File name:

ETHCracker_@spectrix_official.zip

Full analysis: https://app.any.run/tasks/19eeff1d-ef85-4d6b-8ae9-2ca549c0c9f1
Verdict: Malicious activity
Analysis date: January 28, 2025, 15:35:40
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-exec
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

0F15C1347BDBE85190CB74A6C3C2B2A8

SHA1:

67AE37522DDAB19B2A8DD5C08D5E3F655489103A

SHA256:

3107A4339E79010F01F64017D45D0EFE1E30B2D106DF49F59F148B7132793483

SSDEEP:

98304:MsvQrw56Xq6jb74zv9EKhBlYvP7etcJrV9sY+0XCRkP2SxZTP4Ug+ZYr5k6HYBO1:297wvy0

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 4708)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 4708)
  • INFO

    • Reads the machine GUID from the registry

      • SearchApp.exe (PID: 5064)
    • Manual execution by a user

      • ETHCracker.exe (PID: 6812)
      • cmd.exe (PID: 4592)
    • Reads the software policy settings

      • SearchApp.exe (PID: 5064)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 4708)
    • Checks supported languages

      • SearchApp.exe (PID: 5064)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2021:10:23 05:21:20
ZipCRC: 0xf3756569
ZipCompressedSize: 28470
ZipUncompressedSize: 62064
ZipFileName: Microsoft.Extensions.Logging.Abstractions.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
138
Monitored processes
7
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe ethcracker.exe conhost.exe no specs cmd.exe no specs conhost.exe no specs ethcracker.exe searchapp.exe

Process information

PID
CMD
Path
Indicators
Parent process
4592"C:\WINDOWS\system32\cmd.exe" C:\Windows\System32\cmd.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\wldp.dll
4708"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\ETHCracker_@spectrix_official.zipC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
5064"C:\WINDOWS\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe" -ServerName:CortanaUI.AppX8z9r6jm96hw4bsbneegw0kyxx296wr9t.mcaC:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Search application
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\schannel.dll
c:\windows\system32\mskeyprotect.dll
c:\windows\system32\ntasn1.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptnet.dll
c:\windows\system32\webio.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\ncryptsslp.dll
c:\windows\systemapps\microsoft.windows.search_cw5n1h2txyewy\searchapp.exe
5544\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6616C:\Users\admin\Desktop\ETHCracker.exeC:\Users\admin\Desktop\ETHCracker.exe
cmd.exe
User:
admin
Company:
ETHCracker
Integrity Level:
MEDIUM
Description:
ETHCracker
Exit code:
2147516547
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\ethcracker.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
6812"C:\Users\admin\Desktop\ETHCracker.exe" C:\Users\admin\Desktop\ETHCracker.exe
explorer.exe
User:
admin
Company:
ETHCracker
Integrity Level:
MEDIUM
Description:
ETHCracker
Exit code:
2147516547
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\ethcracker.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
6860\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeETHCracker.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
6 933
Read events
6 844
Write events
86
Delete events
3

Modification events

(PID) Process:(4708) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(4708) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(4708) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(4708) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\ETHCracker_@spectrix_official.zip
(PID) Process:(4708) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(4708) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(4708) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(4708) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(4708) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:name
Value:
256
(PID) Process:(4708) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:size
Value:
80
Executable files
28
Suspicious files
50
Text files
13
Unknown types
0

