analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

DarkCometRemover2.zip

Full analysis: https://app.any.run/tasks/f2ffb39f-79e7-4a5a-844e-7efc8bc46e37
Verdict: Malicious activity
Analysis date: January 10, 2019, 22:11:36
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

68D2476642C39BB006BBFBCC49B12EE0

SHA1:

E92A315DE91B10F6592884F2C994562B20D81870

SHA256:

E287187858CFFDE36A94466CAB322CD803E4FA521448C8B89C457700D0601C0D

SSDEEP:

24576:CgUm+GBf2n4CE9S5EER1H6/0t2pmN4DzwyNbjeaj6ZGhvG9ENCi2t515K3lk:jHGdmbct2pmN4DBVS2bhvK29015A2

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • DarkCometRemover2_setup.exe (PID: 3512)
      • DarkCometRemover2_setup.exe (PID: 3280)
      • DCRem.exe (PID: 2752)
      • DarkComet Remover 2 Portable.exe (PID: 2812)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3028)
      • DarkCometRemover2_setup.exe (PID: 3280)
      • DarkCometRemover2_setup.exe (PID: 3512)
      • DarkCometRemover2_setup.tmp (PID: 3668)
    • Reads Windows owner or organization settings

      • DarkCometRemover2_setup.tmp (PID: 3668)
    • Reads the Windows organization settings

      • DarkCometRemover2_setup.tmp (PID: 3668)
    • Creates files in the user directory

      • DarkCometRemover2_setup.tmp (PID: 3668)
  • INFO

    • Application was dropped or rewritten from another process

      • DarkCometRemover2_setup.tmp (PID: 3668)
      • DarkCometRemover2_setup.tmp (PID: 3924)
    • Loads dropped or rewritten executable

      • DarkCometRemover2_setup.tmp (PID: 3668)
    • Creates files in the program directory

      • DarkCometRemover2_setup.tmp (PID: 3668)
    • Creates a software uninstall entry

      • DarkCometRemover2_setup.tmp (PID: 3668)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: DarkCometRemover2_setup.exe
ZipUncompressedSize: 1093409
ZipCompressedSize: 1021505
ZipCRC: 0x39db055f
ZipModifyDate: 2013:04:08 21:37:25
ZipCompression: Deflated
ZipBitFlag: -
ZipRequiredVersion: 20
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
40
Monitored processes
7
Malicious processes
2
Suspicious processes
3

Behavior graph

Click at the process to see the details
drop and start drop and start start drop and start drop and start winrar.exe darkcometremover2_setup.exe darkcometremover2_setup.tmp no specs darkcometremover2_setup.exe darkcometremover2_setup.tmp dcrem.exe no specs darkcomet remover 2 portable.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3028"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\DarkCometRemover2.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.60.0
3512"C:\Users\admin\AppData\Local\Temp\Rar$EXa3028.33660\DarkCometRemover2_setup.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3028.33660\DarkCometRemover2_setup.exe
WinRAR.exe
User:
admin
Company:
Phrozen ® Software 2013.
Integrity Level:
MEDIUM
Description:
DarkComet Remover Setup
Exit code:
0
Version:
3924"C:\Users\admin\AppData\Local\Temp\is-AGLE6.tmp\DarkCometRemover2_setup.tmp" /SL5="$3013E,680460,118784,C:\Users\admin\AppData\Local\Temp\Rar$EXa3028.33660\DarkCometRemover2_setup.exe" C:\Users\admin\AppData\Local\Temp\is-AGLE6.tmp\DarkCometRemover2_setup.tmpDarkCometRemover2_setup.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
3280"C:\Users\admin\AppData\Local\Temp\Rar$EXa3028.33660\DarkCometRemover2_setup.exe" /SPAWNWND=$2015E /NOTIFYWND=$3013E C:\Users\admin\AppData\Local\Temp\Rar$EXa3028.33660\DarkCometRemover2_setup.exe
DarkCometRemover2_setup.tmp
User:
admin
Company:
Phrozen ® Software 2013.
Integrity Level:
HIGH
Description:
DarkComet Remover Setup
Exit code:
0
Version:
3668"C:\Users\admin\AppData\Local\Temp\is-TDR10.tmp\DarkCometRemover2_setup.tmp" /SL5="$3015C,680460,118784,C:\Users\admin\AppData\Local\Temp\Rar$EXa3028.33660\DarkCometRemover2_setup.exe" /SPAWNWND=$2015E /NOTIFYWND=$3013E C:\Users\admin\AppData\Local\Temp\is-TDR10.tmp\DarkCometRemover2_setup.tmp
DarkCometRemover2_setup.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
2752"C:\Users\admin\AppData\Roaming\PhrozenSoft\DCREM\DCRem.exe" C:\Users\admin\AppData\Roaming\PhrozenSoft\DCREM\DCRem.exeexplorer.exe
User:
admin
Company:
PhrozenSoft
Integrity Level:
MEDIUM
Description:
DarkComet RAT Remover
Version:
1.0.0.0
2812"C:\Users\admin\AppData\Local\Temp\Rar$EXa3028.35902\DarkComet Remover 2 Portable.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3028.35902\DarkComet Remover 2 Portable.exeWinRAR.exe
User:
admin
Company:
PhrozenSoft
Integrity Level:
MEDIUM
Description:
DarkComet RAT Remover
Exit code:
0
Version:
1.0.0.0
Total events
1 215
Read events
1 171
Write events
0
Delete events
0

