File name:

ConsoleSniffer v4.1 installer.rar

Full analysis: https://app.any.run/tasks/f742c842-c0e1-48b5-a468-12c8962ad773
Verdict: Malicious activity
Analysis date: September 03, 2019, 08:46:04
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v4, os: Win32
MD5:

0DEB777E98CFA9392BCB4E9E4892C86A

SHA1:

35F246C76270CB5362376C24CB5CED196EE87C5E

SHA256:

05E99DAEF083250077998999CF1A01AA39BBD80C7605186DAE27D2A12928BBAB

SSDEEP:

196608:RRqzBmyrYVWxqyNSocpgqkG0Jbxbnzi/BxIpmLzp:/qUyrY0VNSNJk5WDIpup

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • ConsoleSniffer v4.1 installer.exe (PID: 3364)
      • ConsoleSniffer v4.1 installer.exe (PID: 3876)
      • vcredist_x86 - 2012 update 4.exe (PID: 356)
      • vcredist_x86 - 2012 update 4.exe (PID: 3412)
      • Launcher.exe (PID: 2952)
      • Launcher.exe (PID: 2348)
      • Launcher.exe (PID: 3144)
    • Loads dropped or rewritten executable

      • vcredist_x86 - 2012 update 4.exe (PID: 3412)
      • Launcher.exe (PID: 2952)
      • Launcher.exe (PID: 3144)
    • Changes the autorun value in the registry

      • vcredist_x86 - 2012 update 4.exe (PID: 356)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3700)
      • ConsoleSniffer v4.1 installer.exe (PID: 3876)
      • vcredist_x86 - 2012 update 4.exe (PID: 3412)
      • vcredist_x86 - 2012 update 4.exe (PID: 356)
      • msiexec.exe (PID: 3264)
    • Creates files in the user directory

      • ConsoleSniffer v4.1 installer.exe (PID: 3876)
    • Searches for installed software

      • vcredist_x86 - 2012 update 4.exe (PID: 3412)
      • vcredist_x86 - 2012 update 4.exe (PID: 356)
    • Executed as Windows Service

      • vssvc.exe (PID: 3716)
    • Creates files in the program directory

      • ConsoleSniffer v4.1 installer.exe (PID: 3876)
      • vcredist_x86 - 2012 update 4.exe (PID: 356)
    • Creates a software uninstall entry

      • ConsoleSniffer v4.1 installer.exe (PID: 3876)
      • vcredist_x86 - 2012 update 4.exe (PID: 356)
    • Executed via COM

      • DrvInst.exe (PID: 3540)
    • Creates files in the Windows directory

      • msiexec.exe (PID: 3264)
    • Starts Microsoft Installer

      • Launcher.exe (PID: 3144)
  • INFO

    • Low-level read access rights to disk partition

      • vssvc.exe (PID: 3716)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 3264)
    • Manual execution by user

      • Launcher.exe (PID: 2348)
      • Launcher.exe (PID: 3144)
    • Application launched itself

      • msiexec.exe (PID: 3264)
    • Searches for installed software

      • msiexec.exe (PID: 3264)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

CompressedSize: 383
UncompressedSize: 491
OperatingSystem: Win32
ModifyDate: 2016:08:09 10:21:23
PackingMethod: Normal
ArchivedFileName: READ THIS IF YOU HAVE PROBLEMS.txt
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
52
Monitored processes
13
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start drop and start start drop and start drop and start winrar.exe consolesniffer v4.1 installer.exe no specs consolesniffer v4.1 installer.exe vcredist_x86 - 2012 update 4.exe vcredist_x86 - 2012 update 4.exe vssvc.exe no specs drvinst.exe no specs msiexec.exe launcher.exe no specs launcher.exe no specs launcher.exe msiexec.exe no specs msiexec.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
356"C:\Program Files\Spy Proof Solutions\Console Sniffer\vcredist_x86 - 2012 update 4.exe" /passive /norestartC:\Program Files\Spy Proof Solutions\Console Sniffer\vcredist_x86 - 2012 update 4.exe
ConsoleSniffer v4.1 installer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030
Exit code:
0
Version:
11.0.61030.0
Modules
Images
c:\program files\spy proof solutions\console sniffer\vcredist_x86 - 2012 update 4.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
2348"C:\Program Files\Spy Proof Solutions\Console Sniffer\Launcher.exe" C:\Program Files\Spy Proof Solutions\Console Sniffer\Launcher.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Launcher
Exit code:
3221226540
Version:
1.0.0.0
Modules
Images
c:\program files\spy proof solutions\console sniffer\launcher.exe
c:\systemroot\system32\ntdll.dll
2952"C:\Program Files\Spy Proof Solutions\Console Sniffer\Launcher.exe"C:\Program Files\Spy Proof Solutions\Console Sniffer\Launcher.exeConsoleSniffer v4.1 installer.exe
User:
admin
Integrity Level:
HIGH
Description:
Launcher
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\program files\spy proof solutions\console sniffer\launcher.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
3144"C:\Program Files\Spy Proof Solutions\Console Sniffer\Launcher.exe" C:\Program Files\Spy Proof Solutions\Console Sniffer\Launcher.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
Launcher
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\program files\spy proof solutions\console sniffer\launcher.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
3264C:\Windows\system32\msiexec.exe /VC:\Windows\system32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3364"C:\Users\admin\AppData\Local\Temp\Rar$EXa3700.38989\ConsoleSniffer v4.1 installer.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3700.38989\ConsoleSniffer v4.1 installer.exeWinRAR.exe
User:
admin
Company:
Spy Proof Solutions
Integrity Level:
MEDIUM
Description:
Console Sniffer 4.00 Installation
Exit code:
3221226540
Version:
4.00
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3700.38989\consolesniffer v4.1 installer.exe
c:\systemroot\system32\ntdll.dll
3412"C:\Program Files\Spy Proof Solutions\Console Sniffer\vcredist_x86 - 2012 update 4.exe" /passive /norestart -burn.unelevated BurnPipe.{26511C5C-153D-497E-B608-B32F1F912B77} {7370DCF8-3514-4619-88C2-F7D08D75F180} 356C:\Program Files\Spy Proof Solutions\Console Sniffer\vcredist_x86 - 2012 update 4.exe
vcredist_x86 - 2012 update 4.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030
Exit code:
0
Version:
11.0.61030.0
Modules
Images
c:\program files\spy proof solutions\console sniffer\vcredist_x86 - 2012 update 4.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
3540DrvInst.exe "1" "200" "STORAGE\VolumeSnapshot\HarddiskVolumeSnapshot22" "" "" "695c3f483" "00000000" "000004B8" "000005B8"C:\Windows\system32\DrvInst.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
3700"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\ConsoleSniffer v4.1 installer.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3716C:\Windows\system32\vssvc.exeC:\Windows\system32\vssvc.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\vssvc.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
1 824
Read events
1 247
Write events
553
Delete events
24

