File name:

ESANTCOW11_015_2024-02-29_13_46_01.997.zip

Full analysis: https://app.any.run/tasks/2b545362-ae32-4388-bc78-aaab80536b93
Verdict: Malicious activity
Analysis date: February 29, 2024, 14:07:52
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v4.5 to extract, compression method=deflate
MD5:

38157D5C5F4CA276F2BFB630496EEC64

SHA1:

76E99E8076ACC0169B9F6FEB54B7596AD44E2884

SHA256:

EE7827933E95E4BAE8D258AE5E2F89547CB06AC2820F7ABD42E908DF0B7A8444

SSDEEP:

49152:yY32WbFq8pdHFBremhCYjsZ1Fm1o6ckbNvDOTlQ0ThJJaWDQy5+I+e7RpGtK+2Ik:FXFXpdHbrXhZjszQ1P7bNbOJQ4oly5bf

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Searches for installed software

      • Advanced Tokens Manager.exe (PID: 3304)
    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 4052)
  • INFO

    • Reads Microsoft Office registry keys

      • Advanced Tokens Manager.exe (PID: 3304)
    • Checks supported languages

      • Advanced Tokens Manager.exe (PID: 3304)
    • Reads the computer name

      • Advanced Tokens Manager.exe (PID: 3304)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 4052)
    • Reads the machine GUID from the registry

      • Advanced Tokens Manager.exe (PID: 3304)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 4052)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0801
ZipCompression: Deflated
ZipModifyDate: 1980:00:00 00:00:00
ZipCRC: 0x88713321
ZipCompressedSize: 1171364
ZipUncompressedSize: 1319936
ZipFileName: Device/HarddiskVolume8/Herramientas/0000/GEGeek ToolKit/Backups/Advanced Tokens Manager/Advanced Tokens Manager.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
46
Monitored processes
3
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe advanced tokens manager.exe no specs advanced tokens manager.exe

Process information

PID
CMD
Path
Indicators
Parent process
3304"C:\Users\admin\AppData\Local\Temp\Rar$EXb4052.17079\Device\HarddiskVolume8\Herramientas\0000\GEGeek ToolKit\Backups\Advanced Tokens Manager\Advanced Tokens Manager.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb4052.17079\Device\HarddiskVolume8\Herramientas\0000\GEGeek ToolKit\Backups\Advanced Tokens Manager\Advanced Tokens Manager.exe
WinRAR.exe
User:
admin
Company:
Josh Cell Softwares
Integrity Level:
HIGH
Description:
Advanced Tokens Manager - The Activation Backup Solution
Exit code:
0
Version:
3.5.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb4052.17079\device\harddiskvolume8\herramientas\0000\gegeek toolkit\backups\advanced tokens manager\advanced tokens manager.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3720"C:\Users\admin\AppData\Local\Temp\Rar$EXb4052.17079\Device\HarddiskVolume8\Herramientas\0000\GEGeek ToolKit\Backups\Advanced Tokens Manager\Advanced Tokens Manager.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb4052.17079\Device\HarddiskVolume8\Herramientas\0000\GEGeek ToolKit\Backups\Advanced Tokens Manager\Advanced Tokens Manager.exeWinRAR.exe
User:
admin
Company:
Josh Cell Softwares
Integrity Level:
MEDIUM
Description:
Advanced Tokens Manager - The Activation Backup Solution
Exit code:
3221226540
Version:
3.5.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb4052.17079\device\harddiskvolume8\herramientas\0000\gegeek toolkit\backups\advanced tokens manager\advanced tokens manager.exe
c:\windows\system32\ntdll.dll
4052"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\ESANTCOW11_015_2024-02-29_13_46_01.997.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
5 064
Read events
5 043
Write events
21
Delete events
0

Modification events

(PID) Process:(4052) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(4052) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(4052) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(4052) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(4052) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(4052) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(4052) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\ESANTCOW11_015_2024-02-29_13_46_01.997.zip
(PID) Process:(4052) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(4052) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(4052) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
2
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
4052WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb4052.17079\Device\HarddiskVolume8\Herramientas\0000\GEGeek ToolKit\Backups\Advanced Tokens Manager\Advanced Tokens Manager.exeexecutable
MD5:38D85D0093C2F13E12571480C813AFAF
SHA256:DBE2CC3A9F357E78417B421B9E5FB6D93BE44F535FE82B71DF9EACFE71C1C7DD
4052WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb4052.17079\manifest.jsontext
MD5:BE7F361BD8873A0596E8037998C6C9E4
SHA256:F1BDC2AF3B7C743529FE25548B8F042AD2B8BC8AC59927FE3F57CA7FBFDDB880
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info