File name:

CyberSeal Crypter Cracked.zip

Full analysis: https://app.any.run/tasks/532b0f92-d593-4d88-8df6-1e2aa3bd1414
Verdict: Malicious activity
Analysis date: February 05, 2021, 16:56:20
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

8697313747A2E3078F9730A51DE7D66E

SHA1:

A6FAD2BFF7B3B9DF1204493355E250B168606414

SHA256:

91156F3FA901819A4E82F0CD4F6D87313C2D60DFCE2DAB6A7A9608473880BB87

SSDEEP:

98304:f34oBzl4Ltu4qdZwJ91kjNPCpvhp6dSl1RxX6PShBcOxfROz:f34ix4A4qdZu9I9CpvhpKSl37kOxfA

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • CyberSeal Crypter Cracked.exe (PID: 1184)
      • CyberSeal Cracked by ImFred.exe (PID: 3688)
      • cetrjnxwdvg.exe (PID: 4000)
      • CyberSeal Cracked by ImFred.exe (PID: 2440)
      • SmartAssembly.com (PID: 3808)
    • Drops executable file immediately after starts

      • CyberSeal Crypter Cracked.exe (PID: 1184)
      • vbc.exe (PID: 2136)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • CyberSeal Crypter Cracked.exe (PID: 1184)
      • CyberSeal Cracked by ImFred.exe (PID: 2440)
      • vbc.exe (PID: 2136)
      • SmartAssembly.com (PID: 3808)
    • Drops a file with a compile date too recent

      • CyberSeal Cracked by ImFred.exe (PID: 2440)
      • vbc.exe (PID: 2136)
      • SmartAssembly.com (PID: 3808)
    • Creates files in the user directory

      • CyberSeal Crypter Cracked.exe (PID: 1184)
      • SmartAssembly.com (PID: 3808)
    • Creates files in the Windows directory

      • CyberSeal Cracked by ImFred.exe (PID: 2440)
    • Drops a file that was compiled in debug mode

      • CyberSeal Cracked by ImFred.exe (PID: 2440)
    • Executes scripts

      • CyberSeal Cracked by ImFred.exe (PID: 2440)
    • Starts CMD.EXE for commands execution

      • CyberSeal Cracked by ImFred.exe (PID: 2440)
    • Starts application with an unusual extension

      • cmd.exe (PID: 668)
  • INFO

    • Manual execution by user

      • CyberSeal Crypter Cracked.exe (PID: 1184)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2019:12:19 18:33:25
ZipCRC: 0x1fa7d8e0
ZipCompressedSize: 3927470
ZipUncompressedSize: 4694016
ZipFileName: CyberSeal Crypter Cracked.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
49
Monitored processes
9
Malicious processes
4
Suspicious processes
1

Behavior graph

Click at the process to see the details
start drop and start drop and start drop and start winrar.exe no specs cyberseal crypter cracked.exe cetrjnxwdvg.exe no specs cyberseal cracked by imfred.exe no specs cyberseal cracked by imfred.exe vbc.exe cvtres.exe no specs cmd.exe no specs smartassembly.com

