| download: | ZKW_Tools.bat |
| Full analysis: | https://app.any.run/tasks/0cd0f798-e1e6-46bc-abd5-4f7ac7446f0a |
| Verdict: | Malicious activity |
| Analysis date: | September 12, 2020, 07:54:55 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | text/x-msdos-batch |
| File info: | DOS batch file, ISO-8859 text, with CRLF line terminators |
| MD5: | 48D527F9D95CA8D13461C100188E9F3D |
| SHA1: | AE5DC6E6023BC7414E6822EFA95AC540C8F927EF |
| SHA256: | EDC61EE4D1D4266E00AE2DAD9D881BE8D92C8DBB08EE4724754FCA588DE149EB |
| SSDEEP: | 192:UrtoPpdgO+Y3xIxoTAU7serMF4q0/Fju/bOEgEQviVTGFYZ+9yviU:CIRR/FjxMqFq+9yviU |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 296 | batbox -g 1 3 -c 0x8f -d "Faite 'B' pour acceder au " -c 0x8a -d "'Booter' " -c 0x84 -d "[Beta]" | C:\Users\admin\AppData\Local\Temp\batbox.exe | — | cmd.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 440 | attrib +h batbox.exe | C:\Windows\system32\attrib.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Attribute Utility Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 560 | batbox -g 1 6 -c 0x8b -d "[03/09/2018-08:40] Ajout du bouton " -c 0x8f -d "'S' (Soon...)" | C:\Users\admin\AppData\Local\Temp\batbox.exe | — | cmd.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 560 | batbox -w 10 | C:\Users\admin\AppData\Local\Temp\batbox.exe | — | cmd.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 672 | batbox -g 1 3 -c 0x8b -d "[02/09/2018-19:40] Modification du nom pour " -c 0x8f -d "[ - Farm a IP -???????????? n░?????- v0.6.9 - ]" | C:\Users\admin\AppData\Local\Temp\batbox.exe | — | cmd.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 924 | timeout /t 5 /nobreak | C:\Windows\system32\timeout.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: timeout - pauses command processing Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 988 | batbox -g 1 10 -c 0x8b -d "[05/09/2018-14:32] Modification du nom pour " -c 0x8f -d "[ - tiwen Tools - ???????????? n░????? - v1.3.3 - ]" | C:\Users\admin\AppData\Local\Temp\batbox.exe | — | cmd.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 1196 | batbox -g 1 15 -c 0x8b -d "[05/09/2018-18:05] Modification du " -c 0x8f -d "Menu de l" -c 0x85 -d "'Archive'" | C:\Users\admin\AppData\Local\Temp\batbox.exe | — | cmd.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 1228 | batbox -g 1 9 -c 0x8b -d "[03/09/2018-20:48] 2 Bugs " -c 0x8f -d "Fixed" | C:\Users\admin\AppData\Local\Temp\batbox.exe | — | cmd.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 1736 | batbox -g 1 5 -c 0x8f -d "Faite 'L' pour acceder a l" -c 0x8e -d "'Auto-Lag' " -c 0x84 -d "[Beta]" | C:\Users\admin\AppData\Local\Temp\batbox.exe | — | cmd.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3164 | cmd.exe | C:\Users\admin\AppData\Local\Temp\batbox.ex_ | — | |
MD5:— | SHA256:— | |||
| 3844 | expand.exe | C:\Users\admin\AppData\Local\Temp\$dpx$.tmp\154251493650b9408a3d706c28d318c0.tmp | — | |
MD5:— | SHA256:— | |||
| 3164 | cmd.exe | C:\Users\admin\AppData\Local\Temp\t.dat | text | |
MD5:— | SHA256:— | |||
| 3164 | cmd.exe | C:\Users\admin\AppData\Local\Temp\orther\change_log\log1.4.7 | text | |
MD5:— | SHA256:— | |||
| 3844 | expand.exe | C:\Users\admin\AppData\Local\Temp\batbox.exe | executable | |
MD5:A429CC48C9EB59D7642FC7479508903C | SHA256:8C6C18E14E4462C7BB767B8E6872ED36181F56EF22ADE115DCC824773357449A | |||