File name:

_Getintopc.com_Betternet.VPN.5.3.0.433.win.rar

Full analysis: https://app.any.run/tasks/08cd9353-42f7-4483-9ca8-e5cde541c01a
Verdict: Malicious activity
Analysis date: March 26, 2025, 22:29:04
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
arch-exec
arch-doc
Indicators:
MIME: application/x-rar
File info: RAR archive data, v4, os: Unix
MD5:

ED1A7E2E02B82DF81DFC28E273188451

SHA1:

1C25AF3B6A5022D2D9F2473E11F4296A13A10A27

SHA256:

432D133638F9C0342F1FF5FCE2EDF38F74538EEDF901C8A5EF183CAF9CD01F57

SSDEEP:

98304:cVA7s8CgHl/w7OKBZ06jVli+kE02hgE0kDHLiRFrwlwFcZG2H8xT2/huDZJTAelU:XqZRgP7Nh6nWBn0

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • drvinst.exe (PID: 3000)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 2736)
      • msiexec.exe (PID: 1760)
    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 2736)
      • msiexec.exe (PID: 2932)
      • Betternet.exe (PID: 4020)
    • Executes as Windows Service

      • VSSVC.exe (PID: 1324)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 1760)
    • The process creates files with name similar to system file names

      • msiexec.exe (PID: 1760)
      • tap-windows-9.21.2.exe (PID: 2748)
    • Executable content was dropped or overwritten

      • tap-windows-9.21.2.exe (PID: 2748)
      • tapinstall.exe (PID: 3256)
      • drvinst.exe (PID: 3660)
      • drvinst.exe (PID: 3000)
      • rundll32.exe (PID: 3292)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • tap-windows-9.21.2.exe (PID: 2748)
    • Drops a system driver (possible attempt to evade defenses)

      • tap-windows-9.21.2.exe (PID: 2748)
      • tapinstall.exe (PID: 3256)
      • drvinst.exe (PID: 3660)
      • drvinst.exe (PID: 3000)
    • Starts application with an unusual extension

      • tap-windows-9.21.2.exe (PID: 2748)
    • Adds/modifies Windows certificates

      • msiexec.exe (PID: 2100)
      • tapinstall.exe (PID: 3256)
    • Creates files in the driver directory

      • drvinst.exe (PID: 3660)
      • drvinst.exe (PID: 3000)
    • Uses RUNDLL32.EXE to load library

      • msiexec.exe (PID: 2100)
    • Reads the Internet Settings

      • msiexec.exe (PID: 2932)
      • Betternet.exe (PID: 4020)
    • Creates a software uninstall entry

      • tap-windows-9.21.2.exe (PID: 2748)
  • INFO

    • Reads the computer name

      • msiexec.exe (PID: 1760)
      • msiexec.exe (PID: 2740)
      • msiexec.exe (PID: 2100)
      • tap-windows-9.21.2.exe (PID: 2748)
      • tapinstall.exe (PID: 2728)
      • tapinstall.exe (PID: 3256)
      • drvinst.exe (PID: 3660)
      • drvinst.exe (PID: 3000)
      • Betternet.exe (PID: 4020)
      • msiexec.exe (PID: 2932)
    • Checks supported languages

      • msiexec.exe (PID: 1760)
      • msiexec.exe (PID: 2740)
      • msiexec.exe (PID: 2100)
      • tap-windows-9.21.2.exe (PID: 2748)
      • tapinstall.exe (PID: 2728)
      • nsBE1D.tmp (PID: 148)
      • tapinstall.exe (PID: 3256)
      • nsBF18.tmp (PID: 3004)
      • drvinst.exe (PID: 3660)
      • drvinst.exe (PID: 3000)
      • msiexec.exe (PID: 2932)
      • Betternet.exe (PID: 4020)
    • Reads the machine GUID from the registry

      • msiexec.exe (PID: 1760)
      • msiexec.exe (PID: 2740)
      • msiexec.exe (PID: 2100)
      • tapinstall.exe (PID: 3256)
      • drvinst.exe (PID: 3660)
      • drvinst.exe (PID: 3000)
      • msiexec.exe (PID: 2932)
      • Betternet.exe (PID: 4020)
    • Create files in a temporary directory

      • msiexec.exe (PID: 1760)
      • tap-windows-9.21.2.exe (PID: 2748)
      • tapinstall.exe (PID: 3256)
      • Betternet.exe (PID: 4020)
    • Application launched itself

      • msiexec.exe (PID: 1760)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 1760)
      • msiexec.exe (PID: 2848)
    • The sample compiled with english language support

      • msiexec.exe (PID: 1760)
      • tap-windows-9.21.2.exe (PID: 2748)
      • tapinstall.exe (PID: 3256)
      • drvinst.exe (PID: 3660)
      • drvinst.exe (PID: 3000)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 1760)
    • Creates files in the program directory

      • tap-windows-9.21.2.exe (PID: 2748)
      • rundll32.exe (PID: 3292)
      • Betternet.exe (PID: 4020)
    • Reads the software policy settings

      • tapinstall.exe (PID: 3256)
      • drvinst.exe (PID: 3660)
      • drvinst.exe (PID: 3000)
    • Reads Environment values

      • drvinst.exe (PID: 3000)
      • Betternet.exe (PID: 4020)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

FileVersion: RAR v4
CompressedSize: 7404470
UncompressedSize: 8568832
OperatingSystem: Unix
ModifyDate: 2019:09:28 15:45:10
PackingMethod: Normal
ArchivedFileName: Betternet.VPN.5.3.0.433\Setup.msi
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
57
Monitored processes
17
Malicious processes
4
Suspicious processes
2