Process information

PID
CMD
Path
Indicators
Parent process
668cmd /c ""C:\Users\admin\AppData\Local\Temp\Files\Obfuscate.bat" "C:\Windows\system32\cmd.exeCyberSeal Cracked by ImFred.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
968"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\CyberSeal Crypter Cracked.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
1184"C:\Users\admin\Desktop\CyberSeal Crypter Cracked.exe" C:\Users\admin\Desktop\CyberSeal Crypter Cracked.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\cyberseal crypter cracked.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\version.dll
2136"C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe" /noconfig @"C:\Users\admin\AppData\Local\Temp\cugcue9d.cmdline"C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe
CyberSeal Cracked by ImFred.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Visual Basic Command Line Compiler
Exit code:
0
Version:
8.0.50727.5420
Modules
Images
c:\windows\microsoft.net\framework\v2.0.50727\vbc.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2440"C:\Users\admin\AppData\Roaming\Z46842481\CyberSeal Cracked by ImFred.exe" C:\Users\admin\AppData\Roaming\Z46842481\CyberSeal Cracked by ImFred.exe
CyberSeal Crypter Cracked.exe
User:
admin
Company:
CyberSeal
Integrity Level:
HIGH
Description:
CyberSeal
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\roaming\z46842481\cyberseal cracked by imfred.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3088C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\admin\AppData\Local\Temp\RES253.tmp" "C:\Users\admin\AppData\Local\Temp\vbc252.tmp"C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.exevbc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft® Resource File To COFF Object Conversion Utility
Exit code:
0
Version:
8.00.50727.4940 (Win7SP1.050727-5400)
Modules
Images
c:\windows\system32\wininet.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
c:\windows\system32\oleaut32.dll
c:\users\admin\appdata\roaming\z46842481\cyberseal cracked by imfred.exe
c:\windows\system32\version.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\rsaenh.dll
3688"C:\Users\admin\AppData\Roaming\Z46842481\CyberSeal Cracked by ImFred.exe" C:\Users\admin\AppData\Roaming\Z46842481\CyberSeal Cracked by ImFred.exeCyberSeal Crypter Cracked.exe
User:
admin
Company:
CyberSeal
Integrity Level:
MEDIUM
Description:
CyberSeal
Exit code:
3221226540
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\roaming\z46842481\cyberseal cracked by imfred.exe
c:\systemroot\system32\ntdll.dll
3808"C:\Users\admin\AppData\Local\Temp\Files\smartassembly.com" "C:\Users\admin\AppData\Local\Temp\Files\cyber2.saproj" /input="C:\Users\admin\AppData\Local\Temp\Files\force.exe" /output="C:\Users\admin\AppData\Roaming\Z46842481\cetrjnxwdvg.exe"C:\Users\admin\AppData\Local\Temp\Files\SmartAssembly.com
cmd.exe
User:
admin
Company:
Red Gate Software Ltd.
Integrity Level:
HIGH
Description:
Exit code:
0
Version:
6.0.0.513
Modules
Images
c:\users\admin\appdata\local\temp\files\smartassembly.com
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
4000"C:\Users\admin\AppData\Roaming\Z46842481\cetrjnxwdvg.exe" C:\Users\admin\AppData\Roaming\Z46842481\cetrjnxwdvg.exeCyberSeal Crypter Cracked.exe
User:
admin
Company:
cwvdwei0vfc
Integrity Level:
MEDIUM
Description:
m2joxdcouwy
Exit code:
0
Version:
5.0.3.5
Modules
Images
c:\users\admin\appdata\roaming\z46842481\cetrjnxwdvg.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
1 546
Read events
1 425
Write events
115
Delete events
6

Modification events

(PID) Process:(968) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(968) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(968) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(968) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\CyberSeal Crypter Cracked.zip
(PID) Process:(968) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(968) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(968) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(968) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1184) CyberSeal Crypter Cracked.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(1184) CyberSeal Crypter Cracked.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
Executable files
10
Suspicious files
21
Text files
10
Unknown types
72

Dropped files

PID
Process
Filename
Type
968WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa968.3490\CyberSeal Crypter Cracked.exe
MD5:
SHA256:
1184CyberSeal Crypter Cracked.exeC:\Users\admin\AppData\Local\Temp\aut8A63.tmp
MD5:
SHA256:
1184CyberSeal Crypter Cracked.exeC:\Users\admin\AppData\Local\Temp\aut8B5E.tmp
MD5:
SHA256:
2440CyberSeal Cracked by ImFred.exeC:\Users\admin\AppData\Local\Temp\cugcue9d.0.vb
MD5:
SHA256:
2440CyberSeal Cracked by ImFred.exeC:\Users\admin\AppData\Local\Temp\cugcue9d.cmdline
MD5:
SHA256:
2136vbc.exeC:\Users\admin\AppData\Local\Temp\vbc252.tmp
MD5:
SHA256:
3088cvtres.exeC:\Users\admin\AppData\Local\Temp\RES253.tmp
MD5:
SHA256:
2136vbc.exeC:\Users\admin\AppData\Local\Temp\cugcue9d.out
MD5:
SHA256:
2440CyberSeal Cracked by ImFred.exeC:\Users\admin\AppData\Local\Temp\Files\RCX2CF.tmp
MD5:
SHA256:
2440CyberSeal Cracked by ImFred.exeC:\Users\admin\AppData\Local\Temp\Files\force.exeexecutable
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

Domain
IP
Reputation
frilance.online
malicious

Threats

No threats detected
No debug info