| File name: | 1.zip |
| Full analysis: | https://app.any.run/tasks/d4ae936f-ffc2-46c6-89d5-4d079b23608c |
| Verdict: | Malicious activity |
| Threats: | Gootkit is an advanced banking trojan. It is extremely good at evading detection and has an incredibly effective persistence mechanism, making it a dangerous malware that researchers and organizations should be aware of. |
| Analysis date: | January 18, 2019, 13:09:27 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | FD331EE5DCA1704EB579B2A536CF124A |
| SHA1: | B63D7B251ABB3C11BE9644FE1284D0CBB1DC2DAD |
| SHA256: | D6CDCE2A29DCD4B15980E422411849BE36AE42DB724B877473C208B160E52812 |
| SSDEEP: | 196608:gBBKFGrGBuUBLg7eRI1ONZUgJ+XK1akR+iU1w:UQklN7EOO35IX8xi2 |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 788 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2019:01:11 12:34:04 |
| ZipCRC: | 0x2cb0ad60 |
| ZipCompressedSize: | 214237 |
| ZipUncompressedSize: | 258048 |
| ZipFileName: | 1.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1228 | "C:\Windows\system32\taskmgr.exe" /4 | C:\Windows\system32\taskmgr.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Task Manager Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2188 | "C:\Users\admin\Desktop\tcmd921ax32_64.exe" | C:\Users\admin\Desktop\tcmd921ax32_64.exe | explorer.exe | ||||||||||||
User: admin Company: Ghisler Software GmbH Integrity Level: HIGH Description: Total Commander Installer Exit code: 0 Version: 9.21 Modules
| |||||||||||||||
| 2280 | "C:\Users\admin\Desktop\1.exe" | C:\Users\admin\Desktop\1.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 3176 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\1.zip" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 3448 | "C:\Users\admin\Desktop\tcmd921ax32_64.exe" | C:\Users\admin\Desktop\tcmd921ax32_64.exe | — | explorer.exe | |||||||||||
User: admin Company: Ghisler Software GmbH Integrity Level: MEDIUM Description: Total Commander Installer Exit code: 3221226540 Version: 9.21 Modules
| |||||||||||||||
| 3468 | C:\Users\admin\Desktop\1.exe --vwxyz | C:\Users\admin\Desktop\1.exe | 1.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 3772 | "C:\totalcmd\TOTALCMD.EXE" | C:\totalcmd\TOTALCMD.EXE | — | explorer.exe | |||||||||||
User: admin Company: Ghisler Software GmbH Integrity Level: MEDIUM Description: Total Commander 32 bit Exit code: 0 Version: 9.21 Modules
| |||||||||||||||
| (PID) Process: | (3176) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3176) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3176) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3176) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\1.zip | |||
| (PID) Process: | (3176) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3176) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3176) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3176) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (3176) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop | |||
| (PID) Process: | (3176) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin |
| Operation: | write | Name: | Placement |
Value: 2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3176 | WinRAR.exe | C:\Users\admin\Desktop\1.exe | executable | |
MD5:— | SHA256:— | |||
| 3176 | WinRAR.exe | C:\Users\admin\Desktop\tcmd921ax32_64.exe | executable | |
MD5:— | SHA256:— | |||
| 2188 | tcmd921ax32_64.exe | C:\totalcmd\KEYBOARD.TXT | text | |
MD5:7A4E6F15F1021D196932447949470365 | SHA256:BFE42E35DE6B0790A137DFD76F0FB87A6EF625BBEE092912CD7AF051A91DC123 | |||
| 2188 | tcmd921ax32_64.exe | C:\totalcmd\LANGUAGE\WCMD_DEU.LNG | text | |
MD5:204FF34EBC1865D7CFB94EEC6F7D5929 | SHA256:86319A4E54FEA63005DB9CAB2C97DF951E89F3144A52C2E9C259BB703C76F837 | |||
| 2188 | tcmd921ax32_64.exe | C:\totalcmd\LANGUAGE\WCMD_DEU.MNU | text | |
MD5:071ABBEBABC98916675719777FC84DD0 | SHA256:96504F3FBF117B12FB2720F5C4FDF181D3F31B43277148C00FAE8279233CD541 | |||
| 2188 | tcmd921ax32_64.exe | C:\totalcmd\LANGUAGE\WCMD_DAN.INC | text | |
MD5:2C970AFCC36F0C4474EAD9D0135CF2FA | SHA256:15676A2CD1107859E1ACF384BE658BBF6FEA209CE2E277270E1EB3B99636C335 | |||
| 2188 | tcmd921ax32_64.exe | C:\totalcmd\LANGUAGE\WCMD_DUT.LNG | text | |
MD5:CA497DE753B4A00E7E6283F0283DA0E8 | SHA256:06097327121F172C7381D7F96C02CED8ADBFA4AAB2469C3427A9B200727AA088 | |||
| 2188 | tcmd921ax32_64.exe | C:\totalcmd\LANGUAGE\WCMD_DUT.INC | text | |
MD5:2A33D7D9AE91A3F492D8BE34BF14B20B | SHA256:6A7173F2260E7C293A586FDE513DA82295F7CC3983FF5AD2738435BC2879C709 | |||
| 2188 | tcmd921ax32_64.exe | C:\totalcmd\LANGUAGE\WCMD_ESP.LNG | text | |
MD5:788EC435276281E135A7FE55B06EFD71 | SHA256:EB187C08634AFB183082641FECB8C3DB99DA9BE61A1B00102FD5D6355A583EA9 | |||
| 2188 | tcmd921ax32_64.exe | C:\totalcmd\LANGUAGE\WCMD_CZ.LNG | text | |
MD5:ADAD053363D15B2EBD8973FC90D1ABA1 | SHA256:5177A6EA9053A1291CB3615F6A0821A3421B6727D9524904AD243D440BF57654 | |||
Domain | IP | Reputation |
|---|---|---|
drk.fm604.com |
| malicious |
Process | Message |
|---|---|
1.exe | MP3 file corrupted |
1.exe | WMA 0 |
1.exe | OGG 0 |