File name:

S3TurboTool_v1.53cat_S3THv1_DXETHv1_RAWTHv1b(1).rar

Full analysis: https://app.any.run/tasks/8454f90f-13fe-43ec-a942-3d48169af93c
Verdict: Malicious activity
Analysis date: July 31, 2023, 10:46:11
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

FBFAC4F09537A1B3C851129324CECA21

SHA1:

5A52A6636D1351D2D969D1707E5826C2D90F9F23

SHA256:

079319F6DF8342329C7836B529EFFE596CE61345E5755B3030D7C2BA181208D9

SSDEEP:

196608:9mmTu2uFcQHC3Tu6pV7i8aI8T/pqQugWZTkz/iSWkMR4hiS5axGT+hm:QmTudFZCTu0VG5IG/pyZw+SWAiS5aRo

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • S3TurboTool.exe (PID: 2676)
      • S3TurboTool.exe (PID: 3680)
      • S3TurboTool.exe (PID: 3676)
      • S3TurboTool.exe (PID: 3816)
      • S3TurboTool.exe (PID: 2500)
      • S3TurboTool.exe (PID: 3244)
      • S3TurboTool.exe (PID: 2148)
      • S3TurboTool.exe (PID: 3016)
      • S3TurboTool.exe (PID: 2244)
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1992)
    • Checks supported languages

      • S3TurboTool.exe (PID: 2676)
      • S3TurboTool.exe (PID: 3676)
      • S3TurboTool.exe (PID: 3244)
      • S3TurboTool.exe (PID: 3016)
      • S3TurboTool.exe (PID: 2244)
    • Reads the computer name

      • S3TurboTool.exe (PID: 2676)
      • S3TurboTool.exe (PID: 3676)
      • S3TurboTool.exe (PID: 3244)
      • S3TurboTool.exe (PID: 2244)
      • S3TurboTool.exe (PID: 3016)
    • Manual execution by a user

      • S3TurboTool.exe (PID: 3816)
      • S3TurboTool.exe (PID: 2676)
      • S3TurboTool.exe (PID: 3676)
      • S3TurboTool.exe (PID: 3680)
      • S3TurboTool.exe (PID: 2500)
      • S3TurboTool.exe (PID: 3244)
      • S3TurboTool.exe (PID: 2148)
      • S3TurboTool.exe (PID: 3016)
      • S3TurboTool.exe (PID: 2244)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
67
Monitored processes
10
Malicious processes
4
Suspicious processes
2

Behavior graph

Click at the process to see the details
start winrar.exe s3turbotool.exe no specs s3turbotool.exe s3turbotool.exe no specs s3turbotool.exe s3turbotool.exe no specs s3turbotool.exe s3turbotool.exe no specs s3turbotool.exe s3turbotool.exe

Process information

PID
CMD
Path
Indicators
Parent process
1992"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\S3TurboTool_v1.53cat_S3THv1_DXETHv1_RAWTHv1b(1).rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\winrar\winrar.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2148"C:\Users\admin\Desktop\S3TurboTool\S3TurboTool.exe" C:\Users\admin\Desktop\S3TurboTool\S3TurboTool.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
S3TurboTool
Exit code:
3221226540
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\s3turbotool\s3turbotool.exe
c:\windows\system32\ntdll.dll
2244"C:\Users\admin\Desktop\S3TurboTool\S3TurboTool.exe" C:\Users\admin\Desktop\S3TurboTool\S3TurboTool.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
S3TurboTool
Exit code:
3762504530
Version:
1.0.0.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mscoree.dll
c:\users\admin\desktop\s3turbotool\s3turbotool.exe
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2500"C:\Users\admin\Desktop\S3TurboTool\S3TurboTool.exe" C:\Users\admin\Desktop\S3TurboTool\S3TurboTool.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
S3TurboTool
Exit code:
3221226540
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\s3turbotool\s3turbotool.exe
c:\windows\system32\ntdll.dll
2676"C:\Users\admin\Desktop\S3TurboTool\S3TurboTool.exe" C:\Users\admin\Desktop\S3TurboTool\S3TurboTool.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
S3TurboTool
Exit code:
3762504530
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\s3turbotool\s3turbotool.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3016"C:\Users\admin\Desktop\S3TurboTool\S3TurboTool.exe" C:\Users\admin\Desktop\S3TurboTool\S3TurboTool.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
S3TurboTool
Exit code:
3762504530
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\s3turbotool\s3turbotool.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shlwapi.dll
3244"C:\Users\admin\Desktop\S3TurboTool\S3TurboTool.exe" C:\Users\admin\Desktop\S3TurboTool\S3TurboTool.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
S3TurboTool
Exit code:
3762504530
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\s3turbotool\s3turbotool.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shlwapi.dll
3676"C:\Users\admin\Desktop\S3TurboTool\S3TurboTool.exe" C:\Users\admin\Desktop\S3TurboTool\S3TurboTool.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
S3TurboTool
Exit code:
3762504530
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\s3turbotool\s3turbotool.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3680"C:\Users\admin\Desktop\S3TurboTool\S3TurboTool.exe" C:\Users\admin\Desktop\S3TurboTool\S3TurboTool.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
S3TurboTool
Exit code:
3221226540
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\s3turbotool\s3turbotool.exe
c:\windows\system32\ntdll.dll
3816"C:\Users\admin\Desktop\S3TurboTool\S3TurboTool.exe" C:\Users\admin\Desktop\S3TurboTool\S3TurboTool.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
S3TurboTool
Exit code:
3221226540
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\s3turbotool\s3turbotool.exe
c:\windows\system32\ntdll.dll
Total events
961
Read events
942
Write events
19
Delete events
0

