analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

Zeus Crypter.rar

Full analysis: https://app.any.run/tasks/c44e021f-006d-486c-b928-59a44ac473d9
Verdict: Malicious activity
Threats:

njRAT is a remote access trojan. It is one of the most widely accessible RATs on the market that features an abundance of educational information. Interested attackers can even find tutorials on YouTube. This allows it to become one of the most popular RATs in the world.

Analysis date: June 16, 2019, 10:07:25
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
rat
njrat
bladabindi
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

A64E446C324E0E1C6214954AECE83569

SHA1:

96F049EA46D3366F962E7E18D35977AFBF5A4D10

SHA256:

6BE46E1CC6453F4166160616CDBB4DD3F10D9BB1454C6227FBD069BBCB0A0E07

SSDEEP:

12288:T6O9yWZaAitgFkz1pSqum/1KtUFwMNcXzkfvz6X6F4Hmvh8mptRsTYG8ne0QIOlJ:Z9yW0Ait0+1pSqum/suCgfrvh3pI8jQn

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Zeus Crypter.exe (PID: 2900)
      • Zeus Crypter.exe (PID: 1820)
      • Zeus Crypter.exe (PID: 3996)
      • Zeus Crypter.exe (PID: 392)
    • Changes the autorun value in the registry

      • Zeus Crypter.exe (PID: 392)
      • Zeus Crypter.exe (PID: 1820)
    • Known privilege escalation attack

      • Zeus Crypter.exe (PID: 3996)
      • Zeus Crypter.exe (PID: 2900)
    • NJRAT was detected

      • RegAsm.exe (PID: 2608)
  • SUSPICIOUS

    • Uses NETSH.EXE for network configuration

      • RegAsm.exe (PID: 2608)
    • Modifies the open verb of a shell class

      • Zeus Crypter.exe (PID: 3996)
      • Zeus Crypter.exe (PID: 2900)
    • Executable content was dropped or overwritten

      • Zeus Crypter.exe (PID: 392)
      • WinRAR.exe (PID: 3356)
  • INFO

    • Manual execution by user

      • Zeus Crypter.exe (PID: 3996)
      • Zeus Crypter.exe (PID: 2900)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
50
Monitored processes
12
Malicious processes
6
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe zeus crypter.exe no specs eventvwr.exe no specs eventvwr.exe zeus crypter.exe no specs zeus crypter.exe eventvwr.exe no specs eventvwr.exe zeus crypter.exe #NJRAT regasm.exe regasm.exe no specs netsh.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3356"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Zeus Crypter.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
2900"C:\Users\admin\Desktop\Zeus Crypter.exe" C:\Users\admin\Desktop\Zeus Crypter.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
3152"C:\Windows\System32\eventvwr.exe" C:\Windows\System32\eventvwr.exeZeus Crypter.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Event Viewer Snapin Launcher
Exit code:
3221226540
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
2600"C:\Windows\System32\eventvwr.exe" C:\Windows\System32\eventvwr.exe
Zeus Crypter.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Event Viewer Snapin Launcher
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
3996"C:\Users\admin\Desktop\Zeus Crypter.exe" C:\Users\admin\Desktop\Zeus Crypter.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
392"C:\Users\admin\Desktop\Zeus Crypter.exe" C:\Users\admin\Desktop\Zeus Crypter.exe
eventvwr.exe
User:
admin
Integrity Level:
HIGH
1024"C:\Windows\System32\eventvwr.exe" C:\Windows\System32\eventvwr.exeZeus Crypter.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Event Viewer Snapin Launcher
Exit code:
3221226540
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
3556"C:\Windows\System32\eventvwr.exe" C:\Windows\System32\eventvwr.exe
Zeus Crypter.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Event Viewer Snapin Launcher
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
1820"C:\Users\admin\Desktop\Zeus Crypter.exe" C:\Users\admin\Desktop\Zeus Crypter.exe
eventvwr.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
2608"C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe"C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe
Zeus Crypter.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft .NET Assembly Registration Utility
Version:
2.0.50727.5420 (Win7SP1.050727-5400)
Total events
773
Read events
670
Write events
0
Delete events
0

Modification events

No data
Executable files
2
Suspicious files
0
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
392Zeus Crypter.exeC:\Users\admin\ActiveSyncCsp\SystemPropertiesComputerName.exeexecutable
MD5:230C3D682E8EFF5F4F9560167E2E8772
SHA256:FF8657C2A26E17435B16713704D8A746D9CE9EA0F32CF71520EE6D9C24D3D6E0
3356WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3356.18961\Zeus Crypter\Zeus Crypter.exeexecutable
MD5:85B86E3C4BCEC2178B904715EA1E84A6
SHA256:12B118491B45519EA6D7459EBE8958B86708443362E858D8F863ED1FB72136C9
3356WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3356.18961\Zeus Crypter\Stub2xml
MD5:4D18AC38A92D15A64E2B80447B025B7E
SHA256:835A00D6E7C43DB49AE7B3FA12559F23C2920B7530F4D3F960FD285B42B1EFB5
3356WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3356.18961\Zeus Crypter\Stub1text
MD5:2041E64BFFCCFBC9379235FDF294F188
SHA256:DAA4362A762A472F717A480102883382B41DC5C17484F649272C5BDB5142917C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
1
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2608
RegAsm.exe
89.94.35.57:1604
Bouygues Telecom SA
FR
malicious

DNS requests

No data

Threats

No threats detected
No debug info