File name:

PCVR-Rookie.exe

Full analysis: https://app.any.run/tasks/44c88d8e-c2e2-45d2-b41c-8d47aefc82b2
Verdict: Malicious activity
Analysis date: January 17, 2024, 09:09:31
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5:

1C4C7939B0A3D5A371B6004B543C0A56

SHA1:

FC44E85E02C0FFE75035B5B0B3C5B77ED7148A09

SHA256:

0072AF14AD563CEF549F8F9C0FCB7485D4776E0E38444AEFCE0C6A5B281764D0

SSDEEP:

24576:/Bof8vpaSUHexvHrLMO9srQWGY65P0J0dT5:pof8vpaSUHexfrLMO9srQWGY+P0J0dT5

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • PCVR-Rookie.exe (PID: 2124)
      • PCVR-Rookie.exe (PID: 1768)
  • SUSPICIOUS

    • Reads the Internet Settings

      • PCVR-Rookie.exe (PID: 2124)
      • PCVR-Rookie.exe (PID: 1768)
    • Reads settings of System Certificates

      • PCVR-Rookie.exe (PID: 2124)
      • PCVR-Rookie.exe (PID: 1768)
    • Drops 7-zip archiver for unpacking

      • PCVR-Rookie.exe (PID: 2124)
      • PCVR-Rookie.exe (PID: 1768)
    • Executable content was dropped or overwritten

      • PCVR-Rookie.exe (PID: 2124)
      • PCVR-Rookie.exe (PID: 1768)
  • INFO

    • Checks supported languages

      • PCVR-Rookie.exe (PID: 2124)
      • 7z.exe (PID: 2072)
      • rclone.exe (PID: 492)
      • rclone.exe (PID: 572)
      • rclone.exe (PID: 956)
      • PCVR-Rookie.exe (PID: 1768)
      • 7z.exe (PID: 2260)
      • rclone.exe (PID: 2596)
      • rclone.exe (PID: 2940)
      • rclone.exe (PID: 3056)
      • rclone.exe (PID: 3144)
      • rclone.exe (PID: 1124)
      • rclone.exe (PID: 3204)
      • rclone.exe (PID: 3312)
      • rclone.exe (PID: 3416)
      • rclone.exe (PID: 2524)
      • rclone.exe (PID: 2368)
      • rclone.exe (PID: 3068)
      • rclone.exe (PID: 3640)
    • Reads the computer name

      • PCVR-Rookie.exe (PID: 2124)
      • 7z.exe (PID: 2072)
      • rclone.exe (PID: 492)
      • rclone.exe (PID: 572)
      • rclone.exe (PID: 956)
      • PCVR-Rookie.exe (PID: 1768)
      • 7z.exe (PID: 2260)
      • rclone.exe (PID: 2596)
      • rclone.exe (PID: 2524)
      • rclone.exe (PID: 1124)
      • rclone.exe (PID: 2940)
      • rclone.exe (PID: 3056)
      • rclone.exe (PID: 3144)
      • rclone.exe (PID: 3204)
      • rclone.exe (PID: 3312)
      • rclone.exe (PID: 2368)
      • rclone.exe (PID: 3068)
      • rclone.exe (PID: 3640)
      • rclone.exe (PID: 3416)
    • Reads the machine GUID from the registry

      • PCVR-Rookie.exe (PID: 2124)
      • PCVR-Rookie.exe (PID: 1768)
    • Reads Environment values

      • PCVR-Rookie.exe (PID: 2124)
      • PCVR-Rookie.exe (PID: 1768)
    • Creates files or folders in the user directory

      • PCVR-Rookie.exe (PID: 2124)
      • PCVR-Rookie.exe (PID: 1768)
    • Create files in a temporary directory

      • PCVR-Rookie.exe (PID: 2124)
      • 7z.exe (PID: 2072)
    • Manual execution by a user

      • PCVR-Rookie.exe (PID: 1768)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic CIL Executable (.NET, Mono, etc.) (63.1)
.exe | Win64 Executable (generic) (23.8)
.dll | Win32 Dynamic Link Library (generic) (5.6)
.exe | Win32 Executable (generic) (3.8)
.exe | Generic Win/DOS Executable (1.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2055:01:06 21:01:48+01:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 48
CodeSize: 529408
InitializedDataSize: 413184
UninitializedDataSize: -
EntryPoint: 0x8325e
OSVersion: 4
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 2.0.0.0
ProductVersionNumber: 2.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: Rookie Sideloader
CompanyName: Rookie.WTF
FileDescription: AndroidSideloader
FileVersion: 2.0.0.0
InternalName: Rookie-PCVR.exe
LegalCopyright: Copyright © 2020
LegalTrademarks: -
OriginalFileName: Rookie-PCVR.exe
ProductName: AndroidSideloader
ProductVersion: 2.0.0.0
AssemblyVersion: 2.0.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
74
Monitored processes
19
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start pcvr-rookie.exe 7z.exe no specs rclone.exe no specs rclone.exe no specs rclone.exe no specs pcvr-rookie.exe 7z.exe no specs rclone.exe no specs rclone.exe no specs rclone.exe no specs rclone.exe no specs rclone.exe no specs rclone.exe no specs rclone.exe no specs rclone.exe no specs rclone.exe no specs rclone.exe no specs rclone.exe no specs rclone.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
492"C:\Users\admin\AppData\Local\Temp\rclone\rclone.exe" listremotes --config vrp.download.configC:\Users\admin\AppData\Local\Temp\rclone\rclone.exePCVR-Rookie.exe
User:
admin
Company:
https://rclone.org
Integrity Level:
MEDIUM
Description:
Rsync for cloud storage
Exit code:
0
Version:
1.62.2
Modules
Images
c:\users\admin\appdata\local\temp\rclone\rclone.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\user32.dll
572"C:\Users\admin\AppData\Local\Temp\rclone\rclone.exe" cat ":PCVR Games/VRP-GameList.txt" --config vrp.download.configC:\Users\admin\AppData\Local\Temp\rclone\rclone.exePCVR-Rookie.exe
User:
admin
Company:
https://rclone.org
Integrity Level:
MEDIUM
Description:
Rsync for cloud storage
Exit code:
1
Version:
1.62.2
Modules
Images
c:\users\admin\appdata\local\temp\rclone\rclone.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\user32.dll
956"C:\Users\admin\AppData\Local\Temp\rclone\rclone.exe" cat ":PCVR Games/VRP-GameList.txt" --config vrp.download.configC:\Users\admin\AppData\Local\Temp\rclone\rclone.exePCVR-Rookie.exe
User:
admin
Company:
https://rclone.org
Integrity Level:
MEDIUM
Description:
Rsync for cloud storage
Exit code:
1
Version:
1.62.2
Modules
Images
c:\users\admin\appdata\local\temp\rclone\rclone.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\user32.dll
1124"C:\Users\admin\Desktop\rclone\rclone.exe" cat ":PCVR Games/VRP-GameList.txt" --config vrp.download.configC:\Users\admin\Desktop\rclone\rclone.exePCVR-Rookie.exe
User:
admin
Company:
https://rclone.org
Integrity Level:
MEDIUM
Description:
Rsync for cloud storage
Exit code:
1
Version:
1.62.2
Modules
Images
c:\users\admin\desktop\rclone\rclone.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\user32.dll
1768"C:\Users\admin\Desktop\PCVR-Rookie.exe" C:\Users\admin\Desktop\PCVR-Rookie.exe
explorer.exe
User:
admin
Company:
Rookie.WTF
Integrity Level:
MEDIUM
Description:
AndroidSideloader
Exit code:
0
Version:
2.0.0.0
Modules
Images
c:\users\admin\desktop\pcvr-rookie.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2072"7z.exe" x "C:\Users\admin\AppData\Local\Temp\rclone.zip" -y -o"C:\Users\admin\AppData\Local\Temp"C:\Users\admin\AppData\Local\Temp\7z.exePCVR-Rookie.exe
User:
admin
Company:
Igor Pavlov
Integrity Level:
MEDIUM
Description:
7-Zip Standalone Console
Exit code:
0
Version:
23.01
Modules
Images
c:\users\admin\appdata\local\temp\7z.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2124"C:\Users\admin\AppData\Local\Temp\PCVR-Rookie.exe" C:\Users\admin\AppData\Local\Temp\PCVR-Rookie.exe
explorer.exe
User:
admin
Company:
Rookie.WTF
Integrity Level:
MEDIUM
Description:
AndroidSideloader
Exit code:
0
Version:
2.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\pcvr-rookie.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2260"7z.exe" x "C:\Users\admin\Desktop\rclone.zip" -y -o"C:\Users\admin\Desktop"C:\Users\admin\Desktop\7z.exePCVR-Rookie.exe
User:
admin
Company:
Igor Pavlov
Integrity Level:
MEDIUM
Description:
7-Zip Standalone Console
Exit code:
0
Version:
23.01
Modules
Images
c:\users\admin\desktop\7z.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2368"C:\Users\admin\Desktop\rclone\rclone.exe" cat ":PCVR Games/VRP-GameList.txt" --config vrp.download.configC:\Users\admin\Desktop\rclone\rclone.exePCVR-Rookie.exe
User:
admin
Company:
https://rclone.org
Integrity Level:
MEDIUM
Description:
Rsync for cloud storage
Exit code:
1
Version:
1.62.2
Modules
Images
c:\users\admin\desktop\rclone\rclone.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\user32.dll
2524"C:\Users\admin\Desktop\rclone\rclone.exe" cat ":PCVR Games/VRP-GameList.txt" --config vrp.download.configC:\Users\admin\Desktop\rclone\rclone.exePCVR-Rookie.exe
User:
admin
Company:
https://rclone.org
Integrity Level:
MEDIUM
Description:
Rsync for cloud storage
Exit code:
1
Version:
1.62.2
Modules
Images
c:\users\admin\desktop\rclone\rclone.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\user32.dll
Total events
13 634
Read events
13 590
Write events
44
Delete events
0

