File name:

Combo Tools.rar

Full analysis: https://app.any.run/tasks/059743fa-8c00-4589-b1af-36cc532edaa4
Verdict: Malicious activity
Analysis date: August 17, 2019, 17:08:58
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

1C0B60B59951FD4C685C1FCFB84A6DD5

SHA1:

904CDC918D0843F97519FD7D82716E2C2729BFC7

SHA256:

15D7C54066815C7CA7FCB767F7817F8B26409A5A71FEE064D7145ADDA555F3F8

SSDEEP:

196608:5VOcW5Gn3JVKiM5c82n/7pBixvIUBs724:5VOdGnZVKiM58jpYxvvi724

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 848)
      • SLAYER Leecher v0.5 By X-SLAYER.exe (PID: 3456)
    • Application was dropped or rewritten from another process

      • SLAYER Leecher v0.5 By X-SLAYER.exe (PID: 3456)
      • fSplit.exe (PID: 3204)
      • Elite Dups Remover 1.5.exe (PID: 2760)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3184)
      • SLAYER Leecher v0.5 By X-SLAYER.exe (PID: 3456)
    • Reads Environment values

      • SLAYER Leecher v0.5 By X-SLAYER.exe (PID: 3456)
  • INFO

    • Manual execution by user

      • SLAYER Leecher v0.5 By X-SLAYER.exe (PID: 3456)
      • Elite Dups Remover 1.5.exe (PID: 2760)
      • fSplit.exe (PID: 3204)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
40
Monitored processes
5
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe searchprotocolhost.exe no specs fsplit.exe no specs slayer leecher v0.5 by x-slayer.exe elite dups remover 1.5.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
848"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2760"C:\Users\admin\Desktop\Combo Tools\dupe_remover\Elite Dups Remover 1.5.exe" C:\Users\admin\Desktop\Combo Tools\dupe_remover\Elite Dups Remover 1.5.exeexplorer.exe
User:
admin
Company:
VEX
Integrity Level:
MEDIUM
Description:
ELITE DUPLICATES REMOVER
Exit code:
0
Version:
1.5.0.0
Modules
Images
c:\users\admin\desktop\combo tools\dupe_remover\elite dups remover 1.5.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3184"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Combo Tools.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3204"C:\Users\admin\Desktop\Combo Tools\Split Combos\fSplit.exe" C:\Users\admin\Desktop\Combo Tools\Split Combos\fSplit.exeexplorer.exe
User:
admin
Company:
dubasdey
Integrity Level:
MEDIUM
Description:
FileSplitter
Exit code:
0
Version:
1.4.1.26382
Modules
Images
c:\users\admin\desktop\combo tools\split combos\fsplit.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3456"C:\Users\admin\Desktop\Combo Tools\SLAYER Leecher v0.5\SLAYER Leecher v0.5 By X-SLAYER.exe" C:\Users\admin\Desktop\Combo Tools\SLAYER Leecher v0.5\SLAYER Leecher v0.5 By X-SLAYER.exe
explorer.exe
User:
admin
Company:
Iheb Briki
Integrity Level:
MEDIUM
Description:
SLAYER Leecher
Exit code:
0
Version:
0.4.1
Modules
Images
c:\users\admin\desktop\combo tools\slayer leecher v0.5\slayer leecher v0.5 by x-slayer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
879
Read events
832
Write events
47
Delete events
0

Modification events

(PID) Process:(3184) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3184) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3184) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3184) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Combo Tools.rar
(PID) Process:(3184) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3184) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3184) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3184) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(848) SearchProtocolHost.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\72\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(848) SearchProtocolHost.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\72\52C64B7E
Operation:writeName:@C:\Windows\system32\notepad.exe,-469
Value:
Text Document
Executable files
9
Suspicious files
0
Text files
9
Unknown types
0

Dropped files

PID
Process
Filename
Type
3184WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3184.26900\Combo Tools\SLAYER Leecher v0.5\FX.wav
MD5:
SHA256:
3204fSplit.exeC:\Users\admin\AppData\Local\dubasdey\fSplit.exe_Url_3vhpqnzq3tkumff2tuivb0ykqffxunly\1.4.1.26382\lhf87m5v.newcfg
MD5:
SHA256:
3184WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3184.26900\Combo Tools\dupe_remover\Elite Dups Remover 1.5.exeexecutable
MD5:
SHA256:
3184WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3184.26900\Combo Tools\SLAYER Leecher v0.5\Keywords & Regex\Keywords by AnimuCracku.txttext
MD5:
SHA256:
3184WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3184.26900\Combo Tools\Split Combos\changelog.txttext
MD5:
SHA256:
3184WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3184.26900\Combo Tools\SLAYER Leecher v0.5\SkinSoft.VisualStyler.dllexecutable
MD5:2D84A619D4BD339F860CB48AF0C9B6C8
SHA256:365FFDE7DF914840EB21C96F34C39912A4B031E3814B8E902B67ACEE6DFF65A1
3184WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3184.26900\Combo Tools\SLAYER Leecher v0.5\Keywords & Regex\Regex List.rtftext
MD5:31025A21B63C80C8C235B28BB03F04BE
SHA256:888C359087D562D7790A027C49B764B09254A49B1C4565F481E8BE3B4274482B
3184WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3184.26900\Combo Tools\Split Combos\fSplit.exeexecutable
MD5:
SHA256:
3184WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3184.26900\Combo Tools\SLAYER Leecher v0.5\xNet.dllexecutable
MD5:3DF8D87A482EFAD957D83819ADB3020F
SHA256:2AC175B4D44245EE8E7AEE9CC36DF86925EF903D8516F20A2C51D84E35F23DA4
3184WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3184.26900\Combo Tools\Split Combos\fSplit.exe.configxml
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
1
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3456
SLAYER Leecher v0.5 By X-SLAYER.exe
104.20.208.21:443
pastebin.com
Cloudflare Inc
US
shared

DNS requests

Domain
IP
Reputation
pastebin.com
  • 104.20.208.21
  • 104.20.209.21
malicious

Threats

No threats detected
No debug info