File name:

HTTP.Debugger.Pro-DARKSiDERS.Keygen.Only.7z

Full analysis: https://app.any.run/tasks/9f086123-1b98-4361-bece-b5451d0aca26
Verdict: Malicious activity
Analysis date: May 28, 2020, 15:35:33
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-7z-compressed
File info: 7-zip archive data, version 0.4
MD5:

7992D1948DB8EC458CF7A65F831AA52F

SHA1:

F846F72FBDD0F4EB4E53DBC65A538310E1CB8CF2

SHA256:

F24D699A88C62647420996616D96DAD1B420BAFFB64D5EF355D81AC4E2582A68

SSDEEP:

12288:MMPV9ds9V+ViV82SKrpExbTKhjirlCEd6b7gbxEhePIm686fvpQkWBUIuP22zC:MMPVr2V+ViG2trpcbzMP86nOkWByO

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • HTTPDebuggerPro_DSiDERS_Keygen.exe (PID: 2772)
      • HTTPDebuggerPro_DSiDERS_Keygen.exe (PID: 3864)
      • HTTPDebuggerPro_DSiDERS_Keygen.exe (PID: 2280)
      • HTTPDebuggerPro_DSiDERS_Keygen.exe (PID: 1476)
    • Actions looks like stealing of personal data

      • HTTPDebuggerPro_DSiDERS_Keygen.exe (PID: 3864)
      • HTTPDebuggerPro_DSiDERS_Keygen.exe (PID: 2280)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1408)
  • INFO

    • Manual execution by user

      • HTTPDebuggerPro_DSiDERS_Keygen.exe (PID: 2772)
      • HTTPDebuggerPro_DSiDERS_Keygen.exe (PID: 3864)
      • HTTPDebuggerPro_DSiDERS_Keygen.exe (PID: 1476)
      • HTTPDebuggerPro_DSiDERS_Keygen.exe (PID: 2280)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.7z | 7-Zip compressed archive (v0.4) (57.1)
.7z | 7-Zip compressed archive (gen) (42.8)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
47
Monitored processes
5
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe httpdebuggerpro_dsiders_keygen.exe no specs httpdebuggerpro_dsiders_keygen.exe httpdebuggerpro_dsiders_keygen.exe no specs httpdebuggerpro_dsiders_keygen.exe

Process information

PID
CMD
Path
Indicators
Parent process
1408"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\HTTP.Debugger.Pro-DARKSiDERS.Keygen.Only.7z"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
1476"C:\Users\admin\Desktop\HTTPDebuggerPro_DSiDERS_Keygen.exe" C:\Users\admin\Desktop\HTTPDebuggerPro_DSiDERS_Keygen.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
DJiNN
Exit code:
3221226540
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\httpdebuggerpro_dsiders_keygen.exe
c:\systemroot\system32\ntdll.dll
2280"C:\Users\admin\Desktop\HTTPDebuggerPro_DSiDERS_Keygen.exe" C:\Users\admin\Desktop\HTTPDebuggerPro_DSiDERS_Keygen.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
DJiNN
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\httpdebuggerpro_dsiders_keygen.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\gdi32.dll
2772"C:\Users\admin\Desktop\HTTPDebuggerPro_DSiDERS_Keygen.exe" C:\Users\admin\Desktop\HTTPDebuggerPro_DSiDERS_Keygen.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
DJiNN
Exit code:
3221226540
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\httpdebuggerpro_dsiders_keygen.exe
c:\systemroot\system32\ntdll.dll
3864"C:\Users\admin\Desktop\HTTPDebuggerPro_DSiDERS_Keygen.exe" C:\Users\admin\Desktop\HTTPDebuggerPro_DSiDERS_Keygen.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
DJiNN
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\httpdebuggerpro_dsiders_keygen.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\gdi32.dll
Total events
1 037
Read events
932
Write events
101
Delete events
4

Modification events

(PID) Process:(1408) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1408) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1408) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1408) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12F\52C64B7E
Operation:writeName:@C:\Windows\system32\NetworkExplorer.dll,-1
Value:
Network
(PID) Process:(1408) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\HTTP.Debugger.Pro-DARKSiDERS.Keygen.Only.7z
(PID) Process:(1408) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1408) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1408) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1408) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1408) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12F\52C64B7E
Operation:writeName:@C:\Windows\system32\msinfo32.exe,-10001
Value:
System Information File
Executable files
1
Suspicious files
0
Text files
3
Unknown types
0

Dropped files

PID
Process
Filename
Type
1408WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1408.49962\HTTP.Debugger.Pro-DARKSiDERS.Keygen.Only\HTTPDebuggerPro_DSiDERS_Keygen.exeexecutable
MD5:7942643E6DC851B7EC0A466FE08BC3DE
SHA256:893693A076447236AE3727A71D0521D8882023160D5D5F392F49BDCC4B764D30
1408WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1408.49962\HTTP.Debugger.Pro-DARKSiDERS.Keygen.Only\file_id.diztext
MD5:41D6B62CBEAD74EB8B302F8F83A0C045
SHA256:6EB68213C7E41959065E6E2F6A4B9872DF4A24E5541C4B0EACE07B9945CBDED1
1408WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1408.49962\HTTP.Debugger.Pro-DARKSiDERS.Keygen.Only\http-debugger-professional.urltext
MD5:733615F8458BA31DDBF47F993CD80BA0
SHA256:CE0B1DCDD1EAF580336C8C1F642D3E70F17AD627CF369742596F6B5280258F92
1408WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1408.49962\HTTP.Debugger.Pro-DARKSiDERS.Keygen.Only\httpdbp.nfotext
MD5:0F15627964C62676CC5D1B640BF7EB30
SHA256:E87E5DFC121CBBAA59282037F25107F9C9CB23E868F60F1B19FFC6E4D5113EC4
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info