| File name: | teste.cmd |
| Full analysis: | https://app.any.run/tasks/e36ab29e-c86f-4992-839a-94a6483e517b |
| Verdict: | Malicious activity |
| Threats: | A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection. |
| Analysis date: | November 16, 2023, 16:41:43 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | text/plain |
| File info: | ASCII text, with no line terminators |
| MD5: | BCBC96BD80948A0CDA2BEDAD08AFD764 |
| SHA1: | 910ABE88F22BE6C5A6B0B956BC1FA942D639A24E |
| SHA256: | 321A51AD12AABD83DEDFA07AFCB4719F21080041F2D04F1A04B64F152526A196 |
| SSDEEP: | 3:oXeFA8jHf2f1yfdVdvV3aBrKVKI5oxL:oXe6u841VKBUKN |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 148 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3400 --field-trial-handle=1104,i,16082196539108800498,5945266350040447983,131072 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 856 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3876 --field-trial-handle=1104,i,16082196539108800498,5945266350040447983,131072 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 1232 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3512 --field-trial-handle=1104,i,16082196539108800498,5945266350040447983,131072 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 1604 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --use-gl=angle --use-angle=swiftshader-webgl --mojo-platform-channel-handle=1256 --field-trial-handle=1104,i,16082196539108800498,5945266350040447983,131072 /prefetch:2 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 2096 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=quarantine.mojom.Quarantine --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=3856 --field-trial-handle=1104,i,16082196539108800498,5945266350040447983,131072 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 2328 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=3660 --field-trial-handle=1104,i,16082196539108800498,5945266350040447983,131072 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 2392 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=12 --mojo-platform-channel-handle=3736 --field-trial-handle=1104,i,16082196539108800498,5945266350040447983,131072 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 2400 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=2112 --field-trial-handle=1104,i,16082196539108800498,5945266350040447983,131072 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 2780 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2208 --field-trial-handle=1104,i,16082196539108800498,5945266350040447983,131072 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 2912 | C:\Windows\system32\msiexec.exe /V | C:\Windows\System32\msiexec.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (3500) wmpnscfg.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{67BAB3AD-54E7-48EC-9904-A878937B6070}\{8BF7F30A-3DEB-4548-81F5-C39F1287B0A1} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (3500) wmpnscfg.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{67BAB3AD-54E7-48EC-9904-A878937B6070} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (3500) wmpnscfg.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Health\{526E136E-7AC2-4B77-8B06-6434DC660AB8} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (3940) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
| (PID) Process: | (3940) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 1 | |||
| (PID) Process: | (3940) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: 01000000 | |||
| (PID) Process: | (3940) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon |
| Operation: | write | Name: | state |
Value: 2 | |||
| (PID) Process: | (3940) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} |
| Operation: | write | Name: | dr |
Value: 1 | |||
| (PID) Process: | (3940) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome\StabilityMetrics |
| Operation: | write | Name: | user_experience_metrics.stability.exited_cleanly |
Value: 1 | |||
| (PID) Process: | (3940) chrome.exe | Key: | HKEY_CURRENT_USER\Software\Google\Chrome |
| Operation: | write | Name: | UsageStatsInSample |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3940 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old~RF174c2c.TMP | — | |
MD5:— | SHA256:— | |||
| 3940 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 3940 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Last Version | text | |
MD5:9F941EA08DBDCA2EB3CFA1DBBBA6F5DC | SHA256:127F71DF0D2AD895D4F293E62284D85971AE047CA15F90B87BF6335898B0B655 | |||
