File name:

RuBot Cracked.zip

Full analysis: https://app.any.run/tasks/6c33ae33-ea50-4306-8dc3-f92ad8dec711
Verdict: Malicious activity
Analysis date: January 07, 2022, 23:45:00
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

D4B95D279E649315950E69963723871E

SHA1:

E62D9959EC5B1FCC80B0337A1DFAEE16EB3B17A8

SHA256:

047D99296AEA20E3C33B2F2B34768A46D39D8473E77E71B4E8813796DC8659C1

SSDEEP:

12288:AUCkdYOaD3wrb8IxQMAu06iqUzdwSMOtF3yHDskgfHkBjR18VKecFajgMTV2nTp5:AYdY/cQVxqUzdwwICHkVfecZmgpMw

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 2716)
      • RuBot2Copy.exe (PID: 3080)
    • Application was dropped or rewritten from another process

      • RuBot2Copy.exe (PID: 3080)
  • SUSPICIOUS

    • Checks supported languages

      • WinRAR.exe (PID: 2288)
      • RuBot2Copy.exe (PID: 3080)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2288)
    • Reads the computer name

      • WinRAR.exe (PID: 2288)
      • RuBot2Copy.exe (PID: 3080)
    • Drops a file that was compiled in debug mode

      • WinRAR.exe (PID: 2288)
  • INFO

    • Manual execution by user

      • RuBot2Copy.exe (PID: 3080)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: RuBot Cracked/RuBot/
ZipUncompressedSize: -
ZipCompressedSize: -
ZipCRC: 0x00000000
ZipModifyDate: 2018:03:31 01:59:12
ZipCompression: None
ZipBitFlag: -
ZipRequiredVersion: 20
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
37
Monitored processes
3
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe searchprotocolhost.exe no specs rubot2copy.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2288"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\RuBot Cracked.zip"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2716"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe3_ Global\UsGthrCtrlFltPipeMssGthrPipe3 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\system32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7601.24542 (win7sp1_ldr_escrow.191209-2211)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3080"C:\Users\admin\Desktop\RuBot Cracked\RuBot\RuBot2Copy.exe" C:\Users\admin\Desktop\RuBot Cracked\RuBot\RuBot2Copy.exeExplorer.EXE
User:
admin
Company:
RuBot.OVH
Integrity Level:
MEDIUM
Description:
RuBot_Tools
Exit code:
0
Version:
6.1.0.0
Modules
Images
c:\users\admin\desktop\rubot cracked\rubot\rubot2copy.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
1 775
Read events
1 750
Write events
25
Delete events
0

Modification events

(PID) Process:(2288) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2288) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2288) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2288) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(2288) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2288) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\RuBot Cracked.zip
(PID) Process:(2288) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2288) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2288) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2288) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
5
Suspicious files
1
Text files
12
Unknown types
2

Dropped files

PID
Process
Filename
Type
2288WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2288.27128\RuBot Cracked\RuBot\Chat Bots Texts\chatBot 2.txttext
MD5:2B4E21C7544F4BCD9232D2859BA96E37
SHA256:9B253AAE47E1D2573CB8508EB235CC9C660826F7D8AE295D82AC495CA2B2C388
2288WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2288.27128\RuBot Cracked\RuBot\Chat Bots Texts\GERMAN CHATBOT.txttext
MD5:10988A198328FC7AF11DD9CDBDB4C52D
SHA256:942C78CF9CA4423E62EA1B6F5D0FD88D955BBAC39F8A52519A54F1C99E734C31
2288WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2288.27128\RuBot Cracked\RuBot\.vs\RuBot Tools\v15\.suobinary
MD5:72047AF58DB7B8A1FEE383AA420C6779
SHA256:F508439301484AA31277BB4C49BC0A14AD95235F8E96C6FFBB0422DEC737A8B6
2288WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2288.27128\RuBot Cracked\RuBot\GrabProxy.txttext
MD5:CF3A4E0E92709928AB2440331F5EBB9B
SHA256:8C47FC94301C20A33FA3DE4E9F301893BA747384BB13C004111A4ED14FD4C084
2288WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2288.27128\RuBot Cracked\RuBot\eXtremeNet.dllexecutable
MD5:613E35243D0F608D7A03A5500CF2F08B
SHA256:91F6647B19613C3F58CF5D75B320CC4F794318906C24D095C78964AA004CE844
2288WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2288.27128\RuBot Cracked\RuBot\HtmlAgilityPack.pdbpdb
MD5:A62E283F655F6C8D13C2157DECC6D526
SHA256:76209CD7521A86B41E27242F6BBB4FB48715840809D4E932351F33AE7C07D19F
2288WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2288.27128\RuBot Cracked\RuBot\HtmlAgilityPack.dllexecutable
MD5:433645B4A51EE5D2A2E48114BE461052
SHA256:129288252BEED0824C8436F3C595BD8E200A2182A229DEC85A2CA722F0CF1A05
2288WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2288.27128\RuBot Cracked\RuBot\MetroFramework.dllexecutable
MD5:34EA7F7D66563F724318E322FF08F4DB
SHA256:C2C12D31B4844E29DE31594FC9632A372A553631DE0A0A04C8AF91668E37CF49
2288WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2288.27128\RuBot Cracked\RuBot\Chat Bots Texts\chatBot 3.txttext
MD5:0E2054A055CE9434A5855CCA28C15FD6
SHA256:F8342ED8D6C1CEB2DF7F01541B004286A570640B7C45620CA4386EE4645F6856
2288WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2288.27128\RuBot Cracked\RuBot\HtmlAgilityPack.xmlxml
MD5:68DBFAD2DFE36860A4D2AA2B6DCC16E6
SHA256:5E8C676CD7A423EF1DD211E1B1C69284946A6DE966EDB00C81566B49A75F8F7B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info