analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

Axenat.zip

Full analysis: https://app.any.run/tasks/f929769d-07c2-4dd9-8c19-9e1917b23cc0
Verdict: Malicious activity
Analysis date: September 30, 2020, 02:47:52
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract
MD5:

5B5779FE1178539ED9E13C161D82C13E

SHA1:

9C9DD3B32135979CB12135A0D17B33E9D3A229EA

SHA256:

6D9BB76551D212EA9A47019DB263926FDAE0191D98B4DB6111AD158B3452B2E6

SSDEEP:

98304:uxJoyeufLCs8Z4OtHuJ/Vy+Jk5GsKKl7Xgd2C5+QclgmC/v+k:uxJofuLCs8mmuJ/+GdKl7m2CVcC/mk

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Axenat.exe (PID: 756)
      • Axenat.exe (PID: 2244)
      • Axenat.exe (PID: 2244)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2080)
  • INFO

    • Manual execution by user

      • Axenat.exe (PID: 2244)
      • Axenat.exe (PID: 2244)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: Axenat/
ZipUncompressedSize: -
ZipCompressedSize: -
ZipCRC: 0x00000000
ZipModifyDate: 2020:06:09 00:49:01
ZipCompression: None
ZipBitFlag: -
ZipRequiredVersion: 10
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
45
Monitored processes
4
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start winrar.exe axenat.exe no specs axenat.exe axenat.exe

Process information

PID
CMD
Path
Indicators
Parent process
2080"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Axenat.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.60.0
756"C:\Users\admin\AppData\Local\Temp\Rar$EXa2080.43016\Axenat\Axenat.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2080.43016\Axenat\Axenat.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Description:
StealerBin
Exit code:
0
Version:
1.0.0.0
2244"C:\Users\admin\Desktop\Axenat.exe" C:\Users\admin\Desktop\Axenat.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
StealerBin
Exit code:
0
Version:
1.0.0.0
2244"C:\Users\admin\Desktop\Axenat.exe" C:\Users\admin\Desktop\Axenat.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
StealerBin
Exit code:
0
Version:
1.0.0.0
Total events
463
Read events
451
Write events
12
Delete events
0

Modification events

(PID) Process:(2080) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2080) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2080) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2080) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Axenat.zip
(PID) Process:(2080) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2080) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2080) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2080) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2080) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(2080) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
Executable files
5
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
2080WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2080.44114\Axenat\Axenat.exe
MD5:
SHA256:
2080WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2080.43016\Axenat\Axenat.exeexecutable
MD5:B24786ADC85768D38E69A04911841478
SHA256:26BDBAC453D590AAE6AB3485CD70A8D87BC7AE5B548406115EA9D19395B3E88E
2080WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2080.43016\Axenat\Osiris.dllexecutable
MD5:B7DC1C80D890E992ED20E7648E97BB73
SHA256:87A9F82BF4E96993B4F34DB48712E22EB68EBAD7E051EFE789305143EB75208F
2080WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2080.43016\Axenat\OTC.dllexecutable
MD5:6CD11F93B4F335E3760519079EADB978
SHA256:9552579A442DCB20689F8EF348688ABE3744D9DCAC466030D8FF320CC889AF00
2080WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2080.43016\Axenat\PageRank.dllexecutable
MD5:B2F23D79EFC6CB304AA31C16D6BC89B8
SHA256:A5F3010B36E56EF93B81FFAB83D4CD2BE12EABC5F8427A12E137D8A845570B82
2080WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2080.43016\Axenat\DevComponents.DotNetBar2.dllexecutable
MD5:D068CE38F5F9CAED1E63FFB1169EDE92
SHA256:08C17E74BE6CEEE14634C12BCEE4985490620C2C39986D2EFC367CC86F3339C7
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info