File name:

Titan-Silent-Exploit-Builder-main.zip

Full analysis: https://app.any.run/tasks/8e157315-f266-4ff2-abce-662af9c7fe93
Verdict: Malicious activity
Analysis date: April 11, 2025, 15:13:51
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
auto
generic
arch-exec
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract, compression method=store
MD5:

E974BE81619C951B76EE66BE681C9C27

SHA1:

B232D7325BE5352311B603943DEEBE03FA46234E

SHA256:

2CACDCE553148F3C8BAA0BE7600FC2B9F8EA787E66E55CE637654153C0140C05

SSDEEP:

98304:iDfbAy8z+yLbDgY2RuHMPlBUvdwMTSbWxfDlxlpljup0snUPk5cYsD+yRPmMVTad:3823qpvH9wekukyETdI+Nzrb3C

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 7484)
    • GENERIC has been found (auto)

      • WinRAR.exe (PID: 7484)
  • SUSPICIOUS

    • There is functionality for taking screenshot (YARA)

      • dnmultiplayerex.exe (PID: 7216)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 7484)
    • Manual execution by a user

      • dnmultiplayerex.exe (PID: 7996)
      • dnmultiplayerex.exe (PID: 7216)
    • The sample compiled with english language support

      • WinRAR.exe (PID: 7484)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2025:03:21 21:40:20
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: Titan-Silent-Exploit-Builder-main/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
131
Monitored processes
5
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
4784C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
7216"C:\Users\admin\Desktop\Titan-Silent-Exploit-Builder-main\dnmultiplayerex.exe" C:\Users\admin\Desktop\Titan-Silent-Exploit-Builder-main\dnmultiplayerex.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\users\admin\desktop\titan-silent-exploit-builder-main\dnmultiplayerex.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
7484"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\Titan-Silent-Exploit-Builder-main.zipC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
7960C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
7996"C:\Users\admin\Desktop\Titan-Silent-Exploit-Builder-main\dnmultiplayerex.exe" C:\Users\admin\Desktop\Titan-Silent-Exploit-Builder-main\dnmultiplayerex.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221225781
Modules
Images
c:\users\admin\desktop\titan-silent-exploit-builder-main\dnmultiplayerex.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
Total events
1 780
Read events
1 761
Write events
19
Delete events
0

Modification events

(PID) Process:(7484) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(7484) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(7484) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(7484) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Titan-Silent-Exploit-Builder-main.zip
(PID) Process:(7484) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(7484) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(7484) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(7484) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(7484) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Comment
Operation:writeName:LeftBorder
Value:
472
(PID) Process:(7484) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF3D0000002D000000FD03000016020000
Executable files
6
Suspicious files
0
Text files
6
Unknown types
0

Dropped files

PID
Process
Filename
Type
7484WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa7484.26000\Titan-Silent-Exploit-Builder-main\dnresource.rcc
MD5:
SHA256:
7484WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa7484.26000\Titan-Silent-Exploit-Builder-main\App.configxml
MD5:E44B6F93C65C87159D701EE8821227EE
SHA256:543CB9FD5AD09E2F9148E6FFEAE10C58C73A6C640469AD9ED9475E586F8A2B52
7484WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa7484.26000\Titan-Silent-Exploit-Builder-main\dnmultiplayerex.exeexecutable
MD5:D375290F6DE6F685A741B674D9CCF9A2
SHA256:2B23A62EF89DF8F291E745754909211C8570A67DF6AA344ADBE73A690BC2848C
7484WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa7484.26000\Titan-Silent-Exploit-Builder-main\README.mdtext
MD5:C05F5B98210F9F091565E3003273AB8E
SHA256:D50E7EEB200C1917D6F4DB4EF874AF5B792394793CD5DC248D5D3425330F5D0B
7484WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa7484.26000\Titan-Silent-Exploit-Builder-main\Form1.Designer.vbtext
MD5:CEAD8AF3A03B4A46B375D947DA058BBD
SHA256:2EC29CDF5E8D6AD9706C785F93F495A0C32E9E38C9F81E87AA67898C8494CADF
7484WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa7484.26000\Titan-Silent-Exploit-Builder-main\Form1.vbtext
MD5:AA94E7E1ADD029AA760A0C1EAD96E4BB
SHA256:6EDDDD03E463A781CFB707CABE39C7C7BE3CF6CBC4E5CEE35780EE26BAFE0C1C
7484WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa7484.26000\Titan-Silent-Exploit-Builder-main\Form1.resxxml
MD5:4EB5913A0E5AA842250F7419538FA230
SHA256:4363CD7D5B8671C72442CE1A1BFC10D64EBD24B2D718B54BD4FCD025E4967298
7484WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa7484.26000\Titan-Silent-Exploit-Builder-main\cximagecrt.dllexecutable
MD5:66DF6F7B7A98FF750AADE522C22D239A
SHA256:91E3035A01437B54ADDA33D424060C57320504E7E6A0C85DB2654815BA29C71F
7484WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa7484.26000\Titan-Silent-Exploit-Builder-main\ILMerge Generator.vbprojxml
MD5:79AA91BA8412A79C3064B576D088D484
SHA256:B74A9CBE276EA8CF573E366B547EFE7A017F792293186F58CD5159A040AE4103
7484WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa7484.26000\Titan-Silent-Exploit-Builder-main\libcurl.dllexecutable
MD5:2D40F6C6A4F88C8C2685EE25B53EC00D
SHA256:1D7037DA4222DE3D7CA0AF6A54B2942D58589C264333EF814CB131D703B5C334
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
16
DNS requests
11
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
2.19.11.105:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
NL
binary
825 b
whitelisted
8132
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
DE
binary
407 b
whitelisted
8132
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
DE
binary
419 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2.19.11.105:80
crl.microsoft.com
Elisa Oyj
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
2104
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3216
svchost.exe
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
8132
SIHClient.exe
172.202.163.200:443
slscr.update.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
GB
whitelisted
8132
SIHClient.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
8132
SIHClient.exe
13.95.31.18:443
fe3cr.delivery.mp.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
7400
slui.exe
40.91.76.224:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 40.127.240.158
whitelisted
crl.microsoft.com
  • 2.19.11.105
  • 2.19.11.120
whitelisted
google.com
  • 216.58.212.142
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
slscr.update.microsoft.com
  • 172.202.163.200
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.95.31.18
whitelisted
activation-v2.sls.microsoft.com
  • 40.91.76.224
whitelisted

Threats

No threats detected
No debug info