| File name: | SoulTaker.zip |
| Full analysis: | https://app.any.run/tasks/a2242a2b-b9f6-4890-afeb-994737bb5bb3 |
| Verdict: | Malicious activity |
| Analysis date: | May 02, 2024, 16:16:27 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v1.0 to extract, compression method=store |
| MD5: | EF8ED6D45E6FBFF7AF9C03A7ABD46FEB |
| SHA1: | CD0E7D7DE94966DB4B75B90191C03630D2E5B96E |
| SHA256: | 98CD5E9A752657BFD7ED31D4EC6F5AAFEA9E46ECFFCA71A5C3EE71814CC2CF9C |
| SSDEEP: | 98304:Wlct4qaFVydiRpPapx5/jFBZxDRakcNJdaDxvfjrHOfQ5K9De0Bp+d2t469yWwvs:dhJ0fa02QSivzzkZA |
| .zip | | | ZIP compressed archive (36.3) |
|---|
| ZipRequiredVersion: | 10 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | None |
| ZipModifyDate: | 2024:05:02 18:09:12 |
| ZipCRC: | 0x00000000 |
| ZipCompressedSize: | - |
| ZipUncompressedSize: | - |
| ZipFileName: | SoulTaker/ |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 284 | C:\Windows\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -Embedding | C:\Windows\explorer.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 600 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --use-gl=angle --use-angle=swiftshader-webgl --mojo-platform-channel-handle=1484 --field-trial-handle=1316,i,9268492104860445456,10698566592223974836,131072 /prefetch:2 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 692 | explorer "https://anonfiles.com/t2h4A025n9" | C:\Windows\explorer.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 864 | C:\Users\admin\Desktop\SoulTaker\PROGRAMS\Dox_Tool_V2.exe | C:\Users\admin\Desktop\SoulTaker\PROGRAMS\Dox_Tool_V2.exe | — | cmd.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Dox Tool V2 Exit code: 0 Version: 2.0.0.2 Modules
| |||||||||||||||
| 1072 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1300 --field-trial-handle=1316,i,9268492104860445456,10698566592223974836,131072 /prefetch:2 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1112 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1796 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=109.0.5414.149 "--annotation=exe=C:\Program Files\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win32 "--annotation=prod=Microsoft Edge" --annotation=ver=109.0.1518.115 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xd8,0x6612f598,0x6612f5a8,0x6612f5b4 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1940 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=1644 --field-trial-handle=1316,i,9268492104860445456,10698566592223974836,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 2040 | C:\Users\admin\Desktop\SoulTaker\PROGRAMS\Dox_Tool_V2.exe | C:\Users\admin\Desktop\SoulTaker\PROGRAMS\Dox_Tool_V2.exe | cmd.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: Dox Tool V2 Exit code: 0 Version: 2.0.0.2 Modules
| |||||||||||||||
| 2068 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --single-argument https://anonfiles.com/t2h4A025n9 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| (PID) Process: | (3940) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3940) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3940) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3940) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (3940) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (3940) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
| (PID) Process: | (3940) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\SoulTaker.zip | |||
| (PID) Process: | (3940) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3940) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3940) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3940 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3940.41291\SoulTaker\menu.py | text | |
MD5:87021C161B92F2AF5739D5E457E57F2E | SHA256:974AE2579556991C68B640FD62DC98978DC16903E416376F88E07DA6B306D101 | |||
| 3940 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3940.41291\SoulTaker\PROGRAMS\PHISHING\cryptocurrency\ip.php | text | |
MD5:2B00FAFE2FA08D89CB2605EE8186BD63 | SHA256:D0F8F3E7985A87E0BEB1699CCFADAB7268FFC777C05FA1DFCC35A16B6D393947 | |||
| 3940 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3940.41291\SoulTaker\PROGRAMS\PHISHING\badoo\login.html | html | |
