analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

Nonsense_Diamond_Nonsense_Diamond_4.9.rar

Full analysis: https://app.any.run/tasks/87d98323-c892-4d7a-b6ad-622454690a4e
Verdict: Malicious activity
Analysis date: April 25, 2019, 07:35:48
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

2A3E582FB680A209D98C5154682B1264

SHA1:

8626B47650AE3DBC2BE33AF8FC564ADDA876FB7E

SHA256:

1071ABEB6D73511059BAAFCC4B0509249C666A968496CD9B8D857B089D2A8A94

SSDEEP:

196608:C5Jg0LZWU/B4xYsd89TKyUC2nwELIQsmiiT+wCkmoob2nizO1SMblb:QUUpGYsd88yUbwELIQf1TQCizE

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Nonsense Diamond.exe (PID: 928)
    • Loads dropped or rewritten executable

      • Nonsense Diamond.exe (PID: 928)
  • SUSPICIOUS

    • Modifies the open verb of a shell class

      • Nonsense Diamond.exe (PID: 928)
    • Creates files in the user directory

      • Nonsense Diamond.exe (PID: 928)
    • Writes to a desktop.ini file (may be used to cloak folders)

      • WinRAR.exe (PID: 128)
    • Executable content was dropped or overwritten

      • Nonsense Diamond.exe (PID: 928)
      • WinRAR.exe (PID: 128)
    • Reads internet explorer settings

      • Nonsense Diamond.exe (PID: 928)
  • INFO

    • Reads settings of System Certificates

      • Nonsense Diamond.exe (PID: 928)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
33
Monitored processes
2
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start winrar.exe nonsense diamond.exe

Process information

PID
CMD
Path
Indicators
Parent process
128"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Nonsense_Diamond_Nonsense_Diamond_4.9.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
928"C:\Users\admin\AppData\Local\Temp\Rar$EXa128.28608\Nonsense_Diamond_Nonsense_Diamond_4.9\[Nonsense Diamond] Nonsense Diamond 4.9\Nonsense Diamond.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa128.28608\Nonsense_Diamond_Nonsense_Diamond_4.9\[Nonsense Diamond] Nonsense Diamond 4.9\Nonsense Diamond.exe
WinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Nonsense Diamond
Version:
1.0.0.0
Total events
584
Read events
523
Write events
0
Delete events
0

Modification events

No data
Executable files
10
Suspicious files
0
Text files
11
Unknown types
0

Dropped files

PID
Process
Filename
Type
928Nonsense Diamond.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@google[1].txt
MD5:
SHA256:
928Nonsense Diamond.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\admin@google[2].txttext
MD5:38DF4C1697795143195EE2149767BE1D
SHA256:A1AB321946BFA87FE95DF8222813EE1969AE9B450B163FE4EFA7C1367263EA95
928Nonsense Diamond.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H6QNMHE9\google_com[1].txthtml
MD5:312A6CCB63BBBB931E1E9217EA4E07ED
SHA256:E7254BC93D6F9A385674FF0C375A7998EEEDD6813C4A414F47B4237BE5B908BF
928Nonsense Diamond.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\rs=ACT90oHwAr8G4jAT3j87Efq-CVMdjVNqow[1]text
MD5:A38C85939CA363243EEEF61C6405F21E
SHA256:6A0D02D014826C516847B3E0180E440E37070D7655983ADC24EC64BA9A9BB68B
128WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa128.28608\Nonsense_Diamond_Nonsense_Diamond_4.9\[Nonsense Diamond] Nonsense Diamond 4.9\WeAreDevs_API.dllexecutable
MD5:BE229EC036E67368650219EC91B0F08C
SHA256:354018BF829B623FA45D9D9CDE16D3BD549AF565F8DB28BF5F935C2965B945DE
128WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa128.28608\Nonsense_Diamond_Nonsense_Diamond_4.9\[Nonsense Diamond] Nonsense Diamond 4.9\Nonsense Diamond.exeexecutable
MD5:E40C8AFB7FF5BD4F8EE594A3509650C1
SHA256:81654A21D0E88543EBE629D15C3AA0549234EE6FED8AE07D01516235966D9B93
928Nonsense Diamond.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H6QNMHE9\google_com[2].txthtml
MD5:2980E1252E351FD1ADF75E6EF1F3B528
SHA256:AE54D2CA143EA849541412B3322164C2074874746D69EF63D9E90DC58B910992
128WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa128.28608\Nonsense_Diamond_Nonsense_Diamond_4.9\[Nonsense Diamond] Nonsense Diamond 4.9\Nonsense.dllexecutable
MD5:1632BB33D40C8EB47C2572E465EAB30B
SHA256:1927FD9789B530644688FA0AC13144B9F026A732FB3E5DBF344DCCCC84C008CF
128WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa128.28608\Nonsense_Diamond_Nonsense_Diamond_4.9\[Nonsense Diamond] Nonsense Diamond 4.9\desktop.iniini
MD5:95465295EF69ABC095118F9C6736E709
SHA256:3087860B614A44425F295C009B8AE33CCE02A253BF3EA1DCAF07E45B311548A9
128WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa128.28608\Nonsense_Diamond_Nonsense_Diamond_4.9\[Nonsense Diamond] Nonsense Diamond 4.9\MUST READ!!.txttext
MD5:D19042DCC6B197E6B4910C6465A74C80
SHA256:E681F8557285111BF3D5A97B6F4903802675B46BE9D202E7667E942A1D8BD871
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
5
DNS requests
4
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
928
Nonsense Diamond.exe
104.20.209.21:443
pastebin.com
Cloudflare Inc
US
shared
928
Nonsense Diamond.exe
104.31.78.245:443
www.sparecomputing.com
Cloudflare Inc
US
shared
928
Nonsense Diamond.exe
172.217.18.100:443
www.google.com
Google Inc.
US
whitelisted
928
Nonsense Diamond.exe
172.217.16.206:443
google.com
Google Inc.
US
whitelisted

DNS requests

Domain
IP
Reputation
pastebin.com
  • 104.20.209.21
  • 104.20.208.21
shared
google.com
  • 172.217.16.206
whitelisted
www.google.com
  • 172.217.18.100
whitelisted
www.sparecomputing.com
  • 104.31.78.245
  • 104.31.79.245
suspicious

Threats

No threats detected
No debug info