File name:

AMTEmu-v0_9_1_amtemu-official_com.zip

Full analysis: https://app.any.run/tasks/87a53de7-f45d-41ac-ac76-9fc75552590e
Verdict: Malicious activity
Analysis date: August 09, 2020, 14:29:55
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract
MD5:

C6C152B48393564A8E6B31321FEED755

SHA1:

6F024F82067205E02755641D7BF8CC35E0EA5F4A

SHA256:

BCDA5C883AAAB7DFE8E31F84A0CE8A7F3B4029C5D8CE5E92B20616AB7E064DF5

SSDEEP:

49152:x6kGazf4VR6XdPDP+HDF691oDogNLq6Gmsr:xJe6X9ijoo80u6A

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • amtemu.v0.9.1-painter.exe (PID: 2260)
      • amtemu.v0.9.1-painter.exe (PID: 3644)
    • Loads dropped or rewritten executable

      • amtemu.v0.9.1-painter.exe (PID: 3644)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1928)
      • amtemu.v0.9.1-painter.exe (PID: 3644)
  • INFO

    • Manual execution by user

      • verclsid.exe (PID: 4032)
      • amtemu.v0.9.1-painter.exe (PID: 2260)
      • amtemu.v0.9.1-painter.exe (PID: 3644)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2020:03:19 18:57:15
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: AMTEmu v0.9.1_amtemu-official.com/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
48
Monitored processes
4
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe verclsid.exe no specs amtemu.v0.9.1-painter.exe no specs amtemu.v0.9.1-painter.exe

Process information

PID
CMD
Path
Indicators
Parent process
1928"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\AMTEmu-v0_9_1_amtemu-official_com.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2260"C:\Users\admin\AppData\Local\Temp\AMTEmu-v0_9_1_amtemu-official_com\AMTEmu v0.9.1_amtemu-official.com\amtemu.v0.9.1-painter.exe" C:\Users\admin\AppData\Local\Temp\AMTEmu-v0_9_1_amtemu-official_com\AMTEmu v0.9.1_amtemu-official.com\amtemu.v0.9.1-painter.exeexplorer.exe
User:
admin
Company:
PainteR
Integrity Level:
MEDIUM
Description:
ProxyEmu
Exit code:
3221226540
Version:
0.9.1.0
Modules
Images
c:\users\admin\appdata\local\temp\amtemu-v0_9_1_amtemu-official_com\amtemu v0.9.1_amtemu-official.com\amtemu.v0.9.1-painter.exe
c:\systemroot\system32\ntdll.dll
3644"C:\Users\admin\AppData\Local\Temp\AMTEmu-v0_9_1_amtemu-official_com\AMTEmu v0.9.1_amtemu-official.com\amtemu.v0.9.1-painter.exe" C:\Users\admin\AppData\Local\Temp\AMTEmu-v0_9_1_amtemu-official_com\AMTEmu v0.9.1_amtemu-official.com\amtemu.v0.9.1-painter.exe
explorer.exe
User:
admin
Company:
PainteR
Integrity Level:
HIGH
Description:
ProxyEmu
Exit code:
0
Version:
0.9.1.0
Modules
Images
c:\users\admin\appdata\local\temp\amtemu-v0_9_1_amtemu-official_com\amtemu v0.9.1_amtemu-official.com\amtemu.v0.9.1-painter.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
4032"C:\Windows\system32\verclsid.exe" /S /C {0B2C9183-C9FA-4C53-AE21-C900B0C39965} /I {0C733A8A-2A1C-11CE-ADE5-00AA0044773D} /X 0x401C:\Windows\system32\verclsid.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Extension CLSID Verification Host
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\verclsid.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
948
Read events
904
Write events
43
Delete events
1

Modification events

(PID) Process:(1928) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1928) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1928) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\137\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1928) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\137\52C64B7E
Operation:writeName:@C:\Windows\system32\NetworkExplorer.dll,-1
Value:
Network
(PID) Process:(1928) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\AMTEmu-v0_9_1_amtemu-official_com.zip
(PID) Process:(1928) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1928) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1928) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1928) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1928) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\AMTEmu-v0_9_1_amtemu-official_com
Executable files
2
Suspicious files
0
Text files
4
Unknown types
0

Dropped files

PID
Process
Filename
Type
1928WinRAR.exeC:\Users\admin\AppData\Local\Temp\AMTEmu-v0_9_1_amtemu-official_com\AMTEmu v0.9.1_amtemu-official.com\changelog.txttext
MD5:4027A10DA52763D5CECB8755606DF739
SHA256:4279BD8E74E9C0E671052633C584AB0815B002F4AF24FA3D1F8DADD56D81AA07
1928WinRAR.exeC:\Users\admin\AppData\Local\Temp\AMTEmu-v0_9_1_amtemu-official_com\AMTEmu v0.9.1_amtemu-official.com\amtemu-official.com.nfotext
MD5:6C416C9FD357FCF71808CE8FD26A842B
SHA256:020B3B582FD3C17837928B1DE3D790C7F7466102088EEEBB3D8B593E6AB7C535
1928WinRAR.exeC:\Users\admin\AppData\Local\Temp\AMTEmu-v0_9_1_amtemu-official_com\AMTEmu v0.9.1_amtemu-official.com\ZIP Password.txttext
MD5:0C4F9705D2854F0B2405B55056567707
SHA256:A35E6536CC578382090F7CCBB5CE80E7D16F4859A5D9941B807AB370596F566E
1928WinRAR.exeC:\Users\admin\AppData\Local\Temp\AMTEmu-v0_9_1_amtemu-official_com\AMTEmu v0.9.1_amtemu-official.com\AMTEmu – Universal Adobe Patcher.urltext
MD5:9BF1453A3D8D72054E1B961DA2784E3E
SHA256:956DDFAA048DABEF6EDFEDFBB37D169398BD8F076715206700E7F37D46504237
1928WinRAR.exeC:\Users\admin\AppData\Local\Temp\AMTEmu-v0_9_1_amtemu-official_com\AMTEmu v0.9.1_amtemu-official.com\amtemu.v0.9.1-painter.exeexecutable
MD5:A209B88B9B2CF7339BE0AC5126417875
SHA256:C2F6D462A20F92B97C49C3AF19872FC4DF6AABD4F66F4B8B298A1303881422F6
3644amtemu.v0.9.1-painter.exeC:\Users\admin\AppData\Local\Temp\spc_player.dllexecutable
MD5:41AFBF49BA7F6EE164F31FAA2CD38E15
SHA256:50D30B7AA7B9858F91F33165314C7CF7F2ACC97157091676C7E7925E018FD387
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info