File name: | RoYo.zip |
Full analysis: | https://app.any.run/tasks/a70351b0-7546-4a02-a728-15f091224b4e |
Verdict: | Malicious activity |
Threats: | AsyncRAT is a RAT that can monitor and remotely control infected systems. This malware was introduced on Github as a legitimate open-source remote administration software, but hackers use it for its many powerful malicious functions. |
Analysis date: | April 01, 2023, 17:13:40 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Tags: | |
Indicators: | |
MIME: | application/zip |
File info: | Zip archive data, at least v2.0 to extract |
MD5: | EA8986395F4E341DBE4F4240615992CA |
SHA1: | E6163093D3C0C14DC2682A27CA4BCAC451EDBFF4 |
SHA256: | 65D78BD6EBA9E03C543AEBB7FD64BE32C7D99C30F4BBE9DE2569693E41E50E0E |
SSDEEP: | 24576:SKt8Bzi7pb2kQFNL2kIeGQnw0xlh84kLoEMgxaMHYAnRH:Rqi7pFalh8ZoFgxvYWRH |
.zip | | | ZIP compressed archive (100) |
---|
ZipFileName: | RoYo/RoYo.exe |
---|---|
ZipUncompressedSize: | 3266048 |
ZipCompressedSize: | 1222972 |
ZipCRC: | 0x01e157c3 |
ZipModifyDate: | 2023:04:01 13:56:06 |
ZipCompression: | Deflated |
ZipBitFlag: | - |
ZipRequiredVersion: | 20 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
2512 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\RoYo.zip" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
3864 | "C:\Users\admin\Desktop\RoYo\RoYo.exe" | C:\Users\admin\Desktop\RoYo\RoYo.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: Quasar Client Exit code: 1 Version: 1.4.1 Modules
Quasar(PID) Process(3864) RoYo.exe CertificateMIIE9DCCAtygAwIBAgIQAJ0hC0VNIJLvW03Nv0KWgTANBgkqhkiG9w0BAQ0FADAbMRkwFwYDVQQDDBBRdWFzYXIgU2VydmVyIENBMCAXDTIzMDMzMDE2NDkyNFoYDzk5OTkxMjMxMjM1OTU5WjAbMRkwFwYDVQQDDBBRdWFzYXIgU2VydmVyIENBMIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEAxRD+tQJsGG0NRD8tYPShMwFpG/KS0ofFA8nmFLLSbZfmGk6eQsNgt41GJqW0yGxNwFONytXa... SignatureSN5sWBwo/25lV0Ek+IZyl6lkcCVPkB0H07HAVGQQbY33e0TLR/p3Ah1SD8n1x7YjhQCxfiIGdBY0AFtKgMcGapjGSeOd4aBVOhMSvAyRn7eGeBGfyPHQtIlistC54CFUgivo2DGDCtpaO64GIgYZJWw5G5AsMBNrjm/p1zkWPoXIDY9LdJyUY+1Z61pBVrLvI0lg4PDMrxis2Q0m7ZuB1W3KxzGvs4MPKYriPdCY/b7fztfo5OHm3TJ2gMYY9bVfc6v3RBUxU9tjtwcDeKxaTXELzIqd4iGS5d6jWR4W1Zl4... LogDirLogs TagOffice04 StartupOneDrive Support Mutex115c3855-a135-47d8-b491-a87b371fbb91 Install_NameDefenderSetup.exe Sub_DirSubDir C2 (2)147.185.221.181:4782 Version1.4.1 | |||||||||||||||
2952 | "C:\Users\admin\Desktop\RoYo\RoYo.exe" | C:\Users\admin\Desktop\RoYo\RoYo.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: Quasar Client Exit code: 1 Version: 1.4.1 Modules
Quasar(PID) Process(2952) RoYo.exe CertificateMIIE9DCCAtygAwIBAgIQAJ0hC0VNIJLvW03Nv0KWgTANBgkqhkiG9w0BAQ0FADAbMRkwFwYDVQQDDBBRdWFzYXIgU2VydmVyIENBMCAXDTIzMDMzMDE2NDkyNFoYDzk5OTkxMjMxMjM1OTU5WjAbMRkwFwYDVQQDDBBRdWFzYXIgU2VydmVyIENBMIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEAxRD+tQJsGG0NRD8tYPShMwFpG/KS0ofFA8nmFLLSbZfmGk6eQsNgt41GJqW0yGxNwFONytXa... SignatureSN5sWBwo/25lV0Ek+IZyl6lkcCVPkB0H07HAVGQQbY33e0TLR/p3Ah1SD8n1x7YjhQCxfiIGdBY0AFtKgMcGapjGSeOd4aBVOhMSvAyRn7eGeBGfyPHQtIlistC54CFUgivo2DGDCtpaO64GIgYZJWw5G5AsMBNrjm/p1zkWPoXIDY9LdJyUY+1Z61pBVrLvI0lg4PDMrxis2Q0m7ZuB1W3KxzGvs4MPKYriPdCY/b7fztfo5OHm3TJ2gMYY9bVfc6v3RBUxU9tjtwcDeKxaTXELzIqd4iGS5d6jWR4W1Zl4... LogDirLogs TagOffice04 StartupOneDrive Support Mutex115c3855-a135-47d8-b491-a87b371fbb91 Install_NameDefenderSetup.exe Sub_DirSubDir C2 (2)147.185.221.181:4782 Version1.4.1 | |||||||||||||||
3224 | "C:\Windows\system32\taskmgr.exe" /4 | C:\Windows\System32\taskmgr.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Task Manager Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
|
(PID) Process: | (2512) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\16D\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (2512) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
(PID) Process: | (2512) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
(PID) Process: | (2512) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
(PID) Process: | (2512) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | name |
Value: 120 | |||
(PID) Process: | (2512) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | size |
Value: 80 | |||
(PID) Process: | (2512) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | type |
Value: 120 | |||
(PID) Process: | (2512) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | mtime |
Value: 100 | |||
(PID) Process: | (2512) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin |
Operation: | write | Name: | Placement |
Value: 2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000 | |||
(PID) Process: | (2512) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\General |
Operation: | write | Name: | LastFolder |
Value: C:\Users\admin\Desktop |
PID | Process | Filename | Type | |
---|---|---|---|---|
2512 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2512.21890\RoYo\RoYo.exe | executable | |
MD5:EBE14CBABCED6FA90136D35F9D035E21 | SHA256:AACE4310718783C6B92C3BDEAFA5E7531A479DC4AD0EC521A3CB0C1A03CA3E60 |