Modification events

No data
Executable files
9
Suspicious files
0
Text files
0
Unknown types
3

Dropped files

PID
Process
Filename
Type
3668DarkCometRemover2_setup.tmpC:\Users\admin\AppData\Roaming\PhrozenSoft\DCREM\is-4ON1N.tmp
MD5:
SHA256:
3668DarkCometRemover2_setup.tmpC:\Users\admin\AppData\Roaming\PhrozenSoft\DCREM\is-ARLG9.tmp
MD5:
SHA256:
3028WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3028.35902\DarkCometRemover2_setup.exeexecutable
MD5:32DD87BFDC6B70EF1B54A086DA6F17EA
SHA256:DA17F059651B0F3E040C26A7C896D835EF3678BC295C1D61C79482D156CD805F
3028WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3028.33660\DarkCometRemover2_setup.exeexecutable
MD5:32DD87BFDC6B70EF1B54A086DA6F17EA
SHA256:DA17F059651B0F3E040C26A7C896D835EF3678BC295C1D61C79482D156CD805F
3668DarkCometRemover2_setup.tmpC:\Users\Public\Desktop\DarkComet Remover.lnklnk
MD5:8F385A053A17DAFCA331C0223749B524
SHA256:A41E7584A7CBD89D665549D4014A7F217F6E3FFADA9891E1B396620DC684608B
3668DarkCometRemover2_setup.tmpC:\Users\admin\AppData\Roaming\PhrozenSoft\DCREM\unins000.datdat
MD5:26EA0876A0C0F22BA59A0268C8684A5F
SHA256:B546D832D12AF09B585FE0C93CFA15D81C2191AD5B8D61EED197E4ED5067EAE3
3668DarkCometRemover2_setup.tmpC:\Users\admin\AppData\Roaming\PhrozenSoft\DCREM\DCRem.exeexecutable
MD5:6DAB7A8337FFA447F69F8F4679D643A2
SHA256:1F58B6693C925A1E35896F6FFE6B46B20016A98262A2FC4186577B845FF1851C
3668DarkCometRemover2_setup.tmpC:\Users\admin\AppData\Roaming\PhrozenSoft\DCREM\unins000.exeexecutable
MD5:36766B69EC50D7311527DF48F5CE8A18
SHA256:CEC4D2495DCCAC066A89FB032F71AA86A443293547EB9BDA3C5E1A90E591AEFD
3028WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3028.33660\DarkComet Remover 2 Portable.exeexecutable
MD5:6DAB7A8337FFA447F69F8F4679D643A2
SHA256:1F58B6693C925A1E35896F6FFE6B46B20016A98262A2FC4186577B845FF1851C
3668DarkCometRemover2_setup.tmpC:\ProgramData\Microsoft\Windows\Start Menu\Programs\DarkComet Remover\DarkComet Remover.lnklnk
MD5:6B9119D80B5B143CA108F409BF87CD32
SHA256:AB1A0C2C587414EF351DA7EDE978BC813643ED9043E75EDC0E041E4D3A35DB17
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info