Modification events

(PID) Process:(1992) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1992) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(1992) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(1992) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(1992) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1992) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1992) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1992) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1992) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
(PID) Process:(1992) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\General
Operation:writeName:LastFolder
Value:
C:\Users\admin\Desktop
Executable files
7
Suspicious files
5
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
1992WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1992.38421\S3TurboTool\pmxdll32e.DLLexecutable
MD5:1891B27AF49E866E290A0441C7DC00E9
SHA256:1882C65036142FEE6B89042E2B7BF383AAA8E151B65942F5B74C03AB5CC4E5F9
1992WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1992.38421\S3TurboTool\mmtool\mmtool_a5.exeexecutable
MD5:C6FC1435CBDE2636B33E4F7EE444A079
SHA256:51A85A663B1CB819508E48FD650180E6C79AFD06FB458DD1357508FD9578FC23
1992WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1992.38421\S3TurboTool\S3TurboTool.exeexecutable
MD5:461DD72D19A3857F170ABAB8837D3021
SHA256:EAEACD165CF83CB0659BC711D2D6031AE5D2B56843BC721A263F8B0F91993363
1992WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1992.38421\S3TurboTool\RAWTurboHack\ser8989_RAWTurboHack.binbinary
MD5:8A6D48019B89825DA328A9555EC1F5F7
SHA256:8FD3C9E8F630737EFE55A01E54439E27A4CE0DA4D79C4BFBFB251F2C7441AD0A
1992WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1992.38421\S3TurboTool\AMIBCP5\AMIBCP5.exeexecutable
MD5:C15E0801502A6AD896476E64B93D6924
SHA256:C7ADE67FE0E8F4C22F73CE3168FF6E718086F1EDA83CCE4C065B4FE49BD5AD99
1992WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1992.38421\S3TurboTool\sound\beep.wavbinary
MD5:7AC64FC17777DA99DE88C84AB28E842E
SHA256:C531131B3FAD29BE0D9BF9A819999974BB70D18E684A79B70D70915B79CB3E79
1992WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1992.38421\S3TurboTool\fptw64.exeexecutable
MD5:7CA20261DA7995B382C11A15B2171553
SHA256:B7E942E903F5F6BBA84C3E9294EDC8CC097C1173CA249A41A4CCA1AB9E15A697
1992WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1992.38421\S3TurboTool\fparts.txttext
MD5:5DB816980D2544868D6CE050D62A67E7
SHA256:BDFA0E3BCB17185892978D563055AE3E3F2CB3548B080CC7EF78E06B92363C96
1992WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1992.38421\S3TurboTool\DXETurboHack\ser8989_DXETurboHack.ffsbinary
MD5:F530E6F512E4F32829CBBAE3C917C199
SHA256:CD3D57DED3B5033B0BBF9FA4B8889AEEEF5A10BD27B34A54FF3B5BB5BA5917C6
1992WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1992.38421\S3TurboTool\S3TurboHack\ser8989_S3TurboHack.ffsbinary
MD5:0B810993EC03B1695321B70CB3121B23
SHA256:3AAB6C1F6039F210900BEF8CCF285AB66CC98BD101A347F791A85BE826BEABF7
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
2
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2640
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:137
whitelisted

DNS requests

No data

Threats

No threats detected
No debug info