| 3940 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOG.old~RF174d74.TMP | text | |
MD5:561161B0FF5BCA89BF47F8AC972A7499 | SHA256:ECCA5CCFA0BEED7581B39FCE03D0FD3B694DF0F92BFFF780F702118AD51FC17D | |||
| 3940 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOG.old | text | |
MD5:29B82603A20A26A3F99DB34525AF7448 | SHA256:9601A054A9C6AA6A65CEFAA229046476C1A089989FA6441DAD71D39F6794B980 | |||
| 3940 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\metadata\LOG.old | text | |
MD5:8268A4D53A6A9432A8266584CBD7D624 | SHA256:F785C42945CFE320C52C763837CD41541A8CAAB3E5FD567999EED5343CF0FD7A | |||
| 3940 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\metadata\LOG.old~RF174e20.TMP | text | |
MD5:7C1C23F006788D107F8A01B852CC6701 | SHA256:9FA4E627077EDCBEC8AAA1ED2DD5538E630790893F88F02F1E9CC863E6A27848 | |||
| 3940 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\coupon_db\LOG.old~RF174fa6.TMP | — | |
MD5:— | SHA256:— | |||
| 3940 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\coupon_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 3940 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\646458e8-3a27-41f2-93a5-444983153bec.tmp | binary | |
MD5:5058F1AF8388633F609CADB75A75DC9D | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2912 | msiexec.exe | GET | — | 134.209.227.14:8080 | http://5qw.pw:8080/t34d0RNDudN/admin-PC=admin | unknown | — | — | unknown |
2912 | msiexec.exe | GET | 200 | 134.209.227.14:8080 | http://5qw.pw:8080/t34d0RNDudN/admin-PC=admin | unknown | html | 1.63 Kb | unknown |
4064 | chrome.exe | GET | 200 | 134.209.227.14:8080 | http://5qw.pw:8080/t34d0RNDudN/admin-PC=admin | unknown | html | 1.63 Kb | unknown |
4064 | chrome.exe | GET | 200 | 134.209.227.14:8080 | http://5qw.pw:8080/favicon.ico | unknown | html | 1.63 Kb | unknown |
4064 | chrome.exe | GET | 200 | 134.209.227.14:8080 | http://5qw.pw:8080/t34d0RNDudN/admin-PC=admin | unknown | html | 1.63 Kb | unknown |
4064 | chrome.exe | GET | 200 | 134.209.227.14:8080 | http://5qw.pw:8080/t34d0RNDudN/admin-PC=admin | unknown | html | 1.63 Kb | unknown |
4064 | chrome.exe | GET | 200 | 134.209.227.14:8080 | http://5qw.pw:8080/favicon.ico | unknown | html | 1.63 Kb | unknown |
4064 | chrome.exe | GET | 200 | 134.209.227.14:8080 | http://5qw.pw:8080/favicon.ico | unknown | html | 1.63 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2912 | msiexec.exe | 134.209.227.14:8080 | 5qw.pw | DIGITALOCEAN-ASN | DE | unknown |
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
3940 | chrome.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4064 | chrome.exe | 142.250.186.131:443 | clientservices.googleapis.com | GOOGLE | US | whitelisted |
4064 | chrome.exe | 142.250.185.237:443 | accounts.google.com | GOOGLE | US | unknown |
4064 | chrome.exe | 172.217.18.4:443 | www.google.com | GOOGLE | US | whitelisted |
4064 | chrome.exe | 142.250.185.99:443 | www.gstatic.com | GOOGLE | US | whitelisted |
4064 | chrome.exe | 142.250.186.174:443 | apis.google.com | GOOGLE | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
5qw.pw |
| unknown |
clientservices.googleapis.com |
| whitelisted |
accounts.google.com |
| shared |
www.google.com |
| whitelisted |
www.gstatic.com |
| whitelisted |
apis.google.com |
| whitelisted |
update.googleapis.com |
| whitelisted |
_8080._https.5qw.pw |
| unknown |
upload.wikimedia.org |
| whitelisted |
www.kaspersky.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
1080 | svchost.exe | Potentially Bad Traffic | ET DNS Query to a *.pw domain - Likely Hostile |
1080 | svchost.exe | A Network Trojan was detected | ET MALWARE DNS Query to Raspberry Robin Domain (5qw .pw) |
2912 | msiexec.exe | A Network Trojan was detected | ET MALWARE Possible Raspberry Robin Activity (GET) |
2912 | msiexec.exe | Misc activity | ET INFO HTTP Request to a *.pw domain |
2912 | msiexec.exe | Potential Corporate Privacy Violation | ET HUNTING Suspicious Windows Installer UA for non-MSI |
2912 | msiexec.exe | A Network Trojan was detected | LOADER [ANY.RUN] RaspberryRobin/RRobin/Roshtyak |
2912 | msiexec.exe | A Network Trojan was detected | ET MALWARE Known Sinkhole Response Header |
4064 | chrome.exe | A Network Trojan was detected | ET MALWARE DNS Query to Raspberry Robin Domain (5qw .pw) |
4064 | chrome.exe | Potentially Bad Traffic | ET DNS Query to a *.pw domain - Likely Hostile |
4064 | chrome.exe | Potentially Bad Traffic | ET DNS Query to a *.pw domain - Likely Hostile |