Modification events

(PID) Process:(3700) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3700) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3700) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3700) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\ConsoleSniffer v4.1 installer.rar
(PID) Process:(3700) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3700) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3700) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3700) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3700) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(3700) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
Executable files
47
Suspicious files
17
Text files
49
Unknown types
6

Dropped files

PID
Process
Filename
Type
3876ConsoleSniffer v4.1 installer.exeC:\Users\admin\AppData\Local\Temp\$inst\temp_0.tmp
MD5:
SHA256:
3700WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3700.38989\READ THIS IF YOU HAVE PROBLEMS.txttext
MD5:
SHA256:
3876ConsoleSniffer v4.1 installer.exeC:\Users\admin\AppData\Local\Temp\$inst\2.tmpcompressed
MD5:AF5DE111142A20EA6F01AB6E1606FDC2
SHA256:4DE4CAC91A55053A0C29AD262588B411C19C3FA625C421EF7B95B9EE4F9E3310
3700WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3700.38989\ConsoleSniffer v4.1 installer.exeexecutable
MD5:9E24D7787ACBB9AB91536FC82EC84C6C
SHA256:6B84979505ECF68D5FEEFBC4C47B4770E5ABC1FB18E1CE54503E05FC637812B3
3876ConsoleSniffer v4.1 installer.exeC:\Program Files\Spy Proof Solutions\Console Sniffer\PcapDotNet.Base.dllexecutable
MD5:6F2E6B9046E7ED3CE43A34A7B701FBF9
SHA256:39D850B2412D78580EA842730BB56F59474A8DE4C2D9218D7593CD5B96AC9BAF
3876ConsoleSniffer v4.1 installer.exeC:\Program Files\Spy Proof Solutions\Console Sniffer\nexecutable
MD5:280435C0EB072BB0B08FF30690EB67A1
SHA256:A65FB95F9654140383A9FCE1176533D7A375907C44D98AF2E0886EF79C621372
3876ConsoleSniffer v4.1 installer.exeC:\Program Files\Spy Proof Solutions\Console Sniffer\Bootstrap.dllexecutable
MD5:C7824FEAC987C3983553525E58D937F1
SHA256:2A2759A2FC05841E417F2AF6C80F381F06093254AE36C9E4AB758F7C5A08EB1F
3876ConsoleSniffer v4.1 installer.exeC:\Program Files\Spy Proof Solutions\Console Sniffer\dexecutable
MD5:C614A015978930363C12E0F722884C78
SHA256:84A1E5BECE6CC615A1EB55D0514CB2C3633D03E35BE441DFA4855809F8C0DB49
3876ConsoleSniffer v4.1 installer.exeC:\Program Files\Spy Proof Solutions\Console Sniffer\Launcher.exeexecutable
MD5:345E0B839A2F5DDC69BCC46F6C27FEE3
SHA256:2E9EF7080AE71971B90D6B91122A91F13AF0D74E898BCE3E3A6E41ED1F958C6A
3876ConsoleSniffer v4.1 installer.exeC:\Program Files\Spy Proof Solutions\Console Sniffer\cexecutable
MD5:382CD65512DE4F47E3F6809A90DCDB7C
SHA256:1D9E26121EFD940B15BDFC96EB42EB56C364F37F26E4A437DA817C0DF897F695
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
1
DNS requests
1
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
356
vcredist_x86 - 2012 update 4.exe
GET
200
2.16.186.74:80
http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl
unknown
der
781 b
whitelisted
356
vcredist_x86 - 2012 update 4.exe
GET
200
2.16.186.74:80
http://crl.microsoft.com/pki/crl/products/MicCodSigPCA_08-31-2010.crl
unknown
der
555 b
whitelisted
356
vcredist_x86 - 2012 update 4.exe
GET
200
2.16.186.74:80
http://crl.microsoft.com/pki/crl/products/MicrosoftTimeStampPCA.crl
unknown
der
550 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
356
vcredist_x86 - 2012 update 4.exe
2.16.186.74:80
crl.microsoft.com
Akamai International B.V.
whitelisted

DNS requests

Domain
IP
Reputation
crl.microsoft.com
  • 2.16.186.74
  • 2.16.186.120
whitelisted

Threats

No threats detected
No debug info