| File name: | GTA 6 Builder-Install.rar |
| Full analysis: | https://app.any.run/tasks/3a5fb4eb-7ad3-4199-a799-ae45fb037c8b |
| Verdict: | Malicious activity |
| Threats: | DCrat, also known as Dark Crystal RAT, is a remote access trojan (RAT), which was first introduced in 2018. It is a modular malware that can be customized to perform different tasks. For instance, it can steal passwords, crypto wallet information, hijack Telegram and Steam accounts, and more. Attackers may use a variety of methods to distribute DCrat, but phishing email campaigns are the most common. |
| Analysis date: | December 22, 2023, 10:01:59 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v5 |
| MD5: | 202D57EFC789177CFFC54FC99C0EC76B |
| SHA1: | 5F6439B96A1A378E0D7A53CFA6EF3685BB6790E8 |
| SHA256: | 4359D215AE928EBB5B0EAA8CEBB8E51BACD7E6E9B634740225DF28B846A9352E |
| SSDEEP: | 98304:30bzWVqVlbblV8YOuvHeikS33wy3l/ZCfJQLkh1IfjxRe1/sr1MauHqfM9wfhAxW:2bpehnU4BcPzSLynazPY0QTZUI |
| .rar | | | RAR compressed archive (v5.0) (61.5) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 128 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\GTA 6 Builder-Install.rar" | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 480 | "C:\Users\admin\AppData\Roaming\ms_update.exe" | C:\Users\admin\AppData\Roaming\ms_update.exe | GTA 6 Builder-Install.exe | ||||||||||||
User: admin Company: System32 1989-2023 Integrity Level: MEDIUM Description: System32 Exit code: 0 Version: 15.6.13.6 Modules
| |||||||||||||||
| 712 | "C:\Users\admin\AppData\Roaming\ms_updater.exe" | C:\Users\admin\AppData\Roaming\ms_updater.exe | GTA 6 Builder-Install.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Version: 5.15.2.0 Modules
DcRat(PID) Process(712) ms_updater.exe C2 (1)https://pastebin.com/raw/LWvs8stk Options MutexDCR_MUTEX-jXkHv65ifMXN5oCQdgi1 savebrowsersdatatosinglefilefalse ignorepartiallyemptydatafalse cookiestrue passwordstrue formstrue ccfalse historyfalse telegramtrue steamtrue discordtrue filezillatrue screenshottrue clipboardtrue sysinfotrue searchpath%UsersFolder% - Fast Targetru | |||||||||||||||
| 1040 | "C:\Users\admin\AppData\Roaming\ms_updater.exe" | C:\Users\admin\AppData\Roaming\ms_updater.exe | — | GTA 6 Builder-Install.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Version: 5.15.2.0 Modules
| |||||||||||||||
| 2024 | "C:\Users\admin\Desktop\GTA 6 Builder-Install.exe" | C:\Users\admin\Desktop\GTA 6 Builder-Install.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 2384 | "C:\Windows\explorer.exe" | C:\Windows\explorer.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (128) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (128) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (128) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (128) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (128) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
| (PID) Process: | (128) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (128) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (128) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (128) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (128) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin |
| Operation: | write | Name: | Placement |
Value: 2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 128 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa128.31999\NlsData004a.dll | executable | |
MD5:BE007B645B9D1332E3346107727320D9 | SHA256:7B128BE8D77398CBC3BB789A34E21AFC984C2E87276907A01326F8FB4504E9DA | |||
| 128 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa128.31999\NL7Data0404.dll | executable | |
MD5:81B14FD1C9D2B830E55C93C4C38AFA2F | SHA256:878E2DBAC4B6A6BCCE54742F3C7BFD87AA93A6637CCCC1E5D18AB65215D81BEE | |||
| 128 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa128.31999\GTA 6 Builder-Install.exe | executable | |
MD5:56CBFC6271A60949F8818459A60BDFA6 | SHA256:E860A9206EE832C3C59731D545B551E720318E0B7DD01EA1E4AA44348E5C2F9C | |||
| 128 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa128.31999\README.txt | text | |
MD5:229BFB07694F123E2CB4986F47100A62 | SHA256:8DF26B1F550C80646F01D25B8AAFCABB1342BBB2BE1CD335CDB8D254BE8C4090 | |||
| 2024 | GTA 6 Builder-Install.exe | C:\Users\admin\AppData\Roaming\ms_update.exe | executable | |
MD5:8597488355F310BC0046FD9F3EB87C6B | SHA256:9FA04A8D42F65ABDD06306941A8E83078BB74F70C508FB8030586759A6D408E5 | |||
| 2024 | GTA 6 Builder-Install.exe | C:\Users\admin\AppData\Roaming\ms_updater.exe | executable | |
MD5:5CEE940B52DA0E967FECB1133B6304D0 | SHA256:0CBC0042EA0C1F235C35CFC40A62D29A5D794535FA164DFB57F7B90334FFE767 | |||
| 480 | ms_update.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\System32.exe | executable | |
MD5:8597488355F310BC0046FD9F3EB87C6B | SHA256:9FA04A8D42F65ABDD06306941A8E83078BB74F70C508FB8030586759A6D408E5 | |||
| 128 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa128.31999\NL7Models0804.dll | executable | |
MD5:65525C7B89204D241120B7638934A0D2 | SHA256:18F7F52F14986133F9A9676D5AB959349377A53C0936CEA6EB9880E72F85BC54 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
712 | ms_updater.exe | GET | — | 172.67.129.42:80 | http://714745cm.nyashland.top/nyashsupport.php?YSdnEeA1U=DvuS&17789cb3578c6680ba919ed580bcbc59=c33b5fda8c587ac7ab22b49b86ea1260&024ace78b46de9dec7d33cd74bf374d2=AM5gzYmdjMklTM3QGNjJjNkdzY1QjYjFTMjhzM5YTN4UGNxgTZ3ITZ&YSdnEeA1U=DvuS | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
712 | ms_updater.exe | 172.67.34.170:443 | pastebin.com | CLOUDFLARENET | US | unknown |
712 | ms_updater.exe | 172.67.129.42:80 | 714745cm.nyashland.top | CLOUDFLARENET | US | unknown |
Domain | IP | Reputation |
|---|---|---|
pastebin.com |
| shared |
714745cm.nyashland.top |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
1080 | svchost.exe | Potentially Bad Traffic | ET DNS Query to a *.top domain - Likely Hostile |