| File name: | Fix Discord-YouTube (2).zip |
| Full analysis: | https://app.any.run/tasks/ce6db455-6681-4f10-9bbc-ae6d49f09cd2 |
| Verdict: | Malicious activity |
| Analysis date: | November 25, 2024, 14:30:42 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract, compression method=AES Encrypted |
| MD5: | 90F1DCE5AAE3DB1C4145189F2E868A29 |
| SHA1: | D0EF3DDD4B52DF51A66FFEC9EF7791EFA47A1E7C |
| SHA256: | 89CFBF32A9B7EDF78695385139AEE2EFDE7DAD859E27EEF91D5FADB513AC9E01 |
| SSDEEP: | 49152:eluPSnEsGtcv7vI7xpp7BJwSCB7vuTzJCtEb9OFjQETT7FHM4HRCtfuPwOyTTK0c:uH4cvYpKSCt2RDgFjQ2T5sgsfuPwOyTs |
| .xpi | | | Mozilla Firefox browser extension (66.6) |
|---|---|---|
| .zip | | | ZIP compressed archive (33.3) |
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | 0x0009 |
| ZipCompression: | Unknown (99) |
| ZipModifyDate: | 2024:11:23 12:11:40 |
| ZipCRC: | 0xc36fd4b7 |
| ZipCompressedSize: | 378 |
| ZipUncompressedSize: | 829 |
| ZipFileName: | general (????).bat |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 556 | findstr ":" | C:\Windows\System32\findstr.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Find String (QGREP) Utility Exit code: 1 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 644 | findstr /i "winws.exe" | C:\Windows\System32\findstr.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Find String (QGREP) Utility Exit code: 1 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 776 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Downloads\Fix Discord-YouTube (2).zip" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Version: 5.91.0 Modules
| |||||||||||||||
| 904 | C:\WINDOWS\system32\cmd.exe /S /D /c" echo echo: " | C:\Windows\System32\cmd.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1140 | sc start zapret | C:\Windows\System32\sc.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Service Control Manager Configuration Tool Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2380 | findstr /i "winws.exe" | C:\Windows\System32\findstr.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Find String (QGREP) Utility Exit code: 1 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3128 | findstr ":" | C:\Windows\System32\findstr.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Find String (QGREP) Utility Exit code: 1 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3140 | findstr /i "winws.exe" | C:\Windows\System32\findstr.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Find String (QGREP) Utility Exit code: 1 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3524 | findstr /i "winws.exe" | C:\Windows\System32\findstr.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Find String (QGREP) Utility Exit code: 1 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3532 | C:\WINDOWS\system32\cmd.exe /S /D /c" echo --filter-udp=443 --hostlist="list-general.txt" --dpi-desync=fake --dpi-desync-repeats=6 --dpi-desync-fake-quic="%BIN%quic_initial_www_google_com.bin" --new ^ " | C:\Windows\System32\cmd.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (776) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\preferences.zip | |||
| (PID) Process: | (776) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\chromium_ext.zip | |||
| (PID) Process: | (776) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\omni_23_10_2024_.zip | |||
| (PID) Process: | (776) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Downloads\Fix Discord-YouTube (2).zip | |||
| (PID) Process: | (776) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (776) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (776) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (776) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (776) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface |
| Operation: | write | Name: | ShowPassword |
Value: 0 | |||
| (PID) Process: | (5916) winws.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Cygwin\Installations |
| Operation: | write | Name: | aa5cf26e3c42967f |
Value: \??\C:\Users\admin\Desktop\New folder | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 776 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb776.38808\general (МГТС).bat | text | |
MD5:F3260BE14FB424C425BBB4A994713E24 | SHA256:61B70510D4346D6A10E72F4893DE6D6E96E54844A4BEE2C8BD44F12BEE21AF4B | |||
| 776 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb776.38808\bin\quic_initial_www_google_com.bin | binary | |
MD5:312526D39958D89B1F8AB67789AB985F | SHA256:F4589C57749F956BB30538197A521D7005F8B0A8723B4707E72405E51DDAC50A | |||
| 776 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb776.38808\bin\WinDivert64.sys | executable | |
MD5:89ED5BE7EA83C01D0DE33D3519944AA5 | SHA256:8DA085332782708D8767BCACE5327A6EC7283C17CFB85E40B03CD2323A90DDC2 | |||
| 776 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb776.38808\service_install.bat | text | |
MD5:8375817961B1E5868EF926347405CF1E | SHA256:ED15909B1D14DEFB11D2F9EE25C44F4E60C24717960029BAF53E5BFAEACFB846 | |||
| 776 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb776.38808\service_goodbye_discord.bat | text | |
MD5:8B043F2A0EC87328DC40542B9739988F | SHA256:263102816588BD719FC628A75C8B73185110050564EA21A62B360F3AE545022B | |||
| 776 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb776.38808\list-general.txt | text | |
MD5:BF417BCAF5D7040C1B80B1B57EC07772 | SHA256:DB86FFB24AFDC1FBA9F54C85E52528FEF8517CF05E205F233CD629551D4DF4A6 | |||
| 776 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb776.38808\general.bat | text | |
MD5:9081A3207E99F2A290BD87678516A6FD | SHA256:73482D0D495D556034F8603E146FCAF7E8AAC7FC27ACD51B930BB49330F99A04 | |||
| 776 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb776.38808\ipset-discord.txt | text | |
MD5:347FEBFD859BF77A142C5AA396354B2E | SHA256:6D651044669F1285FCF3F9C9F2DB499AFBF3B201DB9677FAF9BB91186EDFE229 | |||
| 776 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb776.38808\general (МГТС2).bat | text | |
MD5:4FF8F02DD4F251B181BAFD802019E694 | SHA256:B5E3247A64637C8ECF4A9D9B644560CD4216A1A227D56CE75C705F714D06D013 | |||
| 776 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb776.38808\list-discord.txt | text | |
MD5:53C6FE42FF860FDFA8CFAFA9ACFA92FC | SHA256:F015C31EB1C5C13D235AA107B9E618F45AB3AFDEF623C5749BF18494937312A4 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
3040 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
2356 | RUXIMICS.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4712 | MoUsoCoreWorker.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
3040 | svchost.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
3976 | svchost.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |