| File name: | DeepNude v2.0.0 Premium.zip |
| Full analysis: | https://app.any.run/tasks/02c94ca9-a5d4-4a82-b1e6-02ee42d34057 |
| Verdict: | Malicious activity |
| Threats: | Ficker Stealer is a malware that steals passwords, files, credit card details, and other types of sensitive information on Windows systems. It is most often distributed via phishing emails and can perform keylogging, process injection, and browser tracking. |
| Analysis date: | May 24, 2021, 16:13:33 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | 63B528E292A5F5554EF52EB5840D4A3C |
| SHA1: | 51DE67EBDD5CED7E2F4E16EEA2F2C0AA8BEEA8E4 |
| SHA256: | 7FFB707D2F7268420A59018CA637273ACC407FD6044C853F8BFAB2C531524DED |
| SSDEEP: | 49152:qr04wibsMZAIQLhANKdbWOX73xh2jUJxg1YfXrMvBe8kpwNU0vZubA3Oa:qsibsMKIQLhMUbL3xYj8xgaXrtBpIU2F |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipFileName: | Setup.exe |
|---|---|
| ZipUncompressedSize: | 725473280 |
| ZipCompressedSize: | 2811820 |
| ZipCRC: | 0xa30989f9 |
| ZipModifyDate: | 2021:05:20 23:56:04 |
| ZipCompression: | Deflated |
| ZipBitFlag: | - |
| ZipRequiredVersion: | 20 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 116 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa184.16620\Setup.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa184.16620\Setup.exe | — | WinRAR.exe | |||||||||||
User: admin Company: Blacksun Software Integrity Level: MEDIUM Description: ColorMania Exit code: 3221226540 Version: 12.1.0.0 Modules
| |||||||||||||||
| 124 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa184.16620\Setup.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa184.16620\Setup.exe | Setup.exe | ||||||||||||
User: admin Company: Blacksun Software Integrity Level: HIGH Description: ColorMania Exit code: 0 Version: 12.1.0.0 Modules
| |||||||||||||||
| 184 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\DeepNude v2.0.0 Premium.zip" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 2992 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa184.16620\Setup.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa184.16620\Setup.exe | WinRAR.exe | ||||||||||||
User: admin Company: Blacksun Software Integrity Level: HIGH Description: ColorMania Exit code: 0 Version: 12.1.0.0 Modules
| |||||||||||||||
| (PID) Process: | (184) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (184) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (184) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (184) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\DeepNude v2.0.0 Premium.zip | |||
| (PID) Process: | (184) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (184) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (184) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (184) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (184) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (184) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 184 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa184.16620\Setup.exe | — | |
MD5:— | SHA256:— | |||
| 124 | Setup.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\SMFD5SQY.txt | text | |
MD5:— | SHA256:— | |||
| 124 | Setup.exe | C:\ProgramData\krosqm.txt | text | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
124 | Setup.exe | GET | 200 | 54.235.175.90:80 | http://api.ipify.org/?format=xml | US | text | 13 b | shared |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
124 | Setup.exe | 45.93.201.181:80 | — | — | — | malicious |
124 | Setup.exe | 54.235.175.90:80 | api.ipify.org | Amazon.com, Inc. | US | malicious |
Domain | IP | Reputation |
|---|---|---|
api.ipify.org |
| shared |
PID | Process | Class | Message |
|---|---|---|---|
124 | Setup.exe | Potential Corporate Privacy Violation | ET POLICY External IP Lookup (ipify .org) |
124 | Setup.exe | A Network Trojan was detected | ET TROJAN Win32/Ficker Stealer Activity M3 |
124 | Setup.exe | A Network Trojan was detected | ET TROJAN Win32/Ficker Stealer Activity M3 |