File name:

RuBot Cracked.zip

Full analysis: https://app.any.run/tasks/1db9f84c-d577-411d-8d2d-877f7b273bbb
Verdict: Malicious activity
Analysis date: November 03, 2018, 18:53:57
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

D4B95D279E649315950E69963723871E

SHA1:

E62D9959EC5B1FCC80B0337A1DFAEE16EB3B17A8

SHA256:

047D99296AEA20E3C33B2F2B34768A46D39D8473E77E71B4E8813796DC8659C1

SSDEEP:

12288:AUCkdYOaD3wrb8IxQMAu06iqUzdwSMOtF3yHDskgfHkBjR18VKecFajgMTV2nTp5:AYdY/cQVxqUzdwwICHkVfecZmgpMw

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads Internet Cache Settings

      • RuBot2Copy.exe (PID: 3644)
    • Connects to unusual port

      • RuBot2Copy.exe (PID: 3644)
  • INFO

    • Application was crashed

      • RuBot Tools.vshost.exe (PID: 2112)
      • RuBot2Copy.exe (PID: 3644)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2018:03:31 01:59:12
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: RuBot Cracked/RuBot/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
49
Monitored processes
8
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs rubot2copy.exe no specs rubot2copy.exe no specs rubot tools.vshost.exe rubot2copy.exe no specs rubot2copy.exe no specs rubot2copy.exe no specs rubot2copy.exe

Process information

PID
CMD
Path
Indicators
Parent process
2112"C:\Users\admin\Desktop\RuBot Cracked\RuBot\RuBot Tools.vshost.exe" C:\Users\admin\Desktop\RuBot Cracked\RuBot\RuBot Tools.vshost.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
vshost32.exe
Exit code:
3762504530
Version:
14.0.23107.0
Modules
Images
c:\users\admin\desktop\rubot cracked\rubot\rubot tools.vshost.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2180"C:\Users\admin\Desktop\RuBot Cracked\RuBot\RuBot2Copy.exe" C:\Users\admin\Desktop\RuBot Cracked\RuBot\RuBot2Copy.exeexplorer.exe
User:
admin
Company:
RuBot.OVH
Integrity Level:
MEDIUM
Description:
RuBot_Tools
Exit code:
4294967295
Version:
6.1.0.0
Modules
Images
c:\users\admin\desktop\rubot cracked\rubot\rubot2copy.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2724"C:\Users\admin\Desktop\RuBot Cracked\RuBot\RuBot2Copy.exe" C:\Users\admin\Desktop\RuBot Cracked\RuBot\RuBot2Copy.exeexplorer.exe
User:
admin
Company:
RuBot.OVH
Integrity Level:
MEDIUM
Description:
RuBot_Tools
Exit code:
0
Version:
6.1.0.0
Modules
Images
c:\users\admin\desktop\rubot cracked\rubot\rubot2copy.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2896"C:\Users\admin\Desktop\RuBot Cracked\RuBot\RuBot2Copy.exe" C:\Users\admin\Desktop\RuBot Cracked\RuBot\RuBot2Copy.exeexplorer.exe
User:
admin
Company:
RuBot.OVH
Integrity Level:
MEDIUM
Description:
RuBot_Tools
Exit code:
4294967295
Version:
6.1.0.0
Modules
Images
c:\users\admin\desktop\rubot cracked\rubot\rubot2copy.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2916"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\RuBot Cracked.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\comdlg32.dll
3044"C:\Users\admin\Desktop\RuBot Cracked\RuBot\RuBot2Copy.exe" C:\Users\admin\Desktop\RuBot Cracked\RuBot\RuBot2Copy.exeexplorer.exe
User:
admin
Company:
RuBot.OVH
Integrity Level:
MEDIUM
Description:
RuBot_Tools
Exit code:
4294967295
Version:
6.1.0.0
Modules
Images
c:\users\admin\desktop\rubot cracked\rubot\rubot2copy.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3296"C:\Users\admin\Desktop\RuBot Cracked\RuBot\RuBot2Copy.exe" C:\Users\admin\Desktop\RuBot Cracked\RuBot\RuBot2Copy.exeexplorer.exe
User:
admin
Company:
RuBot.OVH
Integrity Level:
MEDIUM
Description:
RuBot_Tools
Exit code:
4294967295
Version:
6.1.0.0
Modules
Images
c:\users\admin\desktop\rubot cracked\rubot\rubot2copy.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3644"C:\Users\admin\Desktop\RuBot Cracked\RuBot\RuBot2Copy.exe" C:\Users\admin\Desktop\RuBot Cracked\RuBot\RuBot2Copy.exe
explorer.exe
User:
admin
Company:
RuBot.OVH
Integrity Level:
MEDIUM
Description:
RuBot_Tools
Exit code:
3221225477
Version:
6.1.0.0
Modules
Images
c:\users\admin\desktop\rubot cracked\rubot\rubot2copy.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
1 059
Read events
978
Write events
80
Delete events
1

Modification events

(PID) Process:(2916) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2916) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2916) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2916) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\RuBot Cracked.zip
(PID) Process:(2916) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2916) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2916) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2916) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2916) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
(PID) Process:(2916) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\General
Operation:writeName:LastFolder
Value:
C:\Users\admin\AppData\Local\Temp
Executable files
0
Suspicious files
1
Text files
3
Unknown types
0

