File name:

NEW MULTITOOL.rar

Full analysis: https://app.any.run/tasks/55c15018-d393-486e-bc1e-6692c7688378
Verdict: Malicious activity
Analysis date: August 08, 2020, 18:42:03
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

5E7DC6833B224937516CA2C8BF4FA7BC

SHA1:

9FE86590FFECD2C565DD531A8011F27103BDBAAE

SHA256:

3BC57CFD9160F44F5C0DA3813A6591083569DCA7A8632C0ED699F14FACC5BF08

SSDEEP:

196608:ZmooVD/sFC/m3njVWvezX/fFsmxHDwDmfeGqVd/1Cs/XQ:6VD/sF/3zv9lxHMK2l38aA

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • MultiTool.exe (PID: 1496)
      • MultiTool.exe (PID: 2092)
    • Loads dropped or rewritten executable

      • MultiTool.exe (PID: 2092)
    • Actions looks like stealing of personal data

      • MultiTool.exe (PID: 2092)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2688)
      • MultiTool.exe (PID: 1496)
    • Application launched itself

      • MultiTool.exe (PID: 1496)
    • Loads Python modules

      • MultiTool.exe (PID: 2092)
    • Starts CMD.EXE for commands execution

      • MultiTool.exe (PID: 2092)
  • INFO

    • Manual execution by user

      • MultiTool.exe (PID: 1496)
    • Dropped object may contain Bitcoin addresses

      • MultiTool.exe (PID: 1496)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
45
Monitored processes
4
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe multitool.exe multitool.exe cmd.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1496"C:\Users\admin\Desktop\MultiTool.exe" C:\Users\admin\Desktop\MultiTool.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\multitool.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
2092"C:\Users\admin\Desktop\MultiTool.exe" C:\Users\admin\Desktop\MultiTool.exe
MultiTool.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\multitool.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
2508C:\Windows\system32\cmd.exe /c clsC:\Windows\system32\cmd.exeMultiTool.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2688"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\NEW MULTITOOL.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
Total events
696
Read events
434
Write events
262
Delete events
0

Modification events

(PID) Process:(2688) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2688) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2688) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\136\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2688) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\136\52C64B7E
Operation:writeName:@C:\Windows\system32\NetworkExplorer.dll,-1
Value:
Network
(PID) Process:(2688) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\NEW MULTITOOL.rar
(PID) Process:(2688) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2688) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2688) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2688) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2688) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\136\52C64B7E
Operation:writeName:@C:\Windows\system32\notepad.exe,-469
Value:
Text Document
Executable files
28
Suspicious files
6
Text files
920
Unknown types
3

Dropped files

PID
Process
Filename
Type
2688WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2688.49316\MultiTool.exeexecutable
MD5:
SHA256:
1496MultiTool.exeC:\Users\admin\AppData\Local\Temp\_MEI14962\Main.exe.manifestxml
MD5:
SHA256:
1496MultiTool.exeC:\Users\admin\AppData\Local\Temp\_MEI14962\_pytransform.dllexecutable
MD5:
SHA256:
1496MultiTool.exeC:\Users\admin\AppData\Local\Temp\_MEI14962\_asyncio.pydexecutable
MD5:A2FFF5C11F404D795E7D2B4907ED4485
SHA256:ED7830D504D726CE42B3B7A1321F39C8E29D1EBAD7B64632E45B712F0C47E189
1496MultiTool.exeC:\Users\admin\AppData\Local\Temp\_MEI14962\_lzma.pydexecutable
MD5:38C434AFB2A885A95999903977DC3624
SHA256:BFE6E288B2D93905F5CBB6D74E9C0FC37145B9225DB6D1F00C0F69EB45AFD051
1496MultiTool.exeC:\Users\admin\AppData\Local\Temp\_MEI14962\_ctypes.pydexecutable
MD5:C827A20FC5F1F4E0EF9431F29EBF03B4
SHA256:D500CFF28678ECED1FC4B3AEABECC0F3B30DE735FDEFE90855536BC29FC2CB4D
1496MultiTool.exeC:\Users\admin\AppData\Local\Temp\_MEI14962\_elementtree.pydexecutable
MD5:FA9381D1851DA8B8F61547013D8CC81E
SHA256:12147B8D57C9C4740D4AC23615F75FC62A2F41379B2BA0E159B9838819B1700A
1496MultiTool.exeC:\Users\admin\AppData\Local\Temp\_MEI14962\_multiprocessing.pydexecutable
MD5:7D3306BA4645463CB0D4C34C77B2BDF2
SHA256:3A183E0F6A31507C3B0ACBCAE5D6C3D843C590BB370DE5382E2DF9CFC2CB156E
1496MultiTool.exeC:\Users\admin\AppData\Local\Temp\_MEI14962\_overlapped.pydexecutable
MD5:09716BCE87ED2BF7E5A1F19952305E5C
SHA256:F4A27F4E242D788FCB1F5DD873608C72CDFC0799358364420ECEA1A7E52CC2B0
1496MultiTool.exeC:\Users\admin\AppData\Local\Temp\_MEI14962\_queue.pydexecutable
MD5:33A3AF108A41C487D6EB6FBC0BBF54DC
SHA256:E7859D57A449BA5D5E78BEF573D9FF4C68D3C9DF692A04737F0737B340D2B618
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
1
DNS requests
1
Threats
3

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2092
MultiTool.exe
54.235.182.194:443
api.ipify.org
Amazon.com, Inc.
US
suspicious

DNS requests

Domain
IP
Reputation
api.ipify.org
  • 54.235.182.194
  • 23.21.118.184
  • 107.22.251.25
  • 54.225.191.113
  • 54.225.195.221
  • 23.21.126.66
  • 54.221.234.156
  • 174.129.214.20
shared

Threats

PID
Process
Class
Message
2092
MultiTool.exe
Misc activity
SUSPICIOUS [PTsecurity] ipify.org External IP Check
2092
MultiTool.exe
Misc activity
SUSPICIOUS [PTsecurity] ipify.org External IP Check
1 ETPRO signatures available at the full report
No debug info