| File name: | XtremeRAT.zip |
| Full analysis: | https://app.any.run/tasks/39b4cb8b-a2ec-404b-a4f4-f1c6f8e38694 |
| Verdict: | Malicious activity |
| Analysis date: | August 29, 2020, 18:16:43 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | 6908D1BEFD41783DA6EBA7F1FCC8FD3A |
| SHA1: | C040740ADB367715F74CAC004C6634DF6EED8427 |
| SHA256: | F4AD6CC762F0998A5BE6D080D780D76846DD5C75C5C02AA96CB15F4D1FF67790 |
| SSDEEP: | 98304:SPghTJ2UIFmXsHug4SznAtEx3jBnzUxV8VSPzz0+iYUk7ozDQDx7dhT:S0TJ2UIFJz4S0Sx3VzUxV8VSv0NFuxPT |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2012:06:13 14:48:13 |
| ZipCRC: | 0x3b6ee1c2 |
| ZipCompressedSize: | 4924111 |
| ZipUncompressedSize: | 5046272 |
| ZipFileName: | XtremeRAT.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2956 | "C:\Program Files\Internet Explorer\iexplore.exe" | C:\Program Files\Internet Explorer\iexplore.exe | server.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| 3016 | "C:\InstallDir\Server.exe" | C:\InstallDir\Server.exe | iexplore.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 3232 | "C:\Program Files\Internet Explorer\iexplore.exe" | C:\Program Files\Internet Explorer\iexplore.exe | Server.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| 3344 | "C:\Users\admin\Desktop\server.exe" | C:\Users\admin\Desktop\server.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 3352 | "C:\Users\admin\AppData\Local\Temp\UPXfile.exe" "C:\Users\admin\Desktop\server.exe" | C:\Users\admin\AppData\Local\Temp\UPXfile.exe | XtremeRAT.exe | ||||||||||||
User: admin Company: The UPX Team http://upx.sf.net Integrity Level: MEDIUM Description: UPX executable packer Exit code: 0 Version: 3.07 (2010-09-08) Modules
| |||||||||||||||
| 3552 | explorer.exe | C:\Windows\explorer.exe | — | server.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3964 | "C:\Users\admin\Desktop\XtremeRAT.exe" | C:\Users\admin\Desktop\XtremeRAT.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 4012 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\XtremeRAT.zip" | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| (PID) Process: | (4012) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (4012) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (4012) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\139\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (4012) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\139\52C64B7E |
| Operation: | write | Name: | @C:\Windows\system32\NetworkExplorer.dll,-1 |
Value: Network | |||
| (PID) Process: | (4012) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\XtremeRAT.zip | |||
| (PID) Process: | (4012) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (4012) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (4012) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (4012) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (4012) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin |
| Operation: | write | Name: | Placement |
Value: 2C0000000200000003000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 4012 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa4012.36245\XtremeRAT.exe | — | |
MD5:— | SHA256:— | |||
| 4012 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa4012.36245\Language\English.ini | — | |
MD5:— | SHA256:— | |||
| 4012 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa4012.36245\Language\Español.ini | — | |
MD5:— | SHA256:— | |||
| 4012 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa4012.36245\Language\Português.ini | — | |
MD5:— | SHA256:— | |||
| 3964 | XtremeRAT.exe | C:\Users\admin\Desktop\RCX6F51.tmp | — | |
MD5:— | SHA256:— | |||
| 3964 | XtremeRAT.exe | C:\Users\admin\AppData\Local\Temp\UPXfile.exe | — | |
MD5:— | SHA256:— | |||
| 3352 | UPXfile.exe | C:\Users\admin\Desktop\server.upx | — | |
MD5:— | SHA256:— | |||
| 2956 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\1234567890[1].htmctions | — | |
MD5:— | SHA256:— | |||
| 3964 | XtremeRAT.exe | C:\Users\admin\Desktop\Settings\Server_USER-PC^admin(C4BA3647).ini | — | |
MD5:— | SHA256:— | |||
| 3964 | XtremeRAT.exe | C:\Users\admin\Desktop\user.info | binary | |
MD5:2685F2A7BDB13EE7EEA90FE21522E8DF | SHA256:1F1D306DB426C2C81A56CA65FBFD41813B5A1620D66E0EFDFBFF60CA62F9D3B6 | |||
Process | Message |
|---|---|
XtremeRAT.exe | VCLFixPack patch installed: PageControlPaintingFix |
XtremeRAT.exe | VCLFixPack patch installed: GridFlickerFix |