analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

GrammarlyChecker.rar

Full analysis: https://app.any.run/tasks/74aa73a0-9813-428a-8154-2a843994191a
Verdict: Malicious activity
Analysis date: February 10, 2019, 19:22:11
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

046139835A20835847910EA5D84E174D

SHA1:

2B1A2AB610D71BAD7E76855B2C753E7B1EE1898D

SHA256:

42570E7F90AB12CD0FAA532676AE3E02B4EDC82FAA8BF0298A9E5A8B724BE2FD

SSDEEP:

12288:0M5s0BbaqvIzJpM1kSwiWvVFKQaBWAdM2rppP1ipIFvX:00Gqw7MuSwFM3ZppHxX

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • GrammarlyChecker.exe (PID: 3096)
    • Application was dropped or rewritten from another process

      • GrammarlyChecker.exe (PID: 3096)
    • Changes settings of System certificates

      • GrammarlyChecker.exe (PID: 3096)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2852)
    • Adds / modifies Windows certificates

      • GrammarlyChecker.exe (PID: 3096)
    • Connects to unusual port

      • GrammarlyChecker.exe (PID: 3096)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
31
Monitored processes
2
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start winrar.exe grammarlychecker.exe

Process information

PID
CMD
Path
Indicators
Parent process
2852"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\GrammarlyChecker.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.60.0
3096"C:\Users\admin\AppData\Local\Temp\Rar$EXa2852.7126\GrammarlyChecker\GrammarlyChecker.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2852.7126\GrammarlyChecker\GrammarlyChecker.exe
WinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Description:
GrammarlyChecker
Version:
1.0.0.0
Total events
472
Read events
440
Write events
29
Delete events
3

Modification events

(PID) Process:(2852) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2852) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2852) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2852) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\GrammarlyChecker.rar
(PID) Process:(2852) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2852) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2852) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2852) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2852) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(2852) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
Executable files
5
Suspicious files
8
Text files
7
Unknown types
2

Dropped files

PID
Process
Filename
Type
3096GrammarlyChecker.exeC:\Users\admin\AppData\Local\Temp\CabF0A0.tmp
MD5:
SHA256:
3096GrammarlyChecker.exeC:\Users\admin\AppData\Local\Temp\TarF0A1.tmp
MD5:
SHA256:
3096GrammarlyChecker.exeC:\Users\admin\AppData\Local\Temp\CabF0D0.tmp
MD5:
SHA256:
3096GrammarlyChecker.exeC:\Users\admin\AppData\Local\Temp\TarF0D1.tmp
MD5:
SHA256:
3096GrammarlyChecker.exeC:\Users\admin\AppData\Local\Temp\CabF1FB.tmp
MD5:
SHA256:
3096GrammarlyChecker.exeC:\Users\admin\AppData\Local\Temp\TarF1FC.tmp
MD5:
SHA256:
3096GrammarlyChecker.exeC:\Users\admin\AppData\Local\Temp\CabF2D8.tmp
MD5:
SHA256:
3096GrammarlyChecker.exeC:\Users\admin\AppData\Local\Temp\TarF2D9.tmp
MD5:
SHA256:
3096GrammarlyChecker.exeC:\Users\admin\AppData\Local\Temp\CabF338.tmp
MD5:
SHA256:
3096GrammarlyChecker.exeC:\Users\admin\AppData\Local\Temp\TarF348.tmp
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
143
DNS requests
3
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3096
GrammarlyChecker.exe
GET
200
2.16.186.56:80
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
unknown
compressed
55.2 Kb
whitelisted
3096
GrammarlyChecker.exe
GET
200
13.32.123.48:80
http://x.ss2.us/x.cer
US
der
1.27 Kb
whitelisted
3096
GrammarlyChecker.exe
GET
200
13.32.123.48:80
http://x.ss2.us/x.cer
US
der
1.27 Kb
whitelisted
3096
GrammarlyChecker.exe
GET
200
2.16.186.56:80
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
unknown
compressed
55.2 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3096
GrammarlyChecker.exe
188.175.195.5:4145
RIO Media a.s.
CZ
unknown
3096
GrammarlyChecker.exe
103.16.63.233:36517
Ministry of Posts and Telecommunication
KH
unknown
3096
GrammarlyChecker.exe
89.216.45.62:1080
Serbia BroadBand-Srpske Kablovske mreze d.o.o.
RS
unknown
3096
GrammarlyChecker.exe
185.14.250.194:37422
Tarin General Trading and Setting Up Internet Device LTD
IQ
suspicious
3096
GrammarlyChecker.exe
196.212.51.234:32060
IS
ZA
unknown
3096
GrammarlyChecker.exe
103.228.2.1:32600
Mynet Limited
BD
unknown
3096
GrammarlyChecker.exe
131.196.4.226:4145
GR SOLUCOES TELECOM LTDA - ME
BR
suspicious
3096
GrammarlyChecker.exe
13.32.123.48:80
x.ss2.us
Amazon.com, Inc.
US
unknown
3096
GrammarlyChecker.exe
81.95.131.10:41398
Avantel, Close Joint Stock Company
RU
suspicious
3096
GrammarlyChecker.exe
177.200.64.123:4145
SKYNET TELECOMUNICACOES LTDA
BR
unknown

DNS requests

Domain
IP
Reputation
auth.grammarly.com
  • 35.153.94.200
  • 18.215.192.228
  • 54.208.222.32
unknown
x.ss2.us
  • 13.32.123.48
  • 13.32.123.175
  • 13.32.123.70
  • 13.32.123.82
whitelisted
www.download.windowsupdate.com
  • 2.16.186.56
  • 2.16.186.81
whitelisted

Threats

PID
Process
Class
Message
3096
GrammarlyChecker.exe
Potential Corporate Privacy Violation
POLICY [PTsecurity] Socks4 Connection
3096
GrammarlyChecker.exe
Potential Corporate Privacy Violation
POLICY [PTsecurity] Socks4 Connection
3096
GrammarlyChecker.exe
Potential Corporate Privacy Violation
POLICY [PTsecurity] Socks4 Connection
3096
GrammarlyChecker.exe
Potential Corporate Privacy Violation
POLICY [PTsecurity] Socks4 Connection
3096
GrammarlyChecker.exe
Potential Corporate Privacy Violation
POLICY [PTsecurity] Socks4 Connection
3096
GrammarlyChecker.exe
Potential Corporate Privacy Violation
POLICY [PTsecurity] Socks4 Connection
3096
GrammarlyChecker.exe
Potential Corporate Privacy Violation
POLICY [PTsecurity] Socks4 Connection
3096
GrammarlyChecker.exe
Potential Corporate Privacy Violation
POLICY [PTsecurity] Socks4 Connection
3096
GrammarlyChecker.exe
Potential Corporate Privacy Violation
POLICY [PTsecurity] Socks4 Connection
3096
GrammarlyChecker.exe
Potential Corporate Privacy Violation
POLICY [PTsecurity] Socks4 Connection
No debug info