analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

Skyjack.zip

Full analysis: https://app.any.run/tasks/5e25fd79-02ea-49f2-81a2-b3f8adef5b6a
Verdict: Malicious activity
Analysis date: September 11, 2019, 01:17:46
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

E289FDFC2568497A18C3972624B54A77

SHA1:

FBAB326D258D803ABA6708358DE812488925F941

SHA256:

827AEDFE4401255C30B6573D6990D07A3BBFE2DAAE5E8D8D09C155186D91647C

SSDEEP:

384:B2CjMNPv21TwZ6gtMCUlAU5lhHOxJS+w9OHM+tLqfaD06FfSOXu6fy:BFM21TO6MaljvHOxMrGpB5tFfSO+ey

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • SkyjackManualSystem.exe (PID: 3760)
      • b2e.exe (PID: 2936)
      • b2e.exe (PID: 2664)
      • SkyjackManualSystem.exe (PID: 3268)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3464)
      • SkyjackManualSystem.exe (PID: 3760)
      • SkyjackManualSystem.exe (PID: 3268)
    • Starts CMD.EXE for commands execution

      • b2e.exe (PID: 2936)
      • b2e.exe (PID: 2664)
  • INFO

    • Manual execution by user

      • SkyjackManualSystem.exe (PID: 3760)
      • SkyjackManualSystem.exe (PID: 3268)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: SkyjackManualSystem.exe
ZipUncompressedSize: 37888
ZipCompressedSize: 14851
ZipCRC: 0x5ca96194
ZipModifyDate: 2019:09:10 18:57:07
ZipCompression: Deflated
ZipBitFlag: -
ZipRequiredVersion: 20
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
51
Monitored processes
9
Malicious processes
1
Suspicious processes
3

Behavior graph

Click at the process to see the details
start drop and start drop and start winrar.exe skyjackmanualsystem.exe b2e.exe no specs cmd.exe no specs cmd.exe no specs skyjackmanualsystem.exe b2e.exe no specs cmd.exe no specs cmd.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3464"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\Skyjack.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
3760"C:\Users\admin\Desktop\Skyjack\SkyjackManualSystem.exe" C:\Users\admin\Desktop\Skyjack\SkyjackManualSystem.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
8851
2936"C:\Users\admin\AppData\Local\Temp\DF1A.tmp\b2e.exe" C:\Users\admin\AppData\Local\Temp\DF1A.tmp\b2e.exe C:\Users\admin\Desktop\Skyjack "C:\Users\admin\Desktop\Skyjack\SkyjackManualSystem.exe" C:\Users\admin\AppData\Local\Temp\DF1A.tmp\b2e.exeSkyjackManualSystem.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
3480cmd /c ""C:\Users\admin\AppData\Local\Temp\DFF5.tmp\batfile.bat" "C:\Windows\system32\cmd.exeb2e.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
1456cmd /c ""C:\Users\admin\AppData\Local\Temp\selfdel0.bat" "C:\Windows\system32\cmd.exeb2e.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
3268"C:\Users\admin\Desktop\Skyjack\SkyjackManualSystem.exe" C:\Users\admin\Desktop\Skyjack\SkyjackManualSystem.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
8851
2664"C:\Users\admin\AppData\Local\Temp\12DC.tmp\b2e.exe" C:\Users\admin\AppData\Local\Temp\12DC.tmp\b2e.exe C:\Users\admin\Desktop\Skyjack "C:\Users\admin\Desktop\Skyjack\SkyjackManualSystem.exe" C:\Users\admin\AppData\Local\Temp\12DC.tmp\b2e.exeSkyjackManualSystem.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
3684cmd /c ""C:\Users\admin\AppData\Local\Temp\1414.tmp\batfile.bat" "C:\Windows\system32\cmd.exeb2e.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
2224cmd /c ""C:\Users\admin\AppData\Local\Temp\selfdel0.bat" "C:\Windows\system32\cmd.exeb2e.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Total events
1 325
Read events
1 280
Write events
45
Delete events
0

Modification events

(PID) Process:(3464) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3464) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3464) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3464) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\Skyjack.zip
(PID) Process:(3464) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3464) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3464) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3464) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3464) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath
Operation:writeName:0
Value:
C:\Users\admin\Desktop\Skyjack
(PID) Process:(3464) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
Executable files
4
Suspicious files
0
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
2936b2e.exeC:\Users\admin\AppData\Local\Temp\selfdel0.bat
MD5:
SHA256:
2664b2e.exeC:\Users\admin\AppData\Local\Temp\selfdel0.bat
MD5:
SHA256:
3464WinRAR.exeC:\Users\admin\Desktop\Skyjack\SkyjackManualSystem.exeexecutable
MD5:189C0458DBCD521E327FCB92D808541F
SHA256:19186F2926FEA8310A181102C27898F54712B13DE471DE0D4C780A7E34788565
3760SkyjackManualSystem.exeC:\Users\admin\AppData\Local\Temp\DF1A.tmp\b2e.exeexecutable
MD5:9E695749B855B6161976D8076399B309
SHA256:31E2A8F9155FC9A6BDB3EB31632D54601C6F3F41FC158418458F486CBDD9AB9E
2664b2e.exeC:\Users\admin\AppData\Local\Temp\1414.tmp\batfile.battext
MD5:752C4F4852843AA528E5576D9A3A7449
SHA256:6F84BFBFA5CB42CC1333D13414493C303F1E816ADC9888E553B46CD0EED9895D
3268SkyjackManualSystem.exeC:\Users\admin\AppData\Local\Temp\12DC.tmp\b2e.exeexecutable
MD5:9E695749B855B6161976D8076399B309
SHA256:31E2A8F9155FC9A6BDB3EB31632D54601C6F3F41FC158418458F486CBDD9AB9E
2936b2e.exeC:\Users\admin\AppData\Local\Temp\DFF5.tmp\batfile.battext
MD5:752C4F4852843AA528E5576D9A3A7449
SHA256:6F84BFBFA5CB42CC1333D13414493C303F1E816ADC9888E553B46CD0EED9895D
3464WinRAR.exeC:\Users\admin\Desktop\Skyjack\UpdateUSB\AutoUpdateUSB.exeexecutable
MD5:CD291E38D98726AF11A6F3B2B613BFBB
SHA256:1C751FE5F72BDF063059EB26EA1F2BC243F61CDE8C040E74CFFA38BA8AF0610D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info