| File name: | Steam Account generator FIX1.zip |
| Full analysis: | https://app.any.run/tasks/0879e1eb-e7d8-4789-8e0b-34dae8689e93 |
| Verdict: | Malicious activity |
| Analysis date: | February 16, 2019, 09:31:32 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | 4901FD539CB24456CAFFAA8B67DE2336 |
| SHA1: | DA81A617723C3ED01C3E7A7916F643047119F6A6 |
| SHA256: | 94A6C9386B3789EF9B4A0E7845F505797DD9EC29B8A05C0BC95C85EE52C2D919 |
| SSDEEP: | 98304:+Iu2e8h/JftwREsZ4Qw37W+1A24HL9DTQp6okhWROgIZElbM6xQrHTgl7kWVU:+vv8LYFwo24rpTQpN6W4kZsHTqFU |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2019:02:14 10:54:25 |
| ZipCRC: | 0x9b800da8 |
| ZipCompressedSize: | 85 |
| ZipUncompressedSize: | 107 |
| ZipFileName: | Note on captcha Service.txt |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 3156 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Steam Account generator FIX1.zip" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 3184 | "C:\Users\admin\AppData\Local\Temp\Steam Account generator FIX1\Steam Account Generator.exe" | C:\Users\admin\AppData\Local\Temp\Steam Account generator FIX1\Steam Account Generator.exe | explorer.exe | ||||||||||||
User: admin Company: @DedSec1337 Integrity Level: MEDIUM Description: SteamAccountGenerator Exit code: 0 Version: 99.0.0.0 Modules
| |||||||||||||||
| (PID) Process: | (3156) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3156) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3156) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3156) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Steam Account generator FIX1.zip | |||
| (PID) Process: | (3156) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3156) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3156) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3156) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (3156) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Steam Account generator FIX1 | |||
| (PID) Process: | (3184) Steam Account Generator.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Steam Account Generator_RASAPI32 |
| Operation: | write | Name: | EnableFileTracing |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3156 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Steam Account generator FIX1\Note on captcha Service.txt | text | |
MD5:— | SHA256:— | |||
| 3156 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Steam Account generator FIX1\CaptchaHelper.dll | executable | |
MD5:— | SHA256:— | |||
| 3156 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Steam Account generator FIX1\Steam Account Generator.exe | executable | |
MD5:— | SHA256:— | |||
| 3156 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Steam Account generator FIX1\accounts.txt | text | |
MD5:— | SHA256:— | |||
| 3184 | Steam Account Generator.exe | C:\Users\admin\AppData\Local\Temp\b7aefdf7-d352-4a7c-865e-776fd750ad45\CaptchaHelper.dll | executable | |
MD5:DB956A02DABA647F229B01D56EA5D892 | SHA256:5B4F5E6CC52DF647673B94249E5392E6F00CC5FFB7E1FC7C4219351762618CDD | |||
| 3156 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Steam Account generator FIX1\LICENSE | text | |
MD5:C25DCA6F05D3D0D952C7FE9373C8B429 | SHA256:83E4DD21429A91FB7CEA67A476032A9641425E5355DF2E0F589A738B6EC9FD2C | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3184 | Steam Account Generator.exe | 150.101.201.180:443 | makemeapassword.ligos.net | Internode Pty Ltd | AU | unknown |
3184 | Steam Account Generator.exe | 23.45.96.174:443 | store.steampowered.com | Akamai International B.V. | NL | whitelisted |
3184 | Steam Account Generator.exe | 130.211.93.80:443 | newdedsecmail.now.sh | Google Inc. | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
makemeapassword.ligos.net |
| unknown |
newdedsecmail.now.sh |
| malicious |
store.steampowered.com |
| whitelisted |