| File name: | WebStressTester.rar |
| Full analysis: | https://app.any.run/tasks/aa29441e-89e3-4c98-a238-472a8683f7c7 |
| Verdict: | Malicious activity |
| Analysis date: | September 01, 2019, 07:54:30 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v4, os: Win32 |
| MD5: | C88C0AD28C709E03802C6E755D828ED4 |
| SHA1: | 1625B4FCD926CA9C0B77C4C37BB1DD3D118BB421 |
| SHA256: | 344CD75409EB7D6FEDF0D3ED2A6B7F2E1DFAD6834AE09F3BB487DB956C42AC31 |
| SSDEEP: | 24576:gqizA5yBr4ePkQsYUvBrbLnLXpskeEldWRhMfVa4PJeFe3AtK8rBUN3:zT5Mr9sYUvBLLqEldhfVpJcyAn0 |
| .rar | | | RAR compressed archive (v-4.x) (58.3) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (41.6) |
| CompressedSize: | 468443 |
|---|---|
| UncompressedSize: | 1199104 |
| OperatingSystem: | Win32 |
| ModifyDate: | 2011:04:28 11:19:06 |
| PackingMethod: | Normal |
| ArchivedFileName: | Web Stress Tester\libeay32.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1876 | "C:\Users\admin\AppData\Local\Temp\Rar$EXb2864.11580\Web Stress Tester\WebStressTester.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXb2864.11580\Web Stress Tester\WebStressTester.exe | WinRAR.exe | ||||||||||||
User: admin Company: Fastream Technologies Integrity Level: MEDIUM Description: Web Stress Tester Exit code: 0 Version: 4.0.0.0 Modules
| |||||||||||||||
| 2864 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\WebStressTester.rar" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 3872 | "C:\Users\admin\AppData\Local\Temp\Rar$EXb2864.8800\Web Stress Tester\WebStressTester.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXb2864.8800\Web Stress Tester\WebStressTester.exe | — | WinRAR.exe | |||||||||||
User: admin Company: Fastream Technologies Integrity Level: MEDIUM Description: Web Stress Tester Exit code: 0 Version: 4.0.0.0 Modules
| |||||||||||||||
| 3904 | "C:\Users\admin\AppData\Local\Temp\Rar$EXb2864.10792\Web Stress Tester\WebStressTester.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXb2864.10792\Web Stress Tester\WebStressTester.exe | — | WinRAR.exe | |||||||||||
User: admin Company: Fastream Technologies Integrity Level: MEDIUM Description: Web Stress Tester Exit code: 0 Version: 4.0.0.0 Modules
| |||||||||||||||
| (PID) Process: | (2864) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (2864) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (2864) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2864) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\WebStressTester.rar | |||
| (PID) Process: | (2864) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2864) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2864) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2864) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (2864) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E |
| Operation: | write | Name: | @C:\Windows\System32\ieframe.dll,-10046 |
Value: Internet Shortcut | |||
| (PID) Process: | (2864) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface |
| Operation: | write | Name: | ShowPassword |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2864 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb2864.8800\Web Stress Tester\WebStressTester.ini | text | |
MD5:— | SHA256:— | |||
| 2864 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb2864.8800\Web Stress Tester\MainUnit.cpp | text | |
MD5:E386B2C921EF60F73BBA08B81FEA0AE4 | SHA256:DB69B19EC52D4C99AAECD70F7F51C0795F3150C0B40302D1CFCADA493D0E3DDB | |||
| 2864 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb2864.8800\Web Stress Tester\pasall.drc | text | |
MD5:E68B01323D61AF6C706A822722D9F8F1 | SHA256:A4ED6B0A306FF8E0CB0CAC8536AD0F724AD540959C8AD6EAC14F42096BE1F94D | |||
| 2864 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb2864.8800\Web Stress Tester\ssleay32.dll | executable | |
MD5:184F9ECE573354A1DEF046DFBAB2CDEC | SHA256:515815D8DDF6D4A9E2815A1F20153C5D82FB94BBCD4D65F9E8D77ECDB8CD5E74 | |||
| 2864 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb2864.8800\Web Stress Tester\WebStressTester.cpp | text | |
MD5:DCFA3777954AF9EC5E87FDB504FD8973 | SHA256:CF03472014C71FCFE63148F517970D1E89F3608B0CB9A7A38083134786215A7D | |||
| 2864 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb2864.8800\Web Stress Tester\WebStressTester.cbproj.local | xml | |
MD5:0980CD829F3477ACC4F6B37503A8681C | SHA256:F1E2BBC08D5D1DDD1F477AE44F4CD5ED9F75A42651115DF7F2144287774AB15B | |||
| 2864 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb2864.8800\Web Stress Tester\WebStressTester.res | res | |
MD5:29F86E908E9D3D996C1BAD5DC6A500A9 | SHA256:13368C9B61676F003704213317FDFDA58D3E802E5FB986AAA49B00A38E7F2C00 | |||
| 2864 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb2864.8800\Web Stress Tester\__history\MainUnit.dfm.~1~ | text | |
MD5:4DC1EE9349240CB075E99EF3E1E579A1 | SHA256:6F5E3C3A89EEE241CDDBD06D9C7F572FC37007FCD1357F33741B6BEA9B28EEB1 | |||
| 2864 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb2864.8800\Web Stress Tester\MainUnit.h | text | |
MD5:78667D4318C8DBACAB1878181CFEE9A6 | SHA256:EED25A1101CD40915211E199849F61BFC966ED66219E1E29CEB1A69EEC369A1E | |||
| 2864 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb2864.8800\Web Stress Tester\TesterThreadUnit.cpp | text | |
MD5:06427EABD13C5E139FBCBAD506AF8B15 | SHA256:C069CDE9E8281C523A1872AFD6A7D3959FF3564FB8EF884DD62516E00BA2F066 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
1876 | WebStressTester.exe | 104.27.136.207:443 | faceit.ruprofiles.com | Cloudflare Inc | US | shared |
— | — | 104.27.136.207:443 | faceit.ruprofiles.com | Cloudflare Inc | US | shared |
Domain | IP | Reputation |
|---|---|---|
faceit.ruprofiles.com |
| unknown |