| File name: | AbStealer Builder.7z |
| Full analysis: | https://app.any.run/tasks/745b90ea-9585-4d5b-8d1d-efbd4b9a91d5 |
| Verdict: | Malicious activity |
| Analysis date: | March 14, 2024, 13:44:41 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-7z-compressed |
| File info: | 7-zip archive data, version 0.4 |
| MD5: | EDD911EB6F5A540B93A1FBC3FA5972BD |
| SHA1: | 722802EBB60ACF876D723E10423A432BC1A2D216 |
| SHA256: | B9D5B9E6591F359BAC9F4983A4FEEB555D3D59F94BA22F6FA5874424EF6A4790 |
| SSDEEP: | 6144:P2KxSQMTRgte0IuKZb9w7kpdbGwuxEH9480OXd3iAG8QqKm7vSgvYA:P9iete5wA3Fuxsn0OZJYmWOR |
| .7z | | | 7-Zip compressed archive (v0.4) (57.1) |
|---|---|---|
| .7z | | | 7-Zip compressed archive (gen) (42.8) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1340 | "C:\Users\admin\Desktop\jjjjjj.exe" | C:\Users\admin\Desktop\jjjjjj.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: WindowsApplication710 Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 1656 | "C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\Desktop\Ab-Stealer-main\README.md | C:\Windows\System32\rundll32.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1768 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2072 | "C:\Users\admin\Desktop\Ab-Stealer-main\AbBuild v.1.0.exe" | C:\Users\admin\Desktop\Ab-Stealer-main\AbBuild v.1.0.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: AbBuilder Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 2304 | "C:\Users\admin\Desktop\Ab-Stealer-main\AbBuild v.1.0.exe" | C:\Users\admin\Desktop\Ab-Stealer-main\AbBuild v.1.0.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: AbBuilder Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 3656 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\AbStealer Builder.7z" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| (PID) Process: | (3656) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3656) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3656) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3656) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (3656) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (3656) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
| (PID) Process: | (3656) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\AbStealer Builder.7z | |||
| (PID) Process: | (3656) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3656) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3656) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3656 | WinRAR.exe | C:\Users\admin\Desktop\Ab-Stealer-main\Panel\img\bg.jpg | image | |
MD5:18D7DAD119F6F3E1267C2197991A4701 | SHA256:B62832EE99520844A46D56B8AEF7D1EA8FC6A9D1912B70B65E8B0C84A88DCE20 | |||
| 3656 | WinRAR.exe | C:\Users\admin\Desktop\Ab-Stealer-main\Panel\style.css | text | |
MD5:611B331AF666B427BF8B70C187C207B4 | SHA256:D1A2D6B4B5881187A38897BE95A5273E0465D1DC576F12DA956F1F0A56D1DE38 | |||
| 3656 | WinRAR.exe | C:\Users\admin\Desktop\Ab-Stealer-main\Panel\Panel.php | text | |
MD5:7053F732191EDF96FD4512762DDF0845 | SHA256:0C7D070541161E43AB3EF8A87723865BF638965B2BD961A6D08125FE12F1ED98 | |||
| 3656 | WinRAR.exe | C:\Users\admin\Desktop\Ab-Stealer-main\Panel\img\Logo.png | image | |
MD5:9EC35234F894111839CB6325762B022D | SHA256:A7D277AFFBC6AF9148515EE1DF84C0552971C200A2F255AA04B9B33A3663C2FC | |||
| 3656 | WinRAR.exe | C:\Users\admin\Desktop\Ab-Stealer-main\Panel\info.php | text | |
MD5:A629991B6585F3F6BE19B90B900BBF8F | SHA256:E3A7DBFA0A61CFC36B4D59FD7092487E714AD1468F9C1044F403C5B4EEDE9946 | |||
| 3656 | WinRAR.exe | C:\Users\admin\Desktop\Ab-Stealer-main\Panel\logout.php | text | |
MD5:5BCBAA8CBA49A91786BEE395780E9A75 | SHA256:4C88F4B31B7027E03FF6C3DC5A932DEDF2B65F350FD0C66F95F36295DF5C4DFD | |||
| 3656 | WinRAR.exe | C:\Users\admin\Desktop\Ab-Stealer-main\Panel\POST.php | text | |
MD5:274AA12CC165219574AB9437C5AB4C04 | SHA256:80E2A2AB43164F2EF40271C85AC5F67CD57CF08D40EABCFAF7830BFEAA7A51FB | |||
| 3656 | WinRAR.exe | C:\Users\admin\Desktop\Ab-Stealer-main\Panel\img\AbBuild v.1.0\AbBuild v.1.0.exe | executable | |
MD5:9E44C10307AA8194753896ECF8102167 | SHA256:E1DECC2F7B00CA0AE9055A28D3E3A464D95158A2BED01BEBAE28BD6658870074 | |||
| 3656 | WinRAR.exe | C:\Users\admin\Desktop\Ab-Stealer-main\Panel\ps.php | text | |
MD5:6DAB11CF5FE8767C35DAC54367E1C5A0 | SHA256:74AF340F1246845F0A4B6D6CE6C227EA205F89205AAF726868BFFC4CE57CE535 | |||
| 3656 | WinRAR.exe | C:\Users\admin\Desktop\Ab-Stealer-main\Panel\login.php | text | |
MD5:D358B18130F2E7BBCACE5DFE7F004D20 | SHA256:E0A856D3E2B2F391F1FB11DB2A4311F7D1DE021B57DDC837CEC963B201B692F4 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1340 | jjjjjj.exe | GET | 200 | 208.95.112.1:80 | http://ip-api.com/json | unknown | binary | 315 b | unknown |
1340 | jjjjjj.exe | GET | 200 | 208.95.112.1:80 | http://ip-api.com/json | unknown | binary | 315 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | unknown |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
1340 | jjjjjj.exe | 208.95.112.1:80 | ip-api.com | TUT-AS | US | unknown |
Domain | IP | Reputation |
|---|---|---|
ip-api.com |
| shared |
PID | Process | Class | Message |
|---|---|---|---|
1340 | jjjjjj.exe | Device Retrieving External IP Address Detected | ET POLICY External IP Lookup ip-api.com |
1340 | jjjjjj.exe | Potential Corporate Privacy Violation | AV POLICY Internal Host Retrieving External IP Address (ip-api. com) |
1340 | jjjjjj.exe | Potential Corporate Privacy Violation | AV POLICY Internal Host Retrieving External IP Address (ip-api. com) |
1340 | jjjjjj.exe | Device Retrieving External IP Address Detected | ET POLICY External IP Lookup ip-api.com |