| File name: | Hex-Rays IDA Pro v7.3.zip |
| Full analysis: | https://app.any.run/tasks/aa9f9ac1-de1a-4ef0-a5f6-7d88fbeaa8f5 |
| Verdict: | Malicious activity |
| Threats: | Ficker Stealer is a malware that steals passwords, files, credit card details, and other types of sensitive information on Windows systems. It is most often distributed via phishing emails and can perform keylogging, process injection, and browser tracking. |
| Analysis date: | January 12, 2021, 17:58:40 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v1.0 to extract |
| MD5: | 0E08C931CE47CD0157EF52557704A405 |
| SHA1: | 46F471C242CC0CDEAA9B3BEF8BC498A102FAFAF3 |
| SHA256: | 531E000A244C140FBD5907075B835F48D265BE1D6AAE9E970B92E5D9A670E2FB |
| SSDEEP: | 196608:Lcz/YPbPJJbTMCHfBmT4VhIQSRye27lMeytJECR3FfjiGo5:Yz/YPbPQFTShIQG27ty73tE |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 10 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | None |
| ZipModifyDate: | 2021:01:12 17:55:10 |
| ZipCRC: | 0x50c868d6 |
| ZipCompressedSize: | 3218 |
| ZipUncompressedSize: | 3218 |
| ZipFileName: | Readme!.txt |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1252 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Hex-Rays IDA Pro v7.3.zip" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 2344 | "C:\Users\admin\Desktop\Hex-Rays IDA Pro v7.3.190614 (x64) Patched - [haxNode].exe" | C:\Users\admin\Desktop\Hex-Rays IDA Pro v7.3.190614 (x64) Patched - [haxNode].exe | — | explorer.exe | |||||||||||
User: admin Company: The GIMP Team Integrity Level: MEDIUM Description: GIMP Setup Exit code: 3221226540 Version: 2.10.22 Modules
| |||||||||||||||
| 3492 | "C:\Users\admin\Desktop\Hex-Rays IDA Pro v7.3.190614 (x64) Patched - [haxNode].exe" | C:\Windows\system32\calc.exe | Hex-Rays IDA Pro v7.3.190614 (x64) Patched - [haxNode].exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Calculator Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3712 | "C:\Users\admin\Desktop\Hex-Rays IDA Pro v7.3.190614 (x64) Patched - [haxNode].exe" | C:\Users\admin\Desktop\Hex-Rays IDA Pro v7.3.190614 (x64) Patched - [haxNode].exe | explorer.exe | ||||||||||||
User: admin Company: The GIMP Team Integrity Level: HIGH Description: GIMP Setup Exit code: 0 Version: 2.10.22 Modules
| |||||||||||||||
| (PID) Process: | (1252) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (1252) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (1252) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (1252) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Hex-Rays IDA Pro v7.3.zip | |||
| (PID) Process: | (1252) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (1252) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (1252) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (1252) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (1252) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E |
| Operation: | write | Name: | @C:\Windows\system32\msinfo32.exe,-10001 |
Value: System Information File | |||
| (PID) Process: | (1252) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E |
| Operation: | write | Name: | @C:\Windows\System32\ieframe.dll,-10046 |
Value: Internet Shortcut | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1252 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1252.18681\data.dat | — | |
MD5:— | SHA256:— | |||
| 1252 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1252.18681\Hex-Rays IDA Pro v7.3.190614 (x64) Patched - [haxNode].exe | executable | |
MD5:— | SHA256:— | |||
| 3492 | calc.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\93ZIKSE7.txt | text | |
MD5:— | SHA256:— | |||
| 1252 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1252.18681\Readme!.txt | text | |
MD5:— | SHA256:— | |||
| 3492 | calc.exe | C:\ProgramData\krosqm.txt | text | |
MD5:— | SHA256:— | |||
| 1252 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1252.18681\Info.nfo | binary | |
MD5:— | SHA256:— | |||
| 1252 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1252.18681\THEPIRATEBAY.ORG.url | text | |
MD5:F0A05245942DF80720C52D58064731EE | SHA256:650CAE89065A9B00E4A7A1F3DFE4FB03A33F5BF96453A71DB1C05B30F5469F66 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3492 | calc.exe | GET | 200 | 54.235.189.250:80 | http://api.ipify.org/?format=xml | US | text | 13 b | shared |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3492 | calc.exe | 54.235.189.250:80 | api.ipify.org | Amazon.com, Inc. | US | suspicious |
3492 | calc.exe | 85.17.190.28:80 | — | LeaseWeb Netherlands B.V. | NL | malicious |
Domain | IP | Reputation |
|---|---|---|
api.ipify.org |
| shared |
PID | Process | Class | Message |
|---|---|---|---|
3492 | calc.exe | Potential Corporate Privacy Violation | ET POLICY External IP Lookup (ipify .org) |
3492 | calc.exe | A Network Trojan was detected | ET TROJAN Win32/Ficker Stealer Activity M3 |
3492 | calc.exe | A Network Trojan was detected | STEALER [PTsecurity] Ficker |
3492 | calc.exe | A Network Trojan was detected | ET TROJAN Win32/Ficker Stealer Activity M3 |
3492 | calc.exe | A Network Trojan was detected | STEALER [PTsecurity] Ficker |