| File name: | Pack of netflix checkers.rar |
| Full analysis: | https://app.any.run/tasks/0d1f07ef-d377-47f6-919c-37e4be376ee5 |
| Verdict: | Malicious activity |
| Analysis date: | January 01, 2019, 11:25:53 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v5 |
| MD5: | FAA80D863CE7188E78D60AB5237383E7 |
| SHA1: | 3ABE2CCE5C0F7C33673BF6E085B9A47C112B285A |
| SHA256: | 1002DB78D7A50E475D7E3909EF68205DB1F577FAD0992B544E0D8AC11AB8C64F |
| SSDEEP: | 98304:QDjQQnRXcRdAZRxlUYX3Vd5vp7u0H1wibr4HKks:8QQdcC7xGYXhQ0Nv4HKF |
| .rar | | | RAR compressed archive (v5.0) (61.5) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1144 | "C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe6_ Global\UsGthrCtrlFltPipeMssGthrPipe6 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" | C:\Windows\System32\SearchProtocolHost.exe | — | SearchIndexer.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft Windows Search Protocol Host Exit code: 0 Version: 7.00.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2316 | "C:\Windows\svchost.com" "C:\Users\admin\AppData\Local\Temp\3582-490\NETFLI~1.EXE" | C:\Windows\svchost.com | — | Netflix Proxyless Cracker v2.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2424 | "C:\Windows\svchost.com" "C:\Users\admin\AppData\Local\Temp\3582-490\NETFLI~1.EXE" | C:\Windows\svchost.com | — | Netflix Checker V0.3.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2652 | "C:\Users\admin\Desktop\Pack of netflix checkers\New folder\Netflix V2.0.exe" | C:\Users\admin\Desktop\Pack of netflix checkers\New folder\Netflix V2.0.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Netflix V2.0 Exit code: 3221225786 Version: 1.0.0.0 Modules
| |||||||||||||||
| 2936 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Pack of netflix checkers.rar" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 3016 | "C:\Users\admin\Desktop\Pack of netflix checkers\Netflix Checker 2018 V0.3\Netflix Checker V0.3.exe" | C:\Users\admin\Desktop\Pack of netflix checkers\Netflix Checker 2018 V0.3\Netflix Checker V0.3.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 3028 | C:\Users\admin\AppData\Local\Temp\3582-490\NETFLI~1.EXE | C:\Users\admin\AppData\Local\Temp\3582-490\NETFLI~1.EXE | svchost.com | ||||||||||||
User: admin Company: www.crackingcenter.ir Integrity Level: HIGH Description: Netflix Cracker Coded By EVG Exit code: 3762504530 Version: 1.0.0.0 Modules
| |||||||||||||||
| 3104 | "C:\Users\admin\Desktop\Pack of netflix checkers\rrr\Netflix V2.0.exe" | C:\Users\admin\Desktop\Pack of netflix checkers\rrr\Netflix V2.0.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Netflix V2.0 Exit code: 3221225786 Version: 1.0.0.0 Modules
| |||||||||||||||
| 3200 | "C:\Users\admin\AppData\Local\Temp\3582-490\Netflix Checker v0.2.2.exe" | C:\Users\admin\AppData\Local\Temp\3582-490\Netflix Checker v0.2.2.exe | — | Netflix Checker v0.2.2.exe | |||||||||||
User: admin Company: julioverne Integrity Level: HIGH Description: Netflix Checker Exit code: 0 Version: 2.2.0.0 Modules
| |||||||||||||||
| 3300 | "C:\Users\admin\Desktop\Pack of netflix checkers\NETFLIX Checker\Netflix Proxyless Cracker v2.exe" | C:\Users\admin\Desktop\Pack of netflix checkers\NETFLIX Checker\Netflix Proxyless Cracker v2.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| (PID) Process: | (2936) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (2936) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (2936) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2936) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Pack of netflix checkers.rar | |||
| (PID) Process: | (2936) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2936) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2936) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2936) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (4024) Netflix Checker v0.2.2.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (4024) Netflix Checker v0.2.2.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2936 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2936.48042\Pack of netflix checkers\Netflix Checker 2018 V0.3\MetroFramework.Design.dll | — | |
MD5:— | SHA256:— | |||
| 2936 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2936.48042\Pack of netflix checkers\Netflix Checker 2018 V0.3\MetroFramework.dll | — | |
MD5:— | SHA256:— | |||
| 2936 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2936.48042\Pack of netflix checkers\Netflix Checker 2018 V0.3\MetroFramework.Fonts.dll | — | |
MD5:— | SHA256:— | |||
| 2936 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2936.48042\Pack of netflix checkers\Netflix Checker 2018 V0.3\Netflix Checker V0.3.exe | — | |
MD5:— | SHA256:— | |||
| 2936 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2936.48042\Pack of netflix checkers\Netflix Checker 2018 V0.3\Results\04_20\Good.txt | — | |
MD5:— | SHA256:— | |||
| 2936 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2936.48042\Pack of netflix checkers\Netflix Checker 2018 V0.3\Results\04_33\Good.txt | — | |
MD5:— | SHA256:— | |||
| 2936 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2936.48042\Pack of netflix checkers\Netflix Checker 2018 V0.3\Results\04_33\Remainder.txt | — | |
MD5:— | SHA256:— | |||
| 2936 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2936.48042\Pack of netflix checkers\Netflix Checker 2018 V0.3\Results\09_01\Good.txt | — | |
MD5:— | SHA256:— | |||
| 2936 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2936.48042\Pack of netflix checkers\Netflix Checker 2018 V0.3\Results\09_24\Good.txt | — | |
MD5:— | SHA256:— | |||
| 2936 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2936.48042\Pack of netflix checkers\Netflix Checker 2018 V0.3\Tulpep.NotificationWindow.dll | — | |
MD5:— | SHA256:— | |||