File name:

CyberGate RAT 3.4.2.2.zip

Full analysis: https://app.any.run/tasks/dc2aaddb-69ca-46be-81c2-2293dae2483e
Verdict: No threats detected
Analysis date: June 28, 2019, 14:28:28
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

0518E33FBAF974D4E23D6F1C5B5C4275

SHA1:

448219F40094981918C358D547664A1E7C5EFCC1

SHA256:

6DCD5AFBC8EEBB2B5A2036D5EF05F17004299ACE1B879145281F4AEEA4E8931B

SSDEEP:

393216:r+BwBFBOXI97zG/r2HcfEVmYJKG3manB+aNGdnKKEG:ruY797zGKHcfEVbYG2aB+aNGVZ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • CyberGate 3.4.2.2.exe (PID: 560)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2840)
      • CyberGate 3.4.2.2.exe (PID: 560)
  • INFO

    • Manual execution by user

      • CyberGate 3.4.2.2.exe (PID: 560)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2012:12:04 05:06:08
ZipCRC: 0xcda98a32
ZipCompressedSize: 10005208
ZipUncompressedSize: 16828416
ZipFileName: CyberGate 3.4.2.2.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
36
Monitored processes
2
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe cybergate 3.4.2.2.exe

Process information

PID
CMD
Path
Indicators
Parent process
560"C:\Users\admin\Desktop\CyberGate 3.4.2.2.exe" C:\Users\admin\Desktop\CyberGate 3.4.2.2.exe
explorer.exe
User:
admin
Company:
Cyber-Software
Integrity Level:
MEDIUM
Description:
CyberGate RAT
Exit code:
0
Version:
3.4.2.2
Modules
Images
c:\users\admin\desktop\cybergate 3.4.2.2.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2840"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\CyberGate RAT 3.4.2.2.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
438
Read events
419
Write events
19
Delete events
0

Modification events

(PID) Process:(2840) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2840) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2840) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2840) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\CyberGate RAT 3.4.2.2.zip
(PID) Process:(2840) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2840) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2840) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2840) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2840) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
(PID) Process:(2840) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\General
Operation:writeName:LastFolder
Value:
C:\Users\admin\AppData\Local\Temp
Executable files
2
Suspicious files
80
Text files
2
Unknown types
1

Dropped files

PID
Process
Filename
Type
2840WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2840.18405\Profiles\Test.initext
MD5:
SHA256:
2840WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2840.18405\Profiles\Crypt.initext
MD5:
SHA256:
2840WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2840.18405\Skins\Acryl.aszbinary
MD5:F47F02986A9623A09A6789CDFE987FF3
SHA256:4102534AB6CFCE1614A77BB1F57E1AADF1466C88501A24781BB55759E2FDA8CB
2840WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2840.18405\Skins\Air.aszbinary
MD5:700D400A80AA55687AD6A92ACB2C9E13
SHA256:EA7041465D10A0F0830DD2A0A100C4BE060430E63FAA6EA70D8C4730C9C20E89
2840WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2840.18405\CyberGate 3.4.2.2.exeexecutable
MD5:C105D7B50E24D4C571DD8CB4B6E8BBA5
SHA256:1713DC00A8573685838379CE680F6EE1FFBB4A3231CCC0AD4CF45FD9F3B3F837
2840WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2840.18405\GeoIP.datbinary
MD5:1B35820C4520D9B7991AEF1A97089045
SHA256:2426A5FE2995C2132C334C25B4EEB71DE25CD6ECA99520220F02C56383317B0B
2840WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2840.18405\Skins\Beijing Ext.aszbinary
MD5:3AC9FACC1104B9644C9905531643CDDA
SHA256:EFFCBD1ACA0C1036B8C1E4F57EB4AAB75F56EBEC6AA0C6F689DB62777565D958
2840WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2840.18405\Skins\Aluminium.aszbinary
MD5:C999EC75AB880630F1FEF1E62D262E2E
SHA256:706692D2AD410F86404790E760D209F765977EC30AD725B669C1919BC174764C
2840WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2840.18405\Skins\BlueGauze.aszbinary
MD5:D968DF3DDA19C45AC8D3123C2AFB1426
SHA256:9B785E15AF9B99692619A682AE86FAE8994AA92D5DD5FE67D74B0B7B1D185AE0
2840WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2840.18405\Skins\Afterburner.aszbinary
MD5:45AAF10F08368336B8DB52C5BDD67204
SHA256:E66A63EC2B527F8931FC042F9BA02CB955D085A5887EE65DF1BED3C8847BD559
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info