File name:

_Getintopc.com_Betternet.VPN.5.3.0.433.win.rar

Full analysis: https://app.any.run/tasks/08cd9353-42f7-4483-9ca8-e5cde541c01a
Verdict: Malicious activity
Analysis date: March 26, 2025, 22:29:04
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
arch-exec
arch-doc
Indicators:
MIME: application/x-rar
File info: RAR archive data, v4, os: Unix
MD5:

ED1A7E2E02B82DF81DFC28E273188451

SHA1:

1C25AF3B6A5022D2D9F2473E11F4296A13A10A27

SHA256:

432D133638F9C0342F1FF5FCE2EDF38F74538EEDF901C8A5EF183CAF9CD01F57

SSDEEP:

98304:cVA7s8CgHl/w7OKBZ06jVli+kE02hgE0kDHLiRFrwlwFcZG2H8xT2/huDZJTAelU:XqZRgP7Nh6nWBn0

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • drvinst.exe (PID: 3000)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 2736)
      • msiexec.exe (PID: 2932)
      • Betternet.exe (PID: 4020)
    • Executes as Windows Service

      • VSSVC.exe (PID: 1324)
    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 2736)
      • msiexec.exe (PID: 1760)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 1760)
    • The process creates files with name similar to system file names

      • msiexec.exe (PID: 1760)
      • tap-windows-9.21.2.exe (PID: 2748)
    • Adds/modifies Windows certificates

      • msiexec.exe (PID: 2100)
      • tapinstall.exe (PID: 3256)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • tap-windows-9.21.2.exe (PID: 2748)
    • Starts application with an unusual extension

      • tap-windows-9.21.2.exe (PID: 2748)
    • Drops a system driver (possible attempt to evade defenses)

      • tap-windows-9.21.2.exe (PID: 2748)
      • tapinstall.exe (PID: 3256)
      • drvinst.exe (PID: 3660)
      • drvinst.exe (PID: 3000)
    • Executable content was dropped or overwritten

      • tap-windows-9.21.2.exe (PID: 2748)
      • tapinstall.exe (PID: 3256)
      • drvinst.exe (PID: 3660)
      • rundll32.exe (PID: 3292)
      • drvinst.exe (PID: 3000)
    • Creates files in the driver directory

      • drvinst.exe (PID: 3660)
      • drvinst.exe (PID: 3000)
    • Creates a software uninstall entry

      • tap-windows-9.21.2.exe (PID: 2748)
    • Uses RUNDLL32.EXE to load library

      • msiexec.exe (PID: 2100)
    • Reads the Internet Settings

      • msiexec.exe (PID: 2932)
      • Betternet.exe (PID: 4020)
  • INFO

    • Checks supported languages

      • msiexec.exe (PID: 2740)
      • msiexec.exe (PID: 1760)
      • msiexec.exe (PID: 2100)
      • tap-windows-9.21.2.exe (PID: 2748)
      • nsBE1D.tmp (PID: 148)
      • tapinstall.exe (PID: 2728)
      • nsBF18.tmp (PID: 3004)
      • tapinstall.exe (PID: 3256)
      • drvinst.exe (PID: 3660)
      • msiexec.exe (PID: 2932)
      • Betternet.exe (PID: 4020)
      • drvinst.exe (PID: 3000)
    • Reads the machine GUID from the registry

      • msiexec.exe (PID: 1760)
      • msiexec.exe (PID: 2740)
      • msiexec.exe (PID: 2100)
      • tapinstall.exe (PID: 3256)
      • drvinst.exe (PID: 3660)
      • msiexec.exe (PID: 2932)
      • drvinst.exe (PID: 3000)
      • Betternet.exe (PID: 4020)
    • Reads the computer name

      • msiexec.exe (PID: 2740)
      • msiexec.exe (PID: 1760)
      • msiexec.exe (PID: 2100)
      • tap-windows-9.21.2.exe (PID: 2748)
      • tapinstall.exe (PID: 2728)
      • tapinstall.exe (PID: 3256)
      • drvinst.exe (PID: 3660)
      • msiexec.exe (PID: 2932)
      • Betternet.exe (PID: 4020)
      • drvinst.exe (PID: 3000)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 1760)
      • msiexec.exe (PID: 2848)
    • Create files in a temporary directory

      • msiexec.exe (PID: 1760)
      • tap-windows-9.21.2.exe (PID: 2748)
      • tapinstall.exe (PID: 3256)
      • Betternet.exe (PID: 4020)
    • Application launched itself

      • msiexec.exe (PID: 1760)
    • The sample compiled with english language support

      • msiexec.exe (PID: 1760)
      • tap-windows-9.21.2.exe (PID: 2748)
      • tapinstall.exe (PID: 3256)
      • drvinst.exe (PID: 3660)
      • drvinst.exe (PID: 3000)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 1760)
    • Creates files in the program directory

      • tap-windows-9.21.2.exe (PID: 2748)
      • rundll32.exe (PID: 3292)
      • Betternet.exe (PID: 4020)
    • Reads the software policy settings

      • drvinst.exe (PID: 3660)
      • drvinst.exe (PID: 3000)
      • tapinstall.exe (PID: 3256)
    • Reads Environment values

      • drvinst.exe (PID: 3000)
      • Betternet.exe (PID: 4020)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

FileVersion: RAR v4
CompressedSize: 7404470
UncompressedSize: 8568832
OperatingSystem: Unix
ModifyDate: 2019:09:28 15:45:10
PackingMethod: Normal
ArchivedFileName: Betternet.VPN.5.3.0.433\Setup.msi
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
57
Monitored processes
17
Malicious processes
4
Suspicious processes
2

