| File name: | Cs 2 SkinChanger.zip |
| Full analysis: | https://app.any.run/tasks/eff1a7b9-3d40-45fe-be48-356fcbc59c76 |
| Verdict: | Malicious activity |
| Threats: | RisePro, an information-stealing malware, targets a wide range of sensitive data, including credit cards, passwords, and cryptocurrency wallets. By compromising infected devices, RisePro can steal valuable information and potentially cause significant financial and personal losses for victims. |
| Analysis date: | December 04, 2023, 14:16:41 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v1.0 to extract |
| MD5: | 9EFA4D31D6BE7777F5C104B1C6DF7361 |
| SHA1: | 004DC09F364BC651EEE4C3A378CAE6772087119F |
| SHA256: | 33661CE27FB6A02156CF58124CC03F598B57A01E8AD102B8D5BD6DABD35BCE90 |
| SSDEEP: | 98304:ryWVnLNJnlvQ5kKIRLte0TEbu/SSQeQ6Lz6UfeHUa0Oarq45HqBWZZXBitfEkUwW:Kr3QaJSp5h0Yal/75L6XAziVbQW |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 10 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | None |
| ZipModifyDate: | 2023:10:14 16:07:04 |
| ZipCRC: | 0x00000000 |
| ZipCompressedSize: | - |
| ZipUncompressedSize: | - |
| ZipFileName: | Cs 2 SkinChanger/ |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 844 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Cs 2 SkinChanger.zip" | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 1036 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\New WinRAR archive.rar" | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 2072 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\New WinRAR ZIP archive.zip" | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 2332 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\New WinRAR archive.rar" | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 2608 | "C:\Windows\system32\cmd.exe" | C:\Windows\System32\cmd.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2920 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\New WinRAR ZIP archive.zip" | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 2968 | "C:\Windows\system32\taskmgr.exe" /4 | C:\Windows\System32\taskmgr.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Task Manager Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3272 | "C:\ProgramData\IEUpdater140\IEUpdater140.exe" | C:\ProgramData\IEUpdater140\IEUpdater140.exe | Loader.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
RisePro(PID) Process(3272) IEUpdater140.exe C246.4.10.254 | |||||||||||||||
| 3504 | schtasks /create /f /RU "admin" /tr "C:\ProgramData\IEUpdater140\IEUpdater140.exe" /tn "IEUpdater140 LG" /sc ONLOGON /rl HIGHEST | C:\Windows\System32\schtasks.exe | — | Loader.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Manages scheduled tasks Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3644 | "C:\Users\admin\Desktop\Cs 2 SkinChanger\Loader.exe" | C:\Users\admin\Desktop\Cs 2 SkinChanger\Loader.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221225477 Modules
| |||||||||||||||
| (PID) Process: | (844) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\17F\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (844) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (844) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (844) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (844) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (844) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (844) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (844) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (844) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin |
| Operation: | write | Name: | Placement |
Value: 2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000 | |||
| (PID) Process: | (844) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\General |
| Operation: | write | Name: | LastFolder |
Value: C:\Users\admin\Desktop | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 844 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb844.40742\Cs 2 SkinChanger\bin\UbuilderB.dll | executable | |
