File name: | Nitro-Generator-master.zip |
Full analysis: | https://app.any.run/tasks/e77ccf81-2ffa-4cef-95b8-cd2896bce54d |
Verdict: | Malicious activity |
Analysis date: | August 08, 2020, 15:14:13 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/zip |
File info: | Zip archive data, at least v1.0 to extract |
MD5: | 41D778D5B5A77E74A53DD72F0DB70A1A |
SHA1: | 056975C9BE2FB8A7CA616C496BF9A8BA797F51FD |
SHA256: | D239CCABD062A5B4047FA833E06F2156FC7B287AE8FD7C5E038765316449D4B2 |
SSDEEP: | 1536:H7h0PZzJAas3ttAVKy9rmUtJsYNKU5993EX:90BDsxyhftfNKUlUX |
.zip | | | ZIP compressed archive (100) |
---|
ZipRequiredVersion: | 10 |
---|---|
ZipBitFlag: | - |
ZipCompression: | None |
ZipModifyDate: | 2020:06:18 13:09:08 |
ZipCRC: | 0x00000000 |
ZipCompressedSize: | - |
ZipUncompressedSize: | - |
ZipFileName: | Nitro-Generator-master/ |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
2504 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Nitro-Generator-master.zip" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | |
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 | ||||
2172 | "C:\Users\admin\Desktop\Nitro-Generator-master\Nitro-Generator-V7.exe" | C:\Users\admin\Desktop\Nitro-Generator-master\Nitro-Generator-V7.exe | — | explorer.exe |
User: admin Integrity Level: MEDIUM Exit code: 0 | ||||
2600 | "C:\Windows\system32\cmd" /c "C:\Users\admin\AppData\Local\Temp\20D2.tmp\20D3.tmp\20D4.bat C:\Users\admin\Desktop\Nitro-Generator-master\Nitro-Generator-V7.exe" | C:\Windows\system32\cmd.exe | — | Nitro-Generator-V7.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) | ||||
2236 | mode con cols=100 lines=40 | C:\Windows\system32\mode.com | — | cmd.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: DOS Device MODE Utility Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
1584 | "C:\Users\admin\Desktop\Nitro-Generator-master\Nitro-Generator-V7.exe" | C:\Users\admin\Desktop\Nitro-Generator-master\Nitro-Generator-V7.exe | — | explorer.exe |
User: admin Integrity Level: MEDIUM Exit code: 0 | ||||
2768 | "C:\Windows\system32\cmd" /c "C:\Users\admin\AppData\Local\Temp\36AC.tmp\36AD.tmp\36AE.bat C:\Users\admin\Desktop\Nitro-Generator-master\Nitro-Generator-V7.exe" | C:\Windows\system32\cmd.exe | — | Nitro-Generator-V7.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) | ||||
3564 | mode con cols=100 lines=40 | C:\Windows\system32\mode.com | — | cmd.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: DOS Device MODE Utility Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
1552 | "C:\Users\admin\Desktop\Nitro-Generator-master\Nitro-Generator-V7.exe" | C:\Users\admin\Desktop\Nitro-Generator-master\Nitro-Generator-V7.exe | — | explorer.exe |
User: admin Integrity Level: MEDIUM Exit code: 1 | ||||
1800 | "C:\Windows\system32\cmd" /c "C:\Users\admin\AppData\Local\Temp\5976.tmp\5977.tmp\5978.bat C:\Users\admin\Desktop\Nitro-Generator-master\Nitro-Generator-V7.exe" | C:\Windows\system32\cmd.exe | — | Nitro-Generator-V7.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 1 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) | ||||
2136 | mode con cols=100 lines=40 | C:\Windows\system32\mode.com | — | cmd.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: DOS Device MODE Utility Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) |
PID | Process | Filename | Type | |
---|---|---|---|---|
2504 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Nitro-Generator-master\Nitro-Generator-master\Help if dont work\Dont Work.txt | text | |
MD5:18F815ED9A9C15DBAA0F0463DE09EE8E | SHA256:6878D0F6139EC9B76E6BF7946C2CE4CE16CB2735173980B96D40FA0FEDE1DFBA | |||
2504 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Nitro-Generator-master\Nitro-Generator-master\App_(dont_open).js | text | |
MD5:E8848FC5D9F45BEBBDAC4619E1E0465A | SHA256:550A154B8FAAD94BE4FF34C5A9D7BD6667A1B55E6EA7AA214531125FAC14E415 | |||
2504 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Nitro-Generator-master\Nitro-Generator-master\Nitro-Generator-V7.exe | executable | |
MD5:507DB4D1D3ADC9102207E854C969270C | SHA256:8D4B66A005B5CF1B891E51E81943F105945A2A57DF4EFD63CED59B8252705EF1 | |||
2504 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Nitro-Generator-master\Nitro-Generator-master\Credit\Contact.txt | text | |
MD5:0B0646CC33F7D1337A465B3356CA710F | SHA256:8EF18D81E431E2141FADAB3EFB738484A2FBC20C36FCA20F2FA94F55BCB910D3 | |||
2504 | WinRAR.exe | C:\Users\admin\Desktop\Nitro-Generator-master\hit.txt | text | |
MD5:ABCEED07F6A3E374E3211E4A34B0FF2E | SHA256:A1EB9FB51378DAE2F0645866744A0088844BF7FFBD5AA9921A7559134450F02D | |||
2504 | WinRAR.exe | C:\Users\admin\Desktop\Nitro-Generator-master\Credit\Contact.txt | text | |
MD5:0B0646CC33F7D1337A465B3356CA710F | SHA256:8EF18D81E431E2141FADAB3EFB738484A2FBC20C36FCA20F2FA94F55BCB910D3 | |||
3544 | Nitro-Generator-V7.exe | C:\Users\admin\AppData\Local\Temp\7D88.tmp\7D89.tmp\7D8A.bat | text | |
MD5:FBD529569AEF8933F0A30A2A6A3F608C | SHA256:83683698835C891DF1C58C3AB7335315C30AF6CCB59BAD816D6094D1CEA96BB3 | |||
2504 | WinRAR.exe | C:\Users\admin\Desktop\Nitro-Generator-master\logs.txt | text | |
MD5:BDBBFB87CAD539B554D027C5242E7F1B | SHA256:76E39C77D4F62D56FA32F3B2C71A74A44EEB6C1A43D9638A4AB2BFFC36827A77 | |||
2504 | WinRAR.exe | C:\Users\admin\Desktop\Nitro-Generator-master\App_(dont_open).js | text | |
MD5:E8848FC5D9F45BEBBDAC4619E1E0465A | SHA256:550A154B8FAAD94BE4FF34C5A9D7BD6667A1B55E6EA7AA214531125FAC14E415 | |||
2504 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Nitro-Generator-master\Nitro-Generator-master\hit.txt | text | |
MD5:ABCEED07F6A3E374E3211E4A34B0FF2E | SHA256:A1EB9FB51378DAE2F0645866744A0088844BF7FFBD5AA9921A7559134450F02D |