File name:

CrimsonRat 2.2.7 Private.zip

Full analysis: https://app.any.run/tasks/e019a90f-1b20-4767-aa0d-1a118c83f698
Verdict: Malicious activity
Analysis date: November 16, 2019, 09:25:43
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
evasion
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

B2326F902283F2639F324A5403E6FBEA

SHA1:

28E3ACC154082EBD07F8A3C572C354D6A493BD7A

SHA256:

B99040C2008B78775C46DA7FEAE12D83E6D324FEFB4F6D437BD61DD48D08BFD7

SSDEEP:

98304:lbhEHzKJ9cXIjaKsctNBTYNIS5/goNIHPN7:/ETKJ9cXIjswfEb9IHN

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Actions looks like stealing of personal data

      • javaw.exe (PID: 1788)
    • Changes the autorun value in the registry

      • reg.exe (PID: 2964)
  • SUSPICIOUS

    • Uses ATTRIB.EXE to modify file attributes

      • javaw.exe (PID: 1788)
      • javaw.exe (PID: 2620)
    • Creates files in the user directory

      • javaw.exe (PID: 1788)
      • javaw.exe (PID: 2620)
    • Application launched itself

      • javaw.exe (PID: 1788)
      • javaw.exe (PID: 2620)
    • Executes JAVA applets

      • javaw.exe (PID: 1788)
      • javaw.exe (PID: 2620)
    • Checks for external IP

      • javaw.exe (PID: 1788)
    • Uses REG.EXE to modify Windows registry

      • javaw.exe (PID: 2620)
    • Writes to a desktop.ini file (may be used to cloak folders)

      • javaw.exe (PID: 2620)
  • INFO

    • Manual execution by user

      • javaw.exe (PID: 1788)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.kmz | Google Earth saved working session (60)
.zip | ZIP compressed archive (40)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0808
ZipCompression: Deflated
ZipModifyDate: 2019:11:16 17:25:09
ZipCRC: 0x00000000
ZipCompressedSize: 2
ZipUncompressedSize: -
ZipFileName: CrimsonRat 2.2.7 Private/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
52
Monitored processes
8
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs javaw.exe attrib.exe no specs javaw.exe no specs reg.exe attrib.exe no specs attrib.exe no specs javaw.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1412"C:\Program Files\Java\jre1.8.0_92\bin\javaw.exe" -jar "C:\Users\admin\AppData\Roaming\mgYMAZRR9oAQWE\9zlMmaTQcHQQQWE.txt"C:\Program Files\Java\jre1.8.0_92\bin\javaw.exejavaw.exe
User:
admin
Company:
Oracle Corporation
Integrity Level:
MEDIUM
Description:
Java(TM) Platform SE binary
Exit code:
0
Version:
8.0.920.14
Modules
Images
c:\program files\java\jre1.8.0_92\bin\javaw.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1788"C:\Program Files\Java\jre1.8.0_92\bin\javaw.exe" -jar "C:\Users\admin\Desktop\CrimsonRat 2.2.7 Private\CrimsonRAT v2.2.7 Private FULL.jar" C:\Program Files\Java\jre1.8.0_92\bin\javaw.exe
explorer.exe
User:
admin
Company:
Oracle Corporation
Integrity Level:
MEDIUM
Description:
Java(TM) Platform SE binary
Exit code:
0
Version:
8.0.920.14
Modules
Images
c:\program files\java\jre1.8.0_92\bin\javaw.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2004attrib +h .Ssettings.propertiesC:\Windows\system32\attrib.exejavaw.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Attribute Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\attrib.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ulib.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2304"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\CrimsonRat 2.2.7 Private.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2620"C:\Program Files\Java\jre1.8.0_92\bin\javaw.exe" -jar "C:\Users\admin\AppData\Local\Temp\Windows7552542972655710588.png"C:\Program Files\Java\jre1.8.0_92\bin\javaw.exejavaw.exe
User:
admin
Company:
Oracle Corporation
Integrity Level:
MEDIUM
Description:
Java(TM) Platform SE binary
Exit code:
0
Version:
8.0.920.14
Modules
Images
c:\program files\java\jre1.8.0_92\bin\javaw.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2708attrib +s +h +r "C:\Users\admin\AppData\Roaming\mgYMAZRR9oAQWE\*.*"C:\Windows\system32\attrib.exejavaw.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Attribute Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\attrib.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ulib.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2964reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v bFnTnqeht7QWEQW /t REG_SZ /d "\"C:\Program Files\Java\jre1.8.0_92\bin\javaw.exe\" -jar \"C:\Users\admin\AppData\Roaming\mgYMAZRR9oAQWE\9zlMmaTQcHQQQWE.txt\"" /fC:\Windows\system32\reg.exe
javaw.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Registry Console Tool
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\reg.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3892attrib +s +h +r "C:\Users\admin\AppData\Roaming\mgYMAZRR9oAQWE"C:\Windows\system32\attrib.exejavaw.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Attribute Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\attrib.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ulib.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
901
Read events
876
Write events
25
Delete events
0

