| File name: | Roblox Account Checker v2.0.0.rar |
| Full analysis: | https://app.any.run/tasks/fbd20e51-fc79-4aa7-8a99-26c75566b2ce |
| Verdict: | Malicious activity |
| Threats: | njRAT is a remote access trojan. It is one of the most widely accessible RATs on the market that features an abundance of educational information. Interested attackers can even find tutorials on YouTube. This allows it to become one of the most popular RATs in the world. |
| Analysis date: | August 06, 2021, 09:56:31 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v5 |
| MD5: | 5172116B2A742D31A15434BA2170E848 |
| SHA1: | 0DD5D95FE5D13633FE3472AE28B7C0E426F07E50 |
| SHA256: | 26C2639964C45707EE91CBA9C11F5FBA37BEAADADD9CDC89CCA62CF1450B8E47 |
| SSDEEP: | 98304:SxiAqKgYTTeudNre3usr9vnEA/Q5002MdCnxM3toudm:SezYTCudNX2Z30zO |
| .rar | | | RAR compressed archive (v5.0) (61.5) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1064 | "C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe" | C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe | — | Roblox Account Checker v2.0.0.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft .NET Assembly Registration Utility Exit code: 0 Version: 2.0.50727.5483 (Win7SP1GDR.050727-5400) Modules
| |||||||||||||||
| 1136 | "C:\Users\admin\Desktop\Roblox Account Checker v2.0.0.exe" | C:\Users\admin\Desktop\Roblox Account Checker v2.0.0.exe | — | eventvwr.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2260 | "C:\Users\admin\AppData\Local\Temp\Roblox Account Checker v1.0.0.exe" | C:\Users\admin\AppData\Local\Temp\Roblox Account Checker v1.0.0.exe | Roblox Account Checker v2.0.0.exe | ||||||||||||
User: admin Company: Microsoft Integrity Level: HIGH Description: Roblox Checker Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 2516 | "C:\Users\admin\AppData\Local\Temp\Roblox Account Checker v1.0.0.exe" | C:\Users\admin\AppData\Local\Temp\Roblox Account Checker v1.0.0.exe | Roblox Account Checker v2.0.0.exe | ||||||||||||
User: admin Company: Microsoft Integrity Level: HIGH Description: Roblox Checker Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 2608 | "C:\Windows\System32\eventvwr.exe" | C:\Windows\System32\eventvwr.exe | — | Roblox Account Checker v2.0.0.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Event Viewer Snapin Launcher Exit code: 3221226540 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2612 | "C:\Windows\System32\eventvwr.exe" | C:\Windows\System32\eventvwr.exe | Roblox Account Checker v2.0.0.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Event Viewer Snapin Launcher Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2920 | "C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe" | C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe | Roblox Account Checker v2.0.0.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft .NET Assembly Registration Utility Exit code: 0 Version: 2.0.50727.5483 (Win7SP1GDR.050727-5400) Modules
| |||||||||||||||
| 3036 | netsh firewall add allowedprogram "C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe" "RegAsm.exe" ENABLE | C:\Windows\system32\netsh.exe | — | RegAsm.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Network Command Shell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3044 | "C:\Users\admin\Desktop\Roblox Account Checker v2.0.0.exe" | C:\Users\admin\Desktop\Roblox Account Checker v2.0.0.exe | eventvwr.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 3500 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Roblox Account Checker v2.0.0.rar" | C:\Program Files\WinRAR\WinRAR.exe | Explorer.EXE | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| (PID) Process: | (3500) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3500) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3500) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3500) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (3500) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Roblox Account Checker v2.0.0.rar | |||
