File name:

AppNee.com.AMT.Emulator.v0.9.2.rar

Full analysis: https://app.any.run/tasks/d6653980-fb82-4515-8561-e8180990d9c4
Verdict: Malicious activity
Analysis date: September 02, 2018, 16:49:10
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

16273D81025FE1CCB018E81BEAFA5C2C

SHA1:

9FD5815D4CD354283D282B656641697BE4EA791F

SHA256:

314258BB8A334CE2B727652037F461566C1DCCB347BE655AC1C0304C1363A2A8

SSDEEP:

49152:kKDpEzBmyJ5jhrHjqoiwEvUxkNXY20QjktPNlUR467QH:BDGAchCPikNXYr2kt1C4CQH

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • amtemu.v0.9.2-painter.exe (PID: 3680)
      • amtemu.v0.9.2-painter.exe (PID: 3952)
    • Loads dropped or rewritten executable

      • amtemu.v0.9.2-painter.exe (PID: 3952)
      • SearchProtocolHost.exe (PID: 996)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • amtemu.v0.9.2-painter.exe (PID: 3952)
      • WinRAR.exe (PID: 1548)
  • INFO

    • Dropped object may contain URL's

      • WinRAR.exe (PID: 1548)
      • amtemu.v0.9.2-painter.exe (PID: 3952)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
41
Monitored processes
4
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start drop and start start winrar.exe amtemu.v0.9.2-painter.exe no specs amtemu.v0.9.2-painter.exe searchprotocolhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
996"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe12_ Global\UsGthrCtrlFltPipeMssGthrPipe12 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1548"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\AppNee.com.AMT.Emulator.v0.9.2.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3680"C:\Users\admin\AppData\Local\Temp\Rar$EXa1548.15198\AppNee.com.AMT.Emulator.v0.9.2\amtemu.v0.9.2-painter.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa1548.15198\AppNee.com.AMT.Emulator.v0.9.2\amtemu.v0.9.2-painter.exeWinRAR.exe
User:
admin
Company:
PainteR
Integrity Level:
MEDIUM
Description:
ProxyEmu
Exit code:
3221226540
Version:
0.9.2.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa1548.15198\appnee.com.amt.emulator.v0.9.2\amtemu.v0.9.2-painter.exe
c:\systemroot\system32\ntdll.dll
3952"C:\Users\admin\AppData\Local\Temp\Rar$EXa1548.15198\AppNee.com.AMT.Emulator.v0.9.2\amtemu.v0.9.2-painter.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa1548.15198\AppNee.com.AMT.Emulator.v0.9.2\amtemu.v0.9.2-painter.exe
WinRAR.exe
User:
admin
Company:
PainteR
Integrity Level:
HIGH
Description:
ProxyEmu
Exit code:
0
Version:
0.9.2.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa1548.15198\appnee.com.amt.emulator.v0.9.2\amtemu.v0.9.2-painter.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
Total events
1 059
Read events
967
Write events
91
Delete events
1

Modification events

(PID) Process:(1548) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1548) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1548) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\59\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1548) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\AppNee.com.AMT.Emulator.v0.9.2.rar
(PID) Process:(1548) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1548) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1548) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1548) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1548) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\59\52C64B7E
Operation:writeName:@C:\Windows\System32\ieframe.dll,-10046
Value:
Internet Shortcut
(PID) Process:(1548) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
Executable files
5
Suspicious files
0
Text files
12
Unknown types
0

Dropped files

PID
Process
Filename
Type
1548WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1548.15627\AppNee.com.AMT.Emulator.v0.9.2\amtlib.dll
MD5:
SHA256:
1548WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1548.15198\AppNee.com.AMT.Emulator.v0.9.2\Original source.urltext
MD5:
SHA256:
1548WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1548.15198\AppNee.com.AMT.Emulator.v0.9.2\Latest version.urltext
MD5:
SHA256:
1548WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1548.15198\AppNee.com.AMT.Emulator.v0.9.2\amtlib.dllexecutable
MD5:
SHA256:
3952amtemu.v0.9.2-painter.exeC:\Users\admin\Desktop\amtlib.dll.DELexecutable
MD5:
SHA256:
3952amtemu.v0.9.2-painter.exeC:\Users\admin\AppData\Local\Temp\spc_player.dllexecutable
MD5:41AFBF49BA7F6EE164F31FAA2CD38E15
SHA256:50D30B7AA7B9858F91F33165314C7CF7F2ACC97157091676C7E7925E018FD387
1548WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1548.15198\AppNee.com.AMT.Emulator.v0.9.2\changelog.txttext
MD5:24882987B223569D21F827A935E468B9
SHA256:CF271FDA61A832897F6770F2ABAC23B49CCFBE667889AAF6BD39A3B913D5671E
1548WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1548.15198\AppNee.com.AMT.Emulator.v0.9.2\amtemu.v0.9.2-painter.exeexecutable
MD5:8ABDC20F619641E29AA9AD2B999A0DCC
SHA256:CDC95D0113A2AF05C2E70FAB23F6C218AE583EBCB47077DD5B705A476F9D6B96
3952amtemu.v0.9.2-painter.exeC:\Users\admin\Desktop\amtlib.dllexecutable
MD5:219218AE29B2F9DFC8F6B745C004B1E3
SHA256:649F3B0148C4F8202B0C2D24A490A99523ACC0BD3245C08499162B94CA5D30A5
3952amtemu.v0.9.2-painter.exeC:\Users\admin\Desktop\painter.initext
MD5:4BE40389409CA2312CFBEA5790046261
SHA256:E1919072E9DA0C48F653571619FD0336CE5DC835624C739C10746581C675A54D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info