File name:

Roblox Account Checker v2.0.0.rar

Full analysis: https://app.any.run/tasks/fbd20e51-fc79-4aa7-8a99-26c75566b2ce
Verdict: Malicious activity
Threats:

njRAT is a remote access trojan. It is one of the most widely accessible RATs on the market that features an abundance of educational information. Interested attackers can even find tutorials on YouTube. This allows it to become one of the most popular RATs in the world.

Analysis date: August 06, 2021, 09:56:31
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
rat
njrat
bladabindi
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

5172116B2A742D31A15434BA2170E848

SHA1:

0DD5D95FE5D13633FE3472AE28B7C0E426F07E50

SHA256:

26C2639964C45707EE91CBA9C11F5FBA37BEAADADD9CDC89CCA62CF1450B8E47

SSDEEP:

98304:SxiAqKgYTTeudNre3usr9vnEA/Q5002MdCnxM3toudm:SezYTCudNX2Z30zO

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Roblox Account Checker v2.0.0.exe (PID: 3788)
      • Roblox Account Checker v2.0.0.exe (PID: 3044)
      • Roblox Account Checker v1.0.0.exe (PID: 2516)
      • Roblox Account Checker v2.0.0.exe (PID: 3876)
      • Roblox Account Checker v2.0.0.exe (PID: 1136)
      • Roblox Account Checker v1.0.0.exe (PID: 2260)
    • Known privilege escalation attack

      • Roblox Account Checker v2.0.0.exe (PID: 3788)
      • Roblox Account Checker v2.0.0.exe (PID: 3876)
    • Writes to a start menu file

      • Roblox Account Checker v2.0.0.exe (PID: 3044)
    • NJRAT was detected

      • RegAsm.exe (PID: 2920)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3500)
      • Roblox Account Checker v2.0.0.exe (PID: 3044)
    • Reads the computer name

      • WinRAR.exe (PID: 3500)
      • Roblox Account Checker v2.0.0.exe (PID: 3788)
      • Roblox Account Checker v2.0.0.exe (PID: 3044)
      • Roblox Account Checker v1.0.0.exe (PID: 2516)
      • RegAsm.exe (PID: 2920)
      • Roblox Account Checker v2.0.0.exe (PID: 3876)
      • Roblox Account Checker v2.0.0.exe (PID: 1136)
      • Roblox Account Checker v1.0.0.exe (PID: 2260)
      • RegAsm.exe (PID: 1064)
    • Checks supported languages

      • WinRAR.exe (PID: 3500)
      • Roblox Account Checker v2.0.0.exe (PID: 3788)
      • Roblox Account Checker v2.0.0.exe (PID: 3044)
      • Roblox Account Checker v1.0.0.exe (PID: 2516)
      • RegAsm.exe (PID: 2920)
      • Roblox Account Checker v2.0.0.exe (PID: 3876)
      • Roblox Account Checker v2.0.0.exe (PID: 1136)
      • Roblox Account Checker v1.0.0.exe (PID: 2260)
      • RegAsm.exe (PID: 1064)
    • Reads mouse settings

      • Roblox Account Checker v2.0.0.exe (PID: 3788)
      • Roblox Account Checker v2.0.0.exe (PID: 3044)
      • Roblox Account Checker v2.0.0.exe (PID: 3876)
      • Roblox Account Checker v2.0.0.exe (PID: 1136)
    • Changes default file association

      • Roblox Account Checker v2.0.0.exe (PID: 3788)
      • Roblox Account Checker v2.0.0.exe (PID: 3876)
    • Uses NETSH.EXE for network configuration

      • RegAsm.exe (PID: 2920)
    • Reads Environment values

      • Roblox Account Checker v1.0.0.exe (PID: 2516)
      • RegAsm.exe (PID: 2920)
      • netsh.exe (PID: 3036)
      • Roblox Account Checker v1.0.0.exe (PID: 2260)
    • Creates files in the user directory

      • Roblox Account Checker v2.0.0.exe (PID: 3044)
  • INFO

    • Manual execution by user

      • Roblox Account Checker v2.0.0.exe (PID: 3788)
      • Roblox Account Checker v2.0.0.exe (PID: 3876)
    • Checks supported languages