| (PID) Process: | (3500) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3500) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3500) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3500) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (3500) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E |
| Operation: | write | Name: | @C:\Windows\system32\notepad.exe,-469 |
Value: Text Document | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3500 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3500.47194\200k UP UHQ MIXED.txt | — | |
MD5:— | SHA256:— | |||
| 3500 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3500.47194\Roblox Account Checker v2.0.0.exe | executable | |
MD5:— | SHA256:— | |||
| 3044 | Roblox Account Checker v2.0.0.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\bridgeres.url | text | |
MD5:— | SHA256:— | |||
| 3044 | Roblox Account Checker v2.0.0.exe | C:\Users\admin\AppData\Local\Temp\Roblox Account Checker v1.0.0.exe | executable | |
MD5:— | SHA256:— | |||
| 3500 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3500.47194\10000 SOCKS4 WORKING (1).txt | text | |
MD5:— | SHA256:— | |||
| 3044 | Roblox Account Checker v2.0.0.exe | C:\Users\admin\AppData\Roaming\PrintBrmUi\data.exe | executable | |
MD5:— | SHA256:— | |||
| 3044 | Roblox Account Checker v2.0.0.exe | C:\Users\admin\AppData\Roaming\PrintBrmUi\bridgeres.vbs | text | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2516 | Roblox Account Checker v1.0.0.exe | CONNECT | — | 117.204.255.108:5678 | http://www.roblox.com:5678www.roblox.com:443 | IN | — | — | unknown |
2516 | Roblox Account Checker v1.0.0.exe | CONNECT | — | 102.223.221.180:5678 | http://www.roblox.com:5678www.roblox.com:443 | unknown | — | — | unknown |
2516 | Roblox Account Checker v1.0.0.exe | CONNECT | — | 190.4.8.194:5678 | http://www.roblox.com:5678www.roblox.com:443 | GT | — | — | unknown |
2516 | Roblox Account Checker v1.0.0.exe | CONNECT | — | 177.37.104.250:5678 | http://www.roblox.com:5678www.roblox.com:443 | BR | — | — | unknown |
2516 | Roblox Account Checker v1.0.0.exe | CONNECT | — | 190.4.8.194:5678 | http://www.roblox.com:5678www.roblox.com:443 | GT | — | — | unknown |
2516 | Roblox Account Checker v1.0.0.exe | CONNECT | — | 187.95.120.138:5678 | http://www.roblox.com:5678www.roblox.com:443 | BR | — | — | unknown |
2516 | Roblox Account Checker v1.0.0.exe | CONNECT | — | 117.204.255.108:5678 | http://www.roblox.com:5678www.roblox.com:443 | IN | — | — | unknown |
2516 | Roblox Account Checker v1.0.0.exe | CONNECT | — | 103.120.232.251:5678 | http://www.roblox.com:5678www.roblox.com:443 | unknown | — | — | unknown |
2516 | Roblox Account Checker v1.0.0.exe | CONNECT | — | 103.152.43.6:5678 | http://www.roblox.com:5678www.roblox.com:443 | unknown | — | — | unknown |
2516 | Roblox Account Checker v1.0.0.exe | CONNECT | — | 190.4.8.194:5678 | http://www.roblox.com:5678www.roblox.com:443 | GT | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2516 | Roblox Account Checker v1.0.0.exe | 190.4.8.194:5678 | — | METRORED S.A. DE C.V. | GT | unknown |
2516 | Roblox Account Checker v1.0.0.exe | 117.204.255.108:5678 | — | National Internet Backbone | IN | unknown |
2516 | Roblox Account Checker v1.0.0.exe | 42.113.38.187:5678 | — | The Corporation for Financing & Promoting Technology | VN | unknown |
2516 | Roblox Account Checker v1.0.0.exe | 176.74.118.133:5678 | — | System Net Ltd | GE | unknown |
2516 | Roblox Account Checker v1.0.0.exe | 102.223.221.180:5678 | — | — | — | unknown |
2516 | Roblox Account Checker v1.0.0.exe | 177.37.104.250:5678 | — | Indagraf Ltda | BR | unknown |
2516 | Roblox Account Checker v1.0.0.exe | 187.95.120.138:5678 | — | COPEL Telecomunicações S.A. | BR | unknown |
2516 | Roblox Account Checker v1.0.0.exe | 103.120.232.251:5678 | — | — | — | unknown |
2516 | Roblox Account Checker v1.0.0.exe | 41.220.136.38:5678 | — | Habari Node Ltd | TZ | unknown |
2516 | Roblox Account Checker v1.0.0.exe | 103.152.43.6:5678 | — | — | — | unknown |
Domain | IP | Reputation |
|---|---|---|
chrome.theworkpc.com |
| malicious |
redlan1.hopto.org |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
— | — | Potentially Bad Traffic | ET POLICY DNS Query to DynDNS Domain *.hopto .org |