File name:

Sentry MBA Latest Version (1.4.1).rar

Full analysis: https://app.any.run/tasks/d50ead78-5f23-4d48-9af1-3d353485a7ec
Verdict: Malicious activity
Analysis date: November 15, 2018, 09:37:28
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
evasion
Indicators:
MIME: application/x-rar
File info: RAR archive data, v4, os: Win32
MD5:

0079563614C21A81C0C4DFDD45456A73

SHA1:

BEEEE21B1AA7FF598033B6A2985713F520FD12FA

SHA256:

2B4CA04990C758C00DF69C82E0D8C407C51C2B9333FDEA471D7B9253F7C4D3BC

SSDEEP:

393216:0ZwPi+FW5k/A2+yyMZwI1ixAx/ohz13FfHi2ADtvFqDo:0ZN+FeFP051iAx/opnHi2Axio

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Sentry_MBA.exe (PID: 2140)
  • SUSPICIOUS

    • Checks for external IP

      • Sentry_MBA.exe (PID: 2140)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2952)
  • INFO

    • Dropped object may contain Bitcoin addresses

      • WinRAR.exe (PID: 2952)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

CompressedSize: 1550
UncompressedSize: 2976
OperatingSystem: Win32
ModifyDate: 2011:10:24 02:12:26
PackingMethod: Normal
ArchivedFileName: Sentry MBA Latest Version (1.4.1)\Sentry MBA Latest Version (1.4.1)\FAQ.txt
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
38
Monitored processes
2
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe sentry_mba.exe

Process information

PID
CMD
Path
Indicators
Parent process
2140"C:\Users\admin\Desktop\Sentry MBA Latest Version (1.4.1)\Sentry MBA Latest Version (1.4.1)\Sentry_MBA.exe" C:\Users\admin\Desktop\Sentry MBA Latest Version (1.4.1)\Sentry MBA Latest Version (1.4.1)\Sentry_MBA.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
Sentry MBA
Exit code:
0
Version:
1.4.0.8701
Modules
Images
c:\users\admin\desktop\sentry mba latest version (1.4.1)\sentry mba latest version (1.4.1)\sentry_mba.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2952"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Sentry MBA Latest Version (1.4.1).rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
431
Read events
412
Write events
19
Delete events
0

Modification events

(PID) Process:(2952) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2952) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2952) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2952) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Sentry MBA Latest Version (1.4.1).rar
(PID) Process:(2952) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2952) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2952) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2952) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2952) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
(PID) Process:(2952) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\General
Operation:writeName:LastFolder
Value:
C:\Users\admin\AppData\Local\Temp
Executable files
3
Suspicious files
22
Text files
203
Unknown types
32

Dropped files

PID
Process
Filename
Type
2952WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2952.20760\Sentry MBA Latest Version (1.4.1)\Sentry MBA Latest Version (1.4.1)\ipfilter.dat
MD5:
SHA256:
2952WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2952.20760\Sentry MBA Latest Version (1.4.1)\Sentry MBA Latest Version (1.4.1)\MyList.initext
MD5:
SHA256:
2952WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2952.20760\Sentry MBA Latest Version (1.4.1)\Sentry MBA Latest Version (1.4.1)\Filters.initext
MD5:
SHA256:
2952WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2952.20760\Sentry MBA Latest Version (1.4.1)\Sentry MBA Latest Version (1.4.1)\History_Backup.initext
MD5:
SHA256:
2952WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2952.20760\Sentry MBA Latest Version (1.4.1)\Sentry MBA Latest Version (1.4.1)\History.initext
MD5:
SHA256:
2952WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2952.20760\Sentry MBA Latest Version (1.4.1)\Sentry MBA Latest Version (1.4.1)\Settings.initext
MD5:
SHA256:
2952WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2952.20760\Sentry MBA Latest Version (1.4.1)\Sentry MBA Latest Version (1.4.1)\Sites.initext
MD5:
SHA256:
2952WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2952.20760\Sentry MBA Latest Version (1.4.1)\Sentry MBA Latest Version (1.4.1)\Sources\AFQJAMMRPPFSMANTSSPH.htmlhtml
MD5:
SHA256:
2952WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2952.20760\Sentry MBA Latest Version (1.4.1)\Sentry MBA Latest Version (1.4.1)\Sources\AFQJAMMRPPFSMANTSSPH.txttext
MD5:
SHA256:
2952WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2952.20760\Sentry MBA Latest Version (1.4.1)\Sentry MBA Latest Version (1.4.1)\GlobalKeys.inihtml
MD5:5D1425C6D1468C88065D32F6290E9229
SHA256:9AF2A80849CABEA9E7089627A75CF14479624876008E8365F98C1CB78EFBF4C3
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
1
DNS requests
1
Threats
3

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2140
Sentry_MBA.exe
GET
200
162.88.100.200:80
http://checkip.dyndns.org/
US
html
105 b
shared
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2140
Sentry_MBA.exe
162.88.100.200:80
checkip.dyndns.org
Dynamic Network Services, Inc.
US
shared

DNS requests

Domain
IP
Reputation
checkip.dyndns.org
  • 162.88.100.200
  • 216.146.43.70
  • 162.88.96.194
  • 216.146.38.70
  • 216.146.43.71
shared

Threats

PID
Process
Class
Message
1056
svchost.exe
Misc activity
ET INFO DYNAMIC_DNS Query to *.dyndns. Domain
2140
Sentry_MBA.exe
Potential Corporate Privacy Violation
ET POLICY External IP Lookup - checkip.dyndns.org
2140
Sentry_MBA.exe
Potentially Bad Traffic
ET POLICY DynDNS CheckIp External IP Address Server Response
No debug info