analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

office 2016 activator.zip

Full analysis: https://app.any.run/tasks/0ae6de8e-9511-4638-9e0c-3f98694568d2
Verdict: Malicious activity
Analysis date: February 10, 2019, 23:24:36
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

B0480ACB7451A8347EB0505EF595BBC1

SHA1:

D8FF1B85ACCB66E427A91B78E4C37A8A740AAC7D

SHA256:

9C835FCF593ACDBA33EE71E8A6A52B9CE6606DCDBC6CF6FF40A51E325166A5F6

SSDEEP:

12:5jmIltAtOBdzXC5KwxjTkXWlAkLdSZJ1d7mB2MY78vaiMEHkxQA0gtAqShs3oWtk:9atO/CULKrLmd7oquOzdoxWtRa6+

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executes scripts

      • cmd.exe (PID: 2360)
    • Starts CMD.EXE for commands execution

      • cmd.exe (PID: 2360)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: office activator.bat
ZipUncompressedSize: 2761
ZipCompressedSize: 964
ZipCRC: 0xa8190517
ZipModifyDate: 2018:08:15 03:14:21
ZipCompression: Deflated
ZipBitFlag: -
ZipRequiredVersion: 20
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
53
Monitored processes
18
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs cmd.exe cmd.exe no specs cmd.exe no specs cscript.exe no specs cscript.exe no specs cscript.exe no specs cscript.exe no specs cscript.exe no specs cscript.exe no specs cscript.exe no specs find.exe no specs cscript.exe no specs cscript.exe no specs find.exe no specs cscript.exe no specs cscript.exe no specs find.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2836"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\office 2016 activator.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
2360"C:\Windows\System32\cmd.exe" /C "C:\Users\admin\Desktop\office activator.bat" C:\Windows\System32\cmd.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
3840C:\Windows\system32\cmd.exe /c dir /b ..\root\Licenses16\proplusvl_kms*.xrm-msC:\Windows\system32\cmd.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
3300C:\Windows\system32\cmd.exe /c dir /b ..\root\Licenses16\proplusvl_mak*.xrm-msC:\Windows\system32\cmd.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
3608cscript //nologo ospp.vbs /unpkey:WFG99 C:\Windows\system32\cscript.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft ® Console Based Script Host
Exit code:
1
Version:
5.8.7600.16385
2116cscript //nologo ospp.vbs /unpkey:DRTFM C:\Windows\system32\cscript.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft ® Console Based Script Host
Exit code:
1
Version:
5.8.7600.16385
2628cscript //nologo ospp.vbs /unpkey:BTDRB C:\Windows\system32\cscript.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft ® Console Based Script Host
Exit code:
1
Version:
5.8.7600.16385
3136cscript //nologo ospp.vbs /unpkey:CPQVG C:\Windows\system32\cscript.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft ® Console Based Script Host
Exit code:
1
Version:
5.8.7600.16385
3652cscript //nologo ospp.vbs /inpkey:XQNVK-8JYDB-WJ9W3-YJ8YR-WFG99 C:\Windows\system32\cscript.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft ® Console Based Script Host
Exit code:
1
Version:
5.8.7600.16385
1288cscript //nologo ospp.vbs /sethst:kms7.MSGuides.com C:\Windows\system32\cscript.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft ® Console Based Script Host
Exit code:
1
Version:
5.8.7600.16385
Total events
353
Read events
330
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
0
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
2836WinRAR.exeC:\Users\admin\Desktop\office 2016 activator\office activator.battext
MD5:768297F17B3F0F68AA7FA60293456A55
SHA256:17F6F3D489E71E3D8C18E0DC8F31B1B9148D89709871F1057A2DEC859F4D2340
2836WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2836.14298\office activator.battext
MD5:768297F17B3F0F68AA7FA60293456A55
SHA256:17F6F3D489E71E3D8C18E0DC8F31B1B9148D89709871F1057A2DEC859F4D2340
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info