File name:

SmartGaGa Tweaker Tool.rar

Full analysis: https://app.any.run/tasks/8741d9c0-6564-41a0-aca2-2f0da0a2c042
Verdict: Malicious activity
Analysis date: May 11, 2020, 04:53:32
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

ACBF4FE8464B4FA2086EDD96C647652A

SHA1:

ED58CCCE0BFFABB71B493D74F21F325CD582D539

SHA256:

0CD05BC63ED29A9F60699724E9919E0E50F76B778CDC8E74F6997CFA002A8531

SSDEEP:

12288:g82n3FNoijU5pwfgTAOldqxyYLRhi+X/EzMUbINn7cyMEn1D+1onIk2kS60H/kq6:gWUU5pwf0PEthfX/EzLyGy9yD6dqFOF

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • SmartGaGa Tweaker Tool.exe (PID: 3980)
      • cmd.exe (PID: 2348)
      • UTransfer64.dll (PID: 2064)
      • UTransfer64.dll (PID: 3212)
      • UTransfer64.dll (PID: 2600)
      • UTransfer64.dll (PID: 2208)
      • UTransfer64.dll (PID: 3196)
      • UTransfer64.dll (PID: 2104)
      • UTransfer64.dll (PID: 1332)
      • UTransfer64.dll (PID: 3376)
    • Application was dropped or rewritten from another process

      • SmartGaGa Tweaker Tool.exe (PID: 3980)
      • SmartGaGa Tweaker Tool.exe (PID: 2456)
      • UTransfer64.dll (PID: 2064)
      • UTransfer64.dll (PID: 3212)
      • UTransfer64.dll (PID: 2600)
      • UTransfer64.dll (PID: 1332)
      • UTransfer64.dll (PID: 2208)
      • UTransfer64.dll (PID: 3196)
      • UTransfer64.dll (PID: 2104)
      • UTransfer64.dll (PID: 3376)
    • Runs PING.EXE for delay simulation

      • cmd.exe (PID: 2348)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2700)
    • Creates files in the driver directory

      • SmartGaGa Tweaker Tool.exe (PID: 3980)
    • Starts CMD.EXE for self-deleting

      • SmartGaGa Tweaker Tool.exe (PID: 3980)
    • Starts CMD.EXE for commands execution

      • SmartGaGa Tweaker Tool.exe (PID: 3980)
    • Creates files in the Windows directory

      • SmartGaGa Tweaker Tool.exe (PID: 3980)
    • Starts application with an unusual extension

      • cmd.exe (PID: 2348)
      • UTransfer64.dll (PID: 3212)
    • Application launched itself

      • UTransfer64.dll (PID: 3212)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
58
Monitored processes
14
Malicious processes
3
Suspicious processes
7