      • eventvwr.exe (PID: 2612)
      • netsh.exe (PID: 3036)
      • eventvwr.exe (PID: 3864)
    • Reads the computer name

      • eventvwr.exe (PID: 2612)
      • netsh.exe (PID: 3036)
      • eventvwr.exe (PID: 3864)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
59
Monitored processes
14
Malicious processes
5
Suspicious processes
2

Behavior graph

Click at the process to see the details
start drop and start winrar.exe roblox account checker v2.0.0.exe no specs eventvwr.exe no specs eventvwr.exe roblox account checker v2.0.0.exe roblox account checker v1.0.0.exe #NJRAT regasm.exe no specs netsh.exe no specs roblox account checker v2.0.0.exe no specs eventvwr.exe no specs eventvwr.exe roblox account checker v2.0.0.exe no specs roblox account checker v1.0.0.exe regasm.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1064"C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe"C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exeRoblox Account Checker v2.0.0.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft .NET Assembly Registration Utility
Exit code:
0
Version:
2.0.50727.5483 (Win7SP1GDR.050727-5400)
Modules
Images
c:\windows\microsoft.net\framework\v2.0.50727\regasm.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
1136"C:\Users\admin\Desktop\Roblox Account Checker v2.0.0.exe" C:\Users\admin\Desktop\Roblox Account Checker v2.0.0.exeeventvwr.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\roblox account checker v2.0.0.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\version.dll
2260"C:\Users\admin\AppData\Local\Temp\Roblox Account Checker v1.0.0.exe" C:\Users\admin\AppData\Local\Temp\Roblox Account Checker v1.0.0.exe
Roblox Account Checker v2.0.0.exe
User:
admin
Company:
Microsoft
Integrity Level:
HIGH
Description:
Roblox Checker
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\roblox account checker v1.0.0.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
2516"C:\Users\admin\AppData\Local\Temp\Roblox Account Checker v1.0.0.exe" C:\Users\admin\AppData\Local\Temp\Roblox Account Checker v1.0.0.exe
Roblox Account Checker v2.0.0.exe
User:
admin
Company:
Microsoft
Integrity Level:
HIGH
Description:
Roblox Checker
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\roblox account checker v1.0.0.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shlwapi.dll
2608"C:\Windows\System32\eventvwr.exe" C:\Windows\System32\eventvwr.exeRoblox Account Checker v2.0.0.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Event Viewer Snapin Launcher
Exit code:
3221226540
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\eventvwr.exe
c:\windows\system32\ntdll.dll
2612"C:\Windows\System32\eventvwr.exe" C:\Windows\System32\eventvwr.exe
Roblox Account Checker v2.0.0.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Event Viewer Snapin Launcher
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\eventvwr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
2920"C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe"C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe
Roblox Account Checker v2.0.0.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft .NET Assembly Registration Utility
Exit code:
0
Version:
2.0.50727.5483 (Win7SP1GDR.050727-5400)
Modules
Images
c:\windows\microsoft.net\framework\v2.0.50727\regasm.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
3036netsh firewall add allowedprogram "C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe" "RegAsm.exe" ENABLEC:\Windows\system32\netsh.exeRegAsm.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Network Command Shell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\netsh.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\credui.dll
c:\windows\system32\user32.dll
3044"C:\Users\admin\Desktop\Roblox Account Checker v2.0.0.exe" C:\Users\admin\Desktop\Roblox Account Checker v2.0.0.exe
eventvwr.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\roblox account checker v2.0.0.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\nsi.dll
3500"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Roblox Account Checker v2.0.0.rar"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
8 833
Read events
8 467
Write events
353
Delete events
13

Modification events

(PID) Process:(3500) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3500) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3500) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3500) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(3500) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Roblox Account Checker v2.0.0.rar
(PID) Process:(3500) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3500) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3500) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3500) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3500) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:@C:\Windows\system32\notepad.exe,-469
Value:
Text Document
Executable files
3
Suspicious files
0
Text files
3
Unknown types
0

