| File name: | All.ElectroRAT.zip |
| Full analysis: | https://app.any.run/tasks/3667be01-6622-4d82-8ec9-aaa693c89378 |
| Verdict: | Malicious activity |
| Analysis date: | August 16, 2023, 00:20:53 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | 7FF8D31AD43F62F1C6876B725A1EBB1F |
| SHA1: | E23BAF502BF5B2EB81FEA0A2E570E7ADE8998BEE |
| SHA256: | DDA14413450A11F336A8305CF274943D614905C3429D4F0EFEFFE6BF4B8B7BDC |
| SSDEEP: | 12288:yykcN4NEaT6082MQxzgoOnAlUiQNd83MBBPXyyg1/UgGc3G4af3ENPNBAIhH6oRt:vkckET92MAs8oNvLKBU5l4iCsWvVbGo |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipFileName: | 0468127a19daf4c7bc41015c5640fe1f |
|---|---|
| ZipUncompressedSize: | 124616 |
| ZipCompressedSize: | 54732 |
| ZipCRC: | 0xef53b4ac |
| ZipModifyDate: | 2021:03:28 13:43:32 |
| ZipCompression: | Deflated |
| ZipBitFlag: | 0x0001 |
| ZipRequiredVersion: | 788 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 692 | "C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\Desktop\fatherscientific.rtf" | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Word Exit code: 0 Version: 14.0.6024.1000 Modules
| |||||||||||||||
| 900 | "C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\AppData\Local\Temp\Rar$DIb3484.35161\ca467e332368cbae652245faa4978aa4" | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | — | rundll32.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Word Exit code: 0 Version: 14.0.6024.1000 Modules
| |||||||||||||||
| 908 | "C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\AppData\Local\Temp\Rar$DIb3484.33123\b154ac015c0d1d6250032f63c749f9cf | C:\Windows\System32\rundll32.exe | — | WinRAR.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1040 | "C:\Program Files\Internet Explorer\iexplore.exe" C:\Users\admin\AppData\Local\Temp\Rar$DIb3484.33123\b154ac015c0d1d6250032f63c749f9cf | C:\Program Files\Internet Explorer\iexplore.exe | — | rundll32.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Exit code: 1 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| 1348 | "C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\AppData\Local\Temp\Rar$DIb3484.31409\0468127a19daf4c7bc41015c5640fe1f | C:\Windows\System32\rundll32.exe | — | WinRAR.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2028 | "C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\AppData\Local\Temp\Rar$DIb3484.35161\ca467e332368cbae652245faa4978aa4 | C:\Windows\System32\rundll32.exe | — | WinRAR.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2040 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:1040 CREDAT:144385 /prefetch:2 | C:\Program Files\Internet Explorer\iexplore.exe | — | iexplore.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| 2440 | "C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\AppData\Local\Temp\Rar$DIb3484.27589\2a3b92f6180367306d750e59c9b6446b | C:\Windows\System32\rundll32.exe | — | iexplore.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2472 | "C:\Program Files\Internet Explorer\iexplore.exe" C:\Users\admin\AppData\Local\Temp\Rar$DIb3484.27589\2a3b92f6180367306d750e59c9b6446b | C:\Program Files\Internet Explorer\iexplore.exe | — | rundll32.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Exit code: 1 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| 2476 | "C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\AppData\Local\Temp\Rar$DIb3484.27589\2a3b92f6180367306d750e59c9b6446b | C:\Windows\System32\rundll32.exe | — | WinRAR.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (3484) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3484) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (3484) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (3484) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (3484) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3484) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3484) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3484) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (3484) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (3484) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 900 | WINWORD.EXE | C:\Users\admin\AppData\Local\Temp\CVR276B.tmp.cvr | — | |
MD5:— | SHA256:— | |||
| 1040 | iexplore.exe | C:\Users\admin\AppData\Local\Temp\~DF795AC9656252F904.TMP | binary | |
MD5:185FAF8FD3B71DA67FC3DBBAD3ADDBD4 | SHA256:9680C1D88090D2C67E841E21B851B89B937D4E8A1F50BBF03F6FFF3256A6977A | |||
| 900 | WINWORD.EXE | C:\Users\admin\AppData\Roaming\Microsoft\Templates\~$Normal.dotm | binary | |
MD5:F51F4D12E7E33176B1B1E326C256423C | SHA256:B66FB8AF4021B7BA74391EDE255A761C686EA34F766EF778517C98F91E415A46 | |||
| 3484 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DIb3484.27589\2a3b92f6180367306d750e59c9b6446b | executable | |
MD5:2A3B92F6180367306D750E59C9B6446B | SHA256:18FD6B193BE1D5416A3188F5D9E4047CCA719FA067D7D0169CF2DF5C7FED54C0 | |||
| 2472 | iexplore.exe | C:\Users\admin\AppData\Local\Temp\~DF95A9DD19BF6AA33F.TMP | binary | |
MD5:62DDBB08C00DC380D4CA3F21809F2FE3 | SHA256:0BCFE195DA9888A1AC0B1555813ACCE454A1D148F1A23A3FAFEA19D3EABB430E | |||
| 2472 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{DF51C65B-3BCA-11EE-ACBF-12A9866C77DE}.dat | binary | |
MD5:CC5F7AA52DB72690F369B5C0FAAD033F | SHA256:D75D15028D41338FDAF9F09A950079BC56F27CDD89C9214E745AA5415E455383 | |||
| 692 | WINWORD.EXE | C:\Users\admin\AppData\Local\Temp\CVR7397.tmp.cvr | — | |
MD5:— | SHA256:— | |||
| 2472 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{DF51C659-3BCA-11EE-ACBF-12A9866C77DE}.dat | binary | |
MD5:9EB3B15CD5778D220211921834F7DD62 | SHA256:4EE44A264E255B238ED72FF7E7D810AD73CC8347C34994043CAAF647575EC30B | |||
| 2472 | iexplore.exe | C:\Users\admin\AppData\Local\Temp\~DFD44A1CDF4148B20D.TMP | binary | |
MD5:66F233E55E1284F093EAA8ACDC34F7E8 | SHA256:AFCDD85F8F47F279A9B50E04B27718DF41ACE8A856254E7776A2C7D29BE97822 | |||
| 3484 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DIb3484.31409\0468127a19daf4c7bc41015c5640fe1f | executable | |
MD5:0468127A19DAF4C7BC41015C5640FE1F | SHA256:DD1792BCDF560EBAA633F72DE4037E78FE1ADA5C8694B9D4879554AEDC323AC9 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |