File name:

Malwarebytes Premium 4.1.2.73.rar

Full analysis: https://app.any.run/tasks/211069b6-9023-4c3f-91c5-9eff353e7035
Verdict: Malicious activity
Analysis date: July 26, 2020, 00:15:00
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

1790056F18408343C56F8DDE3907392A

SHA1:

D1E8E492F8548C481DD09033A6FC92C8D235DA60

SHA256:

06DD3AE6606B892A444749328519A722DCFA865B9D053CB50DC96384C735DBF8

SSDEEP:

196608:kK6rIjgQg5cJIyZt6WzallwvBXbXzA769:oH5cJrtVz2MBrXzug

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • MBSetup.exe (PID: 2216)
      • MBSetup.exe (PID: 3936)
      • MBAMInstallerService.exe (PID: 1744)
      • MBAMService.exe (PID: 2260)
      • MBAMService.exe (PID: 3188)
      • mbamtray.exe (PID: 1784)
      • mbam.exe (PID: 2400)
      • LicenseMalwareBytes.exe (PID: 2676)
      • LicenseMalwareBytes.exe (PID: 3700)
      • E.exe (PID: 3212)
      • LicenseMalwareBytes.exe (PID: 4036)
      • LicenseMalwareBytes.exe (PID: 2380)
      • E.exe (PID: 2604)
      • malwarebytes_assistant.exe (PID: 1932)
      • malwarebytes_assistant.exe (PID: 1572)
      • LicenseMalwareBytes.exe (PID: 2968)
      • LicenseMalwareBytes.exe (PID: 2864)
      • E.exe (PID: 1752)
      • mbam.exe (PID: 1740)
      • MBAMService.exe (PID: 656)
      • mbamtray.exe (PID: 1768)
    • Changes settings of System certificates

      • MBSetup.exe (PID: 3936)
      • certutil.exe (PID: 1728)
      • certutil.exe (PID: 3008)
    • Loads dropped or rewritten executable

      • MBAMInstallerService.exe (PID: 1744)
      • MBAMService.exe (PID: 3188)
      • mbamtray.exe (PID: 1784)
      • mbam.exe (PID: 2400)
      • malwarebytes_assistant.exe (PID: 1572)
      • mbam.exe (PID: 1740)
      • MBAMService.exe (PID: 656)
      • mbamtray.exe (PID: 1768)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2592)
      • MBSetup.exe (PID: 3936)
      • MBAMService.exe (PID: 3188)
      • LicenseMalwareBytes.exe (PID: 3700)
      • MBAMInstallerService.exe (PID: 1744)
      • LicenseMalwareBytes.exe (PID: 2380)
      • LicenseMalwareBytes.exe (PID: 2864)
      • MBAMService.exe (PID: 656)
    • Creates files in the program directory

      • MBSetup.exe (PID: 3936)
      • MBAMInstallerService.exe (PID: 1744)
      • MBAMService.exe (PID: 3188)
      • MBAMService.exe (PID: 656)
    • Adds / modifies Windows certificates

      • MBSetup.exe (PID: 3936)
    • Executed as Windows Service

      • MBAMInstallerService.exe (PID: 1744)
      • MBAMService.exe (PID: 3188)
      • MBAMService.exe (PID: 656)
    • Creates files in the driver directory

      • MBAMInstallerService.exe (PID: 1744)
      • MBAMService.exe (PID: 3188)
      • MBAMService.exe (PID: 656)
    • Creates files in the Windows directory

      • certutil.exe (PID: 1728)
      • certutil.exe (PID: 3008)
      • MBAMService.exe (PID: 2260)
      • MBAMService.exe (PID: 3188)
      • MBAMService.exe (PID: 656)
      • MBAMInstallerService.exe (PID: 1744)
    • Removes files from Windows directory

      • certutil.exe (PID: 1728)
      • certutil.exe (PID: 3008)
      • MBAMService.exe (PID: 3188)
      • MBAMService.exe (PID: 656)
      • MBAMInstallerService.exe (PID: 1744)
    • Changes IE settings (feature browser emulation)

      • MBAMInstallerService.exe (PID: 1744)
      • MBAMService.exe (PID: 3188)
      • MBAMService.exe (PID: 656)
    • Modifies the open verb of a shell class

      • MBAMInstallerService.exe (PID: 1744)
    • Creates COM task schedule object

      • MBAMService.exe (PID: 3188)
    • Creates or modifies windows services

      • MBAMService.exe (PID: 3188)
      • MBAMService.exe (PID: 656)
    • Reads Internet Cache Settings

      • mbamtray.exe (PID: 1784)
      • mbam.exe (PID: 2400)
      • mbam.exe (PID: 1740)
      • mbamtray.exe (PID: 1768)
    • Creates a software uninstall entry

      • MBAMInstallerService.exe (PID: 1744)
    • Application launched itself

      • LicenseMalwareBytes.exe (PID: 2676)
      • LicenseMalwareBytes.exe (PID: 2968)
      • LicenseMalwareBytes.exe (PID: 4036)
    • Creates files in the user directory

      • mbam.exe (PID: 2400)
      • mbam.exe (PID: 1740)
    • Starts CMD.EXE for commands execution

      • LicenseMalwareBytes.exe (PID: 3700)
      • LicenseMalwareBytes.exe (PID: 2380)
      • LicenseMalwareBytes.exe (PID: 2864)
  • INFO

    • Reads settings of System Certificates

      • MBSetup.exe (PID: 3936)
      • MBAMService.exe (PID: 3188)
      • MBAMService.exe (PID: 656)
    • Dropped object may contain Bitcoin addresses

      • MBAMInstallerService.exe (PID: 1744)
      • MBAMService.exe (PID: 656)
    • Manual execution by user

      • mbam.exe (PID: 1740)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
86
Monitored processes
27
Malicious processes
16
Suspicious processes
1

Behavior graph

Click at the process to see the details
drop and start drop and start drop and start drop and start drop and start start drop and start drop and start drop and start drop and start winrar.exe mbsetup.exe no specs mbsetup.exe mbaminstallerservice.exe certutil.exe no specs certutil.exe no specs mbamservice.exe no specs mbamservice.exe mbamtray.exe mbam.exe licensemalwarebytes.exe no specs licensemalwarebytes.exe cmd.exe no specs e.exe no specs licensemalwarebytes.exe no specs licensemalwarebytes.exe cmd.exe no specs e.exe no specs malwarebytes_assistant.exe no specs malwarebytes_assistant.exe licensemalwarebytes.exe no specs licensemalwarebytes.exe cmd.exe no specs e.exe no specs mbam.exe mbamservice.exe mbamtray.exe

Process information

PID
CMD
Path
Indicators
Parent process
312C:\Windows\system32\cmd.exe /c move /y "C:\gecici_proje_klasoru\hosts" "\Windows\System32\drivers\etc"C:\Windows\system32\cmd.exeLicenseMalwareBytes.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
656"C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe"C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
services.exe
User:
SYSTEM
Company:
Malwarebytes
Integrity Level:
SYSTEM
Description:
Malwarebytes Service
Exit code:
0
Version:
3.2.0.903
Modules
Images
c:\program files\malwarebytes\anti-malware\mbamservice.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
1572"C:\Program Files\Malwarebytes\Anti-Malware\malwarebytes_assistant.exe" --stopserviceC:\Program Files\Malwarebytes\Anti-Malware\malwarebytes_assistant.exe
mbamtray.exe
User:
admin
Company:
Malwarebytes
Integrity Level:
HIGH
Description:
Malwarebytes Assistant
Exit code:
0
Version:
4.0.0.753
Modules
Images
c:\program files\malwarebytes\anti-malware\malwarebytes_assistant.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\malwarebytes\anti-malware\qt5widgets.dll
c:\program files\malwarebytes\anti-malware\qt5gui.dll
c:\windows\system32\d3d11.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\user32.dll
1728certutil.exe -f -addstore root "C:\Windows\TEMP\MBInstallTemp\servicepkg\BaltimoreCyberTrustRoot.crt"C:\Windows\system32\certutil.exeMBAMInstallerService.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
CertUtil.exe
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\certutil.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\certcli.dll
c:\windows\system32\atl.dll
1740"C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe" C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe
explorer.exe
User:
admin
Company:
Malwarebytes
Integrity Level:
MEDIUM
Description:
Malwarebytes
Exit code:
0
Version:
4.0.0.753
Modules
Images
c:\program files\malwarebytes\anti-malware\mbam.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\malwarebytes\anti-malware\qt5quick.dll
c:\program files\malwarebytes\anti-malware\qt5gui.dll
c:\windows\system32\d3d11.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\user32.dll
1744"C:\Program Files\Malwarebytes\Anti-Malware\MBAMInstallerService.exe"C:\Program Files\Malwarebytes\Anti-Malware\MBAMInstallerService.exe
services.exe
User:
SYSTEM
Company:
Malwarebytes
Integrity Level:
SYSTEM
Description:
Malwarebytes Installer Service
Exit code:
0
Version:
4.0.0.313
Modules
Images
c:\program files\malwarebytes\anti-malware\mbaminstallerservice.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
1752C:\gecici_proje_klasoru\E.exe C:\gecici_proje_klasoru\E.exeLicenseMalwareBytes.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\gecici_proje_klasoru\e.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1768"C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe" C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
MBAMService.exe
User:
admin
Company:
Malwarebytes
Integrity Level:
MEDIUM
Description:
Malwarebytes Tray Application
Exit code:
0
Version:
4.0.0.753
Modules
Images
c:\program files\malwarebytes\anti-malware\mbamtray.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\malwarebytes\anti-malware\qt5quick.dll
c:\program files\malwarebytes\anti-malware\qt5gui.dll
c:\windows\system32\d3d11.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\user32.dll
1784"C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe" C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
MBAMService.exe
User:
admin
Company:
Malwarebytes
Integrity Level:
MEDIUM
Description:
Malwarebytes Tray Application
Exit code:
3221225547
Version:
4.0.0.753
Modules
Images
c:\program files\malwarebytes\anti-malware\mbamtray.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\malwarebytes\anti-malware\qt5quick.dll
c:\program files\malwarebytes\anti-malware\qt5gui.dll
c:\windows\system32\d3d11.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\user32.dll
1932"C:\Program Files\Malwarebytes\Anti-Malware\malwarebytes_assistant.exe" --stopserviceC:\Program Files\Malwarebytes\Anti-Malware\malwarebytes_assistant.exembamtray.exe
User:
admin
Company:
Malwarebytes
Integrity Level:
MEDIUM
Description:
Malwarebytes Assistant
Exit code:
3221226540
Version:
4.0.0.753
Modules
Images
c:\program files\malwarebytes\anti-malware\malwarebytes_assistant.exe
c:\systemroot\system32\ntdll.dll
Total events
4 310
Read events
2 779
Write events
1 523
Delete events
8

Modification events

(PID) Process:(2592) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2592) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2592) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\132\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2592) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Malwarebytes Premium 4.1.2.73.rar
(PID) Process:(2592) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2592) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2592) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2592) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2592) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\132\52C64B7E
Operation:writeName:@C:\Windows\system32\notepad.exe,-469
Value:
Text Document
(PID) Process:(2592) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
Executable files
303
Suspicious files
87
Text files
1 122
Unknown types
65

Dropped files

PID
Process
Filename
Type
1744MBAMInstallerService.exeC:\Windows\TEMP\MBInstallTemp\servicepkg.7z
MD5:
SHA256:
1744MBAMInstallerService.exeC:\Windows\TEMP\MBInstallTemp\ctlrpkg.7z
MD5:
SHA256:
1744MBAMInstallerService.exeC:\Windows\TEMP\MBInstallTemp\dbclspkg.7z
MD5:
SHA256:
2592WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2592.35569\MBSetup.exeexecutable
MD5:
SHA256:
2592WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2592.35569\pasword 12345 .txttext
MD5:
SHA256:
2592WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2592.36495\pasword 12345 .txttext
MD5:
SHA256:
3936MBSetup.exeC:\Program Files\Malwarebytes\Anti-Malware\MBAMInstallerService.exeexecutable
MD5:
SHA256:
2592WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2592.35569\LicenseMalwareBytes.exeexecutable
MD5:
SHA256:
1744MBAMInstallerService.exeC:\Windows\TEMP\MBInstallTemp\servicepkg\arwversion.dattext
MD5:
SHA256:
1744MBAMInstallerService.exeC:\Windows\TEMP\MBInstallTemp\servicepkg\srvversion.dattext
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
16
DNS requests
11
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3936
MBSetup.exe
52.3.65.251:443
ark.mwbsys.com
Amazon.com, Inc.
US
unknown
3936
MBSetup.exe
2.18.233.58:443
cdn.mwbsys.com
Akamai International B.V.
whitelisted
1744
MBAMInstallerService.exe
52.3.65.251:443
ark.mwbsys.com
Amazon.com, Inc.
US
unknown
1744
MBAMInstallerService.exe
2.18.233.58:443
cdn.mwbsys.com
Akamai International B.V.
whitelisted
3188
MBAMService.exe
52.27.220.180:443
telemetry.malwarebytes.com
Amazon.com, Inc.
US
unknown
3188
MBAMService.exe
34.225.243.41:443
iris.mwbsys.com
Amazon.com, Inc.
US
unknown
3188
MBAMService.exe
18.204.190.100:443
keystone.mwbsys.com
US
unknown
3188
MBAMService.exe
54.191.151.104:443
telemetry.malwarebytes.com
Amazon.com, Inc.
US
unknown
3188
MBAMService.exe
54.149.194.175:443
telemetry.malwarebytes.com
Amazon.com, Inc.
US
unknown
656
MBAMService.exe
54.218.62.156:443
telemetry.malwarebytes.com
Amazon.com, Inc.
US
unknown

DNS requests

Domain
IP
Reputation
ark.mwbsys.com
  • 52.3.65.251
  • 3.82.89.44
suspicious
cdn.mwbsys.com
  • 2.18.233.58
whitelisted
iris.mwbsys.com
  • 34.225.243.41
  • 54.236.117.134
unknown
telemetry.malwarebytes.com
  • 52.27.220.180
  • 50.112.211.186
  • 52.33.143.125
  • 52.10.239.179
  • 44.231.96.35
  • 35.162.54.148
  • 54.149.194.175
  • 54.191.151.104
  • 54.70.156.78
  • 44.233.176.104
  • 54.218.62.156
whitelisted
keystone.mwbsys.com
  • 18.204.190.100
  • 34.203.169.189
unknown

Threats

No threats detected
Process
Message
mbamtray.exe
QAxBase::setControl: requested control {F36AD0D0-B5F0-4C69-AF08-603D177FEF0E} could not be instantiated
mbamtray.exe
Help :
mbamtray.exe
Code : -2147467259
mbamtray.exe
Connect to the exception(int,QString,QString,QString) signal to catch this exception
mbamtray.exe
Source :
mbamtray.exe
QAxBase: Error calling IDispatch member GetLastActiveScanner: Exception thrown by server
mbamtray.exe
Description:
mbamtray.exe
qt.scenegraph.general: Loading backend software
mbamtray.exe
class QSharedPointer<class QPluginLoader> __cdecl FindAndActivatePlugin(const class QString &,const class QString &) Plugin found, activating: "TrayPlugin.dll"
mbamtray.exe
void __thiscall PageStatusMonitor::OnRequestFinished(class QNetworkReply *) "Page: https://links.malwarebytes.com/link/3x_cart?affiliate=&uuid=&x-source=trial-avail&x-action=comparison_chart&x-token_secret=jgQTeomKKCX-ohzCvjCx3hwcIVtPY30kwsHoc_3VxIVdQ0ZNl0JgLqWl2qbt-M8a5qVVelYBg7KVeAsc0nMPsA==&ADDITIONAL_x-token_secret=jgQTeomKKCX-ohzCvjCx3hwcIVtPY30kwsHoc_3VxIVdQ0ZNl0JgLqWl2qbt-M8a5qVVelYBg7KVeAsc0nMPsA==&x-prodcode=MBAM-C&lang=en&version=4.1.2.73&ptb=0 received code: "