Dropped files

PID
Process
Filename
Type
3500WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3500.47194\200k UP UHQ MIXED.txt
MD5:
SHA256:
3500WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3500.47194\Roblox Account Checker v2.0.0.exeexecutable
MD5:
SHA256:
3044Roblox Account Checker v2.0.0.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\bridgeres.urltext
MD5:
SHA256:
3044Roblox Account Checker v2.0.0.exeC:\Users\admin\AppData\Local\Temp\Roblox Account Checker v1.0.0.exeexecutable
MD5:
SHA256:
3500WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3500.47194\10000 SOCKS4 WORKING (1).txttext
MD5:
SHA256:
3044Roblox Account Checker v2.0.0.exeC:\Users\admin\AppData\Roaming\PrintBrmUi\data.exeexecutable
MD5:
SHA256:
3044Roblox Account Checker v2.0.0.exeC:\Users\admin\AppData\Roaming\PrintBrmUi\bridgeres.vbstext
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
699
TCP/UDP connections
924
DNS requests
2
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2516
Roblox Account Checker v1.0.0.exe
CONNECT
117.204.255.108:5678
http://www.roblox.com:5678www.roblox.com:443
IN
unknown
2516
Roblox Account Checker v1.0.0.exe
CONNECT
102.223.221.180:5678
http://www.roblox.com:5678www.roblox.com:443
unknown
unknown
2516
Roblox Account Checker v1.0.0.exe
CONNECT
190.4.8.194:5678
http://www.roblox.com:5678www.roblox.com:443
GT
unknown
2516
Roblox Account Checker v1.0.0.exe
CONNECT
177.37.104.250:5678
http://www.roblox.com:5678www.roblox.com:443
BR
unknown
2516
Roblox Account Checker v1.0.0.exe
CONNECT
190.4.8.194:5678
http://www.roblox.com:5678www.roblox.com:443
GT
unknown
2516
Roblox Account Checker v1.0.0.exe
CONNECT
187.95.120.138:5678
http://www.roblox.com:5678www.roblox.com:443
BR
unknown
2516
Roblox Account Checker v1.0.0.exe
CONNECT
117.204.255.108:5678
http://www.roblox.com:5678www.roblox.com:443
IN
unknown
2516
Roblox Account Checker v1.0.0.exe
CONNECT
103.120.232.251:5678
http://www.roblox.com:5678www.roblox.com:443
unknown
unknown
2516
Roblox Account Checker v1.0.0.exe
CONNECT
103.152.43.6:5678
http://www.roblox.com:5678www.roblox.com:443
unknown
unknown
2516
Roblox Account Checker v1.0.0.exe
CONNECT
190.4.8.194:5678
http://www.roblox.com:5678www.roblox.com:443
GT
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2516
Roblox Account Checker v1.0.0.exe
190.4.8.194:5678
METRORED S.A. DE C.V.
GT
unknown
2516
Roblox Account Checker v1.0.0.exe
117.204.255.108:5678
National Internet Backbone
IN
unknown
2516
Roblox Account Checker v1.0.0.exe
42.113.38.187:5678
The Corporation for Financing & Promoting Technology
VN
unknown
2516
Roblox Account Checker v1.0.0.exe
176.74.118.133:5678
System Net Ltd
GE
unknown
2516
Roblox Account Checker v1.0.0.exe
102.223.221.180:5678
unknown
2516
Roblox Account Checker v1.0.0.exe
177.37.104.250:5678
Indagraf Ltda
BR
unknown
2516
Roblox Account Checker v1.0.0.exe
187.95.120.138:5678
COPEL Telecomunicações S.A.
BR
unknown
2516
Roblox Account Checker v1.0.0.exe
103.120.232.251:5678
unknown
2516
Roblox Account Checker v1.0.0.exe
41.220.136.38:5678
Habari Node Ltd
TZ
unknown
2516
Roblox Account Checker v1.0.0.exe
103.152.43.6:5678
unknown

DNS requests

Domain
IP
Reputation
chrome.theworkpc.com
malicious
redlan1.hopto.org
  • 0.0.0.0
unknown

Threats

PID
Process
Class
Message
Potentially Bad Traffic
ET POLICY DNS Query to DynDNS Domain *.hopto .org
No debug info