| File name: | BeingADIK-0.9.1-pc to 0.10.1.lite.txt |
| Full analysis: | https://app.any.run/tasks/2babec95-4ac0-41f3-8c7d-c9d6277f4843 |
| Verdict: | Malicious activity |
| Analysis date: | February 01, 2024, 22:26:04 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | text/plain |
| File info: | ASCII text, with no line terminators |
| MD5: | D343F4AA6E4F030A30523D1DEC19BC0F |
| SHA1: | 305CD4C1CC842E2033DB245587159815C809FB51 |
| SHA256: | 7D972C8A04D0B5B2D7515338F4A150C97D1F19EFF5AFCE61F9D00A88F58C49F7 |
| SSDEEP: | 3:Yowh/oieVghSz:YhwieVgIz |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1192 | "C:\Users\admin\Desktop\BeingADIK-0.9.1-pc to 0.10.1.lite\BeingADIK-32.exe" | C:\Users\admin\Desktop\BeingADIK-0.9.1-pc to 0.10.1.lite\BeingADIK-32.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 1 Modules
| |||||||||||||||
| 1288 | "C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Desktop\BeingADIK-0.9.1-pc to 0.10.1.lite.rar" "C:\Users\admin\Desktop\BeingADIK-0.9.1-pc to 0.10.1.lite\" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 1380 | "C:\Windows\system32\NOTEPAD.EXE" "C:\Users\admin\Desktop\BeingADIK-0.9.1-pc to 0.10.1.lite.txt" | C:\Windows\System32\notepad.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Notepad Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2136 | "C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\BeingADIK-0.9.1-pc to 0.10.1.lite\traceback.txt | C:\Windows\System32\notepad.exe | — | BeingADIK-32.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Notepad Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2952 | wmic process get Description | C:\Windows\System32\wbem\WMIC.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: WMI Commandline Utility Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3268 | C:\Windows\system32\cmd.exe /c "wmic process get Description" | C:\Windows\System32\cmd.exe | — | BeingADIK-32.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 3432 | C:\Windows\system32\cmd.exe /c "wmic process get Description" | C:\Windows\System32\cmd.exe | — | BeingADIK-32.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 3524 | "C:\Users\admin\Desktop\BeingADIK-0.9.1-pc to 0.10.1.lite\BeingADIK-32.exe" | C:\Users\admin\Desktop\BeingADIK-0.9.1-pc to 0.10.1.lite\BeingADIK-32.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 1 Modules
| |||||||||||||||
| 3592 | wmic process get Description | C:\Windows\System32\wbem\WMIC.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: WMI Commandline Utility Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3660 | "C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\BeingADIK-0.9.1-pc to 0.10.1.lite\traceback.txt | C:\Windows\System32\notepad.exe | — | BeingADIK-32.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Notepad Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (1380) notepad.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Notepad |
| Operation: | write | Name: | iWindowPosX |
Value: 76 | |||
| (PID) Process: | (1380) notepad.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Notepad |
| Operation: | write | Name: | iWindowPosY |
Value: 189 | |||
| (PID) Process: | (1380) notepad.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Notepad |
| Operation: | write | Name: | iWindowPosDX |
