File name:

ETHCracker_@spectrix_official.zip

Full analysis: https://app.any.run/tasks/19eeff1d-ef85-4d6b-8ae9-2ca549c0c9f1
Verdict: Malicious activity
Analysis date: January 28, 2025, 15:35:40
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-exec
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

0F15C1347BDBE85190CB74A6C3C2B2A8

SHA1:

67AE37522DDAB19B2A8DD5C08D5E3F655489103A

SHA256:

3107A4339E79010F01F64017D45D0EFE1E30B2D106DF49F59F148B7132793483

SSDEEP:

98304:MsvQrw56Xq6jb74zv9EKhBlYvP7etcJrV9sY+0XCRkP2SxZTP4Ug+ZYr5k6HYBO1:297wvy0

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 4708)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 4708)
  • INFO

    • Manual execution by a user

      • ETHCracker.exe (PID: 6812)
      • cmd.exe (PID: 4592)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 4708)
    • Checks supported languages

      • SearchApp.exe (PID: 5064)
    • Reads the machine GUID from the registry

      • SearchApp.exe (PID: 5064)
    • Reads the software policy settings

      • SearchApp.exe (PID: 5064)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2021:10:23 05:21:20
ZipCRC: 0xf3756569
ZipCompressedSize: 28470
ZipUncompressedSize: 62064
ZipFileName: Microsoft.Extensions.Logging.Abstractions.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
138
Monitored processes
7
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe ethcracker.exe conhost.exe no specs cmd.exe no specs conhost.exe no specs ethcracker.exe searchapp.exe

Process information

PID
CMD
Path
Indicators
Parent process
4592"C:\WINDOWS\system32\cmd.exe" C:\Windows\System32\cmd.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\wldp.dll
4708"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\ETHCracker_@spectrix_official.zipC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
5064"C:\WINDOWS\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe" -ServerName:CortanaUI.AppX8z9r6jm96hw4bsbneegw0kyxx296wr9t.mcaC:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Search application
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\schannel.dll
c:\windows\system32\mskeyprotect.dll
c:\windows\system32\ntasn1.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptnet.dll
c:\windows\system32\webio.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\ncryptsslp.dll
c:\windows\systemapps\microsoft.windows.search_cw5n1h2txyewy\searchapp.exe
5544\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6616C:\Users\admin\Desktop\ETHCracker.exeC:\Users\admin\Desktop\ETHCracker.exe
cmd.exe
User:
admin
Company:
ETHCracker
Integrity Level:
MEDIUM
Description:
ETHCracker
Exit code:
2147516547
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\ethcracker.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
6812"C:\Users\admin\Desktop\ETHCracker.exe" C:\Users\admin\Desktop\ETHCracker.exe
explorer.exe
User:
admin
Company:
ETHCracker
Integrity Level:
MEDIUM
Description:
ETHCracker
Exit code:
2147516547
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\ethcracker.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
6860\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeETHCracker.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
6 933
Read events
6 844
Write events
86
Delete events
3

Modification events

(PID) Process:(4708) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(4708) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(4708) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(4708) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\ETHCracker_@spectrix_official.zip
(PID) Process:(4708) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(4708) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(4708) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(4708) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(4708) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:name
Value:
256
(PID) Process:(4708) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:size
Value:
80
Executable files
28
Suspicious files
50
Text files
13
Unknown types
0

