| File name: | main.zip |
| Full analysis: | https://app.any.run/tasks/c4c26e64-b8e4-4054-a659-935eae5f090e |
| Verdict: | Malicious activity |
| Analysis date: | November 20, 2024, 18:56:40 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v1.0 to extract, compression method=store |
| MD5: | B667356D0FD2F2B950FAD9D9E92E6ECF |
| SHA1: | 9B89DCD2D459F51BFDE58ED6279E2E5E86A90B0A |
| SHA256: | 7B80B47BF8544DC821175720ADC89ED99FFADBCD4252C132E688F67C3AD11E2A |
| SSDEEP: | 786432:sIXSOzEUq5tK705Bo9f/a19pFVelzQRwau+z:sIXSiuV5Boda9pFVehow2z |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 10 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | None |
| ZipModifyDate: | 2021:09:25 21:14:06 |
| ZipCRC: | 0x00000000 |
| ZipCompressedSize: | - |
| ZipUncompressedSize: | - |
| ZipFileName: | VMProtect-Ultimate--main/ |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1472 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa3608.47213\VMProtect-Ultimate--main\VMProtect Ultimate\VMProtect Ultimate x64\Confused.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa3608.47213\VMProtect-Ultimate--main\VMProtect Ultimate\VMProtect Ultimate x64\Confused.exe | — | WinRAR.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Panel Exit code: 3221226540 Version: 1.0.0.0 Modules
| |||||||||||||||
| 2164 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa3608.47213\VMProtect-Ultimate--main\VMProtect Ultimate\VMProtect Ultimate x64\Confused.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa3608.47213\VMProtect-Ultimate--main\VMProtect Ultimate\VMProtect Ultimate x64\Confused.exe | WinRAR.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Panel Version: 1.0.0.0 Modules
| |||||||||||||||
| 2940 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa3608.47492\VMProtect-Ultimate--main\VMProtect Ultimate\VMProtect Ultimate x64\VaporObfuscator.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa3608.47492\VMProtect-Ultimate--main\VMProtect Ultimate\VMProtect Ultimate x64\VaporObfuscator.exe | — | WinRAR.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: VaporObfuscator Version: 1.0.0.0 Modules
| |||||||||||||||
| 3608 | "C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\Desktop\main.zip | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Version: 5.91.0 Modules
| |||||||||||||||
| (PID) Process: | (3608) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\preferences.zip | |||
| (PID) Process: | (3608) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\chromium_ext.zip | |||
| (PID) Process: | (3608) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\omni_23_10_2024_.zip | |||
| (PID) Process: | (3608) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\main.zip | |||
| (PID) Process: | (3608) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3608) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3608) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3608) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3608 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3608.47213\VMProtect-Ultimate--main\VMProtect Ultimate\VMProtect Ultimate x64\Help\en\_23.cfs | binary | |
MD5:5A56255B3A4220EE8952D39825F3A9A4 | SHA256:10F696C428B625BF0993BE4E012DF770994C55F19DC9B9DA63AE35D23F374D3C | |||
| 3608 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3608.47213\VMProtect-Ultimate--main\VMProtect Ultimate\VMProtect Ultimate x64\Help\en\segments | binary | |
MD5:F957A9DD8D5EE888B5281F70B9A72DA8 | SHA256:F9A4DA0093540FB132061A925230DD25AB8C91D4606111CCA51AF7B587E38695 | |||
| 3608 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3608.47213\VMProtect-Ultimate--main\VMProtect Ultimate\VMProtect Ultimate x64\Help\en.qhc | sqlite | |
MD5:79827B0D245C28B6A38C042BFE33AE6F | SHA256:99883E36D9788B36D66EBFD1434A1C9E861D4679CDED61F3558AA415B11C198D | |||
| 3608 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3608.47213\VMProtect-Ultimate--main\VMProtect Ultimate\VMProtect Ultimate x64\Include\ASM\VMProtectSDK.inc | text | |
MD5:A8C48A4A96B59B8BB464223CC5A7C66F | SHA256:9D41F7BF8F220E721E34F54665DB9B63CACA9EA00FC650F81492736A196F731E | |||
| 3608 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3608.47213\VMProtect-Ultimate--main\VMProtect Ultimate\VMProtect Ultimate x64\Langs\fr.lng | text | |
MD5:187E7FA4A2F429F45F339FC6FCFD224D | SHA256:BCF8B033A2FFBE657683CB2B94CC871F1D0FCDB99680BC54A7AF9BFAE751B4D7 | |||
| 3608 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3608.47213\VMProtect-Ultimate--main\VMProtect Ultimate\VMProtect Ultimate x64\Help\ru.qhc | binary | |
MD5:0ACAAA400E412FB6A4F6C2735522E201 | SHA256:8CAFE2A9A915ED01E3C3384138D574807C580B656669A51F9656E218188596F9 | |||
| 3608 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3608.47213\VMProtect-Ultimate--main\VMProtect Ultimate\VMProtect Ultimate x64\Help\en\deletable | binary | |
MD5:F1D3FF8443297732862DF21DC4E57262 | SHA256:DF3F619804A92FDB4057192DC43DD748EA778ADC52BC498CE80524C014B81119 | |||
| 3608 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3608.47213\VMProtect-Ultimate--main\VMProtect Ultimate\VMProtect Ultimate x64\Help\ru\deletable | binary | |
MD5:F1D3FF8443297732862DF21DC4E57262 | SHA256:DF3F619804A92FDB4057192DC43DD748EA778ADC52BC498CE80524C014B81119 | |||
| 3608 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3608.47213\VMProtect-Ultimate--main\VMProtect Ultimate\VMProtect Ultimate x64\Confused.exe | executable | |
MD5:81C6A8CCD47647C4297AFE20FCF87EEC | SHA256:CBAA687115266698F94F10CC0F7807B5F7D5AE2B734C36306BCC7DD0163C7885 | |||
| 3608 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3608.47213\VMProtect-Ultimate--main\VMProtect Ultimate\VMProtect Ultimate x64\Help\ru\_23.cfs | binary | |
MD5:42B57DDE629AB220606F4D43D57FAEDC | SHA256:E28ECE67BCAC17E2562CFA12B885B4558D0BCCF9EBBF678FC2AB05898B2D445A | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 2.16.241.19:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 88.221.169.152:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
4712 | MoUsoCoreWorker.exe | GET | 200 | 88.221.169.152:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
4932 | svchost.exe | GET | 200 | 88.221.169.152:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 2.16.241.19:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
— | — | 88.221.169.152:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
4712 | MoUsoCoreWorker.exe | 88.221.169.152:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
4932 | svchost.exe | 88.221.169.152:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
— | — | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
self.events.data.microsoft.com |
| whitelisted |