File name:

PCVR-Rookie.exe

Full analysis: https://app.any.run/tasks/44c88d8e-c2e2-45d2-b41c-8d47aefc82b2
Verdict: Malicious activity
Analysis date: January 17, 2024, 09:09:31
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5:

1C4C7939B0A3D5A371B6004B543C0A56

SHA1:

FC44E85E02C0FFE75035B5B0B3C5B77ED7148A09

SHA256:

0072AF14AD563CEF549F8F9C0FCB7485D4776E0E38444AEFCE0C6A5B281764D0

SSDEEP:

24576:/Bof8vpaSUHexvHrLMO9srQWGY65P0J0dT5:pof8vpaSUHexfrLMO9srQWGY+P0J0dT5

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • PCVR-Rookie.exe (PID: 2124)
      • PCVR-Rookie.exe (PID: 1768)
  • SUSPICIOUS

    • Reads settings of System Certificates

      • PCVR-Rookie.exe (PID: 2124)
      • PCVR-Rookie.exe (PID: 1768)
    • Drops 7-zip archiver for unpacking

      • PCVR-Rookie.exe (PID: 2124)
      • PCVR-Rookie.exe (PID: 1768)
    • Reads the Internet Settings

      • PCVR-Rookie.exe (PID: 2124)
      • PCVR-Rookie.exe (PID: 1768)
    • Executable content was dropped or overwritten

      • PCVR-Rookie.exe (PID: 2124)
      • PCVR-Rookie.exe (PID: 1768)
  • INFO

    • Checks supported languages

      • PCVR-Rookie.exe (PID: 2124)
      • 7z.exe (PID: 2072)
      • rclone.exe (PID: 492)
      • rclone.exe (PID: 572)
      • rclone.exe (PID: 956)
      • PCVR-Rookie.exe (PID: 1768)
      • 7z.exe (PID: 2260)
      • rclone.exe (PID: 3068)
      • rclone.exe (PID: 2368)
      • rclone.exe (PID: 3144)
      • rclone.exe (PID: 2940)
      • rclone.exe (PID: 3056)
      • rclone.exe (PID: 1124)
      • rclone.exe (PID: 3312)
      • rclone.exe (PID: 3416)
      • rclone.exe (PID: 3204)
      • rclone.exe (PID: 3640)
      • rclone.exe (PID: 2596)
      • rclone.exe (PID: 2524)
    • Reads Environment values

      • PCVR-Rookie.exe (PID: 2124)
      • PCVR-Rookie.exe (PID: 1768)
    • Reads the computer name

      • PCVR-Rookie.exe (PID: 2124)
      • rclone.exe (PID: 492)
      • 7z.exe (PID: 2072)
      • rclone.exe (PID: 572)
      • rclone.exe (PID: 956)
      • 7z.exe (PID: 2260)
      • PCVR-Rookie.exe (PID: 1768)
      • rclone.exe (PID: 2524)
      • rclone.exe (PID: 2368)
      • rclone.exe (PID: 2940)
      • rclone.exe (PID: 3068)
      • rclone.exe (PID: 3056)
      • rclone.exe (PID: 3144)
      • rclone.exe (PID: 3204)
      • rclone.exe (PID: 1124)
      • rclone.exe (PID: 3312)
      • rclone.exe (PID: 3416)
      • rclone.exe (PID: 3640)
      • rclone.exe (PID: 2596)
    • Reads the machine GUID from the registry

      • PCVR-Rookie.exe (PID: 2124)
      • PCVR-Rookie.exe (PID: 1768)
    • Creates files or folders in the user directory

      • PCVR-Rookie.exe (PID: 2124)
      • PCVR-Rookie.exe (PID: 1768)
    • Create files in a temporary directory

      • 7z.exe (PID: 2072)
      • PCVR-Rookie.exe (PID: 2124)
    • Manual execution by a user

      • PCVR-Rookie.exe (PID: 1768)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic CIL Executable (.NET, Mono, etc.) (63.1)
.exe | Win64 Executable (generic) (23.8)
.dll | Win32 Dynamic Link Library (generic) (5.6)
.exe | Win32 Executable (generic) (3.8)
.exe | Generic Win/DOS Executable (1.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2055:01:06 21:01:48+01:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 48
CodeSize: 529408
InitializedDataSize: 413184
UninitializedDataSize: -
EntryPoint: 0x8325e
OSVersion: 4
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 2.0.0.0
ProductVersionNumber: 2.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: Rookie Sideloader
CompanyName: Rookie.WTF
FileDescription: AndroidSideloader
FileVersion: 2.0.0.0
InternalName: Rookie-PCVR.exe
LegalCopyright: Copyright © 2020
LegalTrademarks: -
OriginalFileName: Rookie-PCVR.exe
ProductName: AndroidSideloader
ProductVersion: 2.0.0.0
AssemblyVersion: 2.0.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
74
Monitored processes
19
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start pcvr-rookie.exe 7z.exe no specs rclone.exe no specs rclone.exe no specs rclone.exe no specs pcvr-rookie.exe 7z.exe no specs rclone.exe no specs rclone.exe no specs rclone.exe no specs rclone.exe no specs rclone.exe no specs rclone.exe no specs rclone.exe no specs rclone.exe no specs rclone.exe no specs rclone.exe no specs rclone.exe no specs rclone.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
492"C:\Users\admin\AppData\Local\Temp\rclone\rclone.exe" listremotes --config vrp.download.configC:\Users\admin\AppData\Local\Temp\rclone\rclone.exePCVR-Rookie.exe
User:
admin
Company:
https://rclone.org
Integrity Level:
MEDIUM
Description:
Rsync for cloud storage
Exit code:
0
Version:
1.62.2
Modules
Images
c:\users\admin\appdata\local\temp\rclone\rclone.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\user32.dll
572"C:\Users\admin\AppData\Local\Temp\rclone\rclone.exe" cat ":PCVR Games/VRP-GameList.txt" --config vrp.download.configC:\Users\admin\AppData\Local\Temp\rclone\rclone.exePCVR-Rookie.exe
User:
admin
Company:
https://rclone.org
Integrity Level:
MEDIUM
Description:
Rsync for cloud storage
Exit code:
1
Version:
1.62.2
Modules
Images
c:\users\admin\appdata\local\temp\rclone\rclone.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\user32.dll
956"C:\Users\admin\AppData\Local\Temp\rclone\rclone.exe" cat ":PCVR Games/VRP-GameList.txt" --config vrp.download.configC:\Users\admin\AppData\Local\Temp\rclone\rclone.exePCVR-Rookie.exe
User:
admin
Company:
https://rclone.org
Integrity Level:
MEDIUM
Description:
Rsync for cloud storage
Exit code:
1
Version:
1.62.2
Modules
Images
c:\users\admin\appdata\local\temp\rclone\rclone.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\user32.dll
1124"C:\Users\admin\Desktop\rclone\rclone.exe" cat ":PCVR Games/VRP-GameList.txt" --config vrp.download.configC:\Users\admin\Desktop\rclone\rclone.exePCVR-Rookie.exe
User:
admin
Company:
https://rclone.org
Integrity Level:
MEDIUM
Description:
Rsync for cloud storage
Exit code:
1
Version:
1.62.2
Modules
Images
c:\users\admin\desktop\rclone\rclone.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\user32.dll
1768"C:\Users\admin\Desktop\PCVR-Rookie.exe" C:\Users\admin\Desktop\PCVR-Rookie.exe
explorer.exe
User:
admin
Company:
Rookie.WTF
Integrity Level:
MEDIUM
Description:
AndroidSideloader
Exit code:
0
Version:
2.0.0.0
Modules
Images
c:\users\admin\desktop\pcvr-rookie.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2072"7z.exe" x "C:\Users\admin\AppData\Local\Temp\rclone.zip" -y -o"C:\Users\admin\AppData\Local\Temp"C:\Users\admin\AppData\Local\Temp\7z.exePCVR-Rookie.exe
User:
admin
Company:
Igor Pavlov
Integrity Level:
MEDIUM
Description:
7-Zip Standalone Console
Exit code:
0
Version:
23.01
Modules
Images
c:\users\admin\appdata\local\temp\7z.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2124"C:\Users\admin\AppData\Local\Temp\PCVR-Rookie.exe" C:\Users\admin\AppData\Local\Temp\PCVR-Rookie.exe
explorer.exe
User:
admin
Company:
Rookie.WTF
Integrity Level:
MEDIUM
Description:
AndroidSideloader
Exit code:
0
Version:
2.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\pcvr-rookie.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2260"7z.exe" x "C:\Users\admin\Desktop\rclone.zip" -y -o"C:\Users\admin\Desktop"C:\Users\admin\Desktop\7z.exePCVR-Rookie.exe
User:
admin
Company:
Igor Pavlov
Integrity Level:
MEDIUM
Description:
7-Zip Standalone Console
Exit code:
0
Version:
23.01
Modules
Images
c:\users\admin\desktop\7z.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2368"C:\Users\admin\Desktop\rclone\rclone.exe" cat ":PCVR Games/VRP-GameList.txt" --config vrp.download.configC:\Users\admin\Desktop\rclone\rclone.exePCVR-Rookie.exe
User:
admin
Company:
https://rclone.org
Integrity Level:
MEDIUM
Description:
Rsync for cloud storage
Exit code:
1
Version:
1.62.2
Modules
Images
c:\users\admin\desktop\rclone\rclone.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\user32.dll
2524"C:\Users\admin\Desktop\rclone\rclone.exe" cat ":PCVR Games/VRP-GameList.txt" --config vrp.download.configC:\Users\admin\Desktop\rclone\rclone.exePCVR-Rookie.exe
User:
admin
Company:
https://rclone.org
Integrity Level:
MEDIUM
Description:
Rsync for cloud storage
Exit code:
1
Version:
1.62.2
Modules
Images
c:\users\admin\desktop\rclone\rclone.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\user32.dll
Total events
13 634
Read events
13 590
Write events
44
Delete events
0

Modification events

(PID) Process:(2124) PCVR-Rookie.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2124) PCVR-Rookie.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2124) PCVR-Rookie.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2124) PCVR-Rookie.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2124) PCVR-Rookie.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1768) PCVR-Rookie.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(1768) PCVR-Rookie.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(1768) PCVR-Rookie.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(1768) PCVR-Rookie.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(1768) PCVR-Rookie.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
Executable files
4
Suspicious files
7
Text files
20
Unknown types
0

Dropped files

PID
Process
Filename
Type
20727z.exeC:\Users\admin\AppData\Local\Temp\rclone-v1.62.2-windows-386\rclone.exe
MD5:
SHA256:
2124PCVR-Rookie.exeC:\Users\admin\AppData\Local\Temp\rclone\vrp.download.config
MD5:
SHA256:
2124PCVR-Rookie.exeC:\Users\admin\AppData\Local\Rookie.WTF\PCVR-Rookie.exe_Url_xvschwsgakn2nagjsqlofr5vkuygxcxa\2.0.0.0\user.configxml
MD5:410AFDA4BDE459246A3CA55E2EE36BC3
SHA256:4C28889E076FC03D80185C5CC0C85F26B4078E84C279CC2943C0B3CCAD0F9B4E
2124PCVR-Rookie.exeC:\Users\admin\AppData\Local\Rookie.WTF\PCVR-Rookie.exe_Url_xvschwsgakn2nagjsqlofr5vkuygxcxa\2.0.0.0\k513vqmd.newcfgxml
MD5:410AFDA4BDE459246A3CA55E2EE36BC3
SHA256:4C28889E076FC03D80185C5CC0C85F26B4078E84C279CC2943C0B3CCAD0F9B4E
2124PCVR-Rookie.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506binary
MD5:1037CC1E5B18CC70745F6910A04AB084
SHA256:9A271971A2FE2F5EB212D7AB36C0136CFC16DE38D7EFBED81E9D78177C78278D
2124PCVR-Rookie.exeC:\Users\admin\AppData\Local\Temp\7z.exeexecutable
MD5:8F57948E69C82BF98704F129C5460576
SHA256:F00836A63BE7EBF14E1B8C40100C59777FE3432506B330927EA1F1B7FD47EE44
2124PCVR-Rookie.exeC:\Users\admin\AppData\Local\Temp\7z.dllexecutable
MD5:AE7DE9A0278F37331D2E9F8D5C0281F0
SHA256:A3FC74468477BA54517157EFA5021EAA6FF72F8F5C31E53D89F07D59071C0AE7
2124PCVR-Rookie.exeC:\Users\admin\AppData\Local\Temp\Cab125B.tmpcompressed
MD5:AC05D27423A85ADC1622C714F2CB6184
SHA256:C6456E12E5E53287A547AF4103E0397CB9697E466CF75844312DC296D43D144D
2124PCVR-Rookie.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506compressed
MD5:AC05D27423A85ADC1622C714F2CB6184
SHA256:C6456E12E5E53287A547AF4103E0397CB9697E466CF75844312DC296D43D144D
2124PCVR-Rookie.exeC:\Users\admin\AppData\Local\Temp\rclone.zipcompressed
MD5:70AEDE552F45E0A9BC6BAC985AA3D7BB
SHA256:5B91EE887762007CD9FEF64003A70C496F855602D1BBB1C32A364008611F98FF
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
13
DNS requests
7
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2124
PCVR-Rookie.exe
GET
200
104.18.38.233:80
http://zerossl.crt.sectigo.com/ZeroSSLECCDomainSecureSiteCA.crt
unknown
binary
905 b
unknown
2124
PCVR-Rookie.exe
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?f9dcd550dac845bb
unknown
compressed
65.2 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2124
PCVR-Rookie.exe
95.217.6.16:443
downloads.rclone.org
Hetzner Online GmbH
FI
unknown
2124
PCVR-Rookie.exe
93.184.221.240:80
ctldl.windowsupdate.com
EDGECAST
GB
whitelisted
2124
PCVR-Rookie.exe
140.82.121.4:443
github.com
GITHUB
US
unknown
2124
PCVR-Rookie.exe
185.199.111.133:443
raw.githubusercontent.com
FASTLY
US
unknown
2124
PCVR-Rookie.exe
185.247.224.87:443
vrpirates.wiki
Flokinet Ltd
SC
unknown
2124
PCVR-Rookie.exe
104.18.38.233:80
zerossl.crt.sectigo.com
CLOUDFLARENET
shared
1768
PCVR-Rookie.exe
95.217.6.16:443
downloads.rclone.org
Hetzner Online GmbH
FI
unknown
1768
PCVR-Rookie.exe
140.82.121.4:443
github.com
GITHUB
US
unknown
1768
PCVR-Rookie.exe
185.199.111.133:443
raw.githubusercontent.com
FASTLY
US
unknown

DNS requests

Domain
IP
Reputation
downloads.rclone.org
  • 95.217.6.16
unknown
ctldl.windowsupdate.com
  • 93.184.221.240
whitelisted
github.com
  • 140.82.121.4
shared
raw.githubusercontent.com
  • 185.199.111.133
  • 185.199.110.133
  • 185.199.109.133
  • 185.199.108.133
shared
vrpirates.wiki
  • 185.247.224.87
unknown
zerossl.crt.sectigo.com
  • 104.18.38.233
  • 172.64.149.23
whitelisted

Threats

PID
Process
Class
Message
2124
PCVR-Rookie.exe
Misc activity
ET INFO Observed ZeroSSL SSL/TLS Certificate
1768
PCVR-Rookie.exe
Misc activity
ET INFO Observed ZeroSSL SSL/TLS Certificate
No debug info