File name:

FakeActivation.zip

Full analysis: https://app.any.run/tasks/14cfb607-48b6-4d9b-98e8-9f1ec5ae4bec
Verdict: Malicious activity
Analysis date: November 30, 2020, 02:43:37
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

6DB8A7DA4E8DC527D445B7A37D02D5D6

SHA1:

4FCC7CFF8B49A834858D8C6016C3C6F109C9C794

SHA256:

7CC43D4259F9DBE6806E1C067EBD1784EAAF56A026047D9380BE944B71E5B984

SSDEEP:

6144:slA1Q2B6SIHODfBeO6706bWyFyA3tvZqfgP6mJJtkvnBM1KgHWR:iCQ2B3IHO1e3WeGoHJJtkvnBOi

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Endermanch@FreeYoutubeDownloader.exe (PID: 1132)
      • Free YouTube Downloader.exe (PID: 2700)
      • Free YouTube Downloader.exe (PID: 3240)
      • Endermanch@FreeYoutubeDownloader.exe (PID: 3416)
      • Free YouTube Downloader.exe (PID: 2932)
    • Changes the autorun value in the registry

      • Endermanch@FreeYoutubeDownloader.exe (PID: 1132)
    • Drops executable file immediately after starts

      • Endermanch@FreeYoutubeDownloader.exe (PID: 1132)
  • SUSPICIOUS

    • Drops a file with too old compile date

      • WinRAR.exe (PID: 2672)
      • Endermanch@FreeYoutubeDownloader.exe (PID: 1132)
    • Creates files in the Windows directory

      • Endermanch@FreeYoutubeDownloader.exe (PID: 1132)
    • Creates a software uninstall entry

      • Endermanch@FreeYoutubeDownloader.exe (PID: 1132)
    • Executable content was dropped or overwritten

      • Endermanch@FreeYoutubeDownloader.exe (PID: 1132)
      • WinRAR.exe (PID: 2672)
    • Drops a file that was compiled in debug mode

      • Endermanch@FreeYoutubeDownloader.exe (PID: 1132)
  • INFO

    • Manual execution by user

      • Free YouTube Downloader.exe (PID: 2932)
      • Free YouTube Downloader.exe (PID: 3240)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0001
ZipCompression: Deflated
ZipModifyDate: 2016:01:22 20:15:24
ZipCRC: 0x00b8d682
ZipCompressedSize: 281609
ZipUncompressedSize: 405748
ZipFileName: Endermanch@FreeYoutubeDownloader.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
44
Monitored processes
6
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start drop and start start drop and start winrar.exe endermanch@freeyoutubedownloader.exe no specs endermanch@freeyoutubedownloader.exe free youtube downloader.exe no specs free youtube downloader.exe no specs free youtube downloader.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1132"C:\Users\admin\AppData\Local\Temp\Rar$EXb2672.7492\Endermanch@FreeYoutubeDownloader.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb2672.7492\Endermanch@FreeYoutubeDownloader.exe
WinRAR.exe
User:
admin
Company:
Free Youtube Downloader
Integrity Level:
HIGH
Description:
Free Youtube Downloader 4.1.1.1 Installation
Exit code:
0
Version:
4.1.1.1
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb2672.7492\endermanch@freeyoutubedownloader.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2672"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\FakeActivation.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2700"C:\Windows\Free Youtube Downloader\Free Youtube Downloader\Free YouTube Downloader.exe" C:\Windows\Free Youtube Downloader\Free Youtube Downloader\Free YouTube Downloader.exeEndermanch@FreeYoutubeDownloader.exe
User:
admin
Integrity Level:
HIGH
Description:
Free YouTube Downloader
Exit code:
0
Version:
4.1.1.1
Modules
Images
c:\windows\free youtube downloader\free youtube downloader\free youtube downloader.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2932"C:\Windows\Free Youtube Downloader\Free Youtube Downloader\Free YouTube Downloader.exe" C:\Windows\Free Youtube Downloader\Free Youtube Downloader\Free YouTube Downloader.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Free YouTube Downloader
Exit code:
0
Version:
4.1.1.1
Modules
Images
c:\windows\free youtube downloader\free youtube downloader\free youtube downloader.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3240"C:\Windows\Free Youtube Downloader\Free Youtube Downloader\Free YouTube Downloader.exe" C:\Windows\Free Youtube Downloader\Free Youtube Downloader\Free YouTube Downloader.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Free YouTube Downloader
Exit code:
0
Version:
4.1.1.1
Modules
Images
c:\windows\free youtube downloader\free youtube downloader\free youtube downloader.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3416"C:\Users\admin\AppData\Local\Temp\Rar$EXb2672.7492\Endermanch@FreeYoutubeDownloader.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb2672.7492\Endermanch@FreeYoutubeDownloader.exeWinRAR.exe
User:
admin
Company:
Free Youtube Downloader
Integrity Level:
MEDIUM
Description:
Free Youtube Downloader 4.1.1.1 Installation
Exit code:
3221226540
Version:
4.1.1.1
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb2672.7492\endermanch@freeyoutubedownloader.exe
c:\systemroot\system32\ntdll.dll
Total events
643
Read events
608
Write events
35
Delete events
0

