download:

Fraps+Free.zip

Full analysis: https://app.any.run/tasks/cccac46d-1a74-4039-88f7-98250714464a
Verdict: Malicious activity
Analysis date: October 23, 2018, 18:05:50
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

02616468F297C85EB82B06DB81D15579

SHA1:

999F79593E8B12543316F8D7F1122D7261477C7D

SHA256:

FD25EC515243EEDB6EF0E8753EA29E9A0B0870133C887F5F6AF988D0AE795AB0

SSDEEP:

49152:5Fo121aNi/TART95tU2KW3b5KcPUA71JlRjeiCUKOeaVIJKCbpZi:ro1/Ni/TeTmG1JPUWXZeKfB

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Fraps 3.4.7 Full Registered Version By JustPingAbuse.exe (PID: 2592)
      • fraps.exe (PID: 3444)
      • Fraps 3.4.7 Full Registered Version By JustPingAbuse.exe (PID: 2084)
      • fraps.exe (PID: 1720)
      • fraps.exe (PID: 3424)
    • Loads dropped or rewritten executable

      • Fraps 3.4.7 Full Registered Version By JustPingAbuse.exe (PID: 2084)
      • fraps.exe (PID: 3444)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Fraps 3.4.7 Full Registered Version By JustPingAbuse.exe (PID: 2084)
    • Creates files in the Windows directory

      • Fraps 3.4.7 Full Registered Version By JustPingAbuse.exe (PID: 2084)
    • Creates files in the user directory

      • Fraps 3.4.7 Full Registered Version By JustPingAbuse.exe (PID: 2084)
    • Creates a software uninstall entry

      • Fraps 3.4.7 Full Registered Version By JustPingAbuse.exe (PID: 2084)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2012:04:15 20:02:04
ZipCRC: 0x1e73ae66
ZipCompressedSize: 2609202
ZipUncompressedSize: 2759624
ZipFileName: Fraps Free/Fraps 3.4.7 Full Registered Version By JustPingAbuse.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
47
Monitored processes
7
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start drop and start winrar.exe no specs fraps 3.4.7 full registered version by justpingabuse.exe no specs fraps 3.4.7 full registered version by justpingabuse.exe fraps.exe no specs notepad.exe no specs fraps.exe no specs fraps.exe

Process information

PID
CMD
Path
Indicators
Parent process
1464"C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\Info.txtC:\Windows\system32\NOTEPAD.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1720"C:\Fraps\fraps.exe" /exitC:\Fraps\fraps.exeFraps 3.4.7 Full Registered Version By JustPingAbuse.exe
User:
admin
Company:
Beepa P/L
Integrity Level:
HIGH
Description:
Fraps
Exit code:
0
Version:
3, 4, 7, 13808
Modules
Images
c:\fraps\fraps.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imm32.dll
2084"C:\Users\admin\Desktop\Fraps 3.4.7 Full Registered Version By JustPingAbuse.exe" C:\Users\admin\Desktop\Fraps 3.4.7 Full Registered Version By JustPingAbuse.exe
explorer.exe
User:
admin
Company:
Beepa Pty Ltd
Integrity Level:
HIGH
Description:
Fraps Installer
Exit code:
0
Version:
3.4.7.13808
Modules
Images
c:\users\admin\desktop\fraps 3.4.7 full registered version by justpingabuse.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
2288"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Fraps+Free.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2592"C:\Users\admin\Desktop\Fraps 3.4.7 Full Registered Version By JustPingAbuse.exe" C:\Users\admin\Desktop\Fraps 3.4.7 Full Registered Version By JustPingAbuse.exeexplorer.exe
User:
admin
Company:
Beepa Pty Ltd
Integrity Level:
MEDIUM
Description:
Fraps Installer
Exit code:
3221226540
Version:
3.4.7.13808
Modules
Images
c:\users\admin\desktop\fraps 3.4.7 full registered version by justpingabuse.exe
c:\systemroot\system32\ntdll.dll
3424"C:\Fraps\fraps.exe" C:\Fraps\fraps.exeexplorer.exe
User:
admin
Company:
Beepa P/L
Integrity Level:
MEDIUM
Description:
Fraps
Exit code:
3221226540
Version:
3, 4, 7, 13808
Modules
Images
c:\fraps\fraps.exe
c:\systemroot\system32\ntdll.dll
3444"C:\Fraps\fraps.exe" C:\Fraps\fraps.exe
explorer.exe
User:
admin
Company:
Beepa P/L
Integrity Level:
HIGH
Description:
Fraps
Exit code:
7
Version:
3, 4, 7, 13808
Modules
Images
c:\fraps\fraps.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imm32.dll
Total events
1 377
Read events
602
Write events
775
Delete events
0

Modification events

(PID) Process:(2288) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2288) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2288) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2288) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Fraps+Free.zip
(PID) Process:(2288) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2288) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2288) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2288) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2288) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
(PID) Process:(2288) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\General
Operation:writeName:LastFolder
Value:
C:\Users\admin\AppData\Local\Temp
Executable files
10
Suspicious files
0
Text files
7
Unknown types
3

Dropped files

PID
Process
Filename
Type
2288WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2288.15877\Fraps Free\Fraps 3.4.7 Full Registered Version By JustPingAbuse.exe
MD5:
SHA256:
2288WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2288.15877\Fraps Free\Info.txt
MD5:
SHA256:
2084Fraps 3.4.7 Full Registered Version By JustPingAbuse.exeC:\Fraps\fraps.exeexecutable
MD5:
SHA256:
2084Fraps 3.4.7 Full Registered Version By JustPingAbuse.exeC:\Fraps\fraps32.dllexecutable
MD5:
SHA256:
2084Fraps 3.4.7 Full Registered Version By JustPingAbuse.exeC:\Fraps\changes.txttext
MD5:
SHA256:
2084Fraps 3.4.7 Full Registered Version By JustPingAbuse.exeC:\Fraps\frapslcd.dllexecutable
MD5:
SHA256:
2084Fraps 3.4.7 Full Registered Version By JustPingAbuse.exeC:\Fraps\fraps64.dllexecutable
MD5:
SHA256:
2084Fraps 3.4.7 Full Registered Version By JustPingAbuse.exeC:\Fraps\README.HTMhtml
MD5:
SHA256:
2084Fraps 3.4.7 Full Registered Version By JustPingAbuse.exeC:\Fraps\fraps64.datexecutable
MD5:
SHA256:
2084Fraps 3.4.7 Full Registered Version By JustPingAbuse.exeC:\Users\admin\AppData\Local\Temp\beepa.bmpimage
MD5:1AA76C32A7033FEB98C3A84C258CC7F9
SHA256:DA3C7D44B495CBF865CD6711FD7A610EB042CB0912E16D2D553135A9BAC7C408
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info