| File name: | Plants.vs.Zombies.Garden.Warfare.CHS.Patch.v1.0-3DM.rar |
| Full analysis: | https://app.any.run/tasks/30c80926-cd93-4b61-85c4-d0f02be19940 |
| Verdict: | Malicious activity |
| Analysis date: | May 14, 2024, 09:41:53 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v4, os: Win32 |
| MD5: | 7B7A1188DE5A83BFEA6B463CE46C1196 |
| SHA1: | 178B38A3A0E41E14CDD5AD5C37D8E5054998EF2A |
| SHA256: | 62BC2E4D32F5D702F3CC4852B7ADFFDECEFA4C6D1B1E404CF0AA088D87C176FA |
| SSDEEP: | 98304:Gpdd5pY8V3yMBeTVXspAU4qoQxSMJ0hNu8OnARY0H7oU8U2tbt44tQlg8SEONQIL:38hU5bNr84PabA4bfJ |
| .rar | | | RAR compressed archive (v-4.x) (58.3) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (41.6) |
| CompressedSize: | 13002281 |
|---|---|
| UncompressedSize: | 13378360 |
| OperatingSystem: | Win32 |
| ModifyDate: | 2014:06:25 18:22:32 |
| PackingMethod: | Best Compression |
| ArchivedFileName: | 3DMGAME-Plants.vs.Zombies.Garden.Warfare.CHS.Patch.v1.0-3DM.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1064 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa3984.4270\3DMGAME-Plants.vs.Zombies.Garden.Warfare.CHS.Patch.v1.0-3DM.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa3984.4270\3DMGAME-Plants.vs.Zombies.Garden.Warfare.CHS.Patch.v1.0-3DM.exe | 3DMGAME-Plants.vs.Zombies.Garden.Warfare.CHS.Patch.v1.0-3DM.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: 3DM汉化补丁安装器 Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 1616 | "C:\Users\admin\Desktop\3DMGAME-Plants.vs.Zombies.Garden.Warfare.CHS.Patch.v1.0-3DM.exe" | C:\Users\admin\Desktop\3DMGAME-Plants.vs.Zombies.Garden.Warfare.CHS.Patch.v1.0-3DM.exe | 3DMGAME-Plants.vs.Zombies.Garden.Warfare.CHS.Patch.v1.0-3DM.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: 3DM汉化补丁安装器 Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 1768 | "C:\Users\admin\Desktop\3DMGAME-Plants.vs.Zombies.Garden.Warfare.CHS.Patch.v1.0-3DM.exe" | C:\Users\admin\Desktop\3DMGAME-Plants.vs.Zombies.Garden.Warfare.CHS.Patch.v1.0-3DM.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: 3DM汉化补丁安装器 Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 3984 | "C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\Plants.vs.Zombies.Garden.Warfare.CHS.Patch.v1.0-3DM.rar | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 4024 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa3984.4270\3DMGAME-Plants.vs.Zombies.Garden.Warfare.CHS.Patch.v1.0-3DM.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa3984.4270\3DMGAME-Plants.vs.Zombies.Garden.Warfare.CHS.Patch.v1.0-3DM.exe | — | WinRAR.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: 3DM汉化补丁安装器 Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| (PID) Process: | (3984) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3984) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3984) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3984) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (3984) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (3984) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
| (PID) Process: | (3984) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Plants.vs.Zombies.Garden.Warfare.CHS.Patch.v1.0-3DM.rar | |||
| (PID) Process: | (3984) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3984) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3984) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3984 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3984.4270\3DMGAME-Plants.vs.Zombies.Garden.Warfare.CHS.Patch.v1.0-3DM.exe | executable | |
MD5:81AF74E9BEAA652CA3BA1968444BCCD9 | SHA256:D74174B52CB8C0B9C93931D9B994854D2D6E42845B64778E1A94FCBF607050ED | |||
| 3984 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3984.5275\3DMGAME-Plants.vs.Zombies.Garden.Warfare.CHS.Patch.v1.0-3DM.exe | executable | |
MD5:81AF74E9BEAA652CA3BA1968444BCCD9 | SHA256:D74174B52CB8C0B9C93931D9B994854D2D6E42845B64778E1A94FCBF607050ED | |||
| 1064 | 3DMGAME-Plants.vs.Zombies.Garden.Warfare.CHS.Patch.v1.0-3DM.exe | C:\Users\admin\AppData\Local\Temp\aut7D21.tmp | binary | |
MD5:7A3AC4AD2F13D7243AAA7077C08E6C3E | SHA256:BC4051C9D6535F450A1A4F7CD67016E9446637F0ECFF47082E9970A7E2331CD7 | |||
| 1616 | 3DMGAME-Plants.vs.Zombies.Garden.Warfare.CHS.Patch.v1.0-3DM.exe | C:\Users\admin\AppData\Local\Temp\autB17F.tmp | binary | |
MD5:7A3AC4AD2F13D7243AAA7077C08E6C3E | SHA256:BC4051C9D6535F450A1A4F7CD67016E9446637F0ECFF47082E9970A7E2331CD7 | |||
| 1064 | 3DMGAME-Plants.vs.Zombies.Garden.Warfare.CHS.Patch.v1.0-3DM.exe | C:\Users\admin\AppData\Local\Temp\3dm\3dm.she | binary | |
MD5:7A3AC4AD2F13D7243AAA7077C08E6C3E | SHA256:BC4051C9D6535F450A1A4F7CD67016E9446637F0ECFF47082E9970A7E2331CD7 | |||
| 1064 | 3DMGAME-Plants.vs.Zombies.Garden.Warfare.CHS.Patch.v1.0-3DM.exe | C:\Users\admin\AppData\Local\Temp\aut7D32.tmp | executable | |
MD5:114054313070472CD1A6D7D28F7C5002 | SHA256:E15D9E1B772FED3DB19E67B8D54533D1A2D46A37F8B12702A5892C6B886E9DB1 | |||
| 1616 | 3DMGAME-Plants.vs.Zombies.Garden.Warfare.CHS.Patch.v1.0-3DM.exe | C:\Users\admin\AppData\Local\Temp\autB50A.tmp | executable | |
MD5:114054313070472CD1A6D7D28F7C5002 | SHA256:E15D9E1B772FED3DB19E67B8D54533D1A2D46A37F8B12702A5892C6B886E9DB1 | |||
| 1064 | 3DMGAME-Plants.vs.Zombies.Garden.Warfare.CHS.Patch.v1.0-3DM.exe | C:\Users\admin\AppData\Local\Temp\3dm\Skin.dll | executable | |
MD5:114054313070472CD1A6D7D28F7C5002 | SHA256:E15D9E1B772FED3DB19E67B8D54533D1A2D46A37F8B12702A5892C6B886E9DB1 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |