File name:

Indetectables Rat v.0.9.5 [AutoIt] Beta By M3.rar

Full analysis: https://app.any.run/tasks/c2d1992e-5539-42ba-9e77-5b3b1cff2193
Verdict: Malicious activity
Analysis date: September 06, 2018, 13:21:38
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v4, os: Win32
MD5:

09BB5777247D06469AF5EEA4D9AB2982

SHA1:

4D1C8F9F2FF027FF1B8F818DF3C58F8FC712EEA0

SHA256:

1E2F183C1DE1D89E67EEE889A2A9D6F96919C6DEC469AB32A60D6D6123BA460D

SSDEEP:

393216:+fKf1lZImbUAGjlCCIh5BYPDtPJxImCN6up:+fGZImAZCph5Bbp

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • IndRat.exe (PID: 1504)
      • Microsoft.ApplicationId.Framework.exe (PID: 2472)
    • Application was dropped or rewritten from another process

      • Aut2exe.exe (PID: 380)
      • Microsoft.ApplicationId.Framework.exe (PID: 2472)
      • 111.exe (PID: 768)
      • Microsoft.ApplicationId.Framework.exe (PID: 2688)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • IndRat.exe (PID: 1504)
      • WinRAR.exe (PID: 868)
      • Aut2exe.exe (PID: 380)
      • upx.exe (PID: 2124)
      • 111.exe (PID: 768)
      • Microsoft.ApplicationId.Framework.exe (PID: 2472)
    • Starts itself from another location

      • 111.exe (PID: 768)
    • Creates files in the program directory

      • Microsoft.ApplicationId.Framework.exe (PID: 2472)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

CompressedSize: 129962
UncompressedSize: 139360
OperatingSystem: Win32
ModifyDate: 2014:01:17 11:30:12
PackingMethod: Normal
ArchivedFileName: IndRat v.9.5\Bandeiras\ad.png
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
57
Monitored processes
12
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start drop and start winrar.exe indrat.exe aut2exe.exe upx.exe 111.exe microsoft.applicationid.framework.exe no specs dllhost.exe no specs Copy/Move/Rename/Delete/Link Object no specs compmgmtlauncher.exe no specs compmgmtlauncher.exe microsoft.applicationid.framework.exe taskmgr.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
380"C:\Users\admin\Desktop\IndRat v.9.5\Compilador\Aut2exe.exe" C:\Users\admin\Desktop\IndRat v.9.5\Compilador\Aut2exe.exe
explorer.exe
User:
admin
Company:
AutoIt Team
Integrity Level:
MEDIUM
Description:
Aut2Exe
Exit code:
0
Version:
3, 3, 8, 1
Modules
Images
c:\users\admin\desktop\indrat v.9.5\compilador\aut2exe.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
584"C:\Windows\system32\dllhost.exe"C:\Windows\system32\dllhost.exeMicrosoft.ApplicationId.Framework.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
COM Surrogate
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\dllhost.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
768"C:\Users\admin\Desktop\111.exe" C:\Users\admin\Desktop\111.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1
Version:
3, 3, 8, 1
Modules
Images
c:\users\admin\desktop\111.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\gdi32.dll
868"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\Indetectables Rat v.0.9.5 [AutoIt] Beta By M3.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
1504"C:\Users\admin\Desktop\IndRat v.9.5\IndRat.exe" C:\Users\admin\Desktop\IndRat v.9.5\IndRat.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Version:
3, 3, 8, 1
Modules
Images
c:\users\admin\desktop\indrat v.9.5\indrat.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\version.dll
2124"C:\Users\admin\Desktop\IndRat v.9.5\Compilador\upx.exe" --best --compress-icons=0 "C:\Users\admin\Desktop\111.exe"C:\Users\admin\Desktop\IndRat v.9.5\Compilador\upx.exe
Aut2exe.exe
User:
admin
Company:
The UPX Team http://upx.sf.net
Integrity Level:
MEDIUM
Description:
UPX executable packer
Exit code:
0
Version:
3.07 (2010-09-08)
Modules
Images
c:\users\admin\desktop\indrat v.9.5\compilador\upx.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
2472"C:\Users\admin\AppData\Local\Temp\Ind\Microsoft.ApplicationId.Framework.exe" C:\Users\admin\AppData\Local\Temp\Ind\Microsoft.ApplicationId.Framework.exeC:\Users\admin\AppData\Local\Temp\Ind\Microsoft.ApplicationId.Framework.exe
CompMgmtLauncher.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Version:
3, 3, 8, 1
Modules
Images
c:\users\admin\appdata\local\temp\ind\microsoft.applicationid.framework.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\gdi32.dll
2656"C:\Windows\System32\CompMgmtLauncher.exe" C:\Windows\System32\CompMgmtLauncher.exeMicrosoft.ApplicationId.Framework.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Computer Management Snapin Launcher
Exit code:
3221226540
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\compmgmtlauncher.exe
c:\systemroot\system32\ntdll.dll
2688"C:\Users\admin\AppData\Local\Temp\Ind\Microsoft.ApplicationId.Framework.exe" C:\Users\admin\AppData\Local\Temp\Ind\Microsoft.ApplicationId.Framework.exe111.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Version:
3, 3, 8, 1
Modules
Images
c:\users\admin\appdata\local\temp\ind\microsoft.applicationid.framework.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\gdi32.dll
2804"C:\Windows\system32\taskmgr.exe" /4C:\Windows\system32\taskmgr.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Task Manager
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskmgr.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
2 801
Read events
2 418
Write events
378
Delete events
5

