File name:

Ultimate-Generator-By-Oafu-And-F4ll-master.zip

Full analysis: https://app.any.run/tasks/fe34718f-f7b1-4498-b56f-4884a8496dde
Verdict: No threats detected
Analysis date: November 02, 2020, 06:47:33
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

3F5615EA7C482CB16F05DAD39DD1C577

SHA1:

07ABB7AAA10CA29C0B060EAE6C7EC4CE3386F0F9

SHA256:

C589B6CF6376EC9E328F80700E6259CB5F374F830130C0E1E718D5127C24B5AD

SSDEEP:

3072:FXROZZlu2YLzYPQX5f2oHZw8sXV2s4CEWv4f99AA4OI:FglJezX5fo4tbWvw9lI

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Ultimate-Gift-Card-Generator.exe (PID: 2484)
      • Ultimate-Gift-Card-Generator.exe (PID: 3088)
  • SUSPICIOUS

    • Starts CMD.EXE for commands execution

      • Ultimate-Gift-Card-Generator.exe (PID: 2484)
      • Ultimate-Gift-Card-Generator.exe (PID: 3088)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2460)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2020:06:16 14:03:02
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: Ultimate-Generator-By-Oafu-And-F4ll-master/Credit/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
39
Monitored processes
5
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start drop and start start winrar.exe ultimate-gift-card-generator.exe no specs cmd.exe no specs ultimate-gift-card-generator.exe no specs cmd.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1548"C:\Windows\system32\cmd" /c "C:\Users\admin\AppData\Local\Temp\A744.tmp\A745.tmp\A746.bat C:\Users\admin\AppData\Local\Temp\Rar$EXa2460.2819\Ultimate-Generator-By-Oafu-And-F4ll-master\Ultimate-Gift-Card-Generator.exe"C:\Windows\system32\cmd.exeUltimate-Gift-Card-Generator.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2460"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Ultimate-Generator-By-Oafu-And-F4ll-master.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2484"C:\Users\admin\AppData\Local\Temp\Rar$EXa2460.1320\Ultimate-Generator-By-Oafu-And-F4ll-master\Ultimate-Gift-Card-Generator.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2460.1320\Ultimate-Generator-By-Oafu-And-F4ll-master\Ultimate-Gift-Card-Generator.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2460.1320\ultimate-generator-by-oafu-and-f4ll-master\ultimate-gift-card-generator.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
2972"C:\Windows\system32\cmd" /c "C:\Users\admin\AppData\Local\Temp\6CEB.tmp\6CEC.tmp\6CED.bat C:\Users\admin\AppData\Local\Temp\Rar$EXa2460.1320\Ultimate-Generator-By-Oafu-And-F4ll-master\Ultimate-Gift-Card-Generator.exe"C:\Windows\system32\cmd.exeUltimate-Gift-Card-Generator.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3088"C:\Users\admin\AppData\Local\Temp\Rar$EXa2460.2819\Ultimate-Generator-By-Oafu-And-F4ll-master\Ultimate-Gift-Card-Generator.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2460.2819\Ultimate-Generator-By-Oafu-And-F4ll-master\Ultimate-Gift-Card-Generator.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2460.2819\ultimate-generator-by-oafu-and-f4ll-master\ultimate-gift-card-generator.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
Total events
457
Read events
444
Write events
13
Delete events
0

Modification events

(PID) Process:(2460) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2460) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2460) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2460) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Ultimate-Generator-By-Oafu-And-F4ll-master.zip
(PID) Process:(2460) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2460) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2460) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2460) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2460) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(2460) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
Executable files
2
Suspicious files
0
Text files
30
Unknown types
0

Dropped files

PID
Process
Filename
Type
2460WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2460.1320\Ultimate-Generator-By-Oafu-And-F4ll-master\Credit\Contact.txttext
MD5:0B0646CC33F7D1337A465B3356CA710F
SHA256:8EF18D81E431E2141FADAB3EFB738484A2FBC20C36FCA20F2FA94F55BCB910D3
2460WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2460.1320\Ultimate-Generator-By-Oafu-And-F4ll-master\modules\robux.jstext
MD5:1ADD4055338820FBE3632360D0D9EF95
SHA256:E119CD4B9C668D358790626EB4A53ADFF16046089E96F898AE2683A158E8BFD2
2460WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2460.2819\Ultimate-Generator-By-Oafu-And-F4ll-master\Credit\Contact.txttext
MD5:0B0646CC33F7D1337A465B3356CA710F
SHA256:8EF18D81E431E2141FADAB3EFB738484A2FBC20C36FCA20F2FA94F55BCB910D3
2460WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2460.1320\Ultimate-Generator-By-Oafu-And-F4ll-master\modules\paysafecard.jstext
MD5:19B9229560B48FA8159453AE7E8A1D79
SHA256:1DEB7C9D73C1324D8F96B87F1FCADF4CE02066B6F53E4D4BF007A29A3E993F54
2460WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2460.1320\Ultimate-Generator-By-Oafu-And-F4ll-master\modules\amazon.jstext
MD5:64A0E4A16F121DA0D48B0EC39083B288
SHA256:6FB04512ED1FBCC878821B6C19F79F1402D0464F7E198038B1F9F7696C08FD6A
2460WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2460.1320\Ultimate-Generator-By-Oafu-And-F4ll-master\Help if dont work\Dont Work.txttext
MD5:18F815ED9A9C15DBAA0F0463DE09EE8E
SHA256:6878D0F6139EC9B76E6BF7946C2CE4CE16CB2735173980B96D40FA0FEDE1DFBA
2460WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2460.1320\Ultimate-Generator-By-Oafu-And-F4ll-master\modules\steam.jstext
MD5:4B77FED9387FDB5BC80D93CFC9F0E40E
SHA256:AF5293E195E0FB328512146D31185C6B344BAFD1F6ED6AD4204A853E1E1DA01B
2460WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2460.1320\Ultimate-Generator-By-Oafu-And-F4ll-master\modules\psn.jstext
MD5:FE852FF4BBABD8B8A87BAC85FB28BCC0
SHA256:8D3FA2BEAFA01AD3B04D5989C0A11E56FCAF579F6F52E801DBC975C11DA35A00
2460WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2460.1320\Ultimate-Generator-By-Oafu-And-F4ll-master\modules\xbox.jstext
MD5:762749BAA040BDF4505BCBF630C6EC93
SHA256:2D6A290DCAA9F09BD44C5E2288C650A1AD98A46C3C65E163197266668D71A15D
2460WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2460.1320\Ultimate-Generator-By-Oafu-And-F4ll-master\Ultimate-Gift-Card-Generator.exeexecutable
MD5:AF9D02427A5B19B7D026C698AFC6185C
SHA256:FBFFDC8089D72B7EEA5186EC422A4BA52E5EA76BCD42130125FD85CCF7FFA460
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info