Value: 960 | |||
| (PID) Process: | (1380) notepad.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Notepad |
| Operation: | write | Name: | iWindowPosDY |
Value: 501 | |||
| (PID) Process: | (1288) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (1288) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (1288) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (1288) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1288 | WinRAR.exe | C:\Users\admin\Desktop\BeingADIK-0.9.1-pc to 0.10.1.lite\renpy\angle\gldraw.pyx | text | |
MD5:CCF8BB0719362E30AF88F8D9BE3537F0 | SHA256:FDDF8BFB7EE5A400BB3D840D9B4BBFD76978F881E17EAEB574B06E4C39D33C97 | |||
| 1288 | WinRAR.exe | C:\Users\admin\Desktop\BeingADIK-0.9.1-pc to 0.10.1.lite\renpy\angle\glblacklist.pyo | text | |
MD5:8D32C19F29458F431732DD9612DD7619 | SHA256:9AF145072D6B451CDCD2EB96261E09B0A3B1D80C2E0381A38D60C555E638A734 | |||
| 1288 | WinRAR.exe | C:\Users\admin\Desktop\BeingADIK-0.9.1-pc to 0.10.1.lite\renpy\angle\gldraw.pxd | text | |
MD5:1649AA0BF1E494B96C180C9F6A3CD661 | SHA256:7A08EC6EB5C69F103910068A77BAE6131942E4C450AD964492525833338DD949 | |||
| 1288 | WinRAR.exe | C:\Users\admin\Desktop\BeingADIK-0.9.1-pc to 0.10.1.lite\renpy\add_from.py | text | |
MD5:A77AD70548881449462CB60BD1614096 | SHA256:FF0E12234DAC7B6B932A7E57CAD2BC094481CBA9CB368560FF143E61B860B30D | |||
| 1288 | WinRAR.exe | C:\Users\admin\Desktop\BeingADIK-0.9.1-pc to 0.10.1.lite\renpy\angle\gl.pyx | text | |
MD5:98F42CB65CDB06C22FBC14FBBE7DE5EB | SHA256:B4E90256E45AE0BF2127D9FC58ED453E424FC6B7ECC5729C5112FA241E7FCE00 | |||
| 1288 | WinRAR.exe | C:\Users\admin\Desktop\BeingADIK-0.9.1-pc to 0.10.1.lite\renpy\angle\gl.pxd | text | |
MD5:87B56F61222E57C0341D8BCF38622CA5 | SHA256:E5A4C7699C6E8FB332E6D1088A9CFAC40A9468C91A61B929FE25D2406EE99DA1 | |||
| 1288 | WinRAR.exe | C:\Users\admin\Desktop\BeingADIK-0.9.1-pc to 0.10.1.lite\renpy\add_from.pyo | text | |
MD5:ABF463E0DF091164438EBC04E3BB5642 | SHA256:CDC96B9AF2E67B5C35FCEB11028D66C2B403A0B18D1302CA74E65614A6924335 | |||
| 1288 | WinRAR.exe | C:\Users\admin\Desktop\BeingADIK-0.9.1-pc to 0.10.1.lite\renpy\angle\glblacklist.py | text | |
MD5:5AF76F747DE98D645CECB06F155EA0E9 | SHA256:07579F48CB2A7266C7CD4762CE0CA906BE3802B71788952B5F93FA87BFAD94B4 | |||
| 1288 | WinRAR.exe | C:\Users\admin\Desktop\BeingADIK-0.9.1-pc to 0.10.1.lite\renpy\angle\gltexture.pyx | text | |
MD5:0C83182CF33BC9E74CE5B9D51CD102C4 | SHA256:C28B1DEF7D53C837FCD89C6B78107F818A8D4955464973BDAE081D1646CD5561 | |||
| 1288 | WinRAR.exe | C:\Users\admin\Desktop\BeingADIK-0.9.1-pc to 0.10.1.lite\renpy\angle\glrtt_fbo.pyx | text | |
MD5:C7AC2FEA1275448105653361D7A31ADE | SHA256:40C610D7B4E655E478E55B37DCBFC7A17B42AF7926BA4F030AC9496AD2C01968 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
Process | Message |
|---|---|
BeingADIK-32.exe | [S_API] SteamAPI_Init(): SteamAPI_IsSteamRunning() did not locate a running instance of Steam.
|
BeingADIK-32.exe | [S_API] SteamAPI_Init(): Sys_LoadModule failed to load: C:\Program Files\Steam\steamclient.dll
|
BeingADIK-32.exe | [S_API] SteamAPI_Init(): SteamAPI_IsSteamRunning() did not locate a running instance of Steam.
|
BeingADIK-32.exe | [S_API] SteamAPI_Init(): Sys_LoadModule failed to load: C:\Program Files\Steam\steamclient.dll
|