Modification events

(PID) Process:(2124) PCVR-Rookie.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2124) PCVR-Rookie.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2124) PCVR-Rookie.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2124) PCVR-Rookie.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2124) PCVR-Rookie.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1768) PCVR-Rookie.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(1768) PCVR-Rookie.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(1768) PCVR-Rookie.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(1768) PCVR-Rookie.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(1768) PCVR-Rookie.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
Executable files
4
Suspicious files
7
Text files
20
Unknown types
0

Dropped files

PID
Process
Filename
Type
20727z.exeC:\Users\admin\AppData\Local\Temp\rclone-v1.62.2-windows-386\rclone.exe
MD5:
SHA256:
2124PCVR-Rookie.exeC:\Users\admin\AppData\Local\Temp\rclone\vrp.download.config
MD5:
SHA256:
2124PCVR-Rookie.exeC:\Users\admin\AppData\Local\Temp\Cab125B.tmpcompressed
MD5:AC05D27423A85ADC1622C714F2CB6184
SHA256:C6456E12E5E53287A547AF4103E0397CB9697E466CF75844312DC296D43D144D
2124PCVR-Rookie.exeC:\Users\admin\AppData\Local\Rookie.WTF\PCVR-Rookie.exe_Url_xvschwsgakn2nagjsqlofr5vkuygxcxa\2.0.0.0\k513vqmd.newcfgxml
MD5:410AFDA4BDE459246A3CA55E2EE36BC3
SHA256:4C28889E076FC03D80185C5CC0C85F26B4078E84C279CC2943C0B3CCAD0F9B4E
2124PCVR-Rookie.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\78118620D6B8F6CB2909CD29DD8239E9binary
MD5:FEE69FEDBBE911A075E70EE382958D1B
SHA256:55AB667FFA184E4CBC67E4875B766B4BB723A5387D930C1CF44FB1C595971D51
2124PCVR-Rookie.exeC:\Users\admin\AppData\Local\Temp\rclone.zipcompressed
MD5:70AEDE552F45E0A9BC6BAC985AA3D7BB
SHA256:5B91EE887762007CD9FEF64003A70C496F855602D1BBB1C32A364008611F98FF
2124PCVR-Rookie.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\78118620D6B8F6CB2909CD29DD8239E9binary
MD5:EE39380F325CF0C51F4C6F7BE0A4C899
SHA256:5DD661D3CB33B5005CBED045A223DDC4445AAA41D1ACB5DF700884CAD9BA4195
20727z.exeC:\Users\admin\AppData\Local\Temp\rclone-v1.62.2-windows-386\rclone.1text
MD5:28913555884B76E183CC217199A74D34
SHA256:F940A104EE3E4BAB9D9A457E2CC0C2BF6619FCEBEF1DEB2D4F733C240682ED4D
2124PCVR-Rookie.exeC:\Users\admin\AppData\Local\Temp\rclone\vrp.upload.configtext
MD5:F06F4B0A6775A75A4EC9904520EC8D91
SHA256:1A47B327964843C1C614F7296D6939B69A36A9A0395179C13FC1BDC9D5F05932
20727z.exeC:\Users\admin\AppData\Local\Temp\rclone-v1.62.2-windows-386\README.htmlhtml
MD5:A350DFB8F5E474403BF404716EB29BA3
SHA256:9FEA3D03E271F38119BA46E71728D7B84420DCEC0427EEEA6DE05E160ED26E97
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
13
DNS requests
7
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2124
PCVR-Rookie.exe
GET
200
104.18.38.233:80
http://zerossl.crt.sectigo.com/ZeroSSLECCDomainSecureSiteCA.crt
unknown
binary
905 b
unknown
2124
PCVR-Rookie.exe
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?f9dcd550dac845bb
unknown
compressed
65.2 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2124
PCVR-Rookie.exe
95.217.6.16:443
downloads.rclone.org
Hetzner Online GmbH
FI
unknown
2124
PCVR-Rookie.exe
93.184.221.240:80
ctldl.windowsupdate.com
EDGECAST
GB
whitelisted
2124
PCVR-Rookie.exe
140.82.121.4:443
github.com
GITHUB
US
unknown
2124
PCVR-Rookie.exe
185.199.111.133:443
raw.githubusercontent.com
FASTLY
US
unknown
2124
PCVR-Rookie.exe
185.247.224.87:443
vrpirates.wiki
Flokinet Ltd
SC
unknown
2124
PCVR-Rookie.exe
104.18.38.233:80
zerossl.crt.sectigo.com
CLOUDFLARENET
shared
1768
PCVR-Rookie.exe
95.217.6.16:443
downloads.rclone.org
Hetzner Online GmbH
FI
unknown
1768
PCVR-Rookie.exe
140.82.121.4:443
github.com
GITHUB
US
unknown
1768
PCVR-Rookie.exe
185.199.111.133:443
raw.githubusercontent.com
FASTLY
US
unknown

DNS requests

Domain
IP
Reputation
downloads.rclone.org
  • 95.217.6.16
unknown
ctldl.windowsupdate.com
  • 93.184.221.240
whitelisted
github.com
  • 140.82.121.4
shared
raw.githubusercontent.com
  • 185.199.111.133
  • 185.199.110.133
  • 185.199.109.133
  • 185.199.108.133
shared
vrpirates.wiki
  • 185.247.224.87
unknown
zerossl.crt.sectigo.com
  • 104.18.38.233
  • 172.64.149.23
whitelisted

Threats

PID
Process
Class
Message
2124
PCVR-Rookie.exe
Misc activity
ET INFO Observed ZeroSSL SSL/TLS Certificate
1768
PCVR-Rookie.exe
Misc activity
ET INFO Observed ZeroSSL SSL/TLS Certificate
No debug info