File name:

CK - Multihack Control Panel 0.4.0.rar

Full analysis: https://app.any.run/tasks/e64926e7-5986-4d7d-9f5e-ace5e2ff0483
Verdict: Malicious activity
Analysis date: February 09, 2022, 11:11:54
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

BA846369D867E993DAF5B72B2D23ABC9

SHA1:

9A1A406FF9CEA6A34EAE0BC7994B93986B40EC74

SHA256:

3D312E4F21286BBA1FC2126FCD77DCE68032B22C4C4FBA375D458C6CE5E20F7C

SSDEEP:

98304:Ic0jcpITDcXxhM76kYxcg9WM6RsawkA6JDIl:IEmkX99Zpa5A6Jm

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 3776)
    • Application was dropped or rewritten from another process

      • Installer.exe (PID: 3300)
      • Installer.exe (PID: 2588)
  • SUSPICIOUS

    • Drops a file with a compile date too recent

      • WinRAR.exe (PID: 3624)
    • Checks supported languages

      • WinRAR.exe (PID: 3624)
      • Installer.exe (PID: 3300)
      • powershell.exe (PID: 3636)
      • cmd.exe (PID: 1008)
      • Installer.exe (PID: 2588)
      • powershell.exe (PID: 2580)
      • cmd.exe (PID: 3296)
    • Reads the computer name

      • WinRAR.exe (PID: 3624)
      • Installer.exe (PID: 3300)
      • powershell.exe (PID: 3636)
      • Installer.exe (PID: 2588)
      • powershell.exe (PID: 2580)
    • Executes PowerShell scripts

      • Installer.exe (PID: 3300)
      • Installer.exe (PID: 2588)
    • Starts CMD.EXE for commands execution

      • powershell.exe (PID: 3636)
      • powershell.exe (PID: 2580)
    • Drops a file with too old compile date

      • WinRAR.exe (PID: 3624)
    • Drops a file that was compiled in debug mode

      • WinRAR.exe (PID: 3624)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3624)
  • INFO

    • Manual execution by user

      • Installer.exe (PID: 3300)
      • NOTEPAD.EXE (PID: 2876)
      • Installer.exe (PID: 2588)
    • Checks Windows Trust Settings

      • powershell.exe (PID: 3636)
      • powershell.exe (PID: 2580)
    • Checks supported languages

      • timeout.exe (PID: 1652)
      • NOTEPAD.EXE (PID: 2876)
      • timeout.exe (PID: 3140)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
51
Monitored processes
11
Malicious processes
4
Suspicious processes
2

Behavior graph

Click at the process to see the details
start winrar.exe searchprotocolhost.exe no specs installer.exe powershell.exe no specs cmd.exe no specs timeout.exe no specs notepad.exe no specs installer.exe powershell.exe no specs cmd.exe no specs timeout.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1008"C:\Windows\system32\cmd.exe" /C timeout 22C:\Windows\system32\cmd.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1652timeout 22C:\Windows\system32\timeout.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
timeout - pauses command processing
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\timeout.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ws2_32.dll
2580"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -enc YwBtAGQAIAAvAEMAIAB0AGkAbQBlAG8AdQB0ACAAMgAyAA==C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeInstaller.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows PowerShell
Exit code:
0
Version:
10.0.14409.1005 (rs1_srvoob.161208-1155)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\atl.dll
c:\windows\system32\user32.dll
2588"C:\Users\admin\Desktop\CK - Multihack Control Panel 0.4.0\Installer.exe" C:\Users\admin\Desktop\CK - Multihack Control Panel 0.4.0\Installer.exe
Explorer.EXE
User:
admin
Integrity Level:
HIGH
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\ck - multihack control panel 0.4.0\installer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2876"C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\CK - Multihack Control Panel 0.4.0\How to use.txtC:\Windows\system32\NOTEPAD.EXEExplorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\user32.dll
3140timeout 22C:\Windows\system32\timeout.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
timeout - pauses command processing
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\timeout.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
3296"C:\Windows\system32\cmd.exe" /C timeout 22C:\Windows\system32\cmd.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
3300"C:\Users\admin\Desktop\CK - Multihack Control Panel 0.4.0\Installer.exe" C:\Users\admin\Desktop\CK - Multihack Control Panel 0.4.0\Installer.exe
Explorer.EXE
User:
admin
Integrity Level:
MEDIUM
Exit code:
3762504530
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\ck - multihack control panel 0.4.0\installer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3624"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\CK - Multihack Control Panel 0.4.0.rar"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
3636"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -enc YwBtAGQAIAAvAEMAIAB0AGkAbQBlAG8AdQB0ACAAMgAyAA==C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeInstaller.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
0
Version:
10.0.14409.1005 (rs1_srvoob.161208-1155)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\atl.dll
c:\windows\system32\user32.dll
Total events
3 314
Read events
3 274
Write events
40
Delete events
0

