File name:

CK - Multihack Control Panel 0.4.0.rar

Full analysis: https://app.any.run/tasks/e64926e7-5986-4d7d-9f5e-ace5e2ff0483
Verdict: Malicious activity
Analysis date: February 09, 2022, 11:11:54
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

BA846369D867E993DAF5B72B2D23ABC9

SHA1:

9A1A406FF9CEA6A34EAE0BC7994B93986B40EC74

SHA256:

3D312E4F21286BBA1FC2126FCD77DCE68032B22C4C4FBA375D458C6CE5E20F7C

SSDEEP:

98304:Ic0jcpITDcXxhM76kYxcg9WM6RsawkA6JDIl:IEmkX99Zpa5A6Jm

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 3776)
    • Application was dropped or rewritten from another process

      • Installer.exe (PID: 3300)
      • Installer.exe (PID: 2588)
  • SUSPICIOUS

    • Drops a file with a compile date too recent

      • WinRAR.exe (PID: 3624)
    • Reads the computer name

      • WinRAR.exe (PID: 3624)
      • Installer.exe (PID: 3300)
      • powershell.exe (PID: 3636)
      • Installer.exe (PID: 2588)
      • powershell.exe (PID: 2580)
    • Checks supported languages

      • WinRAR.exe (PID: 3624)
      • Installer.exe (PID: 3300)
      • powershell.exe (PID: 3636)
      • cmd.exe (PID: 1008)
      • Installer.exe (PID: 2588)
      • powershell.exe (PID: 2580)
      • cmd.exe (PID: 3296)
    • Drops a file with too old compile date

      • WinRAR.exe (PID: 3624)
    • Drops a file that was compiled in debug mode

      • WinRAR.exe (PID: 3624)
    • Executes PowerShell scripts

      • Installer.exe (PID: 3300)
      • Installer.exe (PID: 2588)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3624)
    • Starts CMD.EXE for commands execution

      • powershell.exe (PID: 3636)
      • powershell.exe (PID: 2580)
  • INFO

    • Manual execution by user

      • Installer.exe (PID: 3300)
      • NOTEPAD.EXE (PID: 2876)
      • Installer.exe (PID: 2588)
    • Checks Windows Trust Settings

      • powershell.exe (PID: 3636)
      • powershell.exe (PID: 2580)
    • Checks supported languages

      • timeout.exe (PID: 1652)
      • NOTEPAD.EXE (PID: 2876)
      • timeout.exe (PID: 3140)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
51
Monitored processes
11
Malicious processes
4
Suspicious processes
2

Behavior graph

Click at the process to see the details
start winrar.exe searchprotocolhost.exe no specs installer.exe powershell.exe no specs cmd.exe no specs timeout.exe no specs notepad.exe no specs installer.exe powershell.exe no specs cmd.exe no specs timeout.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1008"C:\Windows\system32\cmd.exe" /C timeout 22C:\Windows\system32\cmd.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1652timeout 22C:\Windows\system32\timeout.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
timeout - pauses command processing
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\timeout.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ws2_32.dll
2580"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -enc YwBtAGQAIAAvAEMAIAB0AGkAbQBlAG8AdQB0ACAAMgAyAA==C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeInstaller.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows PowerShell
Exit code:
0
Version:
10.0.14409.1005 (rs1_srvoob.161208-1155)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\atl.dll
c:\windows\system32\user32.dll
2588"C:\Users\admin\Desktop\CK - Multihack Control Panel 0.4.0\Installer.exe" C:\Users\admin\Desktop\CK - Multihack Control Panel 0.4.0\Installer.exe
Explorer.EXE
User:
admin
Integrity Level:
HIGH
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\ck - multihack control panel 0.4.0\installer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2876"C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\CK - Multihack Control Panel 0.4.0\How to use.txtC:\Windows\system32\NOTEPAD.EXEExplorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\user32.dll
3140timeout 22C:\Windows\system32\timeout.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
timeout - pauses command processing
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\timeout.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
3296"C:\Windows\system32\cmd.exe" /C timeout 22C:\Windows\system32\cmd.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
3300"C:\Users\admin\Desktop\CK - Multihack Control Panel 0.4.0\Installer.exe" C:\Users\admin\Desktop\CK - Multihack Control Panel 0.4.0\Installer.exe
Explorer.EXE
User:
admin
Integrity Level:
MEDIUM
Exit code:
3762504530
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\ck - multihack control panel 0.4.0\installer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3624"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\CK - Multihack Control Panel 0.4.0.rar"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
3636"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -enc YwBtAGQAIAAvAEMAIAB0AGkAbQBlAG8AdQB0ACAAMgAyAA==C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeInstaller.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
0
Version:
10.0.14409.1005 (rs1_srvoob.161208-1155)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\atl.dll
c:\windows\system32\user32.dll
Total events
3 314
Read events
3 274
Write events
40
Delete events
0

