File name:

Downloads.tar.7z

Full analysis: https://app.any.run/tasks/6b9b7f4c-36dc-464c-8cdd-c7bb8602f607
Verdict: Malicious activity
Threats:

A keylogger is a type of spyware that infects a system and has the ability to record every keystroke made on the device. This lets attackers collect personal information of victims, which may include their online banking credentials, as well as personal conversations. The most widespread vector of attack leading to a keylogger infection begins with a phishing email or link. Keylogging is also often present in remote access trojans as part of an extended set of malicious tools.

Analysis date: February 23, 2024, 20:36:10
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
keylogger
remcos
Indicators:
MIME: application/x-7z-compressed
File info: 7-zip archive data, version 0.4
MD5:

C8D5691BC348BCBE277CA76F37270EA5

SHA1:

FB2502671F64F8122FCA2215ED791AA5D3CAF5F4

SHA256:

3ACD54958087E44ED35A83C4DD0625D1095ACADBD7A020B1744F5EC1B24EB937

SSDEEP:

1536:OejlSz4q7vcmkXnbd4L4qLcDyaBbAhQTnKbPPDY81ddqr:zocmcd5qLDaBbsQTKL91Kr

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 3656)
      • 2.exe (PID: 1572)
    • Changes the autorun value in the registry

      • 2.exe (PID: 1772)
      • 2.exe (PID: 1572)
    • REMCOS has been detected (YARA)

      • 2.exe (PID: 3980)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 3656)
      • WinRAR.exe (PID: 3228)
      • 2.exe (PID: 1572)
    • Starts a Microsoft application from unusual location

      • 2.exe (PID: 1572)
      • 2.exe (PID: 1772)
      • 2.exe (PID: 1544)
      • 2.exe (PID: 3980)
    • Reads settings of System Certificates

      • 2.exe (PID: 1772)
      • 2.exe (PID: 1572)
    • Reads the Internet Settings

      • 2.exe (PID: 1772)
      • 2.exe (PID: 1572)
    • Application launched itself

      • 2.exe (PID: 1572)
      • 2.exe (PID: 1772)
    • Writes files like Keylogger logs

      • 2.exe (PID: 3980)
    • Executable content was dropped or overwritten

      • 2.exe (PID: 1572)
    • Connects to unusual port

      • 2.exe (PID: 3980)
  • INFO

    • Checks supported languages

      • wmpnscfg.exe (PID: 2472)
      • 2.exe (PID: 1772)
      • 2.exe (PID: 1572)
      • 2.exe (PID: 3980)
      • 2.exe (PID: 1544)
    • Reads the computer name

      • wmpnscfg.exe (PID: 2472)
      • 2.exe (PID: 1772)
      • 2.exe (PID: 1572)
      • 2.exe (PID: 3980)
    • Manual execution by a user

      • WinRAR.exe (PID: 3228)
      • rundll32.exe (PID: 3992)
      • rundll32.exe (PID: 3092)
      • rundll32.exe (PID: 2756)
      • 2.exe (PID: 1572)
      • 2.exe (PID: 1772)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3228)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 3228)
    • Reads the software policy settings

      • 2.exe (PID: 1772)
      • 2.exe (PID: 1572)
    • Reads the machine GUID from the registry

      • 2.exe (PID: 1772)
      • 2.exe (PID: 1572)
    • Reads Environment values

      • 2.exe (PID: 1772)
      • 2.exe (PID: 1572)
      • 2.exe (PID: 3980)
    • Reads product name

      • 2.exe (PID: 3980)
    • Creates files in the program directory

      • 2.exe (PID: 3980)
    • Creates files or folders in the user directory

      • 2.exe (PID: 1572)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Remcos

(PID) Process(3980) 2.exe
C2 (2)74.119.194.217:2707
dianimpuesto.con-ip.com:2707
BotnetVenePure1
Options
Connect_interval1
Install_flagFalse
Install_HKCU\RunTrue
Install_HKLM\RunTrue
Install_HKLM\Explorer\Run1
Install_HKLM\Winlogon\Shell0
Setup_path%LOCALAPPDATA%
Copy_fileremcos.exe
Startup_valueTrue
Hide_fileFalse
Mutex_nameRc2sjd1hj8471-4YCMCR
Keylog_flag1
Keylog_path%LOCALAPPDATA%
Keylog_filelogs.dat
Keylog_cryptFalse
Hide_keylogTrue
Screenshot_flagFalse
Screenshot_time5
Take_ScreenshotFalse
Screenshot_path%APPDATA%
Screenshot_fileScreenshots
Screenshot_cryptFalse
Mouse_optionFalse
Delete_fileFalse
Audio_record_time5
Audio_path%ProgramFiles%
Audio_dirMicRecords
Connect_delay0
Copy_dirRemcos
Keylog_diroysccss
No Malware configuration.

