| File name: | Nuevo Archivo WinRAR.rar |
| Full analysis: | https://app.any.run/tasks/7b033ce2-ad4b-4934-81d4-5a84c8a9e368 |
| Verdict: | Malicious activity |
| Analysis date: | March 11, 2024, 15:40:01 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v5 |
| MD5: | CEC967D9AEFCA6F7BA94C469CAAE44FF |
| SHA1: | 6EA6C99B88BF47D2FAB14F18C54CB58AC9CF3390 |
| SHA256: | B094A648DF06B8A889D911B158D7B063DD3375410CADCE5AF373FE092C619E59 |
| SSDEEP: | 98304:Jk+mr9Lv5QZzlE/vw3bP4n0hJA/S9a6Cuc0ybuE0KciEetSenoCwX+5+NajYJiuo:v6zfRB |
| .rar | | | RAR compressed archive (v5.0) (61.5) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1172 | SCHTASKS /Create /TN "AutoPico Daily Restart" /TR "C:\Windows\Activador\AutoPico.exe /silent" /SC DAILY /ST 23:59:59 /RU SYSTEM /RL Highest /F | C:\Windows\System32\schtasks.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Manages scheduled tasks Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1308 | "C:\Windows\Activador\AutoPico.exe" | C:\Windows\Activador\AutoPico.exe | cmd.exe | ||||||||||||
User: admin Company: @ByELDI Integrity Level: HIGH Description: AutoPico Exit code: 0 Version: 15.0.0.6 Modules
| |||||||||||||||
| 1692 | "C:\Users\admin\Desktop\Activador\Activador Office v5.exe" | C:\Users\admin\Desktop\Activador\Activador Office v5.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Setup Application Exit code: 0 Version: 9.5.0.0 Modules
| |||||||||||||||
| 1740 | "C:\Windows\regedit.exe" /S DisableSmartScreen.reg | C:\Windows\regedit.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Registry Editor Exit code: 3221226540 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1808 | "C:\Windows\Activador\AutoPico.exe" | C:\Windows\Activador\AutoPico.exe | — | cmd.exe | |||||||||||
User: admin Company: @ByELDI Integrity Level: MEDIUM Description: AutoPico Exit code: 3221226540 Version: 15.0.0.6 Modules
| |||||||||||||||
| 2160 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Nuevo Archivo WinRAR.rar" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 2752 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2904 | "C:\Windows\regedit.exe" /S DisableSmartScreen.reg | C:\Windows\regedit.exe | cmd.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Registry Editor Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3072 | AutoPico.exe | C:\Windows\Activador\AutoPico.exe | — | cmd.exe | |||||||||||
User: admin Company: @ByELDI Integrity Level: MEDIUM Description: AutoPico Exit code: 3221226540 Version: 15.0.0.6 Modules
| |||||||||||||||
| 3092 | "C:\Users\admin\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe" __IRAOFF:1884930 "__IRAFN:C:\Users\admin\Desktop\Activador\Activador Office v5.exe" "__IRCT:3" "__IRTSS:0" "__IRSID:S-1-5-21-1302019708-1500728564-335382590-1000" | C:\Users\admin\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe | Activador Office v5.exe | ||||||||||||
User: admin Company: Indigo Rose Corporation Integrity Level: HIGH Description: Setup Application Exit code: 0 Version: 9.5.0.0 Modules
| |||||||||||||||
| (PID) Process: | (2160) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (2160) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (2160) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2160) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (2160) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (2160) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
| (PID) Process: | (2160) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Nuevo Archivo WinRAR.rar | |||
| (PID) Process: | (2160) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2160) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2160) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3092 | irsetup.exe | C:\Users\admin\AppData\Local\Temp\_ir_sf_temp_0\IRIMG1.JPG | image | |
MD5:D472A0189AA52F36633AC3D89F5E1219 | SHA256:D5E3CD5ADCFDC47B3B9ED57C59960EFC8792A820E404AC8DDA85EF943DE7904B | |||
| 3092 | irsetup.exe | C:\Users\admin\AppData\Local\Temp\_ir_sf_temp_0\IRIMG3.JPG | image | |
MD5:F4E6420595B0418AC0379D33FD264FC0 | SHA256:6A321BBB3FC68CA597217B87C042B7F1F7B136CC1DDFB29F0DD396C14568E779 | |||
| 3092 | irsetup.exe | C:\Windows\Activador\lua5.1.dll | executable | |
MD5:C3F5F4A1FB69B5889F0BBB313CF6017F | SHA256:769416FA7EDF38E91A55F4F7163914EE4AAD9C8C890ED641C300B73157ACAC45 | |||
| 3092 | irsetup.exe | C:\Windows\Activador\Uninstall\uninstall.xml | xml | |
MD5:D79571085424A88EBD3E86E5A92F3DAD | SHA256:A28EA25BBA43A0595DC7BBFF1EB9DBB1250BDF557259DFBF6CEE31B28282A660 | |||
| 3092 | irsetup.exe | C:\Users\admin\AppData\Local\Temp\_ir_sf_temp_0\irsetup.dat | binary | |
MD5:DA9DCB9888E6077CCB53AD5D91BA53D3 | SHA256:2CBE3E29239A97B461156757B376B14EC7B971A6A3A7DA71EB840E8941643208 | |||
| 3092 | irsetup.exe | C:\Windows\Activador\Auto.cmd | text | |
MD5:3D9673422F0CDD485ADE60AC1ABB2F62 | SHA256:7339A4CC48220A161FCC737ED26E99E5678A4D1FAA3F7E2686C46B5A5D234828 | |||
| 1692 | Activador Office v5.exe | C:\Users\admin\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe | executable | |
MD5:9BDCF813D65265255B820BC7A704DA3C | SHA256:B15D67B4A57184E5202DF3C25E20DC0B7F853F4D527D148B337138900989824A | |||
| 3092 | irsetup.exe | C:\Windows\Activador\uninstall.exe | executable | |
MD5:9BDCF813D65265255B820BC7A704DA3C | SHA256:B15D67B4A57184E5202DF3C25E20DC0B7F853F4D527D148B337138900989824A | |||
| 3092 | irsetup.exe | C:\Windows\Activador\DisableSmartScreen.reg | text | |
MD5:98726CF4E77C2A5159801D4E888833DA | SHA256:20AEE3A1B0ECD68E642A5C8FF550D1525DF1C3F2FDA22B7DB51010947153FEBA | |||
| 3092 | irsetup.exe | C:\Windows\Activador\Uninstall\uninstall.dat | binary | |
MD5:DBC805E5DF229A0CB9A8F75901C3C549 | SHA256:354E992403B2F4A66D99DF619FA35A8EBA75E5CCDF62F0107BC0B85BCEA13CE5 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | unknown |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
1308 | AutoPico.exe | 131.188.3.222:123 | 0.pool.ntp.org | — | — | unknown |
Domain | IP | Reputation |
|---|---|---|
0.pool.ntp.org |
| whitelisted |
Process | Message |
|---|---|
regedit.exe | REGEDIT: CreateFile failed, GetLastError() = 2
|