Dropped files

PID
Process
Filename
Type
5064SearchApp.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache\Content\26C212D9399727259664BDFCA073966E_F9F7D6A7ECE73106D2A8C63168CDA10Dbinary
MD5:57C93B925A9E38B3EE20D073854CE89E
SHA256:305D0DA6032938A10441956EA5FA4251A4DA5ACDFE6E34CC76726384051556E4
4708WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa4708.37924\Microsoft.Extensions.Logging.Abstractions.dllexecutable
MD5:A2544F077D57C4EA44A4694EFCBEA30B
SHA256:D575C9D1543CA726CE14DBDFFD103E93EA527CD46BB28316DA1F4122DBC55D56
4708WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa4708.37924\Nethereum.BlockchainProcessing.dllexecutable
MD5:042A2549E3B619D32B106D595263C127
SHA256:3BF96D4CEF868AF49DD37E2EDD201940052814374B986EBF44F262FF8DB91623
4708WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa4708.37924\NBitcoin.dllexecutable
MD5:F435CD6B1D13863BD99FBB970787713A
SHA256:50FB6FD1EBB5F1D91C3E126801C88B8C04CDEC13ABC641B4F6679D9E23108040
4708WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa4708.37924\Nethereum.Contracts.dllexecutable
MD5:7C9402F8DC57F36A5B6AEE8F78F3C32C
SHA256:43EAB7A99109C0C14643BFA497B701F64FA7B154EE59B10AB631161C269A6A73
5064SearchApp.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache\MetaData\26C212D9399727259664BDFCA073966E_F9F7D6A7ECE73106D2A8C63168CDA10Dbinary
MD5:8975807B06E8781FEBD3644FE7618BFA
SHA256:B7E22AEB2B018431EE8E0F3AFD0751A3AF86EBBF4DB683C9350C5E856E5E8C02
4708WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa4708.37924\NBitcoin.Secp256k1.dllexecutable
MD5:9041929F588ACD4968253AF27E96C522
SHA256:05FD297A31A1C339A43D2EBAA395F9CEF8A7684571EE572BA462CF75F17A3B32
4708WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa4708.37924\Nethereum.JsonRpc.RpcClient.dllexecutable
MD5:9973165B0D94E08A4D57CDB61E766778
SHA256:442C1B5B269F72A48CD6C2A3CCD2A4079694C593E04DDA2B0A8991D56D7D0098
4708WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa4708.37924\Nethereum.RPC.dllexecutable
MD5:BFE61C71DF2E000E0DB9403A40EB4E9F
SHA256:600B195FF4D503200FC718634C0004B11B7FC62DEB500DF8AF8C2D2ECD436646
4708WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa4708.37924\Nethereum.Merkle.Patricia.dllexecutable
MD5:63C4A35C3650E26929BD9B29B8BE5D34
SHA256:05BB68F8DAFB03D0B65634AEC3DE19A5671B93102411DA027DF0021C82E2A51A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
38
DNS requests
18
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.48.23.138:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1176
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5064
SearchApp.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
6928
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6928
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
5064
SearchApp.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA77flR%2B3w%2FxBpruV2lte6A%3D
unknown
whitelisted
6300
backgroundTaskHost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
5064
SearchApp.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4712
MoUsoCoreWorker.exe
40.127.240.158:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
40.127.240.158:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
23.48.23.138:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:137
whitelisted
5064
SearchApp.exe
92.123.104.16:443
www.bing.com
Akamai International B.V.
DE
whitelisted
1076
svchost.exe
23.56.254.14:443
go.microsoft.com
Mobile Telecommunications Company
KW
whitelisted
1416
RUXIMICS.exe
40.127.240.158:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
1176
svchost.exe
40.126.32.74:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 216.58.206.78
whitelisted
crl.microsoft.com
  • 23.48.23.138
  • 23.48.23.137
  • 23.48.23.149
  • 23.48.23.157
  • 23.48.23.146
  • 23.48.23.162
  • 23.48.23.140
  • 23.48.23.153
  • 23.48.23.156
whitelisted
www.microsoft.com
  • 23.35.229.160
  • 184.30.21.171
whitelisted
www.bing.com
  • 92.123.104.16
  • 92.123.104.12
  • 92.123.104.21
  • 92.123.104.17
  • 92.123.104.14
  • 92.123.104.20
  • 92.123.104.18
  • 92.123.104.13
  • 92.123.104.5
whitelisted
go.microsoft.com
  • 23.56.254.14
whitelisted
login.live.com
  • 40.126.32.74
  • 40.126.32.140
  • 40.126.32.76
  • 20.190.160.22
  • 40.126.32.138
  • 40.126.32.133
  • 20.190.160.14
  • 40.126.32.136
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
slscr.update.microsoft.com
  • 52.149.20.212
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.242.39.171
whitelisted
fp.msedge.net
  • 204.79.197.222
whitelisted

Threats

No threats detected
Process
Message
ETHCracker.exe
You must install .NET to run this application. App: C:\Users\admin\Desktop\ETHCracker.exe Architecture: x64 App host version: 8.0.10 .NET location: Not found Learn more: https://aka.ms/dotnet/app-launch-failed Download the .NET runtime: https://aka.ms/dotnet-core-applaunch?missing_runtime=true&arch=x64&rid=win-x64&os=win10&apphost_version=8.0.10
ETHCracker.exe
You must install .NET to run this application. App: C:\Users\admin\Desktop\ETHCracker.exe Architecture: x64 App host version: 8.0.10 .NET location: Not found Learn more: https://aka.ms/dotnet/app-launch-failed Download the .NET runtime: https://aka.ms/dotnet-core-applaunch?missing_runtime=true&arch=x64&rid=win-x64&os=win10&apphost_version=8.0.10