Modification events

(PID) Process:(868) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(868) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(868) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\59\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(868) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\Indetectables Rat v.0.9.5 [AutoIt] Beta By M3.rar
(PID) Process:(868) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(868) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(868) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(868) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(868) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
(PID) Process:(868) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF2C0000002C000000EC03000021020000
Executable files
9
Suspicious files
0
Text files
274
Unknown types
5

Dropped files

PID
Process
Filename
Type
868WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb868.30737\IndRat v.9.5\Bandeiras\am.pngimage
MD5:0F82690416FF12366A67B9402735C1DE
SHA256:4AAB0BE2ACA936BD6DE310D5271509D517E9E6D3E74996B11D7EC2358040B4E9
868WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb868.30737\IndRat v.9.5\Bandeiras\af.pngimage
MD5:E5D92DB7336D1DC8B4BE5425FF751325
SHA256:2BF77EE6997D42C789F6BDF02806F66F6615D6AB033353C3246D69020DD92B52
868WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb868.30737\IndRat v.9.5\Bandeiras\ao.pngimage
MD5:5A020033C257E92D7613B278109CC404
SHA256:B82F6BFF7F8772C7A663DDBFEA394695E0970162E7D0E18696CC386160597D1F
868WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb868.30737\IndRat v.9.5\Bandeiras\at.pngimage
MD5:018CB031396887BB748C95FF32FA6B6A
SHA256:F2488FB3A8A7D485E53050A00B6895408F6ADADAD7F68365DB274686CA26864A
868WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb868.30737\IndRat v.9.5\Bandeiras\ad.pngimage
MD5:C22BA67A6B94164AD220C2064994ADD1
SHA256:EEF9B90D0D988CC15B2AC5567852FACC7C0DE9B19A8C12BB96BDB7C64DD0D2C9
868WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb868.30737\IndRat v.9.5\Bandeiras\bh.pngimage
MD5:5417FFBDCD4BAAFD1645ABD2E431765D
SHA256:5BCEA6F1E5301ABD327B3B8E53E9968007D31A52DB8D5B431FE38E7162F886C6
868WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb868.30737\IndRat v.9.5\Bandeiras\bg.pngimage
MD5:01A706C970EED183313E65772ABF89B7
SHA256:BC9901E980C8C2AD60C07C5BF7C69B2705C2602AFE5B7372B297F3F32B471CFE
868WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb868.30737\IndRat v.9.5\Bandeiras\be.pngimage
MD5:18E4B453844A360A88EB140660726BD9
SHA256:10F1D7E798624369C1546581D64267580818D888771EE19853670805275C5841
868WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb868.30737\IndRat v.9.5\Bandeiras\bd.pngimage
MD5:978CA19E2EE0BBD3CE75F92209636841
SHA256:C5405D50A1F056B82002B92D959DA2E25FF8EAB78F56CF62F284FB8686B23B64
868WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb868.30737\IndRat v.9.5\Bandeiras\bj.pngimage
MD5:B4CE7CA69F3C1AEF76616E3D7B609609
SHA256:91544D8F3DA7B3D3CD22CB1BA2B0D7EE33844BB3419542246FC93A5AA7A3088F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info