analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

Steam_Account_Generator_Fixed.zip

Full analysis: https://app.any.run/tasks/6d24c306-9c8d-4bf1-8271-60c3513b83a6
Verdict: Malicious activity
Analysis date: February 11, 2019, 07:37:40
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

61A1B417D0B4923EB932F2A009E2892E

SHA1:

97F439A43D3337114B10BE86A11C457A8B7C9E16

SHA256:

6B97C691A9C50A6C4281750BD1DF4F279690E6D7B0EF9BC5CDAF1C1B116C9349

SSDEEP:

98304:Pet4LW17uwhzUCZmMiV7M+3+q4HRH7uTkgUTKTcyqLidKMcvXI9L5gdWzew:PeGLY9AObigq4xbuTvQKs3BvwL5yWl

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Steam Account Generator Final Fixed.exe (PID: 1044)
    • Loads dropped or rewritten executable

      • Steam Account Generator Final Fixed.exe (PID: 1044)
      • SearchProtocolHost.exe (PID: 920)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Steam Account Generator Final Fixed.exe (PID: 1044)
    • Reads Environment values

      • Steam Account Generator Final Fixed.exe (PID: 1044)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: Steam Account Generator Final Fixed.exe
ZipUncompressedSize: 7627264
ZipCompressedSize: 6260740
ZipCRC: 0x4ac40f99
ZipModifyDate: 2019:02:08 20:49:06
ZipCompression: Deflated
ZipBitFlag: -
ZipRequiredVersion: 20
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
33
Monitored processes
3
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs searchprotocolhost.exe no specs steam account generator final fixed.exe

Process information

PID
CMD
Path
Indicators
Parent process
3172"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Steam_Account_Generator_Fixed.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.60.0
920"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe6_ Global\UsGthrCtrlFltPipeMssGthrPipe6 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
1044"C:\Users\admin\Desktop\Steam Account Generator Final Fixed.exe" C:\Users\admin\Desktop\Steam Account Generator Final Fixed.exe
explorer.exe
User:
admin
Company:
http://steam.bot.nu/
Integrity Level:
MEDIUM
Description:
SteamAccountGenerator
Version:
12.1.0.0
Total events
482
Read events
449
Write events
33
Delete events
0

Modification events

(PID) Process:(3172) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3172) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3172) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3172) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Steam_Account_Generator_Fixed.zip
(PID) Process:(3172) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3172) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3172) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3172) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(920) SearchProtocolHost.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\5F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(920) SearchProtocolHost.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\5F\52C64B7E
Operation:writeName:@C:\Windows\system32\notepad.exe,-469
Value:
Text Document
Executable files
1
Suspicious files
0
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
3172WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3172.19246\Steam Account Generator Final Fixed.exe
MD5:
SHA256:
3172WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3172.19246\CaptchaHelper.dll
MD5:
SHA256:
3172WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3172.19246\LICENSE
MD5:
SHA256:
3172WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3172.19246\Note on captcha Service.txt
MD5:
SHA256:
1044Steam Account Generator Final Fixed.exeC:\Users\admin\Desktop\accounts.txttext
MD5:86B800CE12B01A91A2B33296FF96B8F4
SHA256:1570A8BBCBF29ADCE11032CEA17F054EEBF17631228E3572391B57E138F62AAC
1044Steam Account Generator Final Fixed.exeC:\Users\admin\AppData\Local\Temp\56b0d42d-677a-44c5-b3c0-40d80104e4a7\CaptchaHelper.dllexecutable
MD5:DB956A02DABA647F229B01D56EA5D892
SHA256:5B4F5E6CC52DF647673B94249E5392E6F00CC5FFB7E1FC7C4219351762618CDD
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
7
DNS requests
7
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1044
Steam Account Generator Final Fixed.exe
150.101.201.180:443
makemeapassword.ligos.net
Internode Pty Ltd
AU
unknown
1044
Steam Account Generator Final Fixed.exe
23.45.96.174:443
store.steampowered.com
Akamai International B.V.
NL
whitelisted
1044
Steam Account Generator Final Fixed.exe
167.99.137.12:443
quirky-snyder-56bf7d.netlify.com
US
malicious
1044
Steam Account Generator Final Fixed.exe
130.211.93.80:443
newdedsecmail.now.sh
Google Inc.
US
whitelisted

DNS requests

Domain
IP
Reputation
makemeapassword.ligos.net
  • 150.101.201.180
unknown
quirky-snyder-56bf7d.netlify.com
  • 167.99.137.12
malicious
store.steampowered.com
  • 23.45.96.174
whitelisted
newdedsecmail.now.sh
  • 130.211.93.80
malicious

Threats

No threats detected
No debug info