| File name: | Condo Generator.zip |
| Full analysis: | https://app.any.run/tasks/757ea8e5-aafa-4dc3-a2ce-fdfaa0d2dee8 |
| Verdict: | Malicious activity |
| Threats: | XWorm is a remote access trojan (RAT) sold as a malware-as-a-service. It possesses an extensive hacking toolset and is capable of gathering private information and files from the infected computer, hijacking MetaMask and Telegram accounts, and tracking user activity. XWorm is typically delivered to victims' computers through multi-stage attacks that start with phishing emails. |
| Analysis date: | March 07, 2024, 04:00:36 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v1.0 to extract, compression method=store |
| MD5: | 72495CCB8C55661AF72002D2AD52ECA8 |
| SHA1: | D28863965E2296846586939037437F0847D01448 |
| SHA256: | F0B0E100AB96C9D7638867F710337FBF4B7822BCB82EF23FC9C36D1D2A5E2732 |
| SSDEEP: | 24576:Jt3A7Ex6s5RlHuOi9GQXYT1q2m4MnaQuLkYS:Jt3A7Ex6s5RlHuOi9GQXYT1q2m4MnaQD |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 10 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | None |
| ZipModifyDate: | 2024:02:25 01:08:40 |
| ZipCRC: | 0x00000000 |
| ZipCompressedSize: | - |
| ZipUncompressedSize: | - |
| ZipFileName: | Condo Gen/ |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2472 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\Condo Generator.zip" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 2840 | "C:\Users\admin\Desktop\Condo Generator.exe" | C:\Users\admin\Desktop\Condo Generator.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: Exit code: 0 Version: 1.0.0.0 Modules
XWorm(PID) Process(2840) Condo Generator.exe C279.133.57.98:7323 Keys AESKyAWsrtwJpACek5s Options Splitter<Xwormmm> Sleep time3 USB drop nameXWorm V5.2 MutexpJxOekCCSsBSFg0J | |||||||||||||||
| (PID) Process: | (2472) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (2472) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (2472) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2472) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (2472) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (2472) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
| (PID) Process: | (2472) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\Condo Generator.zip | |||
| (PID) Process: | (2472) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2472) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2472) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2472 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2472.3534\Condo Gen\main.dll | executable | |
MD5:9E4097BD34BF081523425C07EAE55144 | SHA256:CB8B485AEFCBC960FD90DAF5A6E3B3A2BAFE5116A101ABB017A0489DB4E35F77 | |||
| 2472 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2472.3534\Condo Gen\Condo Generator.exe | executable | |
MD5:A758430538BFA522BC97FD3E08B7390B | SHA256:40E46407B549B2A594E3AC4E295D9EAE1059FBC41C2603F1384146AA5983F26A | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2840 | Condo Generator.exe | GET | — | 208.95.112.1:80 | http://ip-api.com/line/?fields=hosting | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2840 | Condo Generator.exe | 208.95.112.1:80 | ip-api.com | TUT-AS | US | unknown |
Domain | IP | Reputation |
|---|---|---|
ip-api.com |
| shared |
PID | Process | Class | Message |
|---|---|---|---|
2840 | Condo Generator.exe | Potential Corporate Privacy Violation | AV POLICY Internal Host Retrieving External IP Address (ip-api. com) |
2840 | Condo Generator.exe | Device Retrieving External IP Address Detected | POLICY [ANY.RUN] External Hosting Lookup by ip-api |
2840 | Condo Generator.exe | Device Retrieving External IP Address Detected | ET POLICY External IP Lookup ip-api.com |