| File name: | LuxNET RAT Cracked.zip |
| Full analysis: | https://app.any.run/tasks/dd79b824-3e0e-43de-9976-679cf069b394 |
| Verdict: | Malicious activity |
| Threats: | Trojans are a group of malicious programs distinguished by their ability to masquerade as benign software. Depending on their type, trojans possess a variety of capabilities, ranging from maintaining full remote control over the victim’s machine to stealing data and files, as well as dropping other malware. At the same time, the main functionality of each trojan family can differ significantly depending on its type. The most common trojan infection chain starts with a phishing email. |
| Analysis date: | March 31, 2022, 10:04:26 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v1.0 to extract |
| MD5: | 3B360BDD209B336819B828F1B5F3302B |
| SHA1: | 93DBF754A0264164AC48853F9570FF4161F819FF |
| SHA256: | 6F787CB460DA3589F4C21D303DE5432A2A5091904EF9D029B79FAAE7A5A6F013 |
| SSDEEP: | 98304:zR0PvOj3uQrJbTHr2rrJe3erv+OBhwFvbSROT:z4O3uCJb3ygeqOByOW |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipFileName: | LuxNET RAT Cracked/ |
|---|---|
| ZipUncompressedSize: | - |
| ZipCompressedSize: | - |
| ZipCRC: | 0x00000000 |
| ZipModifyDate: | 2020:12:21 12:27:27 |
| ZipCompression: | None |
| ZipBitFlag: | - |
| ZipRequiredVersion: | 10 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1764 | "C:\Users\admin\Desktop\LuxNET RAT Cracked\Stub.exe" | C:\Users\admin\Desktop\LuxNET RAT Cracked\Stub.exe | — | Explorer.EXE | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: ILMerge Exit code: 0 Version: 2.12.803.0 Modules
| |||||||||||||||
| 2108 | "C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe" /noconfig @"C:\Users\admin\AppData\Local\Temp\yjapfbly.cmdline" | C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe | LuxNET Cracked By[ıllıllıMя.Hackeяsıllıllı] .exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Visual Basic Command Line Compiler Exit code: 0 Version: 8.0.50727.5483 Modules
| |||||||||||||||
| 2140 | "C:\Users\admin\Desktop\LuxNET RAT Cracked\LuxNET Cracked By[ıllıllıMя.Hackeяsıllıllı] .exe" | C:\Users\admin\Desktop\LuxNET RAT Cracked\LuxNET Cracked By[ıllıllıMя.Hackeяsıllıllı] .exe | Explorer.EXE | ||||||||||||
User: admin Company: XilluX Integrity Level: MEDIUM Description: LuxNET Exit code: 0 Version: 1.1.0.4 Modules
| |||||||||||||||
| 2416 | C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\admin\AppData\Local\Temp\RES48D.tmp" "C:\Users\admin\AppData\Local\Temp\vbc48C.tmp" | C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.exe | — | vbc.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft® Resource File To COFF Object Conversion Utility Exit code: 0 Version: 8.00.50727.5003 (Win7SP1GDR.050727-5400) Modules
| |||||||||||||||
| 2652 | "C:\Users\admin\Desktop\LuxNET RAT Cracked\j.exe" | C:\Users\admin\Desktop\LuxNET RAT Cracked\j.exe | — | Explorer.EXE | |||||||||||
User: admin Integrity Level: MEDIUM Description: Exit code: 0 Version: 0.0.0.0 Modules
| |||||||||||||||
| 2832 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\LuxNET RAT Cracked.zip" | C:\Program Files\WinRAR\WinRAR.exe | Explorer.EXE | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 3616 | "C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe3_ Global\UsGthrCtrlFltPipeMssGthrPipe3 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" | C:\Windows\system32\SearchProtocolHost.exe | — | SearchIndexer.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft Windows Search Protocol Host Exit code: 0 Version: 7.00.7601.24542 (win7sp1_ldr_escrow.191209-2211) Modules