MD5:7E38A80C9B9F7F806B070B3E82652163 | SHA256:DF4D5EEC529E8D3738403FCF6654431241A2614724A7DE37F7A24A22495893AE | |||
| 3940 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3940.41291\SoulTaker\PROGRAMS\PHISHING\cryptocurrency\index.php | text | |
MD5:32D66F4102DCB5918FC7DE8FFF0AE20B | SHA256:5D075785E9770EC2637793B66977CC5C4FD0B7545711033E6DDE3C484EFF15C4 | |||
| 3940 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3940.41291\SoulTaker\PROGRAMS\PHISHING\create\index.php | text | |
MD5:32D66F4102DCB5918FC7DE8FFF0AE20B | SHA256:5D075785E9770EC2637793B66977CC5C4FD0B7545711033E6DDE3C484EFF15C4 | |||
| 3940 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3940.41291\SoulTaker\PROGRAMS\PHISHING\create\login.php | text | |
MD5:A057EF18A7B58806421951FB80C27E25 | SHA256:D03B5D565482B5C331BCC4F0AA9C2BBE9A8488B5103656DA97425BB4B54A3A03 | |||
| 3940 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3940.41291\SoulTaker\PROGRAMS\PHISHING\badoo\login.php | text | |
MD5:CD6D59B9CE8CB57BE7C3AF9CBD218D7E | SHA256:2264BBD8A153860E1B1E03ABA842F54CCD0286DA2DD94AB8B4579D542DC9E1AA | |||
| 3940 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3940.41291\SoulTaker\PROGRAMS\PHISHING\cryptocurrency\login.php | text | |
MD5:04FE743CA0E4F87967EDEF06CD513084 | SHA256:792EAF3957B67EF0122C8CE1B1C7E0A3A61A0293AFCAC90BB316A70103B31CA6 | |||
| 3940 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3940.41291\SoulTaker\PROGRAMS\PHISHING\devianart\index.php | text | |
MD5:32D66F4102DCB5918FC7DE8FFF0AE20B | SHA256:5D075785E9770EC2637793B66977CC5C4FD0B7545711033E6DDE3C484EFF15C4 | |||
| 3940 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3940.41291\SoulTaker\PROGRAMS\PHISHING\adobe\index.php | text | |
MD5:32D66F4102DCB5918FC7DE8FFF0AE20B | SHA256:5D075785E9770EC2637793B66977CC5C4FD0B7545711033E6DDE3C484EFF15C4 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2040 | Dox_Tool_V2.exe | GET | 404 | 188.114.97.3:80 | http://drizzybot.com/releases/version.txt | unknown | — | — | unknown |
2804 | msedge.exe | GET | 200 | 23.65.124.16:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?2a1f22c8726be7ce | unknown | — | — | unknown |
2040 | Dox_Tool_V2.exe | GET | 403 | 172.64.147.186:80 | http://www.411.com/name/Marko-Loeka/Zip%20Code,%20City,%20or%20State | unknown | — | — | unknown |
2040 | Dox_Tool_V2.exe | GET | 301 | 172.67.68.119:80 | http://www.zabasearch.com/people/Marko+Loeka/Zip%20Code,%20City,%20or%20State | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | unknown |
— | — | 224.0.0.252:5355 | — | — | — | unknown |
2040 | Dox_Tool_V2.exe | 188.114.97.3:80 | drizzybot.com | CLOUDFLARENET | NL | unknown |
2040 | Dox_Tool_V2.exe | 172.64.147.186:80 | www.411.com | CLOUDFLARENET | US | unknown |
2040 | Dox_Tool_V2.exe | 172.67.68.119:80 | www.zabasearch.com | CLOUDFLARENET | US | unknown |
2040 | Dox_Tool_V2.exe | 172.67.68.119:443 | www.zabasearch.com | CLOUDFLARENET | US | unknown |
2068 | msedge.exe | 239.255.255.250:1900 | — | — | — | unknown |
2080 | msedge.exe | 13.107.42.16:443 | config.edge.skype.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
2080 | msedge.exe | 204.79.197.239:443 | edge.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
Domain | IP | Reputation |
|---|---|---|
drizzybot.com |
| unknown |
10digits.us |
| unknown |
www.411.com |
| unknown |
www.zabasearch.com |
| malicious |
config.edge.skype.com |
| whitelisted |
anonfiles.com |
| unknown |
edge.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
iplogger.org |
| shared |
ctldl.windowsupdate.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
3044 | msedge.exe | Potential Corporate Privacy Violation | ET POLICY IP Check Domain (iplogger .org in DNS Lookup) |
3044 | msedge.exe | Potential Corporate Privacy Violation | ET POLICY IP Check Domain (iplogger .org in DNS Lookup) |
3044 | msedge.exe | Potential Corporate Privacy Violation | ET POLICY IP Check Domain (iplogger .org in TLS SNI) |
3044 | msedge.exe | Potential Corporate Privacy Violation | ET POLICY IP Check Domain (iplogger .org in TLS SNI) |
3044 | msedge.exe | Potential Corporate Privacy Violation | ET POLICY IP Check Domain (iplogger .org in DNS Lookup) |
3044 | msedge.exe | Potential Corporate Privacy Violation | ET POLICY IP Check Domain (iplogger .org in DNS Lookup) |