| File name: | FIVEM LUA EXEC SOURCE REDENGINE BUILD 3.2.rar |
| Full analysis: | https://app.any.run/tasks/e741bbd5-0fa2-49c1-9430-b87d6281ecac |
| Verdict: | Malicious activity |
| Analysis date: | August 12, 2020, 18:39:12 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v5 |
| MD5: | B38B98922A956B84892DA2FEF8590260 |
| SHA1: | A665578872726528A81D7CAE9F303E042E1B520E |
| SHA256: | 9BE61E9DE16192E7372F8DD31AA48ADB2BADF565806C4D0CDFE55A4DCDB2D61C |
| SSDEEP: | 3072:fDScmDs6tf6h/zUqW7pGavakVOI0nj0Pho/VrcbVhHJXtZ8CofnfyfobDZLrR:bSVz6h/Yq41BVRq4PhGIx16diQBJ |
| .rar | | | RAR compressed archive (v5.0) (61.5) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 668 | "C:\Users\admin\Desktop\FiveM LUA SOURCE (REDENGINE) - DO NOT SEND TO OTHERS !!!.exe" | C:\Users\admin\Desktop\FiveM LUA SOURCE (REDENGINE) - DO NOT SEND TO OTHERS !!!.exe | — | explorer.exe | |||||||||||
User: admin Company: RAYDAM Integrity Level: MEDIUM Description: BY RAYDAM Exit code: 0 Version: 1.2.3.4 Modules
| |||||||||||||||
| 1712 | "C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\AppData\Local\Temp\Rar$DIa2240.41229\IMPORTANT - TUTORIAL.txt | C:\Windows\system32\NOTEPAD.EXE | — | WinRAR.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Notepad Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2240 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\FIVEM LUA EXEC SOURCE REDENGINE BUILD 3.2.rar" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 2288 | "C:\Users\admin\Desktop\FiveM LUA SOURCE (REDENGINE) - DO NOT SEND TO OTHERS !!!.exe" | C:\Users\admin\Desktop\FiveM LUA SOURCE (REDENGINE) - DO NOT SEND TO OTHERS !!!.exe | — | explorer.exe | |||||||||||
User: admin Company: RAYDAM Integrity Level: MEDIUM Description: BY RAYDAM Exit code: 0 Version: 1.2.3.4 Modules
| |||||||||||||||
| 3956 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2240.40680\FIVEM LUA EXEC SOURCE REDENGINE BUILD 3.2\FiveM LUA SOURCE (REDENGINE) - DO NOT SEND TO OTHERS !!!.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2240.40680\FIVEM LUA EXEC SOURCE REDENGINE BUILD 3.2\FiveM LUA SOURCE (REDENGINE) - DO NOT SEND TO OTHERS !!!.exe | — | WinRAR.exe | |||||||||||
User: admin Company: RAYDAM Integrity Level: MEDIUM Description: BY RAYDAM Exit code: 0 Version: 1.2.3.4 Modules
| |||||||||||||||
| (PID) Process: | (2240) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (2240) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (2240) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\137\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2240) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\137\52C64B7E |
| Operation: | write | Name: | @C:\Windows\system32\NetworkExplorer.dll,-1 |
Value: Network | |||
| (PID) Process: | (2240) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\FIVEM LUA EXEC SOURCE REDENGINE BUILD 3.2.rar | |||
| (PID) Process: | (2240) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2240) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2240) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2240) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (2240) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\137\52C64B7E |
| Operation: | write | Name: | @C:\Windows\system32\notepad.exe,-469 |
Value: Text Document | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2240 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2240.45601\FIVEM LUA EXEC SOURCE REDENGINE BUILD 3.2\setup\vorum.dll | — | |
MD5:— | SHA256:— | |||
| 2240 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2240.40680\FIVEM LUA EXEC SOURCE REDENGINE BUILD 3.2\FiveM LUA SOURCE (REDENGINE) - DO NOT SEND TO OTHERS !!!.exe | executable | |
MD5:— | SHA256:— | |||
| 2240 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2240.40680\FIVEM LUA EXEC SOURCE REDENGINE BUILD 3.2\setup\vorum.dll | text | |
MD5:— | SHA256:— | |||
| 2240 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2240.40680\FIVEM LUA EXEC SOURCE REDENGINE BUILD 3.2\IMPORTANT - TUTORIAL.txt | text | |
MD5:— | SHA256:— | |||
| 2240 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2240.43126\FIVEM LUA EXEC SOURCE REDENGINE BUILD 3.2\FiveM LUA SOURCE (REDENGINE) - DO NOT SEND TO OTHERS !!!.exe | executable | |
MD5:— | SHA256:— | |||
| 2240 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DIa2240.41229\IMPORTANT - TUTORIAL.txt | text | |
MD5:— | SHA256:— | |||