Modification events

(PID) Process:(3624) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3624) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3624) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3624) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
(PID) Process:(3624) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(3624) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3624) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\CK - Multihack Control Panel 0.4.0.rar
(PID) Process:(3624) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3624) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3624) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
52
Suspicious files
5
Text files
2
Unknown types
1

Dropped files

PID
Process
Filename
Type
3624WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3624.29890\CK - Multihack Control Panel 0.4.0\Cheats\Battlefield 5.dllexecutable
MD5:18FD51821D0A6F3E94E3FA71DB6DE3AF
SHA256:DBA84E704FFE5FCD42548856258109DC77C6A46FD0B784119A3548EC47E5644B
3624WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3624.29890\CK - Multihack Control Panel 0.4.0\Cheats\Back 4 Blood.dllexecutable
MD5:79EE4A2FCBE24E9A65106DE834CCDA4A
SHA256:9F7BDA59FAAFC8A455F98397A63A7F7D114EFC4E8A41808C791256EBF33C7613
3624WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3624.29890\CK - Multihack Control Panel 0.4.0\Cheats\Anarea.dllexecutable
MD5:CFE87D58F973DAEDA4EE7D2CF4AE521D
SHA256:4997FDA5D0E90B8A0AB7DA314CB56F25D1450B366701C45C294D8DD3254DE483
3624WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3624.29890\CK - Multihack Control Panel 0.4.0\Cheats\Crossfire.dllexecutable
MD5:D91BF81CF5178D47D1A588B0DF98EB24
SHA256:F8E3B45FD3E22866006F16A9E73E28B5E357F31F3C275B517692A5F16918B492
3624WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3624.29890\CK - Multihack Control Panel 0.4.0\Cheats\CoD Vanguard.dllexecutable
MD5:0C48220A4485F36FEED84EF5DD0A5E9C
SHA256:2DD4EBAA12CBBA142B5D61A0EBF84A14D0D1BB8826BA42B63E303FE6721408DF
3624WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3624.29890\CK - Multihack Control Panel 0.4.0\Cheats\Battlefield 4.dllexecutable
MD5:D91BF81CF5178D47D1A588B0DF98EB24
SHA256:F8E3B45FD3E22866006F16A9E73E28B5E357F31F3C275B517692A5F16918B492
3624WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3624.29890\CK - Multihack Control Panel 0.4.0\Cheats\LOL.dllexecutable
MD5:EEFE86B5A3AB256BEED8621A05210DF2
SHA256:1D1C11FC1AD1FEBF9308225C4CCF0431606A4AB08680BA04494D276CB310BF15
3624WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3624.29890\CK - Multihack Control Panel 0.4.0\Cheats\Destiny 2.dllexecutable
MD5:0C48220A4485F36FEED84EF5DD0A5E9C
SHA256:2DD4EBAA12CBBA142B5D61A0EBF84A14D0D1BB8826BA42B63E303FE6721408DF
3624WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3624.29890\CK - Multihack Control Panel 0.4.0\Cheats\Fortnite.dllexecutable
MD5:CFE87D58F973DAEDA4EE7D2CF4AE521D
SHA256:4997FDA5D0E90B8A0AB7DA314CB56F25D1450B366701C45C294D8DD3254DE483
3624WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3624.29890\CK - Multihack Control Panel 0.4.0\Cheats\MIR 4.dllexecutable
MD5:18FD51821D0A6F3E94E3FA71DB6DE3AF
SHA256:DBA84E704FFE5FCD42548856258109DC77C6A46FD0B784119A3548EC47E5644B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info