Behavior graph

Click at the process to see the details
start winrar.exe no specs msiexec.exe msiexec.exe vssvc.exe no specs msiexec.exe no specs msiexec.exe no specs tap-windows-9.21.2.exe nsbe1d.tmp tapinstall.exe no specs nsbf18.tmp tapinstall.exe drvinst.exe drvinst.exe rundll32.exe msiexec.exe no specs betternet.exe no specs betternet.exe

Process information

PID
CMD
Path
Indicators
Parent process
148"C:\Users\admin\AppData\Local\Temp\nsuBD9F.tmp\nsBE1D.tmp" "C:\Program Files\TAP-Windows\bin\tapinstall.exe" hwids tap0901C:\Users\admin\AppData\Local\Temp\nsuBD9F.tmp\nsBE1D.tmp
tap-windows-9.21.2.exe
User:
SYSTEM
Integrity Level:
SYSTEM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\nsubd9f.tmp\nsbe1d.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1324C:\Windows\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1760C:\Windows\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2100C:\Windows\system32\MsiExec.exe -Embedding 381C0E2E97A191C1B68643E9490E5051 E Global\MSI0000C:\Windows\System32\msiexec.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2728"C:\Program Files\TAP-Windows\bin\tapinstall.exe" hwids tap0901C:\Program Files\TAP-Windows\bin\tapinstall.exensBE1D.tmp
User:
SYSTEM
Company:
Windows (R) Win 7 DDK provider
Integrity Level:
SYSTEM
Description:
Windows Setup API
Exit code:
0
Version:
6.1.7600.16385 built by: WinDDK
Modules
Images
c:\program files\tap-windows\bin\tapinstall.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
2736"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\_Getintopc.com_Betternet.VPN.5.3.0.433.win.rarC:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2740C:\Windows\system32\MsiExec.exe -Embedding 5EF3CE529927C2DF4224A0D45FFB5417C:\Windows\System32\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2748"C:\Program Files\Betternet\5.3.0.433\tap-windows-9.21.2.exe" /S /SELECT_SHORTCUTS=0 /D=C:\Program Files\OpenVPNC:\Program Files\Betternet\5.3.0.433\tap-windows-9.21.2.exe
msiexec.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\program files\betternet\5.3.0.433\tap-windows-9.21.2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
2848"C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\Rar$EXa2736.47146\Betternet.VPN.5.3.0.433\Setup.msi" C:\Windows\System32\msiexec.exe
WinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2932C:\Windows\system32\MsiExec.exe -Embedding 70CFE1DF07DBFCB722D9D900A3F1270F CC:\Windows\System32\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
18 529
Read events
17 757
Write events
707
Delete events
65

Modification events

(PID) Process:(2736) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2736) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2736) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2736) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2736) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(2736) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(2736) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\_Getintopc.com_Betternet.VPN.5.3.0.433.win.rar
(PID) Process:(2736) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2736) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2736) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
78
Suspicious files
35
Text files
16
Unknown types
0

Dropped files

PID
Process
Filename
Type
2736WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2736.47146\Betternet.VPN.5.3.0.433\Setup.msi
MD5:
SHA256:
1760msiexec.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
1760msiexec.exeC:\Windows\Installer\18a5ff.msi
MD5:
SHA256:
2736WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2736.47146\Betternet.VPN.5.3.0.433\Read.txttext
MD5:F957322BC170978AE9EA4FE38BCB053C
SHA256:D0E631818932A72B4EDA6FB40A2C8493C0525321D8DF0EC837EFE711E8282CDF
1760msiexec.exeC:\System Volume Information\SPP\snapshot-2binary
MD5:77E0679744BDAC94F73A657E8C318963
SHA256:9C7953849C4C2B239DD0EBEB8992E091445927420274383A23FD0DFBE0D33CF5
1760msiexec.exeC:\Program Files\Betternet\5.3.0.433\KaitaiStruct.Runtime.CSharp.dllexecutable
MD5:477D149171F17932EFCA395B6B62F094
SHA256:BFF245FEFDA3ABF236B03FC25B19DE4E6366A4E5B06EBC73A5248FD9665BA50C
1760msiexec.exeC:\Windows\Installer\MSIAFA6.tmpexecutable
MD5:BA84DD4E0C1408828CCC1DE09F585EDA
SHA256:3CFF4AC91288A0FF0C13278E73B282A64E83D089C5A61A45D483194AB336B852
1760msiexec.exeC:\Windows\Installer\MSIAF08.tmpexecutable
MD5:35FB71DC75736A402F4A7300B2AC88CE
SHA256:097FF79CB72AC1DD5EAA4C68B96A7CF8574A1098C74D3CBD16E629194AFB2125
1760msiexec.exeC:\Users\admin\AppData\Local\Temp\~DF6729A910BF4B7A39.TMPbinary
MD5:EE6AF807CE14A1347F79E13B2C147EF3
SHA256:94CFD58D5649571E9E2E507B67A23AB61055C72F07F905440F7815F2F639F51E
1760msiexec.exeC:\Windows\Installer\MSIAED9.tmpbinary
MD5:D6D86BE3E8E04F9AA671DF4F862275AA
SHA256:3ABE4158F149D95E613C9C2398D26A44EEF7E7A24B9C18D1E45D400547D7A70F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
10
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
whitelisted
1080
svchost.exe
224.0.0.252:5355
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 216.58.206.78
whitelisted

Threats

No threats detected
No debug info