| File name: | Trigon 4.3.2.rar |
| Full analysis: | https://app.any.run/tasks/c0163ff4-c0ee-4ac9-a414-41e325860e29 |
| Verdict: | Malicious activity |
| Analysis date: | October 14, 2019, 03:05:49 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v5 |
| MD5: | 5E7DA5EEEFF90A1543D9B68B7DCD9AB7 |
| SHA1: | 9B221E5E83FDA5016CA8B1AEBE2C6E008C698B39 |
| SHA256: | 1478330B64A3628709741143458EC35F07C020A6DAF2A187C41C79C410402565 |
| SSDEEP: | 196608:xoRhnxzzgDvmmsulaAou+/TdLNglxn+DgGbyOBkr0Q:Chnx5msBrutLnWuNr0Q |
| .rar | | | RAR compressed archive (v5.0) (61.5) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1292 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa1896.38632\Trigon 4.3.2\Trigon.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa1896.38632\Trigon 4.3.2\Trigon.exe | — | WinRAR.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Trigon Exit code: 3221226540 Version: 4.3.2.0 Modules
| |||||||||||||||
| 1584 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa1896.38399\Trigon 4.3.2\Trigon.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa1896.38399\Trigon 4.3.2\Trigon.exe | WinRAR.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Trigon Exit code: 0 Version: 4.3.2.0 Modules
| |||||||||||||||
| 1896 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Trigon 4.3.2.rar" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 2876 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa1896.38632\Trigon 4.3.2\Trigon.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa1896.38632\Trigon 4.3.2\Trigon.exe | WinRAR.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Trigon Exit code: 0 Version: 4.3.2.0 Modules
| |||||||||||||||
| 3940 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa1896.38399\Trigon 4.3.2\Trigon.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa1896.38399\Trigon 4.3.2\Trigon.exe | — | WinRAR.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Trigon Exit code: 3221226540 Version: 4.3.2.0 Modules
| |||||||||||||||
| (PID) Process: | (1896) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (1896) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (1896) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (1896) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Trigon 4.3.2.rar | |||
| (PID) Process: | (1896) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (1896) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (1896) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (1896) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (1896) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (1896) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1896 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1896.38399\Trigon 4.3.2\Scripts\Print.txt | text | |
MD5:— | SHA256:— | |||
| 1896 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1896.38399\Trigon 4.3.2\Scripts\Dark Dex.txt | text | |
MD5:— | SHA256:— | |||
| 1896 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1896.38399\Trigon 4.3.2\Data_\Dark.html | html | |
MD5:— | SHA256:— | |||
| 1896 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1896.38399\Trigon 4.3.2\Data_\vs\editor\editor.main.js | text | |
MD5:9399A8EAA741D04B0AE6566A5EBB8106 | SHA256:93D28520C07FBCA09E20886087F28797BB7BD0E6CF77400153AAB5AE67E3CE18 | |||
| 1896 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1896.38399\Trigon 4.3.2\Scripts\OPFinality.txt | text | |
MD5:E80B40B9B8E8145CE4EBFFB882DDD96E | SHA256:8C95140372EEBA29F20E15A7A49F6B6706F4DD59779A9715286CD3CE5AE71465 | |||
| 1896 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1896.38399\Trigon 4.3.2\Scripts\INFINITE YIELD FD.txt | text | |
MD5:19541BA7A07F3BE547D0D6A7F0091AAE | SHA256:5EAAFB68C57EDDEE8BA659A76375D1CBC1C905A6DDFFD625CB80EEB8D9B8A354 | |||
| 1896 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1896.38399\Trigon 4.3.2\Data_\vs\editor\editor.main.css | text | |
MD5:233217455A3EF3604BF4942024B94F98 | SHA256:2EC118616A1370E7C37342DA85834CA1819400C28F83ABFCBBB1EF50B51F7701 | |||
| 1896 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1896.38399\Trigon 4.3.2\Scripts\Reviz Admin v2.txt | text | |
MD5:DAA4BD50948D97012D74E9A822BB63AF | SHA256:BF1678B49397E7417EEB4D13DCE8951910347238230D431E2A341DDB985E10D8 | |||
| 1896 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1896.38399\Trigon 4.3.2\Data_\vs\basic-languages\csp\csp.js | text | |
MD5:22ADA25D590811DCFF4E5F5D698E583B | SHA256:4B5A5D7D50986B86B00833447E097C0F01A4388CE1765B48E7E371D06E3A4789 | |||
| 1896 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa1896.38399\Trigon 4.3.2\Data_\vs\language\css\cssWorker.js | text | |
MD5:152244E2AB4F663141E9466A8282EBE8 | SHA256:288BB68A2C685957B5DC3E5353B1A03DC482B10858059063B99C1549D5FEF01C | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
1584 | Trigon.exe | 104.22.2.84:443 | pastebin.com | Cloudflare Inc | US | shared |
2876 | Trigon.exe | 104.22.2.84:443 | pastebin.com | Cloudflare Inc | US | shared |
2876 | Trigon.exe | 104.31.79.78:443 | www.arponag.xyz | Cloudflare Inc | US | shared |
2876 | Trigon.exe | 162.159.130.233:443 | cdn.discordapp.com | Cloudflare Inc | — | shared |
1584 | Trigon.exe | 162.159.130.233:443 | cdn.discordapp.com | Cloudflare Inc | — | shared |
1584 | Trigon.exe | 104.31.79.78:443 | www.arponag.xyz | Cloudflare Inc | US | shared |
Domain | IP | Reputation |
|---|---|---|
pastebin.com |
| malicious |
www.arponag.xyz |
| suspicious |
cdn.discordapp.com |
| shared |