File name: | Acrobyte SMS Verification Bypass.zip |
Full analysis: | https://app.any.run/tasks/90a13ff4-74fe-49ec-a212-ecbc9260cc70 |
Verdict: | Malicious activity |
Analysis date: | May 14, 2021 at 11:09:38 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/zip |
File info: | Zip archive data, at least v1.0 to extract |
MD5: | E1D51D7CAE936DF2968B9EAFFFF4B4A5 |
SHA1: | EC1B14999CA1FE9DBD578533788FA3BD85A1F657 |
SHA256: | 58FA34ADA1C771FCDA6BAF9E4FE7968A99B4BD06A0F090CB88C9352CC2926C48 |
SSDEEP: | 196608:HgK00sVRifdZIs8oG38OvE0p7GDgZCdjrjgk/B0vtoEJR12B:MVRkB/GsEp7G6mrp/6R1M |
.zip | | | ZIP compressed archive (100) |
---|
ZipFileName: | Acrobyte SMS Verification Bypass/ |
---|---|
ZipUncompressedSize: | - |
ZipCompressedSize: | - |
ZipCRC: | 0x00000000 |
ZipModifyDate: | 2021:04:15 19:20:24 |
ZipCompression: | None |
ZipBitFlag: | - |
ZipRequiredVersion: | 10 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
1440 | "C:\Users\admin\Desktop\Acrobyte SMS Verification Bypass\Acrobyte SMS Verification Bypass.exe" | C:\Users\admin\Desktop\Acrobyte SMS Verification Bypass\Acrobyte SMS Verification Bypass.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
2704 | "C:\\ProgramData\\Windows Portable Clipboard\\Runtime Broker.exe" | C:\ProgramData\Windows Portable Clipboard\Runtime Broker.exe | — | Acrobyte SMS Verification Bypass.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Runtime Broker Exit code: 0 Version: 10.0.19041.1 Modules
| |||||||||||||||
3500 | "libGLESV2.bin" | C:\Users\admin\Desktop\Acrobyte SMS Verification Bypass\libGLESV2.bin | Acrobyte SMS Verification Bypass.exe | ||||||||||||
User: admin Company: Acrobyte Hacks Integrity Level: HIGH Description: Acrobyte SMS Verification Bypass Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
3704 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\Acrobyte SMS Verification Bypass.zip" | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
|
(PID) Process: | (3704) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtBMP |
Value: | |||
(PID) Process: | (3704) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtIcon |
Value: | |||
(PID) Process: | (3704) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (3704) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E |
Operation: | write | Name: | @C:\Windows\system32\NetworkExplorer.dll,-1 |
Value: Network | |||
(PID) Process: | (3704) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\Acrobyte SMS Verification Bypass.zip | |||
(PID) Process: | (3704) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | name |
Value: 120 | |||
(PID) Process: | (3704) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | size |
Value: 80 | |||
(PID) Process: | (3704) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | type |
Value: 120 | |||
(PID) Process: | (3704) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | mtime |
Value: 100 | |||
(PID) Process: | (3704) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin |
Operation: | write | Name: | Placement |
Value: 2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000 |
PID | Process | Filename | Type | |
---|---|---|---|---|
3704 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3704.45921\Acrobyte SMS Verification Bypass\Acrobyte SMS Verification Bypass.exe | — | |
MD5:— | SHA256:— | |||
3704 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3704.45921\Acrobyte SMS Verification Bypass\lib\btc.exe.manifest | — | |
MD5:— | SHA256:— | |||
3704 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3704.45921\Acrobyte SMS Verification Bypass\lib\bz2.pyd | — | |
MD5:— | SHA256:— | |||
3704 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3704.45921\Acrobyte SMS Verification Bypass\lib\Microsoft.VC90.CRT.manifest | — | |
MD5:— | SHA256:— | |||
3704 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3704.45921\Acrobyte SMS Verification Bypass\lib\msvcm90.dll | — | |
MD5:— | SHA256:— | |||
3704 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3704.45921\Acrobyte SMS Verification Bypass\lib\msvcp90.dll | — | |
MD5:— | SHA256:— | |||
3704 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3704.45921\Acrobyte SMS Verification Bypass\lib\msvcr90.dll | — | |
MD5:— | SHA256:— | |||
3704 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3704.45921\Acrobyte SMS Verification Bypass\lib\perfmon.pyd | — | |
MD5:— | SHA256:— | |||
3704 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3704.45921\Acrobyte SMS Verification Bypass\lib\pyconfig.h | — | |
MD5:— | SHA256:— | |||
3704 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3704.45921\Acrobyte SMS Verification Bypass\lib\pyexpat.pyd | — | |
MD5:— | SHA256:— |