File name:

SteamCrack by nicoloconicolas2.0.zip

Full analysis: https://app.any.run/tasks/8766303c-ce73-4709-86ad-f3112879645d
Verdict: Malicious activity
Analysis date: March 09, 2018, 15:24:45
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

1BC71FF742CC1D4114919F099BA606F1

SHA1:

32311A5B6D7562B99F90F69E08B0AF6618D5201E

SHA256:

D7335DB9AE5F2F624EC1F28948B22B5AE54FE1B3EA4C544C3484BEAEE3E4D454

SSDEEP:

196608:VurAdbx36ahQr5x/8vPgt6uz1WlhRbhd5qrq0ASUYSFIEibZAPT1SCjj/cS:V4obE83gsuz1WrRTcrq0AdYH8PTYS

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application loaded dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 2008)
      • SteamCrack.exe (PID: 2240)
      • SteamCrack.exe (PID: 2768)
      • SteamCrack.exe (PID: 3576)
      • SteamCrack.exe (PID: 3676)
  • SUSPICIOUS

    • Application launched itself

      • SteamCrack.exe (PID: 2240)
      • SteamCrack.exe (PID: 3576)
    • Starts CMD.EXE for commands execution

      • SteamCrack.exe (PID: 2240)
      • SteamCrack.exe (PID: 3576)
    • Uses TASKKILL.EXE to kill process

      • cmd.exe (PID: 2832)
      • cmd.exe (PID: 3760)
  • INFO

    • Dropped object may contain URL's

      • 7zFM.exe (PID: 3176)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2014:12:09 11:49:23
ZipCRC: 0x48a9097b
ZipCompressedSize: 6921
ZipUncompressedSize: 14848
ZipFileName: SteamCrack/AppID_Patch.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
50
Monitored processes
10
Malicious processes
1
Suspicious processes
2

Behavior graph

Click at the process to see the details
start 7zfm.exe searchprotocolhost.exe no specs steamcrack.exe no specs steamcrack.exe cmd.exe no specs taskkill.exe no specs steamcrack.exe steamcrack.exe no specs cmd.exe no specs taskkill.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2008"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe6_ Global\UsGthrCtrlFltPipeMssGthrPipe6 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2240"C:\Users\admin\Desktop\SteamCrack\SteamCrack.exe" C:\Users\admin\Desktop\SteamCrack\SteamCrack.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1
Modules
Images
c:\users\admin\desktop\steamcrack\steamcrack.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\desktop\steamcrack\qt5core.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\users\admin\desktop\steamcrack\libgcc_s_dw2-1.dll
2768"C:\Users\admin\Desktop\SteamCrack\SteamCrack.exe" adminC:\Users\admin\Desktop\SteamCrack\SteamCrack.exe
SteamCrack.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\steamcrack\steamcrack.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\desktop\steamcrack\qt5core.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\users\admin\desktop\steamcrack\libgcc_s_dw2-1.dll
2832C:\Windows\system32\cmd.exe /c taskkill /PID 2240 /FC:\Windows\system32\cmd.exeSteamCrack.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3176"C:\Program Files\7-Zip\7zFM.exe" "C:\Users\admin\AppData\Local\Temp\SteamCrack by nicoloconicolas2.0.zip"C:\Program Files\7-Zip\7zFM.exe
explorer.exe
User:
admin
Company:
Igor Pavlov
Integrity Level:
MEDIUM
Description:
7-Zip File Manager
Exit code:
0
Version:
16.04
Modules
Images
c:\program files\7-zip\7zfm.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3576"C:\Users\admin\Desktop\SteamCrack\SteamCrack.exe" C:\Users\admin\Desktop\SteamCrack\SteamCrack.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
1
Modules
Images
c:\users\admin\desktop\steamcrack\steamcrack.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\desktop\steamcrack\qt5core.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\users\admin\desktop\steamcrack\libgcc_s_dw2-1.dll
3676"C:\Users\admin\Desktop\SteamCrack\SteamCrack.exe" adminC:\Users\admin\Desktop\SteamCrack\SteamCrack.exeSteamCrack.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\steamcrack\steamcrack.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\desktop\steamcrack\qt5core.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\users\admin\desktop\steamcrack\libgcc_s_dw2-1.dll
3760C:\Windows\system32\cmd.exe /c taskkill /PID 3576 /FC:\Windows\system32\cmd.exeSteamCrack.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
4004taskkill /PID 2240 /FC:\Windows\system32\taskkill.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Terminates Processes
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\usp10.dll
4072taskkill /PID 3576 /FC:\Windows\system32\taskkill.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
Total events
600
Read events
583
Write events
17
Delete events
0