Modification events

(PID) Process:(2672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2672) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\FakeActivation.zip
(PID) Process:(2672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
(PID) Process:(2672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
Executable files
5
Suspicious files
1
Text files
1
Unknown types
1

Dropped files

PID
Process
Filename
Type
1132Endermanch@FreeYoutubeDownloader.exeC:\Users\admin\AppData\Local\Temp\$inst\temp_0.tmp
MD5:
SHA256:
1132Endermanch@FreeYoutubeDownloader.exeC:\Users\admin\Desktop\Free Youtube Downloader.lnklnk
MD5:
SHA256:
1132Endermanch@FreeYoutubeDownloader.exeC:\Users\admin\AppData\Local\Temp\$inst\2.tmpcompressed
MD5:8708699D2C73BED30A0A08D80F96D6D7
SHA256:A32E0A83001D2C5D41649063217923DAC167809CAB50EC5784078E41C9EC0F0F
1132Endermanch@FreeYoutubeDownloader.exeC:\Windows\Free Youtube Downloader\Free Youtube Downloader\Uninstall.exeexecutable
MD5:139DF873521412F2AEBC4B45DA0BC3E9
SHA256:EFE6BD2E0FC7030994FC2837B389DA22C52A7B0BBDBD41852FCAF4308A23DA10
1132Endermanch@FreeYoutubeDownloader.exeC:\Windows\Free Youtube Downloader\Free Youtube Downloader\Box.exeexecutable
MD5:1BB4DD43A8AEBC8F3B53ACD05E31D5B5
SHA256:A2380A5F503BC6F5FCFD4C72E5B807DF0740A60A298E8686BF6454F92E5D3C02
2672WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2672.7492\Endermanch@FreeYoutubeDownloader.exeexecutable
MD5:13F4B868603CF0DD6C32702D1BD858C9
SHA256:CAE57A60C4D269CD1CA43EF143AEDB8BFC4C09A7E4A689544883D05CE89406E7
1132Endermanch@FreeYoutubeDownloader.exeC:\Windows\Free Youtube Downloader\Free Youtube Downloader\Free YouTube Downloader.exeexecutable
MD5:F33A4E991A11BAF336A2324F700D874D
SHA256:A87524035509FF7AA277788E1A9485618665B7DA35044D70C41EC0F118F3DFD7
1132Endermanch@FreeYoutubeDownloader.exeC:\Windows\Free Youtube Downloader\Free Youtube Downloader\Uninstall.initext
MD5:2059CA65DCEB7B8D4952017D04D846EF
SHA256:A549548626AD771B4A3C336B2BAF9E57775795BF76420058A0B9FFC425FD4623
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info