| File name: | Locale.Emulator.2.4.1.0.zip |
| Full analysis: | https://app.any.run/tasks/6be92b8b-16a8-4676-9054-4127e8f290f4 |
| Verdict: | Malicious activity |
| Analysis date: | January 29, 2020, 03:51:29 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | 3C856B89B8D72E873858D5AD1EC94116 |
| SHA1: | 325B613DDFE35F936EA561D448876EBC33CD0762 |
| SHA256: | 6C9251CD1B788C1C46BE5541FA1895AD88A37A886785038C4188CAC80ACEAAE4 |
| SSDEEP: | 6144:w5eWqbeAP5tWeQhJ2nJrx2+/xT5cdJDQCAhGY05JbWcVk:w5eWqbz5k3hJM2+T+PQmYibvk |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 788 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | None |
| ZipModifyDate: | 2019:08:16 17:20:08 |
| ZipCRC: | 0x00000000 |
| ZipCompressedSize: | - |
| ZipUncompressedSize: | - |
| ZipFileName: | Locale.Emulator.2.4.1.0/ |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 308 | "C:\Program Files\WinRAR\WinRAR.exe" -elevate2080 | C:\Program Files\WinRAR\WinRAR.exe | WinRAR.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: HIGH Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 576 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa3368.47673\Locale.Emulator.2.4.1.0\LEGUI.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa3368.47673\Locale.Emulator.2.4.1.0\LEGUI.exe | — | WinRAR.exe | |||||||||||
User: admin Company: Paddy Xu Integrity Level: MEDIUM Description: LEGUI Exit code: 0 Version: 0.0.0.0 Modules
| |||||||||||||||
| 852 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa3368.10454\Locale.Emulator.2.4.1.0\LEGUI.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa3368.10454\Locale.Emulator.2.4.1.0\LEGUI.exe | — | WinRAR.exe | |||||||||||
User: admin Company: Paddy Xu Integrity Level: MEDIUM Description: LEGUI Exit code: 0 Version: 0.0.0.0 Modules
| |||||||||||||||
| 1524 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa3368.2032\Locale.Emulator.2.4.1.0\LEProc.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa3368.2032\Locale.Emulator.2.4.1.0\LEProc.exe | — | WinRAR.exe | |||||||||||
User: admin Company: Paddy Xu Integrity Level: MEDIUM Description: LEProc Exit code: 0 Version: 0.0.0.0 Modules
| |||||||||||||||
| 2080 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Rar$DIa3368.11237\Alternative Dlls.zip" | C:\Program Files\WinRAR\WinRAR.exe | WinRAR.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 2796 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa3368.43363\Locale.Emulator.2.4.1.0\LEInstaller.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa3368.43363\Locale.Emulator.2.4.1.0\LEInstaller.exe | — | WinRAR.exe | |||||||||||
User: admin Company: Paddy Xu Integrity Level: MEDIUM Description: LEInstaller Exit code: 3221226540 Version: 0.0.0.0 Modules
| |||||||||||||||
| 3008 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa3368.2032\Locale.Emulator.2.4.1.0\LEUpdater.exe" schedule | C:\Users\admin\AppData\Local\Temp\Rar$EXa3368.2032\Locale.Emulator.2.4.1.0\LEUpdater.exe | LEProc.exe | ||||||||||||
User: admin Company: Paddy Xu Integrity Level: MEDIUM Description: LEUpdater Exit code: 0 Version: 0.0.0.0 Modules
| |||||||||||||||
| 3080 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa3368.43363\Locale.Emulator.2.4.1.0\LEInstaller.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa3368.43363\Locale.Emulator.2.4.1.0\LEInstaller.exe | WinRAR.exe | ||||||||||||
User: admin Company: Paddy Xu Integrity Level: HIGH Description: LEInstaller Exit code: 0 Version: 0.0.0.0 Modules
| |||||||||||||||
| 3356 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa3368.41498\Locale.Emulator.2.4.1.0\LEGUI.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa3368.41498\Locale.Emulator.2.4.1.0\LEGUI.exe | WinRAR.exe | ||||||||||||
User: admin Company: Paddy Xu Integrity Level: MEDIUM Description: LEGUI Exit code: 3762504530 Version: 0.0.0.0 Modules
| |||||||||||||||
| 3368 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Locale.Emulator.2.4.1.0.zip" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| (PID) Process: | (3368) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3368) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3368) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3368) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Locale.Emulator.2.4.1.0.zip | |||
| (PID) Process: | (3368) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3368) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3368) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3368) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (3368) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (3368) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3368 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3368.41498\Locale.Emulator.2.4.1.0\LEVersion.xml | xml | |
MD5:— | SHA256:— | |||
| 3368 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3368.41498\Locale.Emulator.2.4.1.0\LEUpdater.exe | executable | |
MD5:— | SHA256:— | |||
| 3368 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3368.41498\Locale.Emulator.2.4.1.0\LEProc.exe | executable | |
MD5:— | SHA256:— | |||
| 3368 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3368.41498\Locale.Emulator.2.4.1.0\LEInstaller.exe | executable | |
MD5:— | SHA256:— | |||
| 3368 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3368.41498\Locale.Emulator.2.4.1.0\Alternative Dlls.zip | compressed | |
MD5:— | SHA256:— | |||
| 3368 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3368.41498\Locale.Emulator.2.4.1.0\LEGUI.exe | executable | |
MD5:— | SHA256:— | |||
| 3368 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3368.41498\Locale.Emulator.2.4.1.0\Lang\DefaultLanguage.xml | xml | |
MD5:B730CBF194B9A04DF38749022EFAA0D6 | SHA256:A424A9AC3914966988789E420F85B12B1A313513BC6DC3E82D4C5D85002FC5F9 | |||
| 3368 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3368.41498\Locale.Emulator.2.4.1.0\Lang\ca.xaml | text | |
MD5:854F03BE38750DBB9DD7880A21E167A6 | SHA256:875C241BA4671F815CB8A6FC10AA56119CBA6F0511E29FD0A129797C8C9C168F | |||
| 3368 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3368.41498\Locale.Emulator.2.4.1.0\Lang\DefaultLanguage.xaml | text | |
MD5:C27AF0F032D1A4F9FF0DF7AB652711DE | SHA256:D677F5287289C9A6BA13F512D4F1BD21429671790654E8342A2B45F230A12A16 | |||
| 3368 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3368.41498\Locale.Emulator.2.4.1.0\Lang\fr.xml | xml | |
MD5:48E483BE9F67CF4DD7C9E6A4949C15F0 | SHA256:13636C04E56E748FF1C5B9FFAADABB24B77D4E153101E7E7C5DF3DFD0226298F | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3008 | LEUpdater.exe | GET | 200 | 185.199.111.153:80 | http://xupefei.github.io/Locale-Emulator/VersionInfo.xml | NL | xml | 218 b | malicious |
3716 | LEUpdater.exe | GET | 200 | 185.199.111.153:80 | http://xupefei.github.io/Locale-Emulator/VersionInfo.xml | NL | xml | 218 b | malicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3008 | LEUpdater.exe | 185.199.111.153:80 | xupefei.github.io | GitHub, Inc. | NL | shared |
3716 | LEUpdater.exe | 185.199.111.153:80 | xupefei.github.io | GitHub, Inc. | NL | shared |
Domain | IP | Reputation |
|---|---|---|
xupefei.github.io |
| malicious |