Modification events

(PID) Process:(3176) 7zFM.exeKey:HKEY_CURRENT_USER\Software\7-Zip\FM
Operation:writeName:FolderShortcuts
Value:
(PID) Process:(3176) 7zFM.exeKey:HKEY_CURRENT_USER\Software\7-Zip\FM
Operation:writeName:FolderHistory
Value:
43003A005C00550073006500720073005C00610064006D0069006E005C0041007000700044006100740061005C004C006F00630061006C005C00540065006D0070005C0053007400650061006D0043007200610063006B0020006200790020006E00690063006F006C006F0063006F006E00690063006F006C006100730032002E0030002E007A00690070005C000000
(PID) Process:(3176) 7zFM.exeKey:HKEY_CURRENT_USER\Software\7-Zip\FM
Operation:writeName:PanelPath0
Value:
C:\Users\admin\AppData\Local\Temp\
(PID) Process:(3176) 7zFM.exeKey:HKEY_CURRENT_USER\Software\7-Zip\FM
Operation:writeName:FlatViewArc0
Value:
0
(PID) Process:(3176) 7zFM.exeKey:HKEY_CURRENT_USER\Software\7-Zip\FM
Operation:writeName:PanelPath1
Value:
(PID) Process:(3176) 7zFM.exeKey:HKEY_CURRENT_USER\Software\7-Zip\FM
Operation:writeName:FlatViewArc1
Value:
0
(PID) Process:(3176) 7zFM.exeKey:HKEY_CURRENT_USER\Software\7-Zip\FM
Operation:writeName:ListMode
Value:
771
(PID) Process:(3176) 7zFM.exeKey:HKEY_CURRENT_USER\Software\7-Zip\FM
Operation:writeName:Position
Value:
1600000016000000D60300000B02000000000000
(PID) Process:(3176) 7zFM.exeKey:HKEY_CURRENT_USER\Software\7-Zip\FM
Operation:writeName:Panels
Value:
0100000000000000DA010000
(PID) Process:(2240) SteamCrack.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
Executable files
4
Suspicious files
0
Text files
6
Unknown types
0

Dropped files

PID
Process
Filename
Type
31767zFM.exeC:\Users\admin\AppData\Local\Temp\7zE86C04C22\SteamCrack\icons\windows10.pngimage
MD5:
SHA256:
31767zFM.exeC:\Users\admin\AppData\Local\Temp\7zE86C04C22\SteamCrack\icons\bug.icoimage
MD5:
SHA256:
31767zFM.exeC:\Users\admin\AppData\Local\Temp\7zE86C04C22\SteamCrack\icons\windowsvista.pngimage
MD5:
SHA256:
31767zFM.exeC:\Users\admin\AppData\Local\Temp\7zE86C04C22\SteamCrack\AppID_Patch.exeexecutable
MD5:
SHA256:
31767zFM.exeC:\Users\admin\AppData\Local\Temp\7zE86C04C22\SteamCrack\icons\windows 7.pngimage
MD5:
SHA256:
31767zFM.exeC:\Users\admin\AppData\Local\Temp\7zE86C04C22\SteamCrack\icons\windows8.pngimage
MD5:
SHA256:
31767zFM.exeC:\Users\admin\AppData\Local\Temp\7zE86C04C22\SteamCrack\libgcc_s_dw2-1.dllexecutable
MD5:FADDE43C97607E4445A6F924D851F04E
SHA256:F0614835136413217ED3BAEC9BA22AAAC4C37956AFCB0209F1F89B7676AE86BC
31767zFM.exeC:\Users\admin\AppData\Local\Temp\7zE86C04C22\SteamCrack\icons\windowsxp.pngimage
MD5:CBBBED3D7F792833DC3F6BA79671A382
SHA256:A52E95DB7927B0E260B29202111EE96A54BD2604A45AB44DD09223641E075833
31767zFM.exeC:\Users\admin\AppData\Local\Temp\7zE86C04C22\SteamCrack\libwinpthread-1.dllexecutable
MD5:D128AE39A79E5D196FC001907B5EC3D1
SHA256:4195AC1E3A4A8056DE42C31D511E0E595772439ADBA96180B8953EF5F135F7A5
31767zFM.exeC:\Users\admin\AppData\Local\Temp\7zE86C04C22\SteamCrack\libstdc++-6.dllexecutable
MD5:C283D446B34E75019B81D0981CB11F0D
SHA256:F6530962659D0641236A42517A30DC55C4FCB7D30E942C3E820AF343798A770D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info