| download: | file |
| Full analysis: | https://app.any.run/tasks/6361a12c-e524-4fb2-b200-036ddbb48ca9 |
| Verdict: | Malicious activity |
| Threats: | Netwire is an advanced RAT — it is a malware that takes control of infected PCs and allows its operators to perform various actions. Unlike many RATs, this one can target every major operating system, including Windows, Linux, and MacOS. |
| Analysis date: | July 17, 2019, 13:11:53 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-7z-compressed |
| File info: | 7-zip archive data, version 0.4 |
| MD5: | 621E733F92198BA18E4F0318887A49AB |
| SHA1: | 342D2D74EAEF55D70841E67F6C87BE990EDF2D1E |
| SHA256: | 0F0E2733E42882C739129CEC49F6FC12380D85031A24C6A12BD737EC7945B29A |
| SSDEEP: | 3072:2QWUF5g7eoDAOlwP7EMXZeWAP8PXttxv11E+HYH9/KbfXlempaDW:rW+eioEOS7ZXsjEP9txvpyNKbgiay |
| .7z | | | 7-Zip compressed archive (v0.4) (57.1) |
|---|---|---|
| .7z | | | 7-Zip compressed archive (gen) (42.8) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 680 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa3760.14978\proof of payment#.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa3760.14978\proof of payment#.exe | — | WinRAR.exe | |||||||||||
User: admin Company: weirdwoman Integrity Level: MEDIUM Description: Jokul Exit code: 0 Version: 1.09.0008 Modules
| |||||||||||||||
| 916 | C:\Users\admin\AppData\Local\Temp\Rar$EXa3760.14581\proof of payment#.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa3760.14581\proof of payment#.exe | proof of payment#.exe | ||||||||||||
User: admin Company: weirdwoman Integrity Level: MEDIUM Description: Jokul Exit code: 0 Version: 1.09.0008 Modules
| |||||||||||||||
| 1736 | "C:\Users\admin\AppData\Roaming\Install\Host.exe" | C:\Users\admin\AppData\Roaming\Install\Host.exe | — | proof of payment#.exe | |||||||||||
User: admin Company: weirdwoman Integrity Level: MEDIUM Description: Jokul Exit code: 0 Version: 1.09.0008 Modules
| |||||||||||||||
| 2732 | C:\Users\admin\AppData\Local\Temp\Rar$EXa3760.19564\proof of payment#.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa3760.19564\proof of payment#.exe | — | proof of payment#.exe | |||||||||||
User: admin Company: weirdwoman Integrity Level: MEDIUM Description: Jokul Exit code: 0 Version: 1.09.0008 Modules
| |||||||||||||||
| 2856 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa3760.19564\proof of payment#.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa3760.19564\proof of payment#.exe | — | WinRAR.exe | |||||||||||
User: admin Company: weirdwoman Integrity Level: MEDIUM Description: Jokul Exit code: 0 Version: 1.09.0008 Modules
| |||||||||||||||
| 3028 | C:\Users\admin\AppData\Local\Temp\Rar$EXa3760.24436\proof of payment#.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa3760.24436\proof of payment#.exe | — | proof of payment#.exe | |||||||||||
User: admin Company: weirdwoman Integrity Level: MEDIUM Description: Jokul Exit code: 0 Version: 1.09.0008 Modules
| |||||||||||||||
| 3156 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa3760.23809\proof of payment#.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa3760.23809\proof of payment#.exe | — | WinRAR.exe | |||||||||||
User: admin Company: weirdwoman Integrity Level: MEDIUM Description: Jokul Exit code: 0 Version: 1.09.0008 Modules
| |||||||||||||||
| 3224 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa3760.18148\proof of payment#.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa3760.18148\proof of payment#.exe | — | WinRAR.exe | |||||||||||
User: admin Company: weirdwoman Integrity Level: MEDIUM Description: Jokul Exit code: 0 Version: 1.09.0008 Modules
| |||||||||||||||
| 3568 | C:\Users\admin\AppData\Local\Temp\Rar$EXa3760.23809\proof of payment#.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa3760.23809\proof of payment#.exe | — | proof of payment#.exe | |||||||||||
User: admin Company: weirdwoman Integrity Level: MEDIUM Description: Jokul Exit code: 0 Version: 1.09.0008 Modules
| |||||||||||||||
| 3676 | C:\Users\admin\AppData\Local\Temp\Rar$EXa3760.14978\proof of payment#.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa3760.14978\proof of payment#.exe | — | proof of payment#.exe | |||||||||||
User: admin Company: weirdwoman Integrity Level: MEDIUM Description: Jokul Exit code: 0 Version: 1.09.0008 Modules
| |||||||||||||||
| (PID) Process: | (3760) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3760) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3760) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\70\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3760) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\file.7z | |||
| (PID) Process: | (3760) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3760) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3760) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3760) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (3760) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (3760) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3760 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3760.23809\proof of payment#.exe | executable | |
MD5:— | SHA256:— | |||
| 3760 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3760.18148\proof of payment#.exe | executable | |
MD5:— | SHA256:— | |||
| 3760 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3760.14978\proof of payment#.exe | executable | |
MD5:— | SHA256:— | |||
| 3760 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DIa3760.18398\proof of payment#.exe | executable | |
MD5:— | SHA256:— | |||
| 3760 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3760.19564\proof of payment#.exe | executable | |
MD5:— | SHA256:— | |||
| 3760 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3760.24436\proof of payment#.exe | executable | |
MD5:— | SHA256:— | |||
| 3760 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa3760.14581\proof of payment#.exe | executable | |
MD5:— | SHA256:— | |||
| 3760 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\file\proof of payment#.exe | executable | |
MD5:— | SHA256:— | |||
| 916 | proof of payment#.exe | C:\Users\admin\AppData\Roaming\Install\Host.exe | executable | |
MD5:— | SHA256:— | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3908 | Host.exe | 91.193.75.66:2803 | onelove03.duckdns.org | WorldStream B.V. | RS | malicious |
Domain | IP | Reputation |
|---|---|---|
onelove03.duckdns.org |
| malicious |
PID | Process | Class | Message |
|---|---|---|---|
1052 | svchost.exe | Misc activity | ET INFO DYNAMIC_DNS Query to *.duckdns. Domain |
3908 | Host.exe | A Network Trojan was detected | MALWARE [PTsecurity] Netwire.RAT |