analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

620d604895eece013bff467cb16983b3

Full analysis: https://app.any.run/tasks/730c8b73-b568-4974-b55f-0d23679d1bf5
Verdict: Malicious activity
Threats:

WarZone RAT is a remote access trojan, which is written in C++ and offered as a malware-as-a-service. It packs a wide range of capabilities, from stealing victims’ files and passwords to capturing desktop activities. WarZone RAT is primarily distributed via phishing emails and receives regular updates from its C2.

Analysis date: December 03, 2019, 01:31:08
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
trojan
stealer
rat
avemaria
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

620D604895EECE013BFF467CB16983B3

SHA1:

AE41EB2DFA5D9F7933AA94009CAF31551A87B85A

SHA256:

EFEDEA1A1F7DC2B905B238406B40D8E0F254BCA522E84B5E5ACF4C086D0823F3

SSDEEP:

6144:87tO32swRhRt8I7je+cUnwZGEJQnj4f7YEuZ6CDlp7LcHk7fhW+etA9Z8TYy:+932IJjnwztfruZ6U0k7fhnTsh

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Scan5537563.exe (PID: 2344)
      • good.exe (PID: 3088)
    • Changes the autorun value in the registry

      • Scan5537563.exe (PID: 2344)
    • Application was injected by another process

      • explorer.exe (PID: 352)
    • Connects to CnC server

      • good.exe (PID: 3088)
    • Runs injected code in another process

      • good.exe (PID: 3088)
    • AVEMARIA was detected

      • good.exe (PID: 3088)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Scan5537563.exe (PID: 2344)
    • Creates files in the user directory

      • Scan5537563.exe (PID: 2344)
      • good.exe (PID: 3088)
    • Starts itself from another location

      • Scan5537563.exe (PID: 2344)
    • Connects to unusual port

      • good.exe (PID: 3088)
    • Reads the machine GUID from the registry

      • good.exe (PID: 3088)
    • Loads DLL from Mozilla Firefox

      • good.exe (PID: 3088)
  • INFO

    • Manual execution by user

      • Scan5537563.exe (PID: 2344)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: Scan5537563.exe
ZipUncompressedSize: 853504
ZipCompressedSize: 357940
ZipCRC: 0xd65f5fed
ZipModifyDate: 2019:12:02 10:20:06
ZipCompression: Deflated
ZipBitFlag: -
ZipRequiredVersion: 20
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
38
Monitored processes
4
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start drop and start inject winrar.exe no specs scan5537563.exe #AVEMARIA good.exe explorer.exe

Process information

PID
CMD
Path
Indicators
Parent process
2724"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\620d604895eece013bff467cb16983b3.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
2344"C:\Users\admin\Desktop\Scan5537563.exe" C:\Users\admin\Desktop\Scan5537563.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
3088"C:\Users\admin\AppData\Roaming\good.exe"C:\Users\admin\AppData\Roaming\good.exe
Scan5537563.exe
User:
admin
Integrity Level:
MEDIUM
352C:\Windows\Explorer.EXEC:\Windows\explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Total events
1 404
Read events
1 337
Write events
0
Delete events
0

Modification events

No data
Executable files
2
Suspicious files
0
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
2724WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2724.23821\Scan5537563.exe
MD5:
SHA256:
3088good.exeC:\Users\admin\AppData\Roaming\EDrbIl..tmp
MD5:
SHA256:
352explorer.exeC:\Users\admin\Desktop\Scan5537563.exeexecutable
MD5:EE22C8C339D0536E8E3743F3D4CF9B0F
SHA256:F8A43D2EC2692D54C75BED8A5DDFCD2E3C0B8414E2D5F2B9E89948E0354957B7
2344Scan5537563.exeC:\Users\admin\AppData\Roaming\good.exeexecutable
MD5:EE22C8C339D0536E8E3743F3D4CF9B0F
SHA256:F8A43D2EC2692D54C75BED8A5DDFCD2E3C0B8414E2D5F2B9E89948E0354957B7
3088good.exeC:\Users\admin\AppData\Roaming\dcyyDtz.tmptext
MD5:E7CE898AADD69F4E4280010B7808116E
SHA256:C9214BB54F10242AA254F0758372A440C8D8F49934021F8F08B6DF9FB377EB02
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
3
DNS requests
2
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2344
Scan5537563.exe
205.251.242.103:80
amazon.com
Amazon.com, Inc.
US
malicious
3088
good.exe
185.19.85.155:1960
Datawire Ag
CH
malicious
3088
good.exe
205.251.242.103:80
amazon.com
Amazon.com, Inc.
US
malicious

DNS requests

Domain
IP
Reputation
amazon.com
  • 205.251.242.103
  • 176.32.103.205
  • 176.32.98.166
whitelisted

Threats

PID
Process
Class
Message
3088
good.exe
A Network Trojan was detected
AV TROJAN Ave Maria RAT CnC Response
3088
good.exe
A Network Trojan was detected
MALWARE [PTsecurity] AveMaria.RAT Encrypted Checkin
3088
good.exe
A Network Trojan was detected
MALWARE [PTsecurity] AveMaria.RAT Connection
1 ETPRO signatures available at the full report
No debug info