Modification events

(PID) Process:(2304) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2304) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2304) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2304) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\CrimsonRat 2.2.7 Private.zip
(PID) Process:(2304) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2304) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2304) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2304) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2304) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath
Operation:writeName:0
Value:
C:\Users\admin\Desktop
(PID) Process:(2304) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
Executable files
9
Suspicious files
0
Text files
12
Unknown types
1

Dropped files

PID
Process
Filename
Type
2304WinRAR.exeC:\Users\admin\Desktop\CrimsonRat 2.2.7 Private\lib\services.jarjava
MD5:
SHA256:
2304WinRAR.exeC:\Users\admin\Desktop\CrimsonRat 2.2.7 Private\lib\tween-engine-api.jarjava
MD5:
SHA256:
2304WinRAR.exeC:\Users\admin\Desktop\CrimsonRat 2.2.7 Private\lib\JNativeHook.jarjava
MD5:
SHA256:
2304WinRAR.exeC:\Users\admin\Desktop\CrimsonRat 2.2.7 Private\CrimsonRAT v2.2.7 Private FULL.jarjava
MD5:
SHA256:
2304WinRAR.exeC:\Users\admin\Desktop\CrimsonRat 2.2.7 Private\lib\JTattoo-1.6.10.jarjava
MD5:
SHA256:
2304WinRAR.exeC:\Users\admin\Desktop\CrimsonRat 2.2.7 Private\lib\jcalendarbutton-1.4.5.jarjava
MD5:5FCCDEED0F4F76022F320592A378C561
SHA256:0CE6019B261C00E7D4B383AA257BADA229AEEB80CF62E5B1DEDFE5EAEDBAF4BB
1412javaw.exeC:\Users\admin\.oracle_jre_usage\90737d32e3abaa4.timestamptext
MD5:
SHA256:
2304WinRAR.exeC:\Users\admin\Desktop\CrimsonRat 2.2.7 Private\lib\sigar.jarjava
MD5:85D4A580BCD31802064024D33F668E9A
SHA256:DE8725B3BE2C25D44BA41A9450CD03842FAC9466D92DC582CB37691EEEA1F8DB
1412javaw.exeC:\Users\admin\2YmY99xxmY.tmptext
MD5:
SHA256:
2620javaw.exeC:\Users\admin\2YmY99xxmY.tmptext
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
2
DNS requests
3
Threats
3

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1788
javaw.exe
GET
301
104.26.15.73:80
http://freegeoip.net/xml/Unknown
US
malicious
1788
javaw.exe
GET
403
104.26.15.73:80
http://freegeoip.net/shutdown
US
text
1.51 Kb
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1788
javaw.exe
104.26.15.73:80
freegeoip.net
Cloudflare Inc
US
shared

DNS requests

Domain
IP
Reputation
checkip.amazonaws.csom
unknown
freegeoip.net
  • 104.26.15.73
  • 104.26.14.73
malicious
crimsonrat.org
unknown

Threats

Found threats are available for the paid subscriptions
3 ETPRO signatures available at the full report
No debug info