| download: | 887Rat-main.rar |
| Full analysis: | https://app.any.run/tasks/9c6c3e0b-bd06-42c3-b229-42739d5f1fee |
| Verdict: | Malicious activity |
| Analysis date: | August 12, 2022, 15:36:39 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v4, os: Win32, flags: RecoveryRecordPresent |
| MD5: | D7D11FB25A956C2DFC55B46A3B91940A |
| SHA1: | 56A2C72BC1C0A38E3AD15FC34CF360BF93A76659 |
| SHA256: | E27CC65C2A28268E8124719D88075AC9E22DB2A99120EDA1D700DB2519AF3C85 |
| SSDEEP: | 1572864:Sw2BUF2RxxB2B3EWbR2PG3yVqUSMglchm9yXnNEoNafYH1QChZ0/n6J:8B82RxbyELPGyaRLsXnNnNP1h2n6J |
| .rar | | | RAR compressed archive (v-4.x) (58.3) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (41.6) |
| ArchivedFileName: | 887Rat-main\887Rat-main.exe |
|---|---|
| PackingMethod: | Stored |
| ModifyDate: | 2022:06:10 20:38:26 |
| OperatingSystem: | Win32 |
| UncompressedSize: | 100450172 |
| CompressedSize: | 100450225 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 372 | "C:\Users\admin\Desktop\887Rat-main\AQACVJ.exe" | C:\Users\admin\Desktop\887Rat-main\AQACVJ.exe | Explorer.EXE | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Version: 3, 3, 8, 1 Modules
| |||||||||||||||
| 892 | "C:\Users\admin\Desktop\887Rat-main\crack.exe" | C:\Users\admin\Desktop\887Rat-main\crack.exe | Explorer.EXE | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 1760 | "C:\Users\admin\Desktop\887Rat-main\crack.exe" | C:\Users\admin\Desktop\887Rat-main\crack.exe | 887Rat-main.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 1864 | C:\Users\admin\AppData\Local\Temp\Aut2exe.exe /in C:\Users\admin\AppData\Local\Temp/AVNLUS /out C:\Users\admin\AppData\Local\Temp/PNCOMD.exe /icon C:\Users\admin\AppData\Local\Temp\ssc.ico /comp 2 /nopack /Unicode | C:\Users\admin\AppData\Local\Temp\Aut2exe.exe | 887Rat.exe | ||||||||||||
User: admin Company: AutoIt Team Integrity Level: MEDIUM Description: Aut2Exe Exit code: 0 Version: 3, 3, 8, 1 Modules
| |||||||||||||||
| 2248 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\887Rat-main\887Rat-main.exe" | C:\Program Files\WinRAR\WinRAR.exe | — | Explorer.EXE | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 2572 | "C:\Users\admin\AppData\Local\Temp\exe2msi.exe" | C:\Users\admin\AppData\Local\Temp\exe2msi.exe | — | 887Rat.exe | |||||||||||
User: admin Company: APREL Technologies Integrity Level: MEDIUM Description: Exe to MSI Conveter Exit code: 0 Version: 2.0 Modules
| |||||||||||||||
| 2600 | C:\Users\admin\AppData\Local\Temp\Aut2exe.exe /in C:\Users\admin\AppData\Local\Temp/QDZPLS /out C:\Users\admin\AppData\Local\Temp/AQACVJ.exe /icon C:\Users\admin\AppData\Local\Temp\ssc.ico /comp 2 /nopack /Unicode | C:\Users\admin\AppData\Local\Temp\Aut2exe.exe | 887Rat.exe | ||||||||||||
User: admin Company: AutoIt Team Integrity Level: MEDIUM Description: Aut2Exe Exit code: 0 Version: 3, 3, 8, 1 Modules
| |||||||||||||||
| 3012 | "C:\Users\admin\Desktop\887Rat-main\PNCOMD.exe" | C:\Users\admin\Desktop\887Rat-main\PNCOMD.exe | — | Explorer.EXE | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Version: 3, 3, 8, 1 Modules
| |||||||||||||||
| 3116 | "C:\Users\admin\Desktop\887Rat-main\887Rat.exe" | C:\Users\admin\Desktop\887Rat-main\887Rat.exe | Explorer.EXE | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 3132 | "C:\Users\admin\Desktop\887Rat-main\887Rat-main.exe" | C:\Users\admin\Desktop\887Rat-main\887Rat-main.exe | Explorer.EXE | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| (PID) Process: | (3532) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3532) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3532) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3532) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (3532) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (3532) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\887Rat-main.rar | |||
| (PID) Process: | (3532) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3532) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3532) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3532) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3532 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3532.33003\887Rat-main\887Rat-main.exe | — | |
MD5:— | SHA256:— | |||
| 3132 | 887Rat-main.exe | C:\Users\admin\Desktop\887Rat-main\887Rat.exe | — | |
MD5:— | SHA256:— | |||
| 3116 | 887Rat.exe | C:\Users\admin\AppData\Local\Temp\aut8E32.tmp | — | |
MD5:— | SHA256:— | |||
| 3116 | 887Rat.exe | C:\Users\admin\AppData\Local\Temp\ziwbnfi | — | |
MD5:— | SHA256:— | |||
| 3132 | 887Rat-main.exe | C:\Users\admin\Desktop\887Rat-main\crack.exe | executable | |
MD5:A0A22BA1E62B67B91905665B86DF33B3 | SHA256:E3CB33466BED760B23A24BD723B68CCB5DA82EE350793F4CDE7AA5AD53541B94 | |||
| 3116 | 887Rat.exe | C:\Users\admin\AppData\Local\Temp\skin.888Gre.msstyles | executable | |
MD5:BE3A84875ADC7D0B536E303D02EEC694 | SHA256:116A4D6121EC515E2117C136B54D9C359929C720F50536E41C9DF050C9D4628F | |||
| 3132 | 887Rat-main.exe | C:\Users\admin\Desktop\887Rat-main\learn all kind of hacking.url | url | |
MD5:7ADE4A739CBD8F44D0EF52A2F1BC6E7B | SHA256:CC7649ED53C65E4851ACE414529564FE16801BB2BED4CB15588BFD6B4AC13616 | |||
| 3116 | 887Rat.exe | C:\Users\admin\AppData\Local\Temp\skin.dll | executable | |
MD5:29E1D5770184BF45139084BCED50D306 | SHA256:794987C4069286F797631F936C73B925C663C42D552AECA821106DFC7C7BA307 | |||
| 3116 | 887Rat.exe | C:\Users\admin\AppData\Local\Temp\autA9CD.tmp | binary | |
MD5:E2323BCE869FD1FF07BAD42D5B6AD64E | SHA256:886DACD85465BF0ABFEA19A0B52E6E42C6937BA60E5EC320FC4856925D975BD1 | |||
| 3116 | 887Rat.exe | C:\Users\admin\AppData\Local\Temp\autA5E1.tmp | binary | |
MD5:45560860BD0124A558B78D440C2C9DF7 | SHA256:CB4906BE641770E2D24165A2CE804529C9CD96EE26029458E8A0E869CA1C5E88 | |||