File name:

Indetectables Rat v.0.9.5 [AutoIt] Beta By M3.rar

Full analysis: https://app.any.run/tasks/c2d1992e-5539-42ba-9e77-5b3b1cff2193
Verdict: Malicious activity
Analysis date: September 06, 2018, 13:21:38
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v4, os: Win32
MD5:

09BB5777247D06469AF5EEA4D9AB2982

SHA1:

4D1C8F9F2FF027FF1B8F818DF3C58F8FC712EEA0

SHA256:

1E2F183C1DE1D89E67EEE889A2A9D6F96919C6DEC469AB32A60D6D6123BA460D

SSDEEP:

393216:+fKf1lZImbUAGjlCCIh5BYPDtPJxImCN6up:+fGZImAZCph5Bbp

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Aut2exe.exe (PID: 380)
      • Microsoft.ApplicationId.Framework.exe (PID: 2688)
      • 111.exe (PID: 768)
      • Microsoft.ApplicationId.Framework.exe (PID: 2472)
    • Loads dropped or rewritten executable

      • IndRat.exe (PID: 1504)
      • Microsoft.ApplicationId.Framework.exe (PID: 2472)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • upx.exe (PID: 2124)
      • WinRAR.exe (PID: 868)
      • IndRat.exe (PID: 1504)
      • 111.exe (PID: 768)
      • Microsoft.ApplicationId.Framework.exe (PID: 2472)
      • Aut2exe.exe (PID: 380)
    • Starts itself from another location

      • 111.exe (PID: 768)
    • Creates files in the program directory

      • Microsoft.ApplicationId.Framework.exe (PID: 2472)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

CompressedSize: 129962
UncompressedSize: 139360
OperatingSystem: Win32
ModifyDate: 2014:01:17 11:30:12
PackingMethod: Normal
ArchivedFileName: IndRat v.9.5\Bandeiras\ad.png
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
57
Monitored processes
12
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start drop and start winrar.exe indrat.exe aut2exe.exe upx.exe 111.exe microsoft.applicationid.framework.exe no specs dllhost.exe no specs Copy/Move/Rename/Delete/Link Object no specs compmgmtlauncher.exe no specs compmgmtlauncher.exe microsoft.applicationid.framework.exe taskmgr.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
380"C:\Users\admin\Desktop\IndRat v.9.5\Compilador\Aut2exe.exe" C:\Users\admin\Desktop\IndRat v.9.5\Compilador\Aut2exe.exe
explorer.exe
User:
admin
Company:
AutoIt Team
Integrity Level:
MEDIUM
Description:
Aut2Exe
Exit code:
0
Version:
3, 3, 8, 1
Modules
Images
c:\users\admin\desktop\indrat v.9.5\compilador\aut2exe.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
584"C:\Windows\system32\dllhost.exe"C:\Windows\system32\dllhost.exeMicrosoft.ApplicationId.Framework.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
COM Surrogate
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\dllhost.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
768"C:\Users\admin\Desktop\111.exe" C:\Users\admin\Desktop\111.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1
Version:
3, 3, 8, 1
Modules
Images
c:\users\admin\desktop\111.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\gdi32.dll
868"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\Indetectables Rat v.0.9.5 [AutoIt] Beta By M3.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
1504"C:\Users\admin\Desktop\IndRat v.9.5\IndRat.exe" C:\Users\admin\Desktop\IndRat v.9.5\IndRat.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Version:
3, 3, 8, 1
Modules
Images
c:\users\admin\desktop\indrat v.9.5\indrat.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\version.dll
2124"C:\Users\admin\Desktop\IndRat v.9.5\Compilador\upx.exe" --best --compress-icons=0 "C:\Users\admin\Desktop\111.exe"C:\Users\admin\Desktop\IndRat v.9.5\Compilador\upx.exe
Aut2exe.exe
User:
admin
Company:
The UPX Team http://upx.sf.net
Integrity Level:
MEDIUM
Description:
UPX executable packer
Exit code:
0
Version:
3.07 (2010-09-08)
Modules
Images
c:\users\admin\desktop\indrat v.9.5\compilador\upx.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
2472"C:\Users\admin\AppData\Local\Temp\Ind\Microsoft.ApplicationId.Framework.exe" C:\Users\admin\AppData\Local\Temp\Ind\Microsoft.ApplicationId.Framework.exeC:\Users\admin\AppData\Local\Temp\Ind\Microsoft.ApplicationId.Framework.exe
CompMgmtLauncher.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Version:
3, 3, 8, 1
Modules
Images
c:\users\admin\appdata\local\temp\ind\microsoft.applicationid.framework.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\gdi32.dll
2656"C:\Windows\System32\CompMgmtLauncher.exe" C:\Windows\System32\CompMgmtLauncher.exeMicrosoft.ApplicationId.Framework.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Computer Management Snapin Launcher
Exit code:
3221226540
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\compmgmtlauncher.exe
c:\systemroot\system32\ntdll.dll
2688"C:\Users\admin\AppData\Local\Temp\Ind\Microsoft.ApplicationId.Framework.exe" C:\Users\admin\AppData\Local\Temp\Ind\Microsoft.ApplicationId.Framework.exe111.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Version:
3, 3, 8, 1
Modules
Images
c:\users\admin\appdata\local\temp\ind\microsoft.applicationid.framework.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\gdi32.dll
2804"C:\Windows\system32\taskmgr.exe" /4C:\Windows\system32\taskmgr.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Task Manager
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskmgr.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
2 801
Read events
2 418
Write events
378
Delete events
5

