| File name: | Anubis Crypter FUD.zip |
| Full analysis: | https://app.any.run/tasks/63ec1165-0718-455b-b0bf-3729a52962ec |
| Verdict: | Malicious activity |
| Analysis date: | March 06, 2024, 01:40:03 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract, compression method=deflate |
| MD5: | A13C23D5EBA2838E675A10765874FD8E |
| SHA1: | 39C86102300420DC6594D8D6B28C9C10005763B2 |
| SHA256: | 8222DB6AD6FEA8631D3771C6756F371F79B6B6E5B7F8D99F2C7F26AB82C703BF |
| SSDEEP: | 98304:RwX72o/79+qgKxNx6NMFWW/cWReAy11zukxCTH70pq1h0ptDvU9GZI23CnFq8I1U:CCjRhZrfa |
| .kmz | | | Google Earth saved working session (60) |
|---|---|---|
| .zip | | | ZIP compressed archive (40) |
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2022:12:26 07:24:14 |
| ZipCRC: | 0xff829623 |
| ZipCompressedSize: | 3008560 |
| ZipUncompressedSize: | 6405120 |
| ZipFileName: | DataAnubis.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1876 | "C:\Users\admin\Desktop\svchost.exe" | C:\Users\admin\Desktop\svchost.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: Host Process for Windows Services Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 2472 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Anubis Crypter FUD.zip" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 3736 | "C:\Users\admin\Desktop\DataAnubis.exe" | C:\Users\admin\Desktop\DataAnubis.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Encrypt Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| (PID) Process: | (2472) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (2472) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (2472) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2472) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (2472) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (2472) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
| (PID) Process: | (2472) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Anubis Crypter FUD.zip | |||
| (PID) Process: | (2472) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2472) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2472) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2472 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Anubis Crypter FUD\Mono.Cecil.dll | executable | |
MD5:DE69BB29D6A9DFB615A90DF3580D63B1 | SHA256:F66F97866433E688ACC3E4CD1E6EF14505F81DF6B26DD6215E376767F6F954BC | |||
| 2472 | WinRAR.exe | C:\Users\admin\Desktop\DataAnubis.exe | executable | |
MD5:696493DC19825DC66D7167567CD5DDEC | SHA256:2ED6653B023B53AA4E3EED7303A765CB18D7C4C20FD99A76F674CC1463A8066D | |||
| 2472 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Anubis Crypter FUD\Stub.exe | executable | |
MD5:2B9ECB8EDE4DC4F5BB709DA1ED006736 | SHA256:5F514A6E41B8D7C773212C38760DF6C99A32FF09ECE46B345B90657650C73625 | |||
| 2472 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Anubis Crypter FUD\MetroFramework.Fonts.dll | executable | |
MD5:65EF4B23060128743CEF937A43B82AA3 | SHA256:C843869AACA5135C2D47296985F35C71CA8AF4431288D04D481C4E46CC93EE26 | |||
| 2472 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Anubis Crypter FUD\MetroFramework.Design.dll | executable | |
MD5:AB4C3529694FC8D2427434825F71B2B8 | SHA256:0A4A96082E25767E4697033649B16C76A652E120757A2CECAB8092AD0D716B65 | |||
| 2472 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Anubis Crypter FUD\svchost.exe | executable | |
MD5:F83C1904404D2B40622D28A5C05420F9 | SHA256:58FA8679EB278C0FBE4B9348E61CD274234037AF160878289A988260EAF6246E | |||
| 2472 | WinRAR.exe | C:\Users\admin\Desktop\MetroFramework.dll | executable | |
MD5:34EA7F7D66563F724318E322FF08F4DB | SHA256:C2C12D31B4844E29DE31594FC9632A372A553631DE0A0A04C8AF91668E37CF49 | |||
| 2472 | WinRAR.exe | C:\Users\admin\Desktop\MetroFramework.Design.dll | executable | |
MD5:AB4C3529694FC8D2427434825F71B2B8 | SHA256:0A4A96082E25767E4697033649B16C76A652E120757A2CECAB8092AD0D716B65 | |||
| 2472 | WinRAR.exe | C:\Users\admin\Desktop\MetroFramework.Fonts.dll | executable | |
MD5:65EF4B23060128743CEF937A43B82AA3 | SHA256:C843869AACA5135C2D47296985F35C71CA8AF4431288D04D481C4E46CC93EE26 | |||
| 2472 | WinRAR.exe | C:\Users\admin\Desktop\Mono.Cecil.dll | executable | |
MD5:DE69BB29D6A9DFB615A90DF3580D63B1 | SHA256:F66F97866433E688ACC3E4CD1E6EF14505F81DF6B26DD6215E376767F6F954BC | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |