| File name: | Crypto Wallet Cracker v2.3 cracked By @vidhayakji786.zip |
| Full analysis: | https://app.any.run/tasks/449999d7-1288-4d5b-bc32-7d512dca6f75 |
| Verdict: | Malicious activity |
| Threats: | Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns. |
| Analysis date: | January 15, 2025, 10:30:37 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract, compression method=deflate |
| MD5: | 60D98208A4CFCD9DE2AF4186898AC322 |
| SHA1: | 5E264C8DF663EB2C430C81C659CB606C5FC93C03 |
| SHA256: | A80C67E2AD0CE7B77D1CD7A9A43560525F6B2AC3D4692F8223D854313A60A336 |
| SSDEEP: | 98304:Y755864Dv4pz/PrZgNYDaBh7TKelVrvW2a2gRq/4waqg3KOGaasee8mNEBVN0isA:LU0 |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2023:10:09 16:58:50 |
| ZipCRC: | 0x29015e4d |
| ZipCompressedSize: | 201 |
| ZipUncompressedSize: | 428 |
| ZipFileName: | Crypto Wallet Cracker v2.3 cracked By @vidhayakji786/Darkminer v6.deps.json |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2612 | C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding | C:\Windows\System32\rundll32.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2972 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\Crypto Wallet Cracker v2.3 cracked By @vidhayakji786.zip" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 4764 | "C:\Users\admin\AppData\Local\Temp\3582-490\Darkminer v6.exe" | C:\Users\admin\AppData\Local\Temp\3582-490\Darkminer v6.exe | Darkminer v6.exe | ||||||||||||
User: admin Company: Darkminer v6 Integrity Level: MEDIUM Description: Darkminer v6 Exit code: 2147516570 Version: 1.0.0.0 Modules
| |||||||||||||||
| 5032 | "C:\Users\admin\Desktop\Crypto Wallet Cracker v2.3 cracked By @vidhayakji786\Darkminer v6.exe" | C:\Users\admin\Desktop\Crypto Wallet Cracker v2.3 cracked By @vidhayakji786\Darkminer v6.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 5256 | "C:\Users\admin\AppData\Local\Temp\3582-490\Darkminer v6.exe" | C:\Users\admin\AppData\Local\Temp\3582-490\Darkminer v6.exe | Darkminer v6.exe | ||||||||||||
User: admin Company: Darkminer v6 Integrity Level: MEDIUM Description: Darkminer v6 Exit code: 2147516570 Version: 1.0.0.0 Modules
| |||||||||||||||
| 5320 | "C:\Users\admin\Desktop\Crypto Wallet Cracker v2.3 cracked By @vidhayakji786\Darkminer v6.exe" | C:\Users\admin\Desktop\Crypto Wallet Cracker v2.3 cracked By @vidhayakji786\Darkminer v6.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Modules
| |||||||||||||||
| 5696 | "C:\WINDOWS\system32\mspaint.exe" "C:\Users\admin\Desktop\Crypto Wallet Cracker v2.3 cracked By @vidhayakji786\mining_bitcoin_coin_cryptocurrency_money_icon_211007.ico" | C:\Windows\System32\mspaint.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Paint Exit code: 0 Version: 10.0.19041.3758 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6556 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\Crypto Wallet Cracker v2.3 cracked By @vidhayakji786.zip" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| (PID) Process: | (6556) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\preferences.zip | |||
| (PID) Process: | (6556) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\chromium_ext.zip | |||
| (PID) Process: | (6556) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\omni_23_10_2024_.zip | |||
| (PID) Process: | (6556) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\Crypto Wallet Cracker v2.3 cracked By @vidhayakji786.zip | |||
| (PID) Process: | (6556) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (6556) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (6556) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (6556) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (6556) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath |
| Operation: | delete value | Name: | 15 |
Value: | |||
| (PID) Process: | (6556) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath |
| Operation: | delete value | Name: | 14 |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6556 | WinRAR.exe | C:\Users\admin\Desktop\Crypto Wallet Cracker v2.3 cracked By @vidhayakji786\Darkminer v6.pdb | binary | |
MD5:37875F67F67F2F9D750F27AA47DEB6A3 | SHA256:A9C743213AD48BFDDCBB332E568F640581AF95B9B522731A1D90F764054E62A0 | |||
| 2972 | WinRAR.exe | C:\Users\admin\Desktop\Crypto Wallet Cracker v2.3 cracked By @vidhayakji786\Darkminer v6.runtimeconfig.json | binary | |
MD5:D720176A229E9D969B40FABEB0BAF62E | SHA256:321B4E463BBACD6113AA337511BDEBF5E7356E9971744346B28424607C7B483A | |||
| 6556 | WinRAR.exe | C:\Users\admin\Desktop\Crypto Wallet Cracker v2.3 cracked By @vidhayakji786\Darkminer v6.deps.json | binary | |
MD5:F1728A969B6DF0A9DA9D6C94C5015E9A | SHA256:4F0193049D820402B1874E80FD12F131A9D9989812FE548AA7055AE9A406DC30 | |||
| 6556 | WinRAR.exe | C:\Users\admin\Desktop\Crypto Wallet Cracker v2.3 cracked By @vidhayakji786\Darkminer v6.exe | executable | |
MD5:82AED2B114642857DA21B46AD83FCF21 | SHA256:3603803A35881BF623D136B2288FDC68164C351251C2DA50C295135264A0E2AB | |||
| 2972 | WinRAR.exe | C:\Users\admin\Desktop\Crypto Wallet Cracker v2.3 cracked By @vidhayakji786\Darkminer v6.pdb | binary | |
MD5:37875F67F67F2F9D750F27AA47DEB6A3 | SHA256:A9C743213AD48BFDDCBB332E568F640581AF95B9B522731A1D90F764054E62A0 | |||
| 2972 | WinRAR.exe | C:\Users\admin\Desktop\Crypto Wallet Cracker v2.3 cracked By @vidhayakji786\Darkminer v6.deps.json | binary | |
MD5:F1728A969B6DF0A9DA9D6C94C5015E9A | SHA256:4F0193049D820402B1874E80FD12F131A9D9989812FE548AA7055AE9A406DC30 | |||
| 2972 | WinRAR.exe | C:\Users\admin\Desktop\Crypto Wallet Cracker v2.3 cracked By @vidhayakji786\Darkminer v6.exe | executable | |
MD5:82AED2B114642857DA21B46AD83FCF21 | SHA256:3603803A35881BF623D136B2288FDC68164C351251C2DA50C295135264A0E2AB | |||
| 5320 | Darkminer v6.exe | C:\ProgramData\Adobe\ARM\S\388\AdobeARMHelper.exe | executable | |
MD5:85A67D34298E33D2D5A9EC789B6AB594 | SHA256:1DEE143B4F88F2375B85C6271A58E2E78FED081BEAE4090678CB2DD7A37FB2D4 | |||
| 2972 | WinRAR.exe | C:\Users\admin\Desktop\Crypto Wallet Cracker v2.3 cracked By @vidhayakji786\mining_bitcoin_coin_cryptocurrency_money_icon_211007.ico | image | |
MD5:E43373361B937C1035A8D8F9366D8AD0 | SHA256:270B31B91C23CAB04604D08DD08EE72EF08F83F8CC8E9450BAA2212B40FE00D1 | |||
| 5320 | Darkminer v6.exe | C:\Users\admin\AppData\Local\Temp\3582-490\Darkminer v6.exe | executable | |
MD5:E64ACD0826C046EED8B42583ADB58447 | SHA256:B8E4871C8E64009DC97AFF74F987AAFD0466C224A0DB3744631246CABA1D9453 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
640 | svchost.exe | GET | 200 | 23.48.23.156:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
4712 | MoUsoCoreWorker.exe | GET | 200 | 23.48.23.156:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
4712 | MoUsoCoreWorker.exe | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
640 | svchost.exe | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
1176 | svchost.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
6524 | backgroundTaskHost.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | whitelisted |
6420 | SIHClient.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
6420 | SIHClient.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4712 | MoUsoCoreWorker.exe | 23.48.23.156:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
640 | svchost.exe | 23.48.23.156:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
4712 | MoUsoCoreWorker.exe | 23.35.229.160:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
— | — | 23.35.229.160:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
640 | svchost.exe | 23.35.229.160:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
5064 | SearchApp.exe | 92.123.104.19:443 | www.bing.com | Akamai International B.V. | DE | whitelisted |
— | — | 2.17.190.73:80 | ocsp.digicert.com | AKAMAI-AS | DE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
www.bing.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
login.live.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
arc.msn.com |
| whitelisted |
fd.api.iris.microsoft.com |
| whitelisted |
Process | Message |
|---|---|
Darkminer v6.exe | The application to execute does not exist: 'C:\Users\admin\AppData\Local\Temp\3582-490\Darkminer v6.dll'. |
Darkminer v6.exe | The application to execute does not exist: 'C:\Users\admin\AppData\Local\Temp\3582-490\Darkminer v6.dll'. |