File name:

AMT-Emulator-v0_9_2_amtemu-official_com.zip

Full analysis: https://app.any.run/tasks/a959cb85-aeb5-4f11-8da2-c2489a018beb
Verdict: Malicious activity
Analysis date: July 14, 2021, 07:03:03
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract
MD5:

7606EC1BA43CE2BC2FC3D2C37CC59433

SHA1:

56DA235707D66DCA48D6386A5270873EBB0B914B

SHA256:

C2089ACF24A19F1613157B84A87C508E0856157F021DD7045C40E588A22DF817

SSDEEP:

24576:z+ZyasFq0UkUuBFjDY+Op1PS7svoAN2ftKrhtLdL32yFU/+kzoVlFE29BIfk:zKNsM0UkU2kTvOsvw0VrmWU/+kzoH2k

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • amtemu.v0.9.2-painter.exe (PID: 3824)
      • amtemu.v0.9.2-painter.exe (PID: 3992)
    • Drops executable file immediately after starts

      • amtemu.v0.9.2-painter.exe (PID: 3992)
    • Loads dropped or rewritten executable

      • amtemu.v0.9.2-painter.exe (PID: 3992)
  • SUSPICIOUS

    • Reads the computer name

      • WinRAR.exe (PID: 1288)
      • amtemu.v0.9.2-painter.exe (PID: 3992)
    • Checks supported languages

      • WinRAR.exe (PID: 1288)
      • amtemu.v0.9.2-painter.exe (PID: 3992)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1288)
      • amtemu.v0.9.2-painter.exe (PID: 3992)
    • Drops a file with too old compile date

      • WinRAR.exe (PID: 1288)
  • INFO

    • Manual execution by user

      • amtemu.v0.9.2-painter.exe (PID: 3824)
      • amtemu.v0.9.2-painter.exe (PID: 3992)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: AMT Emulator v0.9.2_amtemu-official.com/
ZipUncompressedSize: -
ZipCompressedSize: -
ZipCRC: 0x00000000
ZipModifyDate: 2020:03:19 18:57:18
ZipCompression: None
ZipBitFlag: -
ZipRequiredVersion: 10
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
39
Monitored processes
3
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe amtemu.v0.9.2-painter.exe no specs amtemu.v0.9.2-painter.exe

Process information

PID
CMD
Path
Indicators
Parent process
1288"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\AMT-Emulator-v0_9_2_amtemu-official_com.zip"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3824"C:\Users\admin\Desktop\AMT Emulator v0.9.2_amtemu-official.com\amtemu.v0.9.2-painter.exe" C:\Users\admin\Desktop\AMT Emulator v0.9.2_amtemu-official.com\amtemu.v0.9.2-painter.exeExplorer.EXE
User:
admin
Company:
PainteR
Integrity Level:
MEDIUM
Description:
ProxyEmu
Exit code:
3221226540
Version:
0.9.2.0
Modules
Images
c:\users\admin\desktop\amt emulator v0.9.2_amtemu-official.com\amtemu.v0.9.2-painter.exe
c:\windows\system32\ntdll.dll
3992"C:\Users\admin\Desktop\AMT Emulator v0.9.2_amtemu-official.com\amtemu.v0.9.2-painter.exe" C:\Users\admin\Desktop\AMT Emulator v0.9.2_amtemu-official.com\amtemu.v0.9.2-painter.exe
Explorer.EXE
User:
admin
Company:
PainteR
Integrity Level:
HIGH
Description:
ProxyEmu
Exit code:
0
Version:
0.9.2.0
Modules
Images
c:\users\admin\desktop\amt emulator v0.9.2_amtemu-official.com\amtemu.v0.9.2-painter.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
Total events
5 094
Read events
5 051
Write events
43
Delete events
0

Modification events

(PID) Process:(1288) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1288) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1288) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1288) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(1288) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\AMT-Emulator-v0_9_2_amtemu-official_com.zip
(PID) Process:(1288) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1288) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1288) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1288) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1288) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
Executable files
3
Suspicious files
0
Text files
8
Unknown types
0

Dropped files

PID
Process
Filename
Type
1288WinRAR.exeC:\Users\admin\AppData\Local\Temp\AMT Emulator v0.9.2_amtemu-official.com\AMTEmu � Universal Adobe Patcher.urltext
MD5:9BF1453A3D8D72054E1B961DA2784E3E
SHA256:956DDFAA048DABEF6EDFEDFBB37D169398BD8F076715206700E7F37D46504237
1288WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb1288.5188\AMT Emulator v0.9.2_amtemu-official.com\amtemu.v0.9.2-painter.exeexecutable
MD5:8ABDC20F619641E29AA9AD2B999A0DCC
SHA256:CDC95D0113A2AF05C2E70FAB23F6C218AE583EBCB47077DD5B705A476F9D6B96
1288WinRAR.exeC:\Users\admin\AppData\Local\Temp\AMT Emulator v0.9.2_amtemu-official.com\amtemu-official.com.nfotext
MD5:6C416C9FD357FCF71808CE8FD26A842B
SHA256:020B3B582FD3C17837928B1DE3D790C7F7466102088EEEBB3D8B593E6AB7C535
1288WinRAR.exeC:\Users\admin\AppData\Local\Temp\AMT Emulator v0.9.2_amtemu-official.com\changelog.txttext
MD5:24882987B223569D21F827A935E468B9
SHA256:CF271FDA61A832897F6770F2ABAC23B49CCFBE667889AAF6BD39A3B913D5671E
1288WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb1288.5188\AMT Emulator v0.9.2_amtemu-official.com\ZIP Password.txttext
MD5:0C4F9705D2854F0B2405B55056567707
SHA256:A35E6536CC578382090F7CCBB5CE80E7D16F4859A5D9941B807AB370596F566E
1288WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb1288.5188\AMT Emulator v0.9.2_amtemu-official.com\changelog.txttext
MD5:24882987B223569D21F827A935E468B9
SHA256:CF271FDA61A832897F6770F2ABAC23B49CCFBE667889AAF6BD39A3B913D5671E
1288WinRAR.exeC:\Users\admin\AppData\Local\Temp\AMT Emulator v0.9.2_amtemu-official.com\ZIP Password.txttext
MD5:0C4F9705D2854F0B2405B55056567707
SHA256:A35E6536CC578382090F7CCBB5CE80E7D16F4859A5D9941B807AB370596F566E
1288WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb1288.5188\AMT Emulator v0.9.2_amtemu-official.com\AMTEmu � Universal Adobe Patcher.urltext
MD5:9BF1453A3D8D72054E1B961DA2784E3E
SHA256:956DDFAA048DABEF6EDFEDFBB37D169398BD8F076715206700E7F37D46504237
1288WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb1288.5188\AMT Emulator v0.9.2_amtemu-official.com\amtemu-official.com.nfotext
MD5:6C416C9FD357FCF71808CE8FD26A842B
SHA256:020B3B582FD3C17837928B1DE3D790C7F7466102088EEEBB3D8B593E6AB7C535
3992amtemu.v0.9.2-painter.exeC:\Users\admin\AppData\Local\Temp\spc_player.dllexecutable
MD5:41AFBF49BA7F6EE164F31FAA2CD38E15
SHA256:50D30B7AA7B9858F91F33165314C7CF7F2ACC97157091676C7E7925E018FD387
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info