| File name: | _[Cracked by Grizzly] Seed Watcher.rar.zip |
| Full analysis: | https://app.any.run/tasks/df5d3c8c-223e-457b-a4c2-3afadf375c4b |
| Verdict: | Malicious activity |
| Analysis date: | March 22, 2022, 12:07:13 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | 7054CD093B68BA037B0100BAAC08509E |
| SHA1: | A1991D8D89A49874CD08699477C90F93DED3645F |
| SHA256: | BD178AFC6E823C8228B19E9BEA91DF2895541398B47D00C71B593E5C5AE14ABE |
| SSDEEP: | 393216:hkIW/eWBhYDRUn03ytZfnkvRivtqiQmboD:hubtyytZ/5tqeboD |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipFileName: | _[Cracked by Grizzly] Seed Watcher.rar |
|---|---|
| ZipUncompressedSize: | 12742411 |
| ZipCompressedSize: | 12739412 |
| ZipCRC: | 0x2ddfbb6b |
| ZipModifyDate: | 2022:03:22 12:06:10 |
| ZipCompression: | Deflated |
| ZipBitFlag: | 0x0001 |
| ZipRequiredVersion: | 788 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 3520 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Rar$DIb4016.4809\_[Cracked by Grizzly] Seed Watcher.rar" | C:\Program Files\WinRAR\WinRAR.exe | WinRAR.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 3976 | "C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe3_ Global\UsGthrCtrlFltPipeMssGthrPipe3 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" | C:\Windows\system32\SearchProtocolHost.exe | — | SearchIndexer.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft Windows Search Protocol Host Exit code: 0 Version: 7.00.7601.24542 (win7sp1_ldr_escrow.191209-2211) Modules
| |||||||||||||||
| 4016 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\_[Cracked by Grizzly] Seed Watcher.rar.zip" | C:\Program Files\WinRAR\WinRAR.exe | — | Explorer.EXE | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| (PID) Process: | (4016) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (4016) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (4016) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (4016) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (4016) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (4016) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\_[Cracked by Grizzly] Seed Watcher.rar.zip | |||
| (PID) Process: | (4016) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (4016) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (4016) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (4016) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 4016 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DIb4016.4809\_[Cracked by Grizzly] Seed Watcher.rar | — | |
MD5:— | SHA256:— | |||
| 3520 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3520.5509\[Cracked by Grizzly] Seed Watcher\DevExpress.Data.v16.2.dll | executable | |
MD5:0AB23659ACB6364FA6C724762C636C37 | SHA256:8D6CD66B5D61B0DB9ECC19A762FFA343D87EE91719C602BE6F7263AA2B9AE462 | |||
| 3520 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3520.5509\[Cracked by Grizzly] Seed Watcher\DevExpress.Data.v16.2.xml | xml | |
MD5:B5737FA25CD32EBC60DA868AB4DD857B | SHA256:2EBC33B060F3273A0219133BB8452C4A9AB67A5CAB443753706239150AB63AE6 | |||
| 3520 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3520.5509\[Cracked by Grizzly] Seed Watcher\Common.Logging.Core.xml | xml | |
MD5:02AFBA21E9C365ECD375A33B2CEDD9A2 | SHA256:CA61F734B81ED76607F62B7B211092CD30C77E4F5DCDCAD2E6F0139A921068A2 | |||
| 3520 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3520.5509\[Cracked by Grizzly] Seed Watcher\DevExpress.Pdf.v16.2.Core.dll | executable | |
MD5:42CE6B3D6114224F85918E0AF0BA38E0 | SHA256:50DC1ED3622DA6861A07F0C10DDD599112D080727BC4ADDC4C9020320BFF62B1 | |||
| 3520 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3520.5509\[Cracked by Grizzly] Seed Watcher\BouncyCastle.Crypto.dll | executable | |
MD5:79F298BDEB949083B32DD6602DE71567 | SHA256:CD630C1F254F1851840BE81C575C4B866956D19BD23645DA2AB14DE12EA0F87D | |||
| 3520 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3520.5509\[Cracked by Grizzly] Seed Watcher\Common.Logging.Core.pdb | pdb | |
MD5:3BCE51DFBDBC09CB55EDCD6243D4C706 | SHA256:C32D2BCD1A82B43F19EF76169B80D79F8FB66DD8127D81CA972255D9FF9BE275 | |||
| 3520 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3520.5509\[Cracked by Grizzly] Seed Watcher\Common.Logging.Core.dll | executable | |
MD5:314445E176CD8CCFE3CF274C263E2CDC | SHA256:3D806326BFCE9DDACDD922BDF9C96E45DE9172F45A8A0AF4CC515381CEA01984 | |||
| 3520 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3520.5509\[Cracked by Grizzly] Seed Watcher\Microsoft.Extensions.Logging.Abstractions.dll | executable | |
MD5:73BF8E0F455668D5BC6DCA8DBC2750D2 | SHA256:D331EDF349A4CF8173B29DA9BF30101791F94C63CF68A68DA0EE9328F8704B98 | |||
| 3520 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3520.5509\[Cracked by Grizzly] Seed Watcher\DevExpress.XtraEditors.v16.2.dll | executable | |
MD5:F13BA90440AAA7DA26CE071446FEACAF | SHA256:DB2497325B8699F73CE9E2409C6CF8238092DF6726C4491FFBAABC4C895BD3C1 | |||