Behavior graph

Click at the process to see the details
start winrar.exe no specs msiexec.exe msiexec.exe vssvc.exe no specs msiexec.exe no specs msiexec.exe no specs tap-windows-9.21.2.exe nsbe1d.tmp tapinstall.exe no specs nsbf18.tmp tapinstall.exe drvinst.exe drvinst.exe rundll32.exe msiexec.exe no specs betternet.exe no specs betternet.exe

Process information

PID
CMD
Path
Indicators
Parent process
148"C:\Users\admin\AppData\Local\Temp\nsuBD9F.tmp\nsBE1D.tmp" "C:\Program Files\TAP-Windows\bin\tapinstall.exe" hwids tap0901C:\Users\admin\AppData\Local\Temp\nsuBD9F.tmp\nsBE1D.tmp
tap-windows-9.21.2.exe
User:
SYSTEM
Integrity Level:
SYSTEM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\nsubd9f.tmp\nsbe1d.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1324C:\Windows\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1760C:\Windows\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2100C:\Windows\system32\MsiExec.exe -Embedding 381C0E2E97A191C1B68643E9490E5051 E Global\MSI0000C:\Windows\System32\msiexec.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2728"C:\Program Files\TAP-Windows\bin\tapinstall.exe" hwids tap0901C:\Program Files\TAP-Windows\bin\tapinstall.exensBE1D.tmp
User:
SYSTEM
Company:
Windows (R) Win 7 DDK provider
Integrity Level:
SYSTEM
Description:
Windows Setup API
Exit code:
0
Version:
6.1.7600.16385 built by: WinDDK
Modules
Images
c:\program files\tap-windows\bin\tapinstall.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
2736"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\_Getintopc.com_Betternet.VPN.5.3.0.433.win.rarC:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2740C:\Windows\system32\MsiExec.exe -Embedding 5EF3CE529927C2DF4224A0D45FFB5417C:\Windows\System32\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2748"C:\Program Files\Betternet\5.3.0.433\tap-windows-9.21.2.exe" /S /SELECT_SHORTCUTS=0 /D=C:\Program Files\OpenVPNC:\Program Files\Betternet\5.3.0.433\tap-windows-9.21.2.exe
msiexec.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\program files\betternet\5.3.0.433\tap-windows-9.21.2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
2848"C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\Rar$EXa2736.47146\Betternet.VPN.5.3.0.433\Setup.msi" C:\Windows\System32\msiexec.exe
WinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2932C:\Windows\system32\MsiExec.exe -Embedding 70CFE1DF07DBFCB722D9D900A3F1270F CC:\Windows\System32\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
18 529
Read events
17 757
Write events
707
Delete events
65

Modification events

(PID) Process:(2736) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2736) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2736) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2736) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2736) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(2736) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(2736) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\_Getintopc.com_Betternet.VPN.5.3.0.433.win.rar
(PID) Process:(2736) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2736) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2736) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
78
Suspicious files
35
Text files
16
Unknown types
0

Dropped files

PID
Process
Filename
Type
2736WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2736.47146\Betternet.VPN.5.3.0.433\Setup.msi
MD5:
SHA256:
1760msiexec.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
1760msiexec.exeC:\Windows\Installer\18a5ff.msi
MD5:
SHA256:
1760msiexec.exeC:\System Volume Information\SPP\snapshot-2binary
MD5:77E0679744BDAC94F73A657E8C318963
SHA256:9C7953849C4C2B239DD0EBEB8992E091445927420274383A23FD0DFBE0D33CF5
1760msiexec.exeC:\System Volume Information\SPP\OnlineMetadataCache\{d89df7ce-be04-40af-9893-d15272395d01}_OnDiskSnapshotPropbinary
MD5:77E0679744BDAC94F73A657E8C318963
SHA256:9C7953849C4C2B239DD0EBEB8992E091445927420274383A23FD0DFBE0D33CF5
2736WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2736.47146\Betternet.VPN.5.3.0.433\Read.txttext
MD5:F957322BC170978AE9EA4FE38BCB053C
SHA256:D0E631818932A72B4EDA6FB40A2C8493C0525321D8DF0EC837EFE711E8282CDF
1760msiexec.exeC:\Windows\Installer\MSIAFA6.tmpexecutable
MD5:BA84DD4E0C1408828CCC1DE09F585EDA
SHA256:3CFF4AC91288A0FF0C13278E73B282A64E83D089C5A61A45D483194AB336B852
1760msiexec.exeC:\Windows\Installer\18a600.ipibinary
MD5:6E9FBD457C7DBC375A989412D50EF7CA
SHA256:39260F45A469762F0ABD1E844E5A9645F65FED2CB0BF132FAB5DADF3FE7CED16
1760msiexec.exeC:\Program Files\Betternet\5.3.0.433\System.Runtime.InteropServices.RuntimeInformation.dllexecutable
MD5:82DEB78891F430007E871A35CE28FAC4
SHA256:2F141B72A2AF0458993E27559395D8A8CDB0B752D79B1703541A61E728B55237
1760msiexec.exeC:\Program Files\Betternet\5.3.0.433\Foundation.ExtProc.Hydra.ComTypes.dllexecutable
MD5:B1425D69A17A41E9969BEC945D91A9FC
SHA256:24F36668A8DFD7EBCC1FBB79A65274EE0747E6C4143285CD6F2BD1426848B7DA
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
10
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
whitelisted
1080
svchost.exe
224.0.0.252:5355
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 216.58.206.78
whitelisted

Threats

No threats detected
No debug info