Modification events

(PID) Process:(868) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(868) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(868) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\59\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(868) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\Indetectables Rat v.0.9.5 [AutoIt] Beta By M3.rar
(PID) Process:(868) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(868) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(868) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(868) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(868) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
(PID) Process:(868) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF2C0000002C000000EC03000021020000
Executable files
9
Suspicious files
0
Text files
274
Unknown types
5

Dropped files

PID
Process
Filename
Type
868WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb868.30737\IndRat v.9.5\Bandeiras\af.pngimage
MD5:E5D92DB7336D1DC8B4BE5425FF751325
SHA256:2BF77EE6997D42C789F6BDF02806F66F6615D6AB033353C3246D69020DD92B52
868WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb868.30737\IndRat v.9.5\Bandeiras\am.pngimage
MD5:0F82690416FF12366A67B9402735C1DE
SHA256:4AAB0BE2ACA936BD6DE310D5271509D517E9E6D3E74996B11D7EC2358040B4E9
868WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb868.30737\IndRat v.9.5\Bandeiras\au.pngimage
MD5:2A1384DE781BF1374F8A96710ED5CD70
SHA256:5D7C2318950FD8490EEA8C6C488917E386407D4D0C29FF2B71D10F73A9169162
868WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb868.30737\IndRat v.9.5\Bandeiras\ad.pngimage
MD5:C22BA67A6B94164AD220C2064994ADD1
SHA256:EEF9B90D0D988CC15B2AC5567852FACC7C0DE9B19A8C12BB96BDB7C64DD0D2C9
868WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb868.30737\IndRat v.9.5\Bandeiras\ao.pngimage
MD5:5A020033C257E92D7613B278109CC404
SHA256:B82F6BFF7F8772C7A663DDBFEA394695E0970162E7D0E18696CC386160597D1F
868WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb868.30737\IndRat v.9.5\Bandeiras\at.pngimage
MD5:018CB031396887BB748C95FF32FA6B6A
SHA256:F2488FB3A8A7D485E53050A00B6895408F6ADADAD7F68365DB274686CA26864A
868WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb868.30737\IndRat v.9.5\Bandeiras\ba.pngimage
MD5:1C320DD11E66B35DC1A2350F138181D5
SHA256:115DC28A61F75D2799EEB0B17CC7C9EC8CDF082A60A3CED1E94292AF568FB0FB
868WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb868.30737\IndRat v.9.5\Bandeiras\al.pngimage
MD5:938F6D2AD6EB0754B4B1CE8D6EFE3D00
SHA256:D3AD4F7C40CF88D3072EB158F6083053017D4B4F0537CFB8C0AAAD7CD79D768C
868WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb868.30737\IndRat v.9.5\Bandeiras\ae.pngimage
MD5:AA44839785B2EF1890987B6815791020
SHA256:165A7FE36D6DABA17F36082CEBA573B107FF54293E8792C4FE2E186752210244
868WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb868.30737\IndRat v.9.5\Bandeiras\ag.pngimage
MD5:1C0D859D89EA2FD426B5995629B48C02
SHA256:DB673A779729744BD091322D388F31857B6E4B2F516C212317FB80BB6AE0660E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info