File name: | Windows 10 Activator - www.GameTrex.com.rar |
Full analysis: | https://app.any.run/tasks/680a115b-a200-43c0-b32f-662b6e39685d |
Verdict: | Malicious activity |
Analysis date: | May 01, 2024, 17:51:04 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/x-rar |
File info: | RAR archive data, v4, os: Win32 |
MD5: | B4404EAF4C958E513618141AA3797F05 |
SHA1: | 7C14138D92080467233D62D0B20611E215EDA1E1 |
SHA256: | 699979E19175257D4B867990013317C6B059EFA6A30FC2F88DB6C0572E8569B5 |
SSDEEP: | 49152:iXgYP5CvMfuGoPJY/wb3BajfXMRHrMtEs6bSHG6iVNtNY2tJm8mD+CvKVHi1HE7V:iQYP5CvGu9U7DXMBYt6SmhntdLm8U+AI |
.rar | | | RAR compressed archive (v-4.x) (58.3) |
---|---|---|
.rar | | | RAR compressed archive (gen) (41.6) |
CompressedSize: | 202 |
---|---|
UncompressedSize: | 111 |
OperatingSystem: | Win32 |
ModifyDate: | 2018:10:12 01:42:42 |
PackingMethod: | Best Compression |
ArchivedFileName: | Windows 10 Activator - www.GameTrex.com\GameTrex.com.url |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
304 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --disable-quic --mojo-platform-channel-handle=1340 --field-trial-handle=1164,i,12913168740267606399,13491368707034108055,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | chrome.exe | ||||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Version: 109.0.5414.120 Modules
| |||||||||||||||
316 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --disable-quic --mojo-platform-channel-handle=1616 --field-trial-handle=1164,i,12913168740267606399,13491368707034108055,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Version: 109.0.5414.120 Modules
| |||||||||||||||
324 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --disable-quic --mojo-platform-channel-handle=3612 --field-trial-handle=1164,i,12913168740267606399,13491368707034108055,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
324 | cscript.exe C:\Windows\System32\slmgr.vbs //NoLogo /skms 127.0.0.2:1688 | C:\Windows\System32\cscript.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft ® Console Based Script Host Exit code: 0 Version: 5.8.7600.16385 Modules
| |||||||||||||||
580 | "C:\Windows\System32\cmd.exe" /c cscript.exe C:\Windows\System32\slmgr.vbs //NoLogo /ato | C:\Windows\System32\cmd.exe | — | AAct.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 3221536791 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
588 | "C:\Windows\System32\cmd.exe" /c cscript.exe C:\Windows\System32\slmgr.vbs //NoLogo /ckms-domain | C:\Windows\System32\cmd.exe | — | AAct.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 1 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
600 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --disable-quic --mojo-platform-channel-handle=3696 --field-trial-handle=1164,i,12913168740267606399,13491368707034108055,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Version: 109.0.5414.120 Modules
| |||||||||||||||
748 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win32 --annotation=prod=Chrome --annotation=ver=109.0.5414.120 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xd4,0x6da48b38,0x6da48b48,0x6da48b54 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Version: 109.0.5414.120 Modules
| |||||||||||||||
820 | "C:\Program Files\Google\Chrome\Application\chrome.exe" "--disable-features=OptimizationGuideModelDownloading,OptimizationHintsFetching,OptimizationTargetPrediction,OptimizationHints" | C:\Program Files\Google\Chrome\Application\chrome.exe | explorer.exe | ||||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Version: 109.0.5414.120 Modules
| |||||||||||||||
860 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --use-gl=angle --use-angle=swiftshader-webgl --mojo-platform-channel-handle=1536 --field-trial-handle=1164,i,12913168740267606399,13491368707034108055,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:2 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Version: 109.0.5414.120 Modules
|
(PID) Process: | (3976) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtBMP |
Value: | |||
(PID) Process: | (3976) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtIcon |
Value: | |||
(PID) Process: | (3976) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (3976) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
(PID) Process: | (3976) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
(PID) Process: | (3976) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
(PID) Process: | (3976) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Windows 10 Activator - www.GameTrex.com.rar | |||
(PID) Process: | (3976) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | name |
Value: 120 | |||
(PID) Process: | (3976) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | size |
Value: 80 | |||
(PID) Process: | (3976) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | type |
Value: 120 |
PID | Process | Filename | Type | |
---|---|---|---|---|