Dropped files

PID
Process
Filename
Type
2916WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2916.27578\RuBot Cracked\RuBot\.vs\RuBot Tools\v15\.suo
MD5:
SHA256:
2916WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2916.27578\RuBot Cracked\RuBot\Chat Bots Texts\chatBot 2.txt
MD5:
SHA256:
2916WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2916.27578\RuBot Cracked\RuBot\Chat Bots Texts\chatBot 3.txt
MD5:
SHA256:
2916WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2916.27578\RuBot Cracked\RuBot\Chat Bots Texts\chatBot1.txt
MD5:
SHA256:
2916WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2916.27578\RuBot Cracked\RuBot\Chat Bots Texts\GERMAN CHATBOT.txt
MD5:
SHA256:
2916WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2916.27578\RuBot Cracked\RuBot\eXtremeNet.dll
MD5:
SHA256:
2916WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2916.27578\RuBot Cracked\RuBot\GrabProxy.txt
MD5:
SHA256:
2916WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2916.27578\RuBot Cracked\RuBot\HtmlAgilityPack.dll
MD5:
SHA256:
2916WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2916.27578\RuBot Cracked\RuBot\HtmlAgilityPack.pdb
MD5:
SHA256:
2916WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2916.27578\RuBot Cracked\RuBot\HtmlAgilityPack.xml
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
110
TCP/UDP connections
136
DNS requests
8
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3644
RuBot2Copy.exe
CONNECT
1.10.185.133:30207
http://1.10.185.133:30207api.twitch.tv:443
TH
unknown
3644
RuBot2Copy.exe
CONNECT
1.10.186.12:33349
http://1.10.186.12:33349api.twitch.tv:443
TH
unknown
3644
RuBot2Copy.exe
CONNECT
1.10.186.130:55069
http://1.10.186.130:55069api.twitch.tv:443
TH
unknown
3644
RuBot2Copy.exe
CONNECT
1.10.186.100:55011
http://1.10.186.100:55011api.twitch.tv:443
TH
unknown
3644
RuBot2Copy.exe
CONNECT
1.10.186.132:42150
http://1.10.186.132:42150api.twitch.tv:443
TH
unknown
3644
RuBot2Copy.exe
CONNECT
1.10.186.141:39385
http://1.10.186.141:39385api.twitch.tv:443
TH
unknown
3644
RuBot2Copy.exe
GET
200
216.58.215.243:80
http://www.sslproxies24.top/
US
html
55.3 Kb
whitelisted
3644
RuBot2Copy.exe
GET
200
216.58.215.225:80
http://googleproxies24.blogspot.com/
US
html
37.8 Kb
whitelisted
3644
RuBot2Copy.exe
GET
200
216.58.215.243:80
http://www.proxyserverlist24.top/
US
html
57.6 Kb
whitelisted
3644
RuBot2Copy.exe
GET
200
216.58.215.225:80
http://googleproxies24.blogspot.com/2016/03/18-03-16-free-google-proxies-50.html
US
html
33.9 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3644
RuBot2Copy.exe
172.227.14.92:443
api.twitch.tv
Akamai Technologies, Inc.
US
whitelisted
3644
RuBot2Copy.exe
216.58.215.225:80
sslproxies24.blogspot.com
Google Inc.
US
whitelisted
3644
RuBot2Copy.exe
216.58.215.243:80
www.sslproxies24.top
Google Inc.
US
whitelisted
3644
RuBot2Copy.exe
1.10.141.212:30493
TOT Public Company Limited
TH
unknown
3644
RuBot2Copy.exe
1.10.184.166:57330
TOT Public Company Limited
TH
unknown
3644
RuBot2Copy.exe
1.10.185.133:30207
TOT Public Company Limited
TH
unknown
3644
RuBot2Copy.exe
1.10.186.153:32731
TOT Public Company Limited
TH
unknown
3644
RuBot2Copy.exe
1.10.186.150:60420
TOT Public Company Limited
TH
unknown
3644
RuBot2Copy.exe
1.10.186.157:30693
TOT Public Company Limited
TH
unknown
3644
RuBot2Copy.exe
1.10.186.161:61148
TOT Public Company Limited
TH
unknown

DNS requests

Domain
IP
Reputation
api.twitch.tv
  • 172.227.14.92
whitelisted
sslproxies24.blogspot.com
  • 216.58.215.225
whitelisted
www.sslproxies24.top
  • 216.58.215.243
whitelisted
googleproxies24.blogspot.com
  • 216.58.215.225
whitelisted
proxyserverlist-24.blogspot.com
  • 216.58.215.225
whitelisted
www.proxyserverlist24.top
  • 216.58.215.243
whitelisted
dns.msftncsi.com
  • 131.107.255.255
shared

Threats

PID
Process
Class
Message
1056
svchost.exe
Potentially Bad Traffic
ET DNS Query to a *.top domain - Likely Hostile
3644
RuBot2Copy.exe
Potentially Bad Traffic
ET INFO HTTP Request to a *.top domain
No debug info