| File name: | WebStressTester.rar |
| Full analysis: | https://app.any.run/tasks/aa29441e-89e3-4c98-a238-472a8683f7c7 |
| Verdict: | Malicious activity |
| Analysis date: | September 01, 2019, 07:54:30 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v4, os: Win32 |
| MD5: | C88C0AD28C709E03802C6E755D828ED4 |
| SHA1: | 1625B4FCD926CA9C0B77C4C37BB1DD3D118BB421 |
| SHA256: | 344CD75409EB7D6FEDF0D3ED2A6B7F2E1DFAD6834AE09F3BB487DB956C42AC31 |
| SSDEEP: | 24576:gqizA5yBr4ePkQsYUvBrbLnLXpskeEldWRhMfVa4PJeFe3AtK8rBUN3:zT5Mr9sYUvBLLqEldhfVpJcyAn0 |
| .rar | | | RAR compressed archive (v-4.x) (58.3) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (41.6) |
| CompressedSize: | 468443 |
|---|---|
| UncompressedSize: | 1199104 |
| OperatingSystem: | Win32 |
| ModifyDate: | 2011:04:28 11:19:06 |
| PackingMethod: | Normal |
| ArchivedFileName: | Web Stress Tester\libeay32.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1876 | "C:\Users\admin\AppData\Local\Temp\Rar$EXb2864.11580\Web Stress Tester\WebStressTester.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXb2864.11580\Web Stress Tester\WebStressTester.exe | WinRAR.exe | ||||||||||||
User: admin Company: Fastream Technologies Integrity Level: MEDIUM Description: Web Stress Tester Exit code: 0 Version: 4.0.0.0 Modules
| |||||||||||||||
| 2864 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\WebStressTester.rar" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 3872 | "C:\Users\admin\AppData\Local\Temp\Rar$EXb2864.8800\Web Stress Tester\WebStressTester.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXb2864.8800\Web Stress Tester\WebStressTester.exe | — | WinRAR.exe | |||||||||||
User: admin Company: Fastream Technologies Integrity Level: MEDIUM Description: Web Stress Tester Exit code: 0 Version: 4.0.0.0 Modules
| |||||||||||||||
| 3904 | "C:\Users\admin\AppData\Local\Temp\Rar$EXb2864.10792\Web Stress Tester\WebStressTester.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXb2864.10792\Web Stress Tester\WebStressTester.exe | — | WinRAR.exe | |||||||||||
User: admin Company: Fastream Technologies Integrity Level: MEDIUM Description: Web Stress Tester Exit code: 0 Version: 4.0.0.0 Modules
| |||||||||||||||
| (PID) Process: | (2864) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (2864) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (2864) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2864) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\WebStressTester.rar | |||
| (PID) Process: | (2864) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2864) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2864) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2864) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (2864) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E |
| Operation: | write | Name: | @C:\Windows\System32\ieframe.dll,-10046 |
Value: Internet Shortcut | |||
| (PID) Process: | (2864) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface |
| Operation: | write | Name: | ShowPassword |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2864 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb2864.8800\Web Stress Tester\WebStressTester.ini | text | |
MD5:— | SHA256:— | |||
| 2864 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb2864.8800\Web Stress Tester\MainUnit.h | text | |
MD5:78667D4318C8DBACAB1878181CFEE9A6 | SHA256:EED25A1101CD40915211E199849F61BFC966ED66219E1E29CEB1A69EEC369A1E | |||
| 2864 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb2864.8800\Web Stress Tester\pasall.drc | text | |
MD5:E68B01323D61AF6C706A822722D9F8F1 | SHA256:A4ED6B0A306FF8E0CB0CAC8536AD0F724AD540959C8AD6EAC14F42096BE1F94D | |||
| 2864 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb2864.8800\Web Stress Tester\MainUnit.dfm | text | |
MD5:D1509A95155AEB7B315C4F09E19750A7 | SHA256:E99B715AE50287FA6B7D2FA45FE27D71690E83475B4EFE44B3FBE8B3AD2ADB03 | |||
| 2864 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb2864.8800\Web Stress Tester\TesterThreadUnit.cpp | text | |
MD5:06427EABD13C5E139FBCBAD506AF8B15 | SHA256:C069CDE9E8281C523A1872AFD6A7D3959FF3564FB8EF884DD62516E00BA2F066 | |||
| 2864 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb2864.8800\Web Stress Tester\WebStressTester.bdsproj | xml | |
MD5:E8D08B0BB691AE804FA3E94599B9A74A | SHA256:4FE57D4B248FED71ECC13202F57F3F58E7200169368F1692893FD1131B265AA1 | |||
| 2864 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb2864.8800\Web Stress Tester\WebStressTester.drc | text | |
MD5:A9005185EF5E98721C273EBCB6940658 | SHA256:4D2520B4F9C7A3F371CAF38EFB043207F29EA63AE655AC1C0AE408DD866B97D4 | |||
| 2864 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb2864.8800\Web Stress Tester\WebStressTester.cpp | text | |
MD5:DCFA3777954AF9EC5E87FDB504FD8973 | SHA256:CF03472014C71FCFE63148F517970D1E89F3608B0CB9A7A38083134786215A7D | |||
| 2864 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb2864.8800\Web Stress Tester\ssleay32.dll | executable | |
MD5:184F9ECE573354A1DEF046DFBAB2CDEC | SHA256:515815D8DDF6D4A9E2815A1F20153C5D82FB94BBCD4D65F9E8D77ECDB8CD5E74 | |||
| 2864 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb2864.8800\Web Stress Tester\WebStressTester.bdsproj.local | xml | |
MD5:7D3E1AC49EE4106A8BC817C27A60E0A8 | SHA256:BE97126E3EAF9D0794438C3457F067BC5A183E6A384341938BADDFB75FCFABD8 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
1876 | WebStressTester.exe | 104.27.136.207:443 | faceit.ruprofiles.com | Cloudflare Inc | US | shared |
— | — | 104.27.136.207:443 | faceit.ruprofiles.com | Cloudflare Inc | US | shared |
Domain | IP | Reputation |
|---|---|---|
faceit.ruprofiles.com |
| unknown |