| File name: | [Snipcola] Synapse X (V2).rar |
| Full analysis: | https://app.any.run/tasks/2d316bfe-dc65-499c-94fd-7adec1643884 |
| Verdict: | Suspicious activity |
| Analysis date: | January 11, 2020, 19:32:48 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v5 |
| MD5: | FAF77CCD6047EA423328EEB1CE198784 |
| SHA1: | 683FB62F5C368F7AAC8485AC4A4084263BE61D65 |
| SHA256: | F3BFE8C8523B950642433E1A989FA5FA4DF01968CC9C28B8E7AAA0FF203A3653 |
| SSDEEP: | 393216:RuZopsGcbc6EivKRKCyGm8GmtDpo5kel3WYzmj4jBWZm:goj6PKRKCdDp6kexWYzmcjBWQ |
| .rar | | | RAR compressed archive (v5.0) (61.5) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 3044 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\[Snipcola] Synapse X (V2).rar" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 3924 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa3044.20381\Synapse X (V2)\Synapse X (V2).exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa3044.20381\Synapse X (V2)\Synapse X (V2).exe | — | WinRAR.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: SynapseX - main Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| (PID) Process: | (3044) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3044) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3044) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3044) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\[Snipcola] Synapse X (V2).rar | |||
| (PID) Process: | (3044) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3044) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3044) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3044) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (3044) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (3044) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3044 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3044.20381\Synapse X (V2)\Bunifu_UI_v1.5.3.dll | executable | |
MD5:2ECB51AB00C5F340380ECF849291DBCF | SHA256:F1B3E0F2750A9103E46A6A4A34F1CF9D17779725F98042CC2475EC66484801CF | |||
| 3044 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3044.20381\Synapse X (V2)\Monaco\classfunc.txt | text | |
MD5:BF32E93D11011EB780619B3E17FB824A | SHA256:519DA000DE235C331F10660509FAB51A1815ACE566B8AE5B511B75813922DCB1 | |||
| 3044 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3044.20381\Synapse X (V2)\Monaco\base.txt | text | |
MD5:0D834904A252E1AB786F9637BEF6819F | SHA256:DBE440C5DEE6367EBCA919886FFE593246E1E52618E4713373000C9FC77C87CC | |||
| 3044 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3044.20381\Synapse X (V2)\FastColoredTextBox.dll | executable | |
MD5:8610F4D3CDC6CC50022FEDDCED9FDAEB | SHA256:AC926C92CCFC3789A5AE571CC4415EB1897D500A79604D8495241C19ACDF01B9 | |||
| 3044 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3044.20381\Synapse X (V2)\Monaco\globalv.txt | text | |
MD5:5CF9F238D4E62C8BCDE351651C3A2A45 | SHA256:EEB98F2C9911AE8DDD25F1B3BE3732000F16788BDA60AA962E9F8452012B1062 | |||
| 3044 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3044.20381\Synapse X (V2)\Monaco\globalns.txt | text | |
MD5:BA56C14634B7AE6FB585BE396ACF5F03 | SHA256:5CB987E7C87F2F04CDD45F3A474FB2380BBF846534E38F2B485EAFC562B7B482 | |||
| 3044 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3044.20381\Synapse X (V2)\exploit-main.dll | executable | |
MD5:69907F276CD3B9CE0B2674B239BE9E2C | SHA256:9256432625A30A1E88F383E7E0672D16AC82B3B78EFC9BF40AC971746BF637D4 | |||
| 3044 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3044.20381\Synapse X (V2)\Monaco\vs\basic-languages\coffee\coffee.js | text | |
MD5:9D0C4AC1691EED0A480C3E9246490D29 | SHA256:E706C9F8E5C5A0CB01B2F4E4879EC34A050D6EB2A8840284EB7BADD9D78099F9 | |||
| 3044 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3044.20381\Synapse X (V2)\Monaco\globalf.txt | text | |
MD5:1700DF0210CDA593D3DF64F51B3CAAEA | SHA256:DEAE98F86C62749E4B642ACB41EA5DFCE0CAF09BC77036AAE82EE814A04ED9E0 | |||
| 3044 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3044.20381\Synapse X (V2)\Monaco\vs\basic-languages\handlebars\handlebars.js | text | |
MD5:3CA7CF83292B56444548F2914C0E1811 | SHA256:31D25588D120E7C79F3332FF3B3C794CEBD0554C7578E3BB37B3CAC366E4F6C2 | |||