TRiD

.7z | 7-Zip compressed archive (v0.4) (57.1)
.7z | 7-Zip compressed archive (gen) (42.8)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
53
Monitored processes
10
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs winrar.exe rundll32.exe no specs rundll32.exe no specs rundll32.exe no specs 2.exe 2.exe #REMCOS 2.exe 2.exe no specs wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1544C:\Users\admin\Desktop\2.exeC:\Users\admin\Desktop\2.exe2.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Instalador de paquetes de idioma
Exit code:
2
Version:
6.2.22621.1
Modules
Images
c:\users\admin\desktop\2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1572"C:\Users\admin\Desktop\2.exe" C:\Users\admin\Desktop\2.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Instalador de paquetes de idioma
Exit code:
0
Version:
6.2.22621.1
Modules
Images
c:\users\admin\desktop\2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1772"C:\Users\admin\Desktop\2.exe" C:\Users\admin\Desktop\2.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Instalador de paquetes de idioma
Exit code:
0
Version:
6.2.22621.1
Modules
Images
c:\users\admin\desktop\2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2472"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2756"C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\Desktop\PROCESO LEGAL NOTIFICACION FISCAL.exe (2)C:\Windows\System32\rundll32.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
3092"C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\Desktop\PROCESO LEGAL NOTIFICACION FISCAL.exe (2)C:\Windows\System32\rundll32.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
3228"C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Desktop\Downloads.tar" C:\Users\admin\Desktop\C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3656"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Downloads.tar.7z"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3980C:\Users\admin\Desktop\2.exeC:\Users\admin\Desktop\2.exe
2.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Instalador de paquetes de idioma
Exit code:
0
Version:
6.2.22621.1
Modules
Images
c:\users\admin\desktop\2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
Remcos
(PID) Process(3980) 2.exe
C2 (2)74.119.194.217:2707
dianimpuesto.con-ip.com:2707
BotnetVenePure1
Options
Connect_interval1
Install_flagFalse
Install_HKCU\RunTrue
Install_HKLM\RunTrue
Install_HKLM\Explorer\Run1
Install_HKLM\Winlogon\Shell0
Setup_path%LOCALAPPDATA%
Copy_fileremcos.exe
Startup_valueTrue
Hide_fileFalse
Mutex_nameRc2sjd1hj8471-4YCMCR
Keylog_flag1
Keylog_path%LOCALAPPDATA%
Keylog_filelogs.dat
Keylog_cryptFalse
Hide_keylogTrue
Screenshot_flagFalse
Screenshot_time5
Take_ScreenshotFalse
Screenshot_path%APPDATA%
Screenshot_fileScreenshots
Screenshot_cryptFalse
Mouse_optionFalse
Delete_fileFalse
Audio_record_time5
Audio_path%ProgramFiles%
Audio_dirMicRecords
Connect_delay0
Copy_dirRemcos
Keylog_diroysccss
3992"C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\Desktop\PROCESO LEGAL NOTIFICACION FISCAL.exe (2)C:\Windows\System32\rundll32.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
Total events
13 228
Read events
13 131
Write events
94
Delete events
3

Modification events

(PID) Process:(3656) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3656) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3656) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3656) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3656) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3656) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(3656) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Downloads.tar.7z
(PID) Process:(3656) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3656) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3656) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
2
Suspicious files
1
Text files
1
Unknown types
1

Dropped files

PID
Process
Filename
Type
39802.exeC:\ProgramData\oysccss\logs.datbinary
MD5:19390185B96AC1956508E105587B84DF
SHA256:A691958C436B7CCC83C86C6E03076AEF237C04E7700A9E4F89E5B7A369897AD8
3228WinRAR.exeC:\Users\admin\Desktop\PROCESO LEGAL NOTIFICACION FISCAL.exe (2)executable
MD5:BB254CD0460BFE67260CCAEDD1419DDC
SHA256:AD211F29A77CEE6D453A58567822508D4FAEB2996789119515198EB70ED42F14
3656WinRAR.exeC:\Users\admin\Desktop\Downloads.tarcompressed
MD5:BA8F2413004A9435B99543C09613FBEB
SHA256:453C504BDBE095F4D84BCF348D6AF44000385E48CAA62A35645A0CF4712543E1
15722.exeC:\Users\admin\AppData\Roaming\Srlxqvdcthett.exeexecutable
MD5:BB254CD0460BFE67260CCAEDD1419DDC
SHA256:AD211F29A77CEE6D453A58567822508D4FAEB2996789119515198EB70ED42F14
3228WinRAR.exeC:\Users\admin\Desktop\JUZGADO PERTINENTE USTED HA SIDO NOTIFICACO POR UN PROCESO EN SU CONTRA.vbstext
MD5:3251CA0D8DE6DF2BD2A20EDF37D679CE
SHA256:52C99DD18DC42325AA4C6EDD603E424C1CE186F67E59F9548C4888411A01DDC2
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
140
DNS requests
2
Threats
4

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
1572
2.exe
145.14.144.49:443
laorejadebangogohhhhh.000webhostapp.com
Hostinger International Limited
NL
shared
1772
2.exe
145.14.144.49:443
laorejadebangogohhhhh.000webhostapp.com
Hostinger International Limited
NL
shared
3980
2.exe
74.119.194.217:2707
dianimpuesto.con-ip.com
MIRholding B.V.
US
malicious

DNS requests

Domain
IP
Reputation
laorejadebangogohhhhh.000webhostapp.com
  • 145.14.144.49
unknown
dianimpuesto.con-ip.com
  • 74.119.194.217
malicious

Threats

PID
Process
Class
Message
1080
svchost.exe
Not Suspicious Traffic
ET INFO Observed Free Hosting Domain (*.000webhostapp .com in DNS Lookup)
1572
2.exe
Not Suspicious Traffic
ET INFO Observed SSL Cert for Free Hosting Domain (*.000webhostapp .com)
1772
2.exe
Not Suspicious Traffic
ET INFO Observed SSL Cert for Free Hosting Domain (*.000webhostapp .com)
1080
svchost.exe
Potentially Bad Traffic
ET INFO DNS Redirection Service Domain in DNS Lookup (con-ip .com)
No debug info