File name:

Pack of netflix checkers.rar

Full analysis: https://app.any.run/tasks/0d1f07ef-d377-47f6-919c-37e4be376ee5
Verdict: Malicious activity
Analysis date: January 01, 2019, 11:25:53
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

FAA80D863CE7188E78D60AB5237383E7

SHA1:

3ABE2CCE5C0F7C33673BF6E085B9A47C112B285A

SHA256:

1002DB78D7A50E475D7E3909EF68205DB1F577FAD0992B544E0D8AC11AB8C64F

SSDEEP:

98304:QDjQQnRXcRdAZRxlUYX3Vd5vp7u0H1wibr4HKks:8QQdcC7xGYXhQ0Nv4HKF

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 1144)
    • Application was dropped or rewritten from another process

      • NETFLI~1.EXE (PID: 3472)
      • Netflix Checker v0.2.2.exe (PID: 4024)
      • Netflix Checker v0.2.2.exe (PID: 3200)
      • Netflix Checker V0.3.exe (PID: 3016)
      • Netflix Cracker Coded By EVG.exe (PID: 3828)
      • svchost.com (PID: 3480)
      • NETFLI~1.EXE (PID: 3028)
      • Netflix Proxyless Cracker v2.exe (PID: 3300)
      • svchost.com (PID: 2316)
      • NETFLI~1.EXE (PID: 3992)
      • svchost.com (PID: 2424)
  • SUSPICIOUS

    • Creates files in the Windows directory

      • Netflix Checker v0.2.2.exe (PID: 4024)
      • svchost.com (PID: 2424)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2936)
      • Netflix Checker v0.2.2.exe (PID: 4024)
      • Netflix Checker V0.3.exe (PID: 3016)
      • Netflix Cracker Coded By EVG.exe (PID: 3828)
      • Netflix Proxyless Cracker v2.exe (PID: 3300)
    • Removes files from Windows directory

      • svchost.com (PID: 2424)
      • svchost.com (PID: 3480)
      • Netflix Cracker Coded By EVG.exe (PID: 3828)
      • svchost.com (PID: 2316)
      • Netflix Proxyless Cracker v2.exe (PID: 3300)
      • Netflix Checker V0.3.exe (PID: 3016)
    • Reads internet explorer settings

      • Netflix Checker v0.2.2.exe (PID: 3200)
    • Modifies the open verb of a shell class

      • Netflix Checker v0.2.2.exe (PID: 4024)
    • Reads Internet Cache Settings

      • Netflix V2.0.exe (PID: 2652)
      • Netflix V2.0.exe (PID: 3104)
    • Starts itself from another location

      • Netflix Checker V0.3.exe (PID: 3016)
      • Netflix Cracker Coded By EVG.exe (PID: 3828)
      • Netflix Proxyless Cracker v2.exe (PID: 3300)
    • Starts application with an unusual extension

      • Netflix Cracker Coded By EVG.exe (PID: 3828)
      • Netflix Proxyless Cracker v2.exe (PID: 3300)
      • Netflix Checker V0.3.exe (PID: 3016)
  • INFO

    • Application was crashed

      • NETFLI~1.EXE (PID: 3028)
      • NETFLI~1.EXE (PID: 3472)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
70
Monitored processes
15
Malicious processes
5
Suspicious processes
5