| |||||||||||||||
| 3812 | "C:\Users\admin\Desktop\LuxNET RAT Cracked\Stub.exe" | C:\Users\admin\Desktop\LuxNET RAT Cracked\Stub.exe | Explorer.EXE | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: ILMerge Exit code: 0 Version: 2.12.803.0 Modules
| |||||||||||||||
| (PID) Process: | (2832) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (2832) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (2832) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2832) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (2832) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (2832) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\LuxNET RAT Cracked.zip | |||
| (PID) Process: | (2832) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2832) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2832) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2832) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2832 | WinRAR.exe | C:\Users\admin\Desktop\LuxNET RAT Cracked\AForge.dll | executable | |
MD5:D47353F1879F76E52D45B8C308A63ECC | SHA256:1B0E8CF7E435A552E45EC60ECAFBCBC53DFAD0180E9972484267D4BF67648337 | |||
| 2832 | WinRAR.exe | C:\Users\admin\Desktop\LuxNET RAT Cracked\AForge.Video.dll | executable | |
MD5:3F2E8E0FA359AADD41190C07D23920DD | SHA256:942DBF85423F37093FD1C51E4DC31A423627568E6555E7AE29EE22B03AD32DD9 | |||
| 2832 | WinRAR.exe | C:\Users\admin\Desktop\LuxNET RAT Cracked\Icons\aac.ico | image | |
MD5:B9E947AD8B963E3C6D0CF42A4337FFD8 | SHA256:B682C75548BF7D9AB9269C71B125180EC6AE8300F40B1053BFFEAFEEB829410E | |||
| 2832 | WinRAR.exe | C:\Users\admin\Desktop\LuxNET RAT Cracked\Icons\bmp.ico | image | |
MD5:98DBD8CA36A25D03B7FA010F24299589 | SHA256:FF24343F77B884279B2936ECC908AC7A07B0D4C55AAE689DE3EA5CCF19FA858D | |||
| 2832 | WinRAR.exe | C:\Users\admin\Desktop\LuxNET RAT Cracked\Dissembler Lib.dll | executable | |
MD5:4127D00B294F09835929297A6CC8FA79 | SHA256:263634C93E459CE3497D54903675619C3D4B5BADBB83E26E4015CCD9035C798E | |||
| 2832 | WinRAR.exe | C:\Users\admin\Desktop\LuxNET RAT Cracked\Icons\ini.ico | image | |
MD5:C61E936360BB0DDDBD170E84124ABF1B | SHA256:1F26066839008157AB55ADC34BBA75F7228A86D1B9B632ED71DC48DE1ED84CD7 | |||
| 2832 | WinRAR.exe | C:\Users\admin\Desktop\LuxNET RAT Cracked\AForge.Controls.dll | executable | |
MD5:7C219D50F9E29DBB2FCA2704729405D5 | SHA256:906635A17234A19795404B5AD70C763118D15722F52DC30D95D18464FF4F4A48 | |||
| 2832 | WinRAR.exe | C:\Users\admin\Desktop\LuxNET RAT Cracked\AForge.Video.DirectShow.dll | executable | |
MD5:31421DBF0F52A75142839742D718858D | SHA256:1A51E214FFA7718284614D81333B2FD2F1100FE67042B24AB078F817C26950D5 | |||
| 2832 | WinRAR.exe | C:\Users\admin\Desktop\LuxNET RAT Cracked\Icons\html.ico | image | |
MD5:8899A9C25F10D5D175BAC0E88016AC82 | SHA256:B6080B7A69D7BA032124BC29A749E75F18D22910B122D49AA9742A4994FC426F | |||
| 2832 | WinRAR.exe | C:\Users\admin\Desktop\LuxNET RAT Cracked\Icons\bat.ico | image | |
MD5:66F9A1D849CA4E7BF4C7E7A9FBC84410 | SHA256:644E913915939711CB190A3FDD7C911CDDDD0A0CB5FABFB07EC135DB868D1C98 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2140 | LuxNET Cracked By[ıllıllıMя.Hackeяsıllıllı] .exe | GET | 301 | 104.23.99.190:80 | http://pastebin.com/raw.php?i=Y7A9LibH | US | — | — | malicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 104.23.99.190:80 | pastebin.com | Cloudflare Inc | US | malicious |
2140 | LuxNET Cracked By[ıllıllıMя.Hackeяsıllıllı] .exe | 104.23.99.190:443 | pastebin.com | Cloudflare Inc | US | malicious |
Domain | IP | Reputation |
|---|---|---|
pastebin.com |
| malicious |