File name:

Spectrasonics.Omnisphere.v2.0.Patch.and.Keygen.Only-R2R.rar

Full analysis: https://app.any.run/tasks/72eb2348-a6ef-44d8-95c7-18b0e23299f7
Verdict: Malicious activity
Analysis date: June 19, 2024, 00:26:56
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v4, os: Win32
MD5:

1DA2CDE457A3243FB6904624F5DB98F3

SHA1:

A8EEB31893BF8469DF01348C27EB171F3A69DFAB

SHA256:

02D59F43AA28FD9955EF232CF734639AD4073054EA1C86F01472336B9F050747

SSDEEP:

24576:XNk5YRY9SsUvtTJ3PetqXzOd3cuN2+MeEWJHyOxDNdboE07Poh3+p:XS5UEUvtTJ3uai5cuN2+MeEWr5vboE8V

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 3380)
      • Spectrasonics_2048_KeyGen.exe (PID: 2748)
  • SUSPICIOUS

    • Start notepad (likely ransomware note)

      • WinRAR.exe (PID: 3380)
    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 3380)
    • Executable content was dropped or overwritten

      • Spectrasonics_2048_KeyGen.exe (PID: 2748)
  • INFO

    • Reads the computer name

      • keygen.exe (PID: 2960)
      • Spectrasonics_2048_KeyGen.exe (PID: 2748)
      • wmpnscfg.exe (PID: 1788)
    • Create files in a temporary directory

      • keygen.exe (PID: 2960)
      • Spectrasonics_2048_KeyGen.exe (PID: 2748)
    • Checks supported languages

      • keygen.exe (PID: 2960)
      • wmpnscfg.exe (PID: 1788)
      • Spectrasonics_2048_KeyGen.exe (PID: 2748)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3380)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 1788)
    • Reads the machine GUID from the registry

      • keygen.exe (PID: 2960)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

CompressedSize: 586
UncompressedSize: 908
OperatingSystem: Win32
ModifyDate: 2015:06:18 00:00:00
PackingMethod: Best Compression
ArchivedFileName: R2R.txt
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
45
Monitored processes
6
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe spectrasonics_2048_keygen.exe no specs spectrasonics_2048_keygen.exe keygen.exe no specs notepad.exe no specs wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1788"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2748"C:\Users\admin\AppData\Local\Temp\Rar$EXa3380.13443\Spectrasonics_2048_KeyGen.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3380.13443\Spectrasonics_2048_KeyGen.exe
WinRAR.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3380.13443\spectrasonics_2048_keygen.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
2760"C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\AppData\Local\Temp\Rar$DIa3380.25253\R2R.txtC:\Windows\System32\notepad.exeWinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2960C:\Users\admin\AppData\Local\Temp\keygen.exeC:\Users\admin\AppData\Local\Temp\keygen.exeSpectrasonics_2048_KeyGen.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\users\admin\appdata\local\temp\keygen.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
3380"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\Spectrasonics.Omnisphere.v2.0.Patch.and.Keygen.Only-R2R.rarC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3568"C:\Users\admin\AppData\Local\Temp\Rar$EXa3380.13443\Spectrasonics_2048_KeyGen.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3380.13443\Spectrasonics_2048_KeyGen.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3380.13443\spectrasonics_2048_keygen.exe
c:\windows\system32\ntdll.dll
Total events
10 816
Read events
10 768
Write events
47
Delete events
1

Modification events

(PID) Process:(3380) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3380) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3380) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3380) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3380) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3380) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(3380) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Spectrasonics.Omnisphere.v2.0.Patch.and.Keygen.Only-R2R.rar
(PID) Process:(3380) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3380) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3380) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
5
Suspicious files
1
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
2748Spectrasonics_2048_KeyGen.exeC:\Users\admin\AppData\Local\Temp\bgm.itbinary
MD5:31F24C0967530394A64CB82AC06A1E2F
SHA256:E66ACF2363DAB9A21265651887799B00DC1413B2F70155B9B94A4BB9CFF045BB
3380WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3380.13443\Spectrasonics_2048_KeyGen.exeexecutable
MD5:17174BC990FCFD50BD3F2E00A2D82ED4
SHA256:D1436AAE15D42FFFE91BB0E77114BB66B4C97E58111E09AF2A10166790FE6EA1
2748Spectrasonics_2048_KeyGen.exeC:\Users\admin\AppData\Local\Temp\R2RTOOL.dllexecutable
MD5:0B0214CDF2577A43AF135B741D98BC0C
SHA256:D224BED5BBA63C1B222E6628E19615278490C1139804AAFEDE4627DA5BE655CC
2748Spectrasonics_2048_KeyGen.exeC:\Users\admin\AppData\Local\Temp\keygen.exeexecutable
MD5:F1F1B28254FC2816DF83BC4432A6D7CF
SHA256:62287A6C233820F45E7250CAAE8EE068425ECF1D229E29316D9F0038401A3751
3380WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3380.13443\R2R.txttext
MD5:DE9A56C43338A5114A13D1A5E755DFD0
SHA256:1ECB8B657E6CE09695C42FBF3B3CF6B12E28C32D7DC83ECE5CBAB891741CA3C3
3380WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DIa3380.25253\R2R.txttext
MD5:DE9A56C43338A5114A13D1A5E755DFD0
SHA256:1ECB8B657E6CE09695C42FBF3B3CF6B12E28C32D7DC83ECE5CBAB891741CA3C3
2748Spectrasonics_2048_KeyGen.exeC:\Users\admin\AppData\Local\Temp\BASSMOD.dllexecutable
MD5:E4EC57E8508C5C4040383EBE6D367928
SHA256:8AD9E47693E292F381DA42DDC13724A3063040E51C26F4CA8E1F8E2F1DDD547F
2748Spectrasonics_2048_KeyGen.exeC:\Users\admin\AppData\Local\Temp\R2RSS2048.dllexecutable
MD5:4D97354487A74D33552AFC93A7A8E1B9
SHA256:762548049D64380584D2E77B5499F4BEA16693308EE156618C83F0F0B847B064
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
11
DNS requests
5
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1372
svchost.exe
GET
304
46.228.146.128:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?33775f6043c93e33
unknown
unknown
1372
svchost.exe
GET
200
23.48.23.173:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
unknown
1372
svchost.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
unknown
GET
304
23.50.131.216:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?a9f83325acc8ca75
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2564
svchost.exe
239.255.255.250:3702
unknown
4
System
192.168.100.255:138
whitelisted
1060
svchost.exe
224.0.0.252:5355
unknown
1372
svchost.exe
51.124.78.146:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1372
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1372
svchost.exe
46.228.146.128:80
ctldl.windowsupdate.com
LLNW
US
unknown
1372
svchost.exe
23.48.23.173:80
crl.microsoft.com
Akamai International B.V.
DE
unknown
1372
svchost.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
unknown
1060
svchost.exe
23.50.131.216:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
whitelisted
ctldl.windowsupdate.com
  • 46.228.146.128
  • 46.228.146.0
  • 23.50.131.216
  • 23.50.131.200
whitelisted
crl.microsoft.com
  • 23.48.23.173
  • 23.48.23.143
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted

Threats

No threats detected
No debug info