Behavior graph

Click at the process to see the details
start drop and start winrar.exe netflix checker v0.2.2.exe netflix checker v0.2.2.exe no specs searchprotocolhost.exe no specs netflix v2.0.exe netflix v2.0.exe netflix checker v0.3.exe svchost.com no specs netfli~1.exe netflix cracker coded by evg.exe svchost.com no specs netfli~1.exe netflix proxyless cracker v2.exe svchost.com no specs netfli~1.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1144"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe6_ Global\UsGthrCtrlFltPipeMssGthrPipe6 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2316"C:\Windows\svchost.com" "C:\Users\admin\AppData\Local\Temp\3582-490\NETFLI~1.EXE" C:\Windows\svchost.comNetflix Proxyless Cracker v2.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\windows\svchost.com
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2424"C:\Windows\svchost.com" "C:\Users\admin\AppData\Local\Temp\3582-490\NETFLI~1.EXE" C:\Windows\svchost.comNetflix Checker V0.3.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\windows\svchost.com
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2652"C:\Users\admin\Desktop\Pack of netflix checkers\New folder\Netflix V2.0.exe" C:\Users\admin\Desktop\Pack of netflix checkers\New folder\Netflix V2.0.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
Netflix V2.0
Exit code:
3221225786
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\pack of netflix checkers\new folder\netflix v2.0.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2936"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Pack of netflix checkers.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3016"C:\Users\admin\Desktop\Pack of netflix checkers\Netflix Checker 2018 V0.3\Netflix Checker V0.3.exe" C:\Users\admin\Desktop\Pack of netflix checkers\Netflix Checker 2018 V0.3\Netflix Checker V0.3.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\pack of netflix checkers\netflix checker 2018 v0.3\netflix checker v0.3.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3028C:\Users\admin\AppData\Local\Temp\3582-490\NETFLI~1.EXE C:\Users\admin\AppData\Local\Temp\3582-490\NETFLI~1.EXE
svchost.com
User:
admin
Company:
www.crackingcenter.ir
Integrity Level:
HIGH
Description:
Netflix Cracker Coded By EVG
Exit code:
3762504530
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\3582-490\netfli~1.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3104"C:\Users\admin\Desktop\Pack of netflix checkers\rrr\Netflix V2.0.exe" C:\Users\admin\Desktop\Pack of netflix checkers\rrr\Netflix V2.0.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
Netflix V2.0
Exit code:
3221225786
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\pack of netflix checkers\rrr\netflix v2.0.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3200"C:\Users\admin\AppData\Local\Temp\3582-490\Netflix Checker v0.2.2.exe" C:\Users\admin\AppData\Local\Temp\3582-490\Netflix Checker v0.2.2.exeNetflix Checker v0.2.2.exe
User:
admin
Company:
julioverne
Integrity Level:
HIGH
Description:
Netflix Checker
Exit code:
0
Version:
2.2.0.0
Modules
Images
c:\users\admin\appdata\local\temp\3582-490\netflix checker v0.2.2.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3300"C:\Users\admin\Desktop\Pack of netflix checkers\NETFLIX Checker\Netflix Proxyless Cracker v2.exe" C:\Users\admin\Desktop\Pack of netflix checkers\NETFLIX Checker\Netflix Proxyless Cracker v2.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\pack of netflix checkers\netflix checker\netflix proxyless cracker v2.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
Total events
3 404
Read events
3 259
Write events
140
Delete events
5

Modification events

(PID) Process:(2936) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2936) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2936) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2936) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Pack of netflix checkers.rar
(PID) Process:(2936) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2936) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2936) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2936) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(4024) Netflix Checker v0.2.2.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(4024) Netflix Checker v0.2.2.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
Executable files
18
Suspicious files
1
Text files
11
Unknown types
0

Dropped files

PID
Process
Filename
Type
2936WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2936.48042\Pack of netflix checkers\Netflix Checker 2018 V0.3\MetroFramework.Design.dll
MD5:
SHA256:
2936WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2936.48042\Pack of netflix checkers\Netflix Checker 2018 V0.3\MetroFramework.dll
MD5:
SHA256:
2936WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2936.48042\Pack of netflix checkers\Netflix Checker 2018 V0.3\MetroFramework.Fonts.dll
MD5:
SHA256:
2936WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2936.48042\Pack of netflix checkers\Netflix Checker 2018 V0.3\Netflix Checker V0.3.exe
MD5:
SHA256:
2936WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2936.48042\Pack of netflix checkers\Netflix Checker 2018 V0.3\Results\04_20\Good.txt
MD5:
SHA256:
2936WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2936.48042\Pack of netflix checkers\Netflix Checker 2018 V0.3\Results\04_33\Good.txt
MD5:
SHA256:
2936WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2936.48042\Pack of netflix checkers\Netflix Checker 2018 V0.3\Results\04_33\Remainder.txt
MD5:
SHA256:
2936WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2936.48042\Pack of netflix checkers\Netflix Checker 2018 V0.3\Results\09_01\Good.txt
MD5:
SHA256:
2936WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2936.48042\Pack of netflix checkers\Netflix Checker 2018 V0.3\Results\09_24\Good.txt
MD5:
SHA256:
2936WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2936.48042\Pack of netflix checkers\Netflix Checker 2018 V0.3\Tulpep.NotificationWindow.dll
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info