File name: | office 2016 activator.zip |
Full analysis: | https://app.any.run/tasks/0ae6de8e-9511-4638-9e0c-3f98694568d2 |
Verdict: | Malicious activity |
Analysis date: | February 10, 2019, 23:24:36 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/zip |
File info: | Zip archive data, at least v2.0 to extract |
MD5: | B0480ACB7451A8347EB0505EF595BBC1 |
SHA1: | D8FF1B85ACCB66E427A91B78E4C37A8A740AAC7D |
SHA256: | 9C835FCF593ACDBA33EE71E8A6A52B9CE6606DCDBC6CF6FF40A51E325166A5F6 |
SSDEEP: | 12:5jmIltAtOBdzXC5KwxjTkXWlAkLdSZJ1d7mB2MY78vaiMEHkxQA0gtAqShs3oWtk:9atO/CULKrLmd7oquOzdoxWtRa6+ |
.zip | | | ZIP compressed archive (100) |
---|
ZipFileName: | office activator.bat |
---|---|
ZipUncompressedSize: | 2761 |
ZipCompressedSize: | 964 |
ZipCRC: | 0xa8190517 |
ZipModifyDate: | 2018:08:15 03:14:21 |
ZipCompression: | Deflated |
ZipBitFlag: | - |
ZipRequiredVersion: | 20 |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
2836 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\office 2016 activator.zip" | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe |
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 | ||||
2360 | "C:\Windows\System32\cmd.exe" /C "C:\Users\admin\Desktop\office activator.bat" | C:\Windows\System32\cmd.exe | explorer.exe | |
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) | ||||
3840 | C:\Windows\system32\cmd.exe /c dir /b ..\root\Licenses16\proplusvl_kms*.xrm-ms | C:\Windows\system32\cmd.exe | — | cmd.exe |
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 1 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) | ||||
3300 | C:\Windows\system32\cmd.exe /c dir /b ..\root\Licenses16\proplusvl_mak*.xrm-ms | C:\Windows\system32\cmd.exe | — | cmd.exe |
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 1 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) | ||||
3608 | cscript //nologo ospp.vbs /unpkey:WFG99 | C:\Windows\system32\cscript.exe | — | cmd.exe |
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft ® Console Based Script Host Exit code: 1 Version: 5.8.7600.16385 | ||||
2116 | cscript //nologo ospp.vbs /unpkey:DRTFM | C:\Windows\system32\cscript.exe | — | cmd.exe |
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft ® Console Based Script Host Exit code: 1 Version: 5.8.7600.16385 | ||||
2628 | cscript //nologo ospp.vbs /unpkey:BTDRB | C:\Windows\system32\cscript.exe | — | cmd.exe |
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft ® Console Based Script Host Exit code: 1 Version: 5.8.7600.16385 | ||||
3136 | cscript //nologo ospp.vbs /unpkey:CPQVG | C:\Windows\system32\cscript.exe | — | cmd.exe |
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft ® Console Based Script Host Exit code: 1 Version: 5.8.7600.16385 | ||||
3652 | cscript //nologo ospp.vbs /inpkey:XQNVK-8JYDB-WJ9W3-YJ8YR-WFG99 | C:\Windows\system32\cscript.exe | — | cmd.exe |
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft ® Console Based Script Host Exit code: 1 Version: 5.8.7600.16385 | ||||
1288 | cscript //nologo ospp.vbs /sethst:kms7.MSGuides.com | C:\Windows\system32\cscript.exe | — | cmd.exe |
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft ® Console Based Script Host Exit code: 1 Version: 5.8.7600.16385 |
PID | Process | Filename | Type | |
---|---|---|---|---|
2836 | WinRAR.exe | C:\Users\admin\Desktop\office 2016 activator\office activator.bat | text | |
MD5:768297F17B3F0F68AA7FA60293456A55 | SHA256:17F6F3D489E71E3D8C18E0DC8F31B1B9148D89709871F1057A2DEC859F4D2340 | |||
2836 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2836.14298\office activator.bat | text | |
MD5:768297F17B3F0F68AA7FA60293456A55 | SHA256:17F6F3D489E71E3D8C18E0DC8F31B1B9148D89709871F1057A2DEC859F4D2340 |