Behavior graph

Click at the process to see the details
drop and start drop and start start winrar.exe smartgaga tweaker tool.exe no specs smartgaga tweaker tool.exe cmd.exe no specs ping.exe no specs utransfer64.dll utransfer64.dll utransfer64.dll utransfer64.dll utransfer64.dll utransfer64.dll utransfer64.dll utransfer64.dll cmd.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1332UTransfer64.dll -s emulator-5554 shell rm -rf /storage/emulated/0/Android/data/com.tencent.ig/files/UE4Game/ShadowTrackerExtra/ShadowTrackerExtra/Saved/SaveGames/* C:\Users\admin\AppData\Local\Temp\Rar$EXa2700.17459\UTransfer64.dll
cmd.exe
User:
admin
Integrity Level:
HIGH
Exit code:
4294967295
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2700.17459\utransfer64.dll
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2064UTransfer64.dll kill-server C:\Users\admin\AppData\Local\Temp\Rar$EXa2700.17459\UTransfer64.dll
cmd.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2700.17459\utransfer64.dll
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2104UTransfer64.dll -e push C:\UIElemLayout_Slot01.sav /storage/emulated/0/Android/data/com.tencent.ig/files/UE4Game/ShadowTrackerExtra/ShadowTrackerExtra/Saved/ C:\Users\admin\AppData\Local\Temp\Rar$EXa2700.17459\UTransfer64.dll
cmd.exe
User:
admin
Integrity Level:
HIGH
Exit code:
1
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2700.17459\utransfer64.dll
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
2208UTransfer64.dll root C:\Users\admin\AppData\Local\Temp\Rar$EXa2700.17459\UTransfer64.dll
cmd.exe
User:
admin
Integrity Level:
HIGH
Exit code:
1
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2700.17459\utransfer64.dll
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2348"cmd.exe" /c move %windir%\SysWOW64\drivers\UIElemLayout_Slot01.sav C:\ & ping 127.0.0.1 -n 2 > nul & UTransfer64.dll kill-server & UTransfer64.dll devices & UTransfer64.dll -s emulator-5554 shell rm -rf /storage/emulated/0/Android/data/com.tencent.ig/files/UE4Game/ShadowTrackerExtra/ShadowTrackerExtra/Saved/SaveGames/* & UTransfer64.dll root & UTransfer64.dll remount & UTransfer64.dll -e push C:\UIElemLayout_Slot01.sav /storage/emulated/0/Android/data/com.tencent.ig/files/UE4Game/ShadowTrackerExtra/ShadowTrackerExtra/Saved/ & UTransfer64.dll -s emulator-5554 shell mv /storage/emulated/0/Android/data/com.tencent.ig/files/UE4Game/ShadowTrackerExtra/ShadowTrackerExtra/Saved/UIElemLayout_Slot01.sav /storage/emulated/0/Android/data/com.tencent.ig/files/UE4Game/ShadowTrackerExtra/ShadowTrackerExtra/Saved/SaveGames/ & del C:\UIElemLayout_Slot01.savC:\Windows\system32\cmd.exeSmartGaGa Tweaker Tool.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2456"C:\Users\admin\AppData\Local\Temp\Rar$EXa2700.17459\SmartGaGa Tweaker Tool.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2700.17459\SmartGaGa Tweaker Tool.exeWinRAR.exe
User:
admin
Company:
Free For All
Integrity Level:
MEDIUM
Description:
SmartGaGa Tweaker Tool
Exit code:
3221226540
Version:
1.1.0.1
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2700.17459\smartgaga tweaker tool.exe
c:\systemroot\system32\ntdll.dll
2600adb fork-server serverC:\Users\admin\AppData\Local\Temp\Rar$EXa2700.17459\UTransfer64.dll
UTransfer64.dll
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2700.17459\utransfer64.dll
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2700"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\SmartGaGa Tweaker Tool.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2948"cmd.exe" /c move %windir%\SysWOW64\drivers\com.tencent.ig.sys %windir%\SysWOW64\drivers\com.tencent.ig.bin & move %windir%\SysWOW64\drivers\com.tencent.ig.bin %userprofile%\AppData\Roaming\SmartGaGa\UserConfigsC:\Windows\system32\cmd.exeSmartGaGa Tweaker Tool.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3196UTransfer64.dll remount C:\Users\admin\AppData\Local\Temp\Rar$EXa2700.17459\UTransfer64.dll
cmd.exe
User:
admin
Integrity Level:
HIGH
Exit code:
1
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2700.17459\utransfer64.dll
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
533
Read events
508
Write events
25
Delete events
0

Modification events

(PID) Process:(2700) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2700) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2700) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12D\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2700) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12D\52C64B7E
Operation:writeName:@C:\Windows\system32\NetworkExplorer.dll,-1
Value:
Network
(PID) Process:(2700) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\SmartGaGa Tweaker Tool.rar
(PID) Process:(2700) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2700) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2700) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2700) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2700) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
Executable files
4
Suspicious files
1
Text files
2
Unknown types
1

Dropped files

PID
Process
Filename
Type
2700WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2700.17459\SmartGaGa Tweaker Tool.exeexecutable
MD5:
SHA256:
2700WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2700.17459\Bunifu_UI_v1.5.3.dllexecutable
MD5:2ECB51AB00C5F340380ECF849291DBCF
SHA256:F1B3E0F2750A9103E46A6A4A34F1CF9D17779725F98042CC2475EC66484801CF
2700WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2700.17459\UTransfer.dllexecutable
MD5:
SHA256:
2700WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2700.17459\UTransfer64.dllexecutable
MD5:
SHA256:
3980SmartGaGa Tweaker Tool.exeC:\Windows\system32\drivers\UIElemLayout_Slot01.savbs
MD5:
SHA256:
2600UTransfer64.dllC:\Users\admin\.android\adbkey.pubtext
MD5:
SHA256:
3980SmartGaGa Tweaker Tool.exeC:\Windows\system32\drivers\com.tencent.ig.sysbinary
MD5:
SHA256:
2600UTransfer64.dllC:\Users\admin\.android\adbkeytext
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
1
DNS requests
1
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3980
SmartGaGa Tweaker Tool.exe
GET
403
185.176.43.94:80
http://mokkabypass.atwebpages.com/tweaker/updates.php?version=1.0.2
BG
html
120 b
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3980
SmartGaGa Tweaker Tool.exe
185.176.43.94:80
mokkabypass.atwebpages.com
Zetta Hosting Solutions LLC.
BG
malicious

DNS requests

Domain
IP
Reputation
mokkabypass.atwebpages.com
  • 185.176.43.94
malicious

Threats

No threats detected
No debug info