Modification events

(PID) Process:(3624) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3624) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3624) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3624) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
(PID) Process:(3624) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(3624) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3624) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\CK - Multihack Control Panel 0.4.0.rar
(PID) Process:(3624) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3624) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3624) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
52
Suspicious files
5
Text files
2
Unknown types
1

Dropped files

PID
Process
Filename
Type
3624WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3624.29890\CK - Multihack Control Panel 0.4.0\Cheats\CS GO.dllexecutable
MD5:AABBB38C4110CC0BF7203A567734A7E7
SHA256:24B07028C1E38B9CA2F197750654A0DFB7D33C2E52C9DD67100609499E8028DB
3624WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3624.29890\CK - Multihack Control Panel 0.4.0\Cheats\Battlefield 4.dllexecutable
MD5:D91BF81CF5178D47D1A588B0DF98EB24
SHA256:F8E3B45FD3E22866006F16A9E73E28B5E357F31F3C275B517692A5F16918B492
3624WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3624.29890\CK - Multihack Control Panel 0.4.0\Cheats\Apex.dllexecutable
MD5:3F224766FE9B090333FDB43D5A22F9EA
SHA256:AE5E73416EB64BC18249ACE99F6847024ECEEA7CE9C343696C84196460F3A357
3624WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3624.29890\CK - Multihack Control Panel 0.4.0\Cheats\Anarea.dllexecutable
MD5:CFE87D58F973DAEDA4EE7D2CF4AE521D
SHA256:4997FDA5D0E90B8A0AB7DA314CB56F25D1450B366701C45C294D8DD3254DE483
3624WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3624.29890\CK - Multihack Control Panel 0.4.0\Cheats\COD.dllexecutable
MD5:8894176AF3EA65A09AE5CF4C0E6FF50F
SHA256:C64B7C6400E9BACC1A4F1BAED6374BFBCE9A3F8CF20C2D03F81EF18262F89C60
3624WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3624.29890\CK - Multihack Control Panel 0.4.0\Cheats\Battlefield 2042.dllexecutable
MD5:EEFE86B5A3AB256BEED8621A05210DF2
SHA256:1D1C11FC1AD1FEBF9308225C4CCF0431606A4AB08680BA04494D276CB310BF15
3624WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3624.29890\CK - Multihack Control Panel 0.4.0\Cheats\CoD Vanguard.dllexecutable
MD5:0C48220A4485F36FEED84EF5DD0A5E9C
SHA256:2DD4EBAA12CBBA142B5D61A0EBF84A14D0D1BB8826BA42B63E303FE6721408DF
3624WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3624.29890\CK - Multihack Control Panel 0.4.0\Cheats\Battlefield 5.dllexecutable
MD5:18FD51821D0A6F3E94E3FA71DB6DE3AF
SHA256:DBA84E704FFE5FCD42548856258109DC77C6A46FD0B784119A3548EC47E5644B
3624WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3624.29890\CK - Multihack Control Panel 0.4.0\Cheats\Dota 2.dllexecutable
MD5:AABBB38C4110CC0BF7203A567734A7E7
SHA256:24B07028C1E38B9CA2F197750654A0DFB7D33C2E52C9DD67100609499E8028DB
3624WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3624.29890\CK - Multihack Control Panel 0.4.0\Cheats\Escape from Tarkov.dllexecutable
MD5:FF8026DAB5D3DABCA8F72B6FA7D258FA
SHA256:535E9D20F00A2F1A62F843A4A26CFB763138D5DFE358B0126D33996FBA9CA4D1
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info