File name: | any run.zip |
Full analysis: | https://app.any.run/tasks/f0da527c-cd83-40af-8405-4df6a64ce607 |
Verdict: | Malicious activity |
Analysis date: | May 20, 2022, 21:54:08 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/zip |
File info: | Zip archive data, at least v2.0 to extract |
MD5: | D5580C9560F5FF87A09FC6100654D4E4 |
SHA1: | 5F42337E5F30A7D73546BFBB399453D2328E5A8D |
SHA256: | C33C4CC5639886BFF516F52872C773EC9D7D15B6CAAE3530753A0458B334C60B |
SSDEEP: | 196608:XH/djrRJhxwSAGm7eGfp4mFWjsa0e1y8ky+q:XVvfH2lpbafT+q |
.zip | | | ZIP compressed archive (100) |
---|
ZipFileName: | aramaware.exe |
---|---|
ZipUncompressedSize: | 616717 |
ZipCompressedSize: | 186036 |
ZipCRC: | 0x75455c4d |
ZipModifyDate: | 2022:05:12 13:09:21 |
ZipCompression: | Deflated |
ZipBitFlag: | - |
ZipRequiredVersion: | 20 |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
3148 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\any run.zip" | C:\Program Files\WinRAR\WinRAR.exe | Explorer.EXE | |
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 | ||||
2908 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa3148.34176\aramaware.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa3148.34176\aramaware.exe | — | WinRAR.exe |
User: admin Integrity Level: MEDIUM | ||||
1828 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa3148.35157\Phsyletric.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa3148.35157\Phsyletric.exe | — | WinRAR.exe |
User: admin Integrity Level: MEDIUM Exit code: 3221226540 | ||||
2408 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa3148.35157\Phsyletric.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa3148.35157\Phsyletric.exe | WinRAR.exe | |
User: admin Integrity Level: HIGH | ||||
1012 | C:\Windows\system32\cmd.exe /c REG add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableTaskMgr /t REG_DWORD /d 1 /f | C:\Windows\system32\cmd.exe | — | aramaware.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 1 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) | ||||
3880 | C:\Windows\system32\cmd.exe /c takeown /F %WINDIR%\system32\logonui.exe | C:\Windows\system32\cmd.exe | — | aramaware.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 1 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) | ||||
3500 | C:\Windows\system32\cmd.exe /c takeown /F %WINDIR%\system32\dllcache\logonui.exe | C:\Windows\system32\cmd.exe | — | aramaware.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 1 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) | ||||
3476 | C:\Windows\system32\cmd.exe /c reg delete HKLM /f | C:\Windows\system32\cmd.exe | — | aramaware.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 1 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) | ||||
312 | REG add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableTaskMgr /t REG_DWORD /d 1 /f | C:\Windows\system32\reg.exe | — | cmd.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Registry Console Tool Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
556 | takeown /F C:\Windows\system32\dllcache\logonui.exe | C:\Windows\system32\takeown.exe | — | cmd.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Takes ownership of a file Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) |
(PID) Process: | (3148) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtBMP |
Value: | |||
(PID) Process: | (3148) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtIcon |
Value: | |||
(PID) Process: | (3148) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (3148) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
(PID) Process: | (3148) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
(PID) Process: | (3148) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\any run.zip | |||
(PID) Process: | (3148) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | name |
Value: 120 | |||
(PID) Process: | (3148) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | size |
Value: 80 | |||
(PID) Process: | (3148) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | type |
Value: 120 | |||
(PID) Process: | (3148) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | mtime |
Value: 100 |
PID | Process | Filename | Type | |
---|---|---|---|---|
3148 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3148.37624\Sclerosis.exe | executable | |
MD5:1AD7F52A5B59C3D3F7FBA2F72ECE6FF1 | SHA256:D76F8F1C1B52D353712AD0A74808EBB8B13F513E89C5A58803211CDCB3EDCFD0 | |||
3148 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3148.34176\quantizer.exe | executable | |
MD5:1458480CF8803569195F934D47AC7481 | SHA256:68D528F9AC891E920449188198A233B71B2860838AF4FB970B9966F941CE82CA | |||
2696 | Sclerosis.exe | C:\Windows\Sclerosis\sqmove.exe | executable | |
MD5:8AD1DA4C2B678FFBC0F5D95ADFEB5C9B | SHA256:6CAAD2810E0D398EF80F5AA63F8F9ED09DBC5B6BB169E43B7319FE9A1EEA85F2 | |||
3148 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3148.34176\Sclerosis.exe | executable | |
MD5:1AD7F52A5B59C3D3F7FBA2F72ECE6FF1 | SHA256:D76F8F1C1B52D353712AD0A74808EBB8B13F513E89C5A58803211CDCB3EDCFD0 | |||
3148 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3148.35157\quantizer.exe | executable | |
MD5:1458480CF8803569195F934D47AC7481 | SHA256:68D528F9AC891E920449188198A233B71B2860838AF4FB970B9966F941CE82CA | |||
2696 | Sclerosis.exe | C:\Windows\Sclerosis\run.vbs | text | |
MD5:2B087BB9DEE64442247BB69DA8FBCAF0 | SHA256:A2F3B7C3E0BF6690A243E9088F925396F063549B42568B92D00EBADDC618C3AD | |||
3148 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3148.35157\Sclerosis.exe | executable | |
MD5:1AD7F52A5B59C3D3F7FBA2F72ECE6FF1 | SHA256:D76F8F1C1B52D353712AD0A74808EBB8B13F513E89C5A58803211CDCB3EDCFD0 | |||
3148 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3148.34176\Phsyletric.exe | executable | |
MD5:4DB23CF50F64A83759DB9DF6AD222D65 | SHA256:465F8BF12FE8FC53C9EF45E498B5F9D95B783C61096147BBC09182F6D19DD129 | |||
3148 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3148.34176\Mythlas.exe | executable | |
MD5:1BCCDB1CBBDB299F4053DBAB4236DADC | SHA256:E65C793A31137AE75A6F30AE2933BD7CAE74FCD4330B6C8770C14466BC3A878F | |||
3148 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3148.34176\Losinium.exe | executable | |
MD5:3FAD30EF9BBB47488E86DEFA0F81ACAB | SHA256:69D2AD4DDD61C4B2E6FF350FD87B61DB5DE36218626812E69C4289DE5782CD0C |