File name:

_[Cracked by Grizzly] Seed Watcher.rar.zip

Full analysis: https://app.any.run/tasks/df5d3c8c-223e-457b-a4c2-3afadf375c4b
Verdict: Malicious activity
Analysis date: March 22, 2022, 12:07:13
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

7054CD093B68BA037B0100BAAC08509E

SHA1:

A1991D8D89A49874CD08699477C90F93DED3645F

SHA256:

BD178AFC6E823C8228B19E9BEA91DF2895541398B47D00C71B593E5C5AE14ABE

SSDEEP:

393216:hkIW/eWBhYDRUn03ytZfnkvRivtqiQmboD:hubtyytZ/5tqeboD

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 3976)
  • SUSPICIOUS

    • Checks supported languages

      • WinRAR.exe (PID: 3520)
      • WinRAR.exe (PID: 4016)
    • Application launched itself

      • WinRAR.exe (PID: 4016)
    • Reads the computer name

      • WinRAR.exe (PID: 4016)
      • WinRAR.exe (PID: 3520)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3520)
    • Drops a file that was compiled in debug mode

      • WinRAR.exe (PID: 3520)
    • Drops a file with a compile date too recent

      • WinRAR.exe (PID: 3520)
  • INFO

    • Dropped object may contain Bitcoin addresses

      • WinRAR.exe (PID: 3520)
    • Dropped object may contain TOR URL's

      • WinRAR.exe (PID: 3520)
    • Reads the computer name

      • SearchProtocolHost.exe (PID: 3976)
    • Checks supported languages

      • SearchProtocolHost.exe (PID: 3976)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: _[Cracked by Grizzly] Seed Watcher.rar
ZipUncompressedSize: 12742411
ZipCompressedSize: 12739412
ZipCRC: 0x2ddfbb6b
ZipModifyDate: 2022:03:22 12:06:10
ZipCompression: Deflated
ZipBitFlag: 0x0001
ZipRequiredVersion: 788
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
38
Monitored processes
3
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs winrar.exe searchprotocolhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3520"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Rar$DIb4016.4809\_[Cracked by Grizzly] Seed Watcher.rar"C:\Program Files\WinRAR\WinRAR.exe
WinRAR.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3976"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe3_ Global\UsGthrCtrlFltPipeMssGthrPipe3 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\system32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7601.24542 (win7sp1_ldr_escrow.191209-2211)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
4016"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\_[Cracked by Grizzly] Seed Watcher.rar.zip"C:\Program Files\WinRAR\WinRAR.exeExplorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
2 959
Read events
2 905
Write events
54
Delete events
0

Modification events

(PID) Process:(4016) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(4016) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(4016) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(4016) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(4016) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(4016) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\_[Cracked by Grizzly] Seed Watcher.rar.zip
(PID) Process:(4016) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(4016) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(4016) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(4016) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
24
Suspicious files
0
Text files
13
Unknown types
1

Dropped files

PID
Process
Filename
Type
4016WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DIb4016.4809\_[Cracked by Grizzly] Seed Watcher.rar
MD5:
SHA256:
3520WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3520.5509\[Cracked by Grizzly] Seed Watcher\BouncyCastle.Crypto.dllexecutable
MD5:79F298BDEB949083B32DD6602DE71567
SHA256:CD630C1F254F1851840BE81C575C4B866956D19BD23645DA2AB14DE12EA0F87D
3520WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3520.5509\[Cracked by Grizzly] Seed Watcher\DevExpress.XtraEditors.v16.2.xmlxml
MD5:AE56D706C665D6802CF8B4DB700DD529
SHA256:91A6B0B090D6D52BEA6D7E5744840A1D715837CE64A9F5C35557105BD86F5368
3520WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3520.5509\[Cracked by Grizzly] Seed Watcher\DevExpress.XtraEditors.v16.2.dllexecutable
MD5:F13BA90440AAA7DA26CE071446FEACAF
SHA256:DB2497325B8699F73CE9E2409C6CF8238092DF6726C4491FFBAABC4C895BD3C1
3520WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3520.5509\[Cracked by Grizzly] Seed Watcher\DevExpress.Data.v16.2.xmlxml
MD5:B5737FA25CD32EBC60DA868AB4DD857B
SHA256:2EBC33B060F3273A0219133BB8452C4A9AB67A5CAB443753706239150AB63AE6
3520WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3520.5509\[Cracked by Grizzly] Seed Watcher\DevExpress.Printing.v16.2.Core.dllexecutable
MD5:C95381C80B29839E7A2BD53D6F8F57F5
SHA256:9D45B1E7F8D7626C749CD3222F6D39295C0AF6EBA357E6DC55641A27736F4714
3520WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3520.5509\[Cracked by Grizzly] Seed Watcher\DevExpress.Data.v16.2.dllexecutable
MD5:0AB23659ACB6364FA6C724762C636C37
SHA256:8D6CD66B5D61B0DB9ECC19A762FFA343D87EE91719C602BE6F7263AA2B9AE462
3520WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3520.5509\[Cracked by Grizzly] Seed Watcher\DevExpress.Sparkline.v16.2.Core.dllexecutable
MD5:B409F0A4FFD3512788B44CE318641091
SHA256:D2FB2C2C17B5B46AE91A6F2B31B2E2667661C35B1619D0C8BEA11D86773329EA
3520WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3520.5509\[Cracked by Grizzly] Seed Watcher\Microsoft.Extensions.Logging.Abstractions.dllexecutable
MD5:73BF8E0F455668D5BC6DCA8DBC2750D2
SHA256:D331EDF349A4CF8173B29DA9BF30101791F94C63CF68A68DA0EE9328F8704B98
3520WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3520.5509\[Cracked by Grizzly] Seed Watcher\DevExpress.Sparkline.v16.2.Core.xmlxml
MD5:E8AED8A6E41D4323F1F57E61F36E4D94
SHA256:457EFC9F3A007ACD719E5462E52D6787E70AD7200D96479B70B0BDD588F6FD83
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info