| File name: | _[Cracked by Grizzly] Seed Watcher.rar.zip |
| Full analysis: | https://app.any.run/tasks/df5d3c8c-223e-457b-a4c2-3afadf375c4b |
| Verdict: | Malicious activity |
| Analysis date: | March 22, 2022, 12:07:13 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | 7054CD093B68BA037B0100BAAC08509E |
| SHA1: | A1991D8D89A49874CD08699477C90F93DED3645F |
| SHA256: | BD178AFC6E823C8228B19E9BEA91DF2895541398B47D00C71B593E5C5AE14ABE |
| SSDEEP: | 393216:hkIW/eWBhYDRUn03ytZfnkvRivtqiQmboD:hubtyytZ/5tqeboD |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipFileName: | _[Cracked by Grizzly] Seed Watcher.rar |
|---|---|
| ZipUncompressedSize: | 12742411 |
| ZipCompressedSize: | 12739412 |
| ZipCRC: | 0x2ddfbb6b |
| ZipModifyDate: | 2022:03:22 12:06:10 |
| ZipCompression: | Deflated |
| ZipBitFlag: | 0x0001 |
| ZipRequiredVersion: | 788 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 3520 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Rar$DIb4016.4809\_[Cracked by Grizzly] Seed Watcher.rar" | C:\Program Files\WinRAR\WinRAR.exe | WinRAR.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 3976 | "C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe3_ Global\UsGthrCtrlFltPipeMssGthrPipe3 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" | C:\Windows\system32\SearchProtocolHost.exe | — | SearchIndexer.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft Windows Search Protocol Host Exit code: 0 Version: 7.00.7601.24542 (win7sp1_ldr_escrow.191209-2211) Modules
| |||||||||||||||
| 4016 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\_[Cracked by Grizzly] Seed Watcher.rar.zip" | C:\Program Files\WinRAR\WinRAR.exe | — | Explorer.EXE | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| (PID) Process: | (4016) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (4016) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (4016) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (4016) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (4016) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (4016) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\_[Cracked by Grizzly] Seed Watcher.rar.zip | |||
| (PID) Process: | (4016) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (4016) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (4016) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (4016) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 4016 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DIb4016.4809\_[Cracked by Grizzly] Seed Watcher.rar | — | |
MD5:— | SHA256:— | |||
| 3520 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3520.5509\[Cracked by Grizzly] Seed Watcher\BouncyCastle.Crypto.dll | executable | |
MD5:79F298BDEB949083B32DD6602DE71567 | SHA256:CD630C1F254F1851840BE81C575C4B866956D19BD23645DA2AB14DE12EA0F87D | |||
| 3520 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3520.5509\[Cracked by Grizzly] Seed Watcher\DevExpress.XtraEditors.v16.2.xml | xml | |
MD5:AE56D706C665D6802CF8B4DB700DD529 | SHA256:91A6B0B090D6D52BEA6D7E5744840A1D715837CE64A9F5C35557105BD86F5368 | |||
| 3520 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3520.5509\[Cracked by Grizzly] Seed Watcher\DevExpress.XtraEditors.v16.2.dll | executable | |
MD5:F13BA90440AAA7DA26CE071446FEACAF | SHA256:DB2497325B8699F73CE9E2409C6CF8238092DF6726C4491FFBAABC4C895BD3C1 | |||
| 3520 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3520.5509\[Cracked by Grizzly] Seed Watcher\DevExpress.Data.v16.2.xml | xml | |
MD5:B5737FA25CD32EBC60DA868AB4DD857B | SHA256:2EBC33B060F3273A0219133BB8452C4A9AB67A5CAB443753706239150AB63AE6 | |||
| 3520 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3520.5509\[Cracked by Grizzly] Seed Watcher\DevExpress.Printing.v16.2.Core.dll | executable | |
MD5:C95381C80B29839E7A2BD53D6F8F57F5 | SHA256:9D45B1E7F8D7626C749CD3222F6D39295C0AF6EBA357E6DC55641A27736F4714 | |||
| 3520 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3520.5509\[Cracked by Grizzly] Seed Watcher\DevExpress.Data.v16.2.dll | executable | |
MD5:0AB23659ACB6364FA6C724762C636C37 | SHA256:8D6CD66B5D61B0DB9ECC19A762FFA343D87EE91719C602BE6F7263AA2B9AE462 | |||
| 3520 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3520.5509\[Cracked by Grizzly] Seed Watcher\DevExpress.Sparkline.v16.2.Core.dll | executable | |
MD5:B409F0A4FFD3512788B44CE318641091 | SHA256:D2FB2C2C17B5B46AE91A6F2B31B2E2667661C35B1619D0C8BEA11D86773329EA | |||
| 3520 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3520.5509\[Cracked by Grizzly] Seed Watcher\Microsoft.Extensions.Logging.Abstractions.dll | executable | |
MD5:73BF8E0F455668D5BC6DCA8DBC2750D2 | SHA256:D331EDF349A4CF8173B29DA9BF30101791F94C63CF68A68DA0EE9328F8704B98 | |||
| 3520 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3520.5509\[Cracked by Grizzly] Seed Watcher\DevExpress.Sparkline.v16.2.Core.xml | xml | |
MD5:E8AED8A6E41D4323F1F57E61F36E4D94 | SHA256:457EFC9F3A007ACD719E5462E52D6787E70AD7200D96479B70B0BDD588F6FD83 | |||