| File name: | GameAssist.zip |
| Full analysis: | https://app.any.run/tasks/ffae47b7-47d1-4791-a4cd-c455a4a8db43 |
| Verdict: | Malicious activity |
| Analysis date: | May 13, 2021, 17:49:57 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | 17DB055B1239A9F81EFACA380F5D1B02 |
| SHA1: | B76D92835A39182EAFF5A3A6D16B18237924FCEE |
| SHA256: | ECBCDDA9C43CE659CA2E8E5A42E5B6EFC1A068947E8C618BFF7EB3E121C79F8C |
| SSDEEP: | 49152:fzLt2lGToSZvARJRNx3Do5zPErN7pqWf0BIM1PaPpowWWiWLd6U7/lgzo+hOAlIC:fzLtOGwNWa3qWcBIM1PaBofWLld2o+ht |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipFileName: | GameAssist.exe |
|---|---|
| ZipUncompressedSize: | 4778072 |
| ZipCompressedSize: | 2440392 |
| ZipCRC: | 0x427ee52d |
| ZipModifyDate: | 2021:05:03 13:43:16 |
| ZipCompression: | Deflated |
| ZipBitFlag: | - |
| ZipRequiredVersion: | 20 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1112 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\GameAssist.zip" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| (PID) Process: | (1112) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (1112) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (1112) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\13C\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (1112) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\13C\52C64B7E |
| Operation: | write | Name: | @C:\Windows\system32\NetworkExplorer.dll,-1 |
Value: Network | |||
| (PID) Process: | (1112) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\GameAssist.zip | |||
| (PID) Process: | (1112) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (1112) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (1112) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (1112) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (1112) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin |
| Operation: | write | Name: | Placement |
Value: 2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1112 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1112.8193\Language\English.ini | text | |
MD5:— | SHA256:— | |||
| 1112 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1112.8193\Language\Chinese(Simplified).ini | text | |
MD5:— | SHA256:— | |||
| 1112 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1112.8193\SensorUWP64.dll | executable | |
MD5:— | SHA256:— | |||
| 1112 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1112.8193\Language\Readme.txt | text | |
MD5:— | SHA256:— | |||
| 1112 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1112.8193\GameAssistDB.dll | executable | |
MD5:— | SHA256:— | |||
| 1112 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1112.8193\Language\Korean.ini | text | |
MD5:— | SHA256:— | |||
| 1112 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1112.8193\inpoutx64.sys | executable | |
MD5:9321A61A25C7961D9F36852ECAA86F55 | SHA256:F8965FDCE668692C3785AFA3559159F9A18287BC0D53ABB21902895A8ECF221B | |||
| 1112 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1112.8193\WinRing0x64.sys | executable | |
MD5:0C0195C48B6B8582FA6F6373032118DA | SHA256:11BD2C9F9E2397C9A16E0990E4ED2CF0679498FE0FD418A3DFDAC60B5C160EE5 | |||
| 1112 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1112.8193\WinRing0x64.dll | executable | |
MD5:0030377FA9248751F0B9F56BBD8170AD | SHA256:7E07F66CF41CAC81B1DAE4C5FBC218A98C98FC84B18AC20CAEC7EF6CDF7E250C | |||
| 1112 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa1112.8193\inpoutx64.dll | executable | |
MD5:AC0C3AE82EC0764C605FA59E7BF05614 | SHA256:5F27ED4D5CD58A1EE23DEEB802E09E73F3A1D884CE2135F6E827F67B171269E7 | |||