File name:

CyberGate RAT 3.4.2.2.zip

Full analysis: https://app.any.run/tasks/dc2aaddb-69ca-46be-81c2-2293dae2483e
Verdict: No threats detected
Analysis date: June 28, 2019, 14:28:28
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

0518E33FBAF974D4E23D6F1C5B5C4275

SHA1:

448219F40094981918C358D547664A1E7C5EFCC1

SHA256:

6DCD5AFBC8EEBB2B5A2036D5EF05F17004299ACE1B879145281F4AEEA4E8931B

SSDEEP:

393216:r+BwBFBOXI97zG/r2HcfEVmYJKG3manB+aNGdnKKEG:ruY797zGKHcfEVbYG2aB+aNGVZ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • CyberGate 3.4.2.2.exe (PID: 560)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2840)
      • CyberGate 3.4.2.2.exe (PID: 560)
  • INFO

    • Manual execution by user

      • CyberGate 3.4.2.2.exe (PID: 560)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2012:12:04 05:06:08
ZipCRC: 0xcda98a32
ZipCompressedSize: 10005208
ZipUncompressedSize: 16828416
ZipFileName: CyberGate 3.4.2.2.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
36
Monitored processes
2
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe cybergate 3.4.2.2.exe

Process information

PID
CMD
Path
Indicators
Parent process
560"C:\Users\admin\Desktop\CyberGate 3.4.2.2.exe" C:\Users\admin\Desktop\CyberGate 3.4.2.2.exe
explorer.exe
User:
admin
Company:
Cyber-Software
Integrity Level:
MEDIUM
Description:
CyberGate RAT
Exit code:
0
Version:
3.4.2.2
Modules
Images
c:\users\admin\desktop\cybergate 3.4.2.2.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2840"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\CyberGate RAT 3.4.2.2.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
438
Read events
419
Write events
19
Delete events
0

Modification events

(PID) Process:(2840) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2840) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2840) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2840) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\CyberGate RAT 3.4.2.2.zip
(PID) Process:(2840) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2840) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2840) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2840) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2840) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
(PID) Process:(2840) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\General
Operation:writeName:LastFolder
Value:
C:\Users\admin\AppData\Local\Temp
Executable files
2
Suspicious files
80
Text files
2
Unknown types
1

Dropped files

PID
Process
Filename
Type
2840WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2840.18405\Profiles\Crypt.initext
MD5:
SHA256:
2840WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2840.18405\Profiles\Test.initext
MD5:
SHA256:
2840WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2840.18405\sound.wavwav
MD5:972F7A4B412CBBBE25AB374247A5777D
SHA256:F6CB384A832AAE8FFED2890EE83043C06209BA6D4FA66FB11205D4D45D455524
2840WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2840.18405\Skins\Acryl.aszbinary
MD5:F47F02986A9623A09A6789CDFE987FF3
SHA256:4102534AB6CFCE1614A77BB1F57E1AADF1466C88501A24781BB55759E2FDA8CB
2840WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2840.18405\Skins\Aluminium.aszbinary
MD5:C999EC75AB880630F1FEF1E62D262E2E
SHA256:706692D2AD410F86404790E760D209F765977EC30AD725B669C1919BC174764C
2840WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2840.18405\GeoIP.datbinary
MD5:1B35820C4520D9B7991AEF1A97089045
SHA256:2426A5FE2995C2132C334C25B4EEB71DE25CD6ECA99520220F02C56383317B0B
2840WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2840.18405\Skins\Air.aszbinary
MD5:700D400A80AA55687AD6A92ACB2C9E13
SHA256:EA7041465D10A0F0830DD2A0A100C4BE060430E63FAA6EA70D8C4730C9C20E89
2840WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2840.18405\Skins\Beijing Ext.aszbinary
MD5:3AC9FACC1104B9644C9905531643CDDA
SHA256:EFFCBD1ACA0C1036B8C1E4F57EB4AAB75F56EBEC6AA0C6F689DB62777565D958
2840WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2840.18405\Skins\Beijing.aszbinary
MD5:0E04EBE2EF98F960B26342A3AAA6AA62
SHA256:B16BD39FB1C00A67D551C168CFB7AA8B020B88139AE5FA1284F6DBB15CC269F1
2840WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2840.18405\Skins\BlueGlass.aszbinary
MD5:3F3B40FD6BC88CF1DC8818B65E4F215F
SHA256:6E444D94D3F5BFBA4A72B8DCE54328EF5AB070775970D7336F6B84D85E63FCAD
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info