1.0.exe | executable | |
MD5:BA8E425C41DB31AC3517095283121DAE | SHA256:DF7744898ED8617ACFF8A9CFCBEB07221B51D9747D296A7CB2172312ACA56005 | |||
| 2972 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2972.389\Virus_Maker.exe | executable | |
MD5:83A5B7BC2F149EA64755EFAA332FB18D | SHA256:53CCD7DFB40E152FA560050403A67E2BF8912B012518D5230394B3357D085D65 | |||