File name:

Crypto-Wallet-Cracker_v5.7.0.zip

Full analysis: https://app.any.run/tasks/e29ee8a0-754e-4e18-a144-e4bc70e77597
Verdict: Malicious activity
Analysis date: May 22, 2024, 18:52:20
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

27007434E55D58696A31774DA2995259

SHA1:

A5D61A17C5FE77F41A3956B68F03CE2C88B6C539

SHA256:

CAB725C00D00615E88D945CA3FD8442EEFB7BE71353901C801911B46A1295316

SSDEEP:

98304:aFYypTdXHDlUdEF7di/HKctWpC0zdpl3vWUcF2qncagVm4JyBWBAI8DBM+o2+PuX:3yO2TM

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 3968)
      • msiexec.exe (PID: 1116)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • msiexec.exe (PID: 1200)
      • msiexec.exe (PID: 1116)
    • Executes as Windows Service

      • VSSVC.exe (PID: 1292)
    • Reads the Internet Settings

      • setup.exe (PID: 4084)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 1116)
    • Reads security settings of Internet Explorer

      • setup.exe (PID: 4084)
  • INFO

    • Manual execution by a user

      • setup.exe (PID: 4084)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3968)
      • msiexec.exe (PID: 1200)
      • msiexec.exe (PID: 1116)
    • Checks supported languages

      • setup.exe (PID: 4084)
      • msiexec.exe (PID: 2044)
      • msiexec.exe (PID: 1116)
      • msiexec.exe (PID: 2284)
    • Reads the computer name

      • msiexec.exe (PID: 1116)
      • msiexec.exe (PID: 2044)
      • setup.exe (PID: 4084)
      • msiexec.exe (PID: 2284)
    • Drops the executable file immediately after the start

      • msiexec.exe (PID: 1200)
    • Application launched itself

      • msiexec.exe (PID: 1116)
    • Reads the machine GUID from the registry

      • msiexec.exe (PID: 2044)
      • setup.exe (PID: 4084)
      • msiexec.exe (PID: 1116)
      • msiexec.exe (PID: 2284)
    • Create files in a temporary directory

      • setup.exe (PID: 4084)
      • msiexec.exe (PID: 1116)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 1116)
    • Creates files or folders in the user directory

      • msiexec.exe (PID: 1116)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2024:03:24 10:56:44
ZipCRC: 0x6e2f9326
ZipCompressedSize: 1968007
ZipUncompressedSize: 2321920
ZipFileName: Crypto Wallet Cracker 5.7/Crypto Wallet Cracker 5.7.msi
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
42
Monitored processes
7
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe setup.exe no specs msiexec.exe msiexec.exe msiexec.exe no specs vssvc.exe no specs msiexec.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1116C:\Windows\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1200"C:\Windows\system32\msiexec.exe" -I "C:\Users\admin\Desktop\Crypto Wallet Cracker 5.7\Crypto Wallet Cracker 5.7.msi" C:\Windows\System32\msiexec.exe
setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1292C:\Windows\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2044C:\Windows\system32\MsiExec.exe -Embedding E1C132C2C981767D20129689E9BA07A2 CC:\Windows\System32\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2284C:\Windows\system32\MsiExec.exe -Embedding A174DB5C32055F154E28D0574DE256FCC:\Windows\System32\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3968"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\Crypto-Wallet-Cracker_v5.7.0.zipC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
4084"C:\Users\admin\Desktop\Crypto Wallet Cracker 5.7\setup.exe" C:\Users\admin\Desktop\Crypto Wallet Cracker 5.7\setup.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup
Exit code:
0
Version:
17.0.33606.225 built by: D17.6
Modules
Images
c:\users\admin\desktop\crypto wallet cracker 5.7\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
Total events
8 431
Read events
8 173
Write events
246
Delete events
12

Modification events

(PID) Process:(3968) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3968) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3968) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3968) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3968) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3968) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(3968) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Crypto-Wallet-Cracker_v5.7.0.zip
(PID) Process:(3968) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3968) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3968) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
10
Suspicious files
13
Text files
6
Unknown types
0

Dropped files

PID
Process
Filename
Type
1116msiexec.exeC:\System Volume Information\SPP\snapshot-2
MD5:
SHA256:
1116msiexec.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
1116msiexec.exeC:\Windows\Installer\MSI7DDC.tmpexecutable
MD5:B77A2A2768B9CC78A71BBFFB9812B978
SHA256:F74C97B1A53541B059D3BFAFE41A79005CE5065F8210D7DE9F1B600DC4E28AA0
1200msiexec.exeC:\Users\admin\AppData\Local\Temp\MSI5333.tmpexecutable
MD5:B77A2A2768B9CC78A71BBFFB9812B978
SHA256:F74C97B1A53541B059D3BFAFE41A79005CE5065F8210D7DE9F1B600DC4E28AA0
3968WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3968.26151\Crypto Wallet Cracker 5.7\NOT WORKING.txttext
MD5:163F421ABE0A1639A3BB88635334E845
SHA256:FB78A19EDA3DA2D339E8C38F2D04B8A1A8D34605158E9B2A240D9D4E2E7AD34B
3968WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3968.26151\Crypto Wallet Cracker 5.7\READ ME.txttext
MD5:1025FF7FE4687FD1C16BD96B23863E1A
SHA256:2E21274B48E5031DC1FDAAD00506B9E2F324A5F784122E09D083D28EF3DC0027
1200msiexec.exeC:\Users\admin\AppData\Local\Temp\MSI5372.tmpexecutable
MD5:B77A2A2768B9CC78A71BBFFB9812B978
SHA256:F74C97B1A53541B059D3BFAFE41A79005CE5065F8210D7DE9F1B600DC4E28AA0
3968WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3968.26151\Crypto Wallet Cracker 5.7\KEY.txttext
MD5:EDC6C83A5C7015AA754683278B9D8805
SHA256:327A377BC13C8FA3EEEC3DB35824A409E3BC2F9D967C65A66996EA2960578C9E
3968WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3968.26151\Crypto Wallet Cracker 5.7\setup.exeexecutable
MD5:486C49F2DD4E5683AF1D047FFDFB5EEB
SHA256:091583602D7B6EF59FE5028C536CE89EA98D98C5C2B35CB09454F011478ED29C
3968WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3968.26151\Crypto Wallet Cracker 5.7\Crypto Wallet Cracker 5.7.vdprojtext
MD5:53DB084C1868FFF4B2F086E529D8B838
SHA256:8EC19CEA3E1357CAC069825CE19F9399DC5B7776C4B498B86D0100F2C68E9608
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
unknown
1088
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info