File name:

Crypto Wallet Cracker.zip

Full analysis: https://app.any.run/tasks/f938d5c2-3dc3-441f-bd7b-3c9914d3e53e
Verdict: Malicious activity
Analysis date: January 15, 2024, 23:49:52
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

3C199E94C818EFA1E8DD237E58FCBA78

SHA1:

BA641D1C70BFD98C904C17623766297B48C56A5E

SHA256:

DBA247894810BA62BBC0D7B79FE038EB6F11CC2C7724DED05A5A694F31F91320

SSDEEP:

98304:uveLakBKgL/fpvDAvEO/kzsLgUWjHnckGce0ceyc/HALvYOyKTiH12viOwh3Uuqw:TeZCN4i

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 1072)
      • msiexec.exe (PID: 2084)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • msiexec.exe (PID: 2032)
      • msiexec.exe (PID: 2084)
      • msiexec.exe (PID: 1036)
    • Executes as Windows Service

      • VSSVC.exe (PID: 1504)
    • Reads the Internet Settings

      • setup.exe (PID: 2760)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1072)
      • msiexec.exe (PID: 2032)
      • msiexec.exe (PID: 2084)
      • msiexec.exe (PID: 1036)
    • Checks supported languages

      • msiexec.exe (PID: 2084)
      • msiexec.exe (PID: 1392)
      • msiexec.exe (PID: 2640)
      • setup.exe (PID: 2760)
      • msiexec.exe (PID: 2484)
    • Reads the computer name

      • msiexec.exe (PID: 2084)
      • msiexec.exe (PID: 1392)
      • msiexec.exe (PID: 2640)
      • setup.exe (PID: 2760)
      • msiexec.exe (PID: 2484)
    • Reads the machine GUID from the registry

      • msiexec.exe (PID: 1392)
      • msiexec.exe (PID: 2084)
      • msiexec.exe (PID: 2640)
      • setup.exe (PID: 2760)
      • msiexec.exe (PID: 2484)
    • Drops the executable file immediately after the start

      • msiexec.exe (PID: 2032)
      • msiexec.exe (PID: 1036)
    • Application launched itself

      • msiexec.exe (PID: 2084)
    • Create files in a temporary directory

      • msiexec.exe (PID: 2084)
      • setup.exe (PID: 2760)
    • Creates files or folders in the user directory

      • msiexec.exe (PID: 2084)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2023:10:17 20:42:58
ZipCRC: 0x9068292b
ZipCompressedSize: 1965761
ZipUncompressedSize: 2319872
ZipFileName: Crypto Wallet Cracker/Crypto Wallet Cracker v2.3.msi
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
44
Monitored processes
9
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe msiexec.exe msiexec.exe msiexec.exe no specs vssvc.exe no specs msiexec.exe no specs setup.exe no specs msiexec.exe msiexec.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1036"C:\Windows\system32\msiexec.exe" -I "C:\Users\admin\AppData\Local\Temp\Rar$EXa1072.11558\Crypto Wallet Cracker\Crypto Wallet Cracker v2.3.msi" C:\Windows\System32\msiexec.exe
setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
1602
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1072"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Crypto Wallet Cracker.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
1392C:\Windows\system32\MsiExec.exe -Embedding D0B720113849A8818101B1B6B2A1031B CC:\Windows\System32\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1504C:\Windows\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2032"C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\Rar$EXa1072.9221\Crypto Wallet Cracker\Crypto Wallet Cracker v2.3.msi" C:\Windows\System32\msiexec.exe
WinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2084C:\Windows\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2484C:\Windows\system32\MsiExec.exe -Embedding F54DAA71C7C0D71515C2514DC4858C85 CC:\Windows\System32\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2640C:\Windows\system32\MsiExec.exe -Embedding 71DBFE12292722C8C0D9E98D245ECE94C:\Windows\System32\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2760"C:\Users\admin\AppData\Local\Temp\Rar$EXa1072.11558\Crypto Wallet Cracker\setup.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa1072.11558\Crypto Wallet Cracker\setup.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup
Exit code:
0
Version:
17.0.33606.225 built by: D17.6
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa1072.11558\crypto wallet cracker\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
Total events
4 288
Read events
4 236
Write events
42
Delete events
10

Modification events

(PID) Process:(1072) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1072) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(1072) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(1072) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(1072) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(1072) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1072) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1072) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1072) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1072) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
13
Suspicious files
14
Text files
10
Unknown types
0

Dropped files

PID
Process
Filename
Type
2084msiexec.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
1072WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1072.9221\Crypto Wallet Cracker\Crypto Wallet Cracker v2.3.vdprojtext
MD5:79D8C90C172F14DDDCC58EA59E32F849
SHA256:0663E2DBB6D20D51A642B5D43510BCD1B19DAB31C84D5E6BEFDD687B0E90E91C
1072WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1072.9221\Crypto Wallet Cracker\Crypto Wallet Cracker v2.3.msiexecutable
MD5:0AA7BC441695F50C63F180B6BB8A084D
SHA256:3F061D6733F9BF1F147C2FEB0768F8FE992957C5AB2895BBF01D16C9E7A16C32
1072WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1072.9221\Crypto Wallet Cracker\READ ME.txttext
MD5:BBAAB329B3A3525A8371DFF7B82530BE
SHA256:D0B85BF4294B63D53E9534FF6E94E0016204F19E3368ECCAAF004265B8765253
1072WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1072.9221\Crypto Wallet Cracker\NOT WORKING.txttext
MD5:163F421ABE0A1639A3BB88635334E845
SHA256:FB78A19EDA3DA2D339E8C38F2D04B8A1A8D34605158E9B2A240D9D4E2E7AD34B
2032msiexec.exeC:\Users\admin\AppData\Local\Temp\MSI1FAA.tmpexecutable
MD5:B77A2A2768B9CC78A71BBFFB9812B978
SHA256:F74C97B1A53541B059D3BFAFE41A79005CE5065F8210D7DE9F1B600DC4E28AA0
1072WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1072.9221\Crypto Wallet Cracker\KEY.txttext
MD5:B27F172B3E1C1B44F8B2FF95CB7E6DC0
SHA256:5ECA853F0D2D5E137479BEFCD83C87416E7D6D4A18B4676DB7617585FBC101E9
2032msiexec.exeC:\Users\admin\AppData\Local\Temp\MSI1F4B.tmpexecutable
MD5:B77A2A2768B9CC78A71BBFFB9812B978
SHA256:F74C97B1A53541B059D3BFAFE41A79005CE5065F8210D7DE9F1B600DC4E28AA0
2084msiexec.exeC:\Windows\Installer\e5b6a.msiexecutable
MD5:0AA7BC441695F50C63F180B6BB8A084D
SHA256:3F061D6733F9BF1F147C2FEB0768F8FE992957C5AB2895BBF01D16C9E7A16C32
1072WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1072.9221\Crypto Wallet Cracker\setup.exeexecutable
MD5:A2E415FCAC3787D749EEE6F7817B4C4B
SHA256:ED7481B49BACDFC9B2DB2CB1C6203CA29E4CB1F5BD657094F23B29CA8216BF3E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted

DNS requests

No data

Threats

No threats detected
No debug info