3976 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb3976.19213\Windows 10 Activator - www.GameTrex.com\Software Files\GameTrex.com.url | binary | |
MD5:2B45277389BBF596E6067108F3B82E53 | SHA256:2A6C08CD3A9E6AA64D491A5A78A444F4E2D1D4F71D79170415C80286C55D3E02 | |||
3976 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb3976.20517\Windows 10 Activator - www.GameTrex.com\Software Files\AAct_x64.exe | binary | |
MD5:46C3F7912C2BC8954A5DABD1B85E8663 | SHA256:282AF933F06B38C40A1CDA8B989AC72111E770C91F1CA93AD85923BAA5DCA8AA | |||
3976 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb3976.19213\Windows 10 Activator - www.GameTrex.com\Software Files\Keys.txt | binary | |
MD5:18E4F0294929A01BA93A51B04E6E70EA | SHA256:C123437982DEA3F4A158AFF5D542ACC4AA571C20D1AD6C2E844DDC10192E2A4A | |||
820 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old~RF1168d9.TMP | — | |
MD5:— | SHA256:— | |||
820 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old | — | |
MD5:— | SHA256:— | |||
3976 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb3976.19213\Windows 10 Activator - www.GameTrex.com\Software Files\Read Me.txt | binary | |
MD5:CAB61590B4C510D2A816D1DC26082F09 | SHA256:C6E1F921F960FB6749E48C6C0914D3528DD299ED966FF9EBE066525290413357 | |||
3976 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb3976.19213\Windows 10 Activator - www.GameTrex.com\Software Files\AAct.exe | binary | |
MD5:BDF8C70B7B6A4BD595FE3E9A0B32C5D5 | SHA256:2C15E0A1F4F1BECDB5CE3BCDBDCC225D78D32C038DD8B43256E45C2CD4DFF185 | |||
3976 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb3976.20517\Windows 10 Activator - www.GameTrex.com\Software Files\Keys.txt | binary | |
MD5:2B05AF7B799B207CF91587B4CA8459E6 | SHA256:6A357553C26E1203732A80FA8253505CE0875889BC326117BCEE69A98BFEA5C3 | |||
3976 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb3976.22549\Windows 10 Activator - www.GameTrex.com\Software Files\GameTrex.com.url | binary | |
MD5:2D30D65AE16347EFAA3A79A2BCD85DC3 | SHA256:DCBE45CEF841DBF6F68B4375B56B3D8041F831D488CD5035C9C035ED0E337112 | |||
3976 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb3976.20517\Windows 10 Activator - www.GameTrex.com\Software Files\GameTrex.com.url | binary | |
MD5:11CDF0F085925615F20001D9CE5D6F4D | SHA256:12405D4EEB897A401703B0287CD580E88848274CBFF4CF8542A725D24919BE23 |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
884 | svchost.exe | HEAD | 200 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/ad3rm3ciqs3fjr4bc4x5vwuildeq_9.49.1/gcmjkmgdlgnkkcocmoeiminaijmmjnii_9.49.1_all_ixzyrcu7pvmgu5pjv6enfqq6wa.crx3 | unknown | — | — | — |
884 | svchost.exe | GET | 206 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/ad3rm3ciqs3fjr4bc4x5vwuildeq_9.49.1/gcmjkmgdlgnkkcocmoeiminaijmmjnii_9.49.1_all_ixzyrcu7pvmgu5pjv6enfqq6wa.crx3 | unknown | — | — | — |
884 | svchost.exe | GET | 206 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/ad3rm3ciqs3fjr4bc4x5vwuildeq_9.49.1/gcmjkmgdlgnkkcocmoeiminaijmmjnii_9.49.1_all_ixzyrcu7pvmgu5pjv6enfqq6wa.crx3 | unknown | — | — | — |
3240 | WmiPrvSE.exe | POST | 302 | 88.221.126.57:80 | http://go.microsoft.com/fwlink/?LinkID=88341 | unknown | — | — | — |
3240 | WmiPrvSE.exe | POST | 302 | 88.221.126.57:80 | http://go.microsoft.com/fwlink/?LinkID=88340 | unknown | — | — | — |
3240 | WmiPrvSE.exe | POST | 302 | 88.221.126.57:80 | http://go.microsoft.com/fwlink/?LinkID=88339 | unknown | — | — | — |
884 | svchost.exe | GET | 206 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/ad3rm3ciqs3fjr4bc4x5vwuildeq_9.49.1/gcmjkmgdlgnkkcocmoeiminaijmmjnii_9.49.1_all_ixzyrcu7pvmgu5pjv6enfqq6wa.crx3 | unknown | — | — | — |
884 | svchost.exe | GET | 206 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/ad3rm3ciqs3fjr4bc4x5vwuildeq_9.49.1/gcmjkmgdlgnkkcocmoeiminaijmmjnii_9.49.1_all_ixzyrcu7pvmgu5pjv6enfqq6wa.crx3 | unknown | — | — | — |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
— | — | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | unknown |
1088 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
304 | chrome.exe | 64.233.184.84:443 | accounts.google.com | GOOGLE | US | unknown |
820 | chrome.exe | 239.255.255.250:1900 | — | — | — | unknown |
304 | chrome.exe | 142.250.186.99:443 | clientservices.googleapis.com | GOOGLE | US | unknown |
304 | chrome.exe | 216.58.206.68:443 | www.google.com | GOOGLE | US | unknown |
304 | chrome.exe | 142.250.185.131:443 | www.gstatic.com | GOOGLE | US | unknown |
304 | chrome.exe | 142.250.184.238:443 | apis.google.com | GOOGLE | US | unknown |
Domain | IP | Reputation |
---|---|---|
clientservices.googleapis.com |
| unknown |
accounts.google.com |
| unknown |
www.google.com |
| unknown |
www.gstatic.com |
| unknown |
apis.google.com |
| unknown |
encrypted-tbn0.gstatic.com |
| unknown |
lh5.googleusercontent.com |
| unknown |
update.googleapis.com |
| unknown |
gametrex.com |
| unknown |
fonts.googleapis.com |
| unknown |
PID | Process | Class | Message |
---|---|---|---|
— | — | Not Suspicious Traffic | INFO [ANY.RUN] Cloudflare Network Error Logging (NEL) |