File name: | DarkCometRemover2.zip |
Full analysis: | https://app.any.run/tasks/f2ffb39f-79e7-4a5a-844e-7efc8bc46e37 |
Verdict: | Malicious activity |
Analysis date: | January 10, 2019, 22:11:36 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/zip |
File info: | Zip archive data, at least v2.0 to extract |
MD5: | 68D2476642C39BB006BBFBCC49B12EE0 |
SHA1: | E92A315DE91B10F6592884F2C994562B20D81870 |
SHA256: | E287187858CFFDE36A94466CAB322CD803E4FA521448C8B89C457700D0601C0D |
SSDEEP: | 24576:CgUm+GBf2n4CE9S5EER1H6/0t2pmN4DzwyNbjeaj6ZGhvG9ENCi2t515K3lk:jHGdmbct2pmN4DBVS2bhvK29015A2 |
.zip | | | ZIP compressed archive (100) |
---|
ZipFileName: | DarkCometRemover2_setup.exe |
---|---|
ZipUncompressedSize: | 1093409 |
ZipCompressedSize: | 1021505 |
ZipCRC: | 0x39db055f |
ZipModifyDate: | 2013:04:08 21:37:25 |
ZipCompression: | Deflated |
ZipBitFlag: | - |
ZipRequiredVersion: | 20 |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
3028 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\DarkCometRemover2.zip" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | |
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Version: 5.60.0 | ||||
3512 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa3028.33660\DarkCometRemover2_setup.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa3028.33660\DarkCometRemover2_setup.exe | WinRAR.exe | |
User: admin Company: Phrozen ® Software 2013. Integrity Level: MEDIUM Description: DarkComet Remover Setup Exit code: 0 Version: | ||||
3924 | "C:\Users\admin\AppData\Local\Temp\is-AGLE6.tmp\DarkCometRemover2_setup.tmp" /SL5="$3013E,680460,118784,C:\Users\admin\AppData\Local\Temp\Rar$EXa3028.33660\DarkCometRemover2_setup.exe" | C:\Users\admin\AppData\Local\Temp\is-AGLE6.tmp\DarkCometRemover2_setup.tmp | — | DarkCometRemover2_setup.exe |
User: admin Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 | ||||
3280 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa3028.33660\DarkCometRemover2_setup.exe" /SPAWNWND=$2015E /NOTIFYWND=$3013E | C:\Users\admin\AppData\Local\Temp\Rar$EXa3028.33660\DarkCometRemover2_setup.exe | DarkCometRemover2_setup.tmp | |
User: admin Company: Phrozen ® Software 2013. Integrity Level: HIGH Description: DarkComet Remover Setup Exit code: 0 Version: | ||||
3668 | "C:\Users\admin\AppData\Local\Temp\is-TDR10.tmp\DarkCometRemover2_setup.tmp" /SL5="$3015C,680460,118784,C:\Users\admin\AppData\Local\Temp\Rar$EXa3028.33660\DarkCometRemover2_setup.exe" /SPAWNWND=$2015E /NOTIFYWND=$3013E | C:\Users\admin\AppData\Local\Temp\is-TDR10.tmp\DarkCometRemover2_setup.tmp | DarkCometRemover2_setup.exe | |
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 | ||||
2752 | "C:\Users\admin\AppData\Roaming\PhrozenSoft\DCREM\DCRem.exe" | C:\Users\admin\AppData\Roaming\PhrozenSoft\DCREM\DCRem.exe | — | explorer.exe |
User: admin Company: PhrozenSoft Integrity Level: MEDIUM Description: DarkComet RAT Remover Version: 1.0.0.0 | ||||
2812 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa3028.35902\DarkComet Remover 2 Portable.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa3028.35902\DarkComet Remover 2 Portable.exe | — | WinRAR.exe |
User: admin Company: PhrozenSoft Integrity Level: MEDIUM Description: DarkComet RAT Remover Exit code: 0 Version: 1.0.0.0 |
PID | Process | Filename | Type | |
---|---|---|---|---|
3668 | DarkCometRemover2_setup.tmp | C:\Users\admin\AppData\Roaming\PhrozenSoft\DCREM\is-4ON1N.tmp | — | |
MD5:— | SHA256:— | |||
3668 | DarkCometRemover2_setup.tmp | C:\Users\admin\AppData\Roaming\PhrozenSoft\DCREM\is-ARLG9.tmp | — | |
MD5:— | SHA256:— | |||
3028 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3028.35902\DarkCometRemover2_setup.exe | executable | |
MD5:32DD87BFDC6B70EF1B54A086DA6F17EA | SHA256:DA17F059651B0F3E040C26A7C896D835EF3678BC295C1D61C79482D156CD805F | |||
3028 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3028.33660\DarkCometRemover2_setup.exe | executable | |
MD5:32DD87BFDC6B70EF1B54A086DA6F17EA | SHA256:DA17F059651B0F3E040C26A7C896D835EF3678BC295C1D61C79482D156CD805F | |||
3668 | DarkCometRemover2_setup.tmp | C:\Users\Public\Desktop\DarkComet Remover.lnk | lnk | |
MD5:8F385A053A17DAFCA331C0223749B524 | SHA256:A41E7584A7CBD89D665549D4014A7F217F6E3FFADA9891E1B396620DC684608B | |||
3668 | DarkCometRemover2_setup.tmp | C:\Users\admin\AppData\Roaming\PhrozenSoft\DCREM\unins000.dat | dat | |
MD5:26EA0876A0C0F22BA59A0268C8684A5F | SHA256:B546D832D12AF09B585FE0C93CFA15D81C2191AD5B8D61EED197E4ED5067EAE3 | |||
3668 | DarkCometRemover2_setup.tmp | C:\Users\admin\AppData\Roaming\PhrozenSoft\DCREM\DCRem.exe | executable | |
MD5:6DAB7A8337FFA447F69F8F4679D643A2 | SHA256:1F58B6693C925A1E35896F6FFE6B46B20016A98262A2FC4186577B845FF1851C | |||
3668 | DarkCometRemover2_setup.tmp | C:\Users\admin\AppData\Roaming\PhrozenSoft\DCREM\unins000.exe | executable | |
MD5:36766B69EC50D7311527DF48F5CE8A18 | SHA256:CEC4D2495DCCAC066A89FB032F71AA86A443293547EB9BDA3C5E1A90E591AEFD | |||
3028 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3028.33660\DarkComet Remover 2 Portable.exe | executable | |
MD5:6DAB7A8337FFA447F69F8F4679D643A2 | SHA256:1F58B6693C925A1E35896F6FFE6B46B20016A98262A2FC4186577B845FF1851C | |||
3668 | DarkCometRemover2_setup.tmp | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DarkComet Remover\DarkComet Remover.lnk | lnk | |
MD5:6B9119D80B5B143CA108F409BF87CD32 | SHA256:AB1A0C2C587414EF351DA7EDE978BC813643ED9043E75EDC0E041E4D3A35DB17 |