Dropped files

PID
Process
Filename
Type
4708WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa4708.37924\Nethereum.JsonRpc.RpcClient.dllexecutable
MD5:9973165B0D94E08A4D57CDB61E766778
SHA256:442C1B5B269F72A48CD6C2A3CCD2A4079694C593E04DDA2B0A8991D56D7D0098
4708WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa4708.37924\Nethereum.ABI.dllexecutable
MD5:1694F03A866624294FAE11BFAA9A9715
SHA256:CD7DE8AAA8B8B31305EC2143C0A105B887C2AA9C40F39BFAF5899A3005BE6D36
4708WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa4708.37924\Microsoft.Extensions.Logging.Abstractions.dllexecutable
MD5:A2544F077D57C4EA44A4694EFCBEA30B
SHA256:D575C9D1543CA726CE14DBDFFD103E93EA527CD46BB28316DA1F4122DBC55D56
5064SearchApp.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache\MetaData\26C212D9399727259664BDFCA073966E_F9F7D6A7ECE73106D2A8C63168CDA10Dbinary
MD5:8975807B06E8781FEBD3644FE7618BFA
SHA256:B7E22AEB2B018431EE8E0F3AFD0751A3AF86EBBF4DB683C9350C5E856E5E8C02
4708WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa4708.37924\Nethereum.JsonRpc.Client.dllexecutable
MD5:0D60EE1ED5E62F8FB88E0AC81244CA13
SHA256:4879C86771D23E5F15A61AE85D80E5EA88F99BED365732E89A26E1A489B1CA21
4708WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa4708.37924\Nethereum.Hex.dllexecutable
MD5:9586D80A02A7A4FFF851CC3FB1F9BD60
SHA256:1308EAA3A1936099ADEBD0731B81DFE11E733831EA2448BBC31F21F92FD60229
4708WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa4708.37924\Nethereum.KeyStore.dllexecutable
MD5:B9A60BCC2DE0BC76227EC2D7014B2DFA
SHA256:F93DC1A6B52E0B2B583496B7CA534FB4712B36EB70DBED3C353385570A5C304C
4708WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa4708.37924\Nethereum.BlockchainProcessing.dllexecutable
MD5:042A2549E3B619D32B106D595263C127
SHA256:3BF96D4CEF868AF49DD37E2EDD201940052814374B986EBF44F262FF8DB91623
4708WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa4708.37924\Nethereum.HdWallet.dllexecutable
MD5:F606FB7FB31962BA21133F472979B97A
SHA256:5F5C1DC00DAF09CADE77A3D3AB5C963857C373003E8FA28026BA5329957FE30E
4708WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa4708.37924\Nethereum.Contracts.dllexecutable
MD5:7C9402F8DC57F36A5B6AEE8F78F3C32C
SHA256:43EAB7A99109C0C14643BFA497B701F64FA7B154EE59B10AB631161C269A6A73
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
38
DNS requests
18
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.48.23.138:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5064
SearchApp.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
1176
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6928
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6928
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
5064
SearchApp.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
5064
SearchApp.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA77flR%2B3w%2FxBpruV2lte6A%3D
unknown
whitelisted
6300
backgroundTaskHost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4712
MoUsoCoreWorker.exe
40.127.240.158:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
40.127.240.158:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
23.48.23.138:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:137
whitelisted
5064
SearchApp.exe
92.123.104.16:443
www.bing.com
Akamai International B.V.
DE
whitelisted
1076
svchost.exe
23.56.254.14:443
go.microsoft.com
Mobile Telecommunications Company
KW
whitelisted
1416
RUXIMICS.exe
40.127.240.158:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
1176
svchost.exe
40.126.32.74:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 216.58.206.78
whitelisted
crl.microsoft.com
  • 23.48.23.138
  • 23.48.23.137
  • 23.48.23.149
  • 23.48.23.157
  • 23.48.23.146
  • 23.48.23.162
  • 23.48.23.140
  • 23.48.23.153
  • 23.48.23.156
whitelisted
www.microsoft.com
  • 23.35.229.160
  • 184.30.21.171
whitelisted
www.bing.com
  • 92.123.104.16
  • 92.123.104.12
  • 92.123.104.21
  • 92.123.104.17
  • 92.123.104.14
  • 92.123.104.20
  • 92.123.104.18
  • 92.123.104.13
  • 92.123.104.5
whitelisted
go.microsoft.com
  • 23.56.254.14
whitelisted
login.live.com
  • 40.126.32.74
  • 40.126.32.140
  • 40.126.32.76
  • 20.190.160.22
  • 40.126.32.138
  • 40.126.32.133
  • 20.190.160.14
  • 40.126.32.136
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
slscr.update.microsoft.com
  • 52.149.20.212
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.242.39.171
whitelisted
fp.msedge.net
  • 204.79.197.222
whitelisted

Threats

No threats detected
Process
Message
ETHCracker.exe
You must install .NET to run this application. App: C:\Users\admin\Desktop\ETHCracker.exe Architecture: x64 App host version: 8.0.10 .NET location: Not found Learn more: https://aka.ms/dotnet/app-launch-failed Download the .NET runtime: https://aka.ms/dotnet-core-applaunch?missing_runtime=true&arch=x64&rid=win-x64&os=win10&apphost_version=8.0.10
ETHCracker.exe
You must install .NET to run this application. App: C:\Users\admin\Desktop\ETHCracker.exe Architecture: x64 App host version: 8.0.10 .NET location: Not found Learn more: https://aka.ms/dotnet/app-launch-failed Download the .NET runtime: https://aka.ms/dotnet-core-applaunch?missing_runtime=true&arch=x64&rid=win-x64&os=win10&apphost_version=8.0.10