File name: | lab04_demo.zip |
Full analysis: | https://app.any.run/tasks/e50d8247-4e27-4ec4-a298-551bedb16363 |
Verdict: | Malicious activity |
Analysis date: | March 30, 2020, 19:10:00 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/zip |
File info: | Zip archive data, at least v2.0 to extract |
MD5: | C0651E5B062211C588A3A205D8203D9C |
SHA1: | F35F9D8B2DA1C7BFBF49CA201412842718F06B08 |
SHA256: | 9A54A9D8D9BFD98F8EB0CC92E75BD1529242654BE51E55C93F8242608405211C |
SSDEEP: | 24576:nFsqKpLR1HvS98zMwsyY1+gKPuCduJYKKEcnzb:nFs5pLRY9Us5wlP3Fvn3 |
.zip | | | ZIP compressed archive (100) |
---|
ZipRequiredVersion: | 20 |
---|---|
ZipBitFlag: | 0x0002 |
ZipCompression: | Deflated |
ZipModifyDate: | 2018:03:16 14:31:29 |
ZipCRC: | 0x2b0d3572 |
ZipCompressedSize: | 922632 |
ZipUncompressedSize: | 925184 |
ZipFileName: | lab04_demo.exe |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
2580 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\lab04_demo.zip" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | |
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 | ||||
1064 | "C:\Users\admin\Desktop\lab04_demo.exe" | C:\Users\admin\Desktop\lab04_demo.exe | — | explorer.exe |
User: admin Integrity Level: MEDIUM |
PID | Process | Filename | Type | |
---|---|---|---|---|
2580 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2580.25339\lab04_demo.exe | executable | |
MD5:6CF59B6EC9B32DD63CA14BB0D1BE6186 | SHA256:08C702180CDBF77C552F4B33BDCDA8062520B3B238E9489CB8F076E1134C3FC1 |