MD5:F474BAF2F922F8485752170CC261A72B | SHA256:2F9A39635D6A379577B073945477609C3AB3656C4ADC54A0D7CCE23C4432C04F | |||
| 844 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb844.40742\Cs 2 SkinChanger\user_data\media_cache\version | binary | |
MD5:4352D88A78AA39750BF70CD6F27BCAA5 | SHA256:67ABDD721024F0FF4E0B3F4C2FC13BC5BAD42D0B7851D456D88D203D15AAA450 | |||
| 844 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb844.40742\Cs 2 SkinChanger\user_data\cache\version | binary | |
MD5:4352D88A78AA39750BF70CD6F27BCAA5 | SHA256:67ABDD721024F0FF4E0B3F4C2FC13BC5BAD42D0B7851D456D88D203D15AAA450 | |||
| 844 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb844.40742\Cs 2 SkinChanger\Newtonsoft.Json.dll | executable | |
MD5:E80C8020943C2F7F0111C8DA77983FD6 | SHA256:0E650C2F4331A30DBD889E369BCDD43D98EE0243C4144A1540F973A6EDA3C9D2 | |||
| 844 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb844.40742\Cs 2 SkinChanger\xNet.dll | binary | |
MD5:E50D4C24DDFB38D5C8779346A9266D8D | SHA256:80B5B9A2A344BC99CFDA96E4EB87DED45484FA1E3C31FC6F4BC332F60923A398 | |||
| 844 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb844.40742\Cs 2 SkinChanger\bin\UbuilderS.dll | executable | |
MD5:8627FD537E892AFAE534C5E07F50B2C3 | SHA256:09F156B3D7D51DAD5A9DDD04F9685882A2D479E56DEDA6EAA0E58ECB19C19228 | |||
| 844 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb844.40742\Cs 2 SkinChanger\bin\scv.jar | text | |
MD5:8D94FB4EF8D7ABCB571F4A0C40BC8600 | SHA256:4C49A4774B4185035A923FA4585E5A9B469A4A1CEB115DA738C62D3D0EBF299E | |||
| 844 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb844.40742\Cs 2 SkinChanger\Engine.js | binary | |
MD5:EB4A75F6C414E46CE51637436B741174 | SHA256:3CA88C4E962A789FE31BB64676535D61C40A94A041818A7F4D96DDFFADD31D47 | |||
| 844 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb844.40742\Cs 2 SkinChanger\Loader.exe | executable | |
MD5:F2D782E84A6A93EBD435ACF8A151A98E | SHA256:D9E03030E712CF0AD4ADDC268FBDFD41EDE596D0E5925996165A0497A953B015 | |||
| 844 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb844.40742\Cs 2 SkinChanger\packages\key_datas | binary | |
MD5:6C08232CF95C26D8E452018BD8612AB0 | SHA256:88BA14B7F7929AEFC3F4EDC93D6D5EE4B990DF4E983FFE23458CFE3673ED8721 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
3644 | Loader.exe | 46.4.10.254:50500 | — | Hetzner Online GmbH | DE | malicious |
3644 | Loader.exe | 34.117.59.81:443 | ipinfo.io | GOOGLE-CLOUD-PLATFORM | US | whitelisted |
3644 | Loader.exe | 104.26.4.15:443 | db-ip.com | CLOUDFLARENET | US | unknown |
3272 | IEUpdater140.exe | 46.4.10.254:50500 | — | Hetzner Online GmbH | DE | malicious |
Domain | IP | Reputation |
|---|---|---|
ipinfo.io |
| shared |
db-ip.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
3644 | Loader.exe | Malware Command and Control Activity Detected | ET MALWARE [ANY.RUN] RisePro TCP (Token) |
3644 | Loader.exe | Malware Command and Control Activity Detected | STEALER [ANY.RUN] RisePro TCP (Token) |
3644 | Loader.exe | Malware Command and Control Activity Detected | ET MALWARE [ANY.RUN] RisePro TCP (External IP) |
3644 | Loader.exe | Malware Command and Control Activity Detected | STEALER [ANY.RUN] RisePro TCP (External IP Check) |
3644 | Loader.exe | A Network Trojan was detected | ET MALWARE Suspected RisePro TCP Heartbeat Packet |
3644 | Loader.exe | Device Retrieving External IP Address Detected | ET POLICY Possible External IP Lookup Domain Observed in SNI (ipinfo. io) |
3644 | Loader.exe | Malware Command and Control Activity Detected | STEALER [ANY.RUN] RisePro TCP (get_settings) |
3644 | Loader.exe | Malware Command and Control Activity Detected | ET MALWARE [ANY.RUN] RisePro TCP (Exfiltration) |
3644 | Loader.exe | Successful Credential Theft Detected | STEALER [ANY.RUN] RisePro TCP (exfiltration) |
3272 | IEUpdater140.exe | Malware Command and Control Activity Detected | ET MALWARE [ANY.RUN] RisePro TCP (Token) |