File name:

_[Cracked by Grizzly] Seed Watcher.rar.zip

Full analysis: https://app.any.run/tasks/df5d3c8c-223e-457b-a4c2-3afadf375c4b
Verdict: Malicious activity
Analysis date: March 22, 2022, 12:07:13
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

7054CD093B68BA037B0100BAAC08509E

SHA1:

A1991D8D89A49874CD08699477C90F93DED3645F

SHA256:

BD178AFC6E823C8228B19E9BEA91DF2895541398B47D00C71B593E5C5AE14ABE

SSDEEP:

393216:hkIW/eWBhYDRUn03ytZfnkvRivtqiQmboD:hubtyytZ/5tqeboD

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 3976)
  • SUSPICIOUS

    • Reads the computer name

      • WinRAR.exe (PID: 4016)
      • WinRAR.exe (PID: 3520)
    • Checks supported languages

      • WinRAR.exe (PID: 4016)
      • WinRAR.exe (PID: 3520)
    • Drops a file that was compiled in debug mode

      • WinRAR.exe (PID: 3520)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3520)
    • Application launched itself

      • WinRAR.exe (PID: 4016)
    • Drops a file with a compile date too recent

      • WinRAR.exe (PID: 3520)
  • INFO

    • Checks supported languages

      • SearchProtocolHost.exe (PID: 3976)
    • Reads the computer name

      • SearchProtocolHost.exe (PID: 3976)
    • Dropped object may contain Bitcoin addresses

      • WinRAR.exe (PID: 3520)
    • Dropped object may contain TOR URL's

      • WinRAR.exe (PID: 3520)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: _[Cracked by Grizzly] Seed Watcher.rar
ZipUncompressedSize: 12742411
ZipCompressedSize: 12739412
ZipCRC: 0x2ddfbb6b
ZipModifyDate: 2022:03:22 12:06:10
ZipCompression: Deflated
ZipBitFlag: 0x0001
ZipRequiredVersion: 788
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
38
Monitored processes
3
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs winrar.exe searchprotocolhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3520"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Rar$DIb4016.4809\_[Cracked by Grizzly] Seed Watcher.rar"C:\Program Files\WinRAR\WinRAR.exe
WinRAR.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3976"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe3_ Global\UsGthrCtrlFltPipeMssGthrPipe3 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\system32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7601.24542 (win7sp1_ldr_escrow.191209-2211)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
4016"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\_[Cracked by Grizzly] Seed Watcher.rar.zip"C:\Program Files\WinRAR\WinRAR.exeExplorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
2 959
Read events
2 905
Write events
54
Delete events
0

Modification events

(PID) Process:(4016) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(4016) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(4016) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(4016) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(4016) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(4016) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\_[Cracked by Grizzly] Seed Watcher.rar.zip
(PID) Process:(4016) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(4016) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(4016) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(4016) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
24
Suspicious files
0
Text files
13
Unknown types
1

Dropped files

PID
Process
Filename
Type
4016WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DIb4016.4809\_[Cracked by Grizzly] Seed Watcher.rar
MD5:
SHA256:
3520WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3520.5509\[Cracked by Grizzly] Seed Watcher\DevExpress.Data.v16.2.dllexecutable
MD5:0AB23659ACB6364FA6C724762C636C37
SHA256:8D6CD66B5D61B0DB9ECC19A762FFA343D87EE91719C602BE6F7263AA2B9AE462
3520WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3520.5509\[Cracked by Grizzly] Seed Watcher\DevExpress.Data.v16.2.xmlxml
MD5:B5737FA25CD32EBC60DA868AB4DD857B
SHA256:2EBC33B060F3273A0219133BB8452C4A9AB67A5CAB443753706239150AB63AE6
3520WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3520.5509\[Cracked by Grizzly] Seed Watcher\Common.Logging.Core.xmlxml
MD5:02AFBA21E9C365ECD375A33B2CEDD9A2
SHA256:CA61F734B81ED76607F62B7B211092CD30C77E4F5DCDCAD2E6F0139A921068A2
3520WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3520.5509\[Cracked by Grizzly] Seed Watcher\DevExpress.Pdf.v16.2.Core.dllexecutable
MD5:42CE6B3D6114224F85918E0AF0BA38E0
SHA256:50DC1ED3622DA6861A07F0C10DDD599112D080727BC4ADDC4C9020320BFF62B1
3520WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3520.5509\[Cracked by Grizzly] Seed Watcher\BouncyCastle.Crypto.dllexecutable
MD5:79F298BDEB949083B32DD6602DE71567
SHA256:CD630C1F254F1851840BE81C575C4B866956D19BD23645DA2AB14DE12EA0F87D
3520WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3520.5509\[Cracked by Grizzly] Seed Watcher\Common.Logging.Core.pdbpdb
MD5:3BCE51DFBDBC09CB55EDCD6243D4C706
SHA256:C32D2BCD1A82B43F19EF76169B80D79F8FB66DD8127D81CA972255D9FF9BE275
3520WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3520.5509\[Cracked by Grizzly] Seed Watcher\Common.Logging.Core.dllexecutable
MD5:314445E176CD8CCFE3CF274C263E2CDC
SHA256:3D806326BFCE9DDACDD922BDF9C96E45DE9172F45A8A0AF4CC515381CEA01984
3520WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3520.5509\[Cracked by Grizzly] Seed Watcher\Microsoft.Extensions.Logging.Abstractions.dllexecutable
MD5:73BF8E0F455668D5BC6DCA8DBC2750D2
SHA256:D331EDF349A4CF8173B29DA9BF30101791F94C63CF68A68DA0EE9328F8704B98
3520WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3520.5509\[Cracked by Grizzly] Seed Watcher\DevExpress.XtraEditors.v16.2.dllexecutable
MD5:F13BA90440AAA7DA26CE071446FEACAF
SHA256:DB2497325B8699F73CE9E2409C6CF8238092DF6726C4491FFBAABC4C895BD3C1
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info