File name:

heart-sender-v1.2-cracked-by-jc0der-fireeye.rar

Full analysis: https://app.any.run/tasks/613fb6ad-57cd-4c56-a762-bd85a597140e
Verdict: No threats detected
Analysis date: September 23, 2019, 16:09:33
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

E2CCD39135876DEB4C19112420973DD0

SHA1:

02C158943B4410FE128DA22BAC887DD7BE4ECA90

SHA256:

4738DD26A09045F07D050FA93970762A79AABBFF218AE7ACED33531D74823A59

SSDEEP:

3072:HHXJFGVdxk1HoHUv9FE3xsreEW+6LeAk5OgifE+f0uMGI+ITxceNdIi:n5FGVdW1aUDEur++ceAsf2xI+A6ep

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Heart-Sender-V1.2 Cracked by JC0der-FireEye.exe (PID: 3068)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3336)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
33
Monitored processes
2
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start winrar.exe heart-sender-v1.2 cracked by jc0der-fireeye.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3068"C:\Users\admin\AppData\Local\Temp\Rar$EXa3336.49852\Heart-Sender-V1.2 Cracked by JC0der-FireEye\Heart-Sender-V1.2 Cracked by JC0der-FireEye.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3336.49852\Heart-Sender-V1.2 Cracked by JC0der-FireEye\Heart-Sender-V1.2 Cracked by JC0der-FireEye.exeWinRAR.exe
User:
admin
Company:
HeartFamily
Integrity Level:
MEDIUM
Description:
Heart Sender V1
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3336.49852\heart-sender-v1.2 cracked by jc0der-fireeye\heart-sender-v1.2 cracked by jc0der-fireeye.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3336"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\heart-sender-v1.2-cracked-by-jc0der-fireeye.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
472
Read events
459
Write events
13
Delete events
0

Modification events

(PID) Process:(3336) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3336) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3336) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3336) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\heart-sender-v1.2-cracked-by-jc0der-fireeye.rar
(PID) Process:(3336) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3336) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3336) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3336) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3336) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(3336) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
Executable files
2
Suspicious files
0
Text files
8
Unknown types
0

Dropped files

PID
Process
Filename
Type
3336WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3336.49852\Heart-Sender-V1.2 Cracked by JC0der-FireEye\HtmlAgilityPack.dllexecutable
MD5:97458FB37FCBEA19B16704474E0BB747
SHA256:EB6841497CAFAB1AAC432B09F4979997FA3314D4828BE15CDBD37F621BA38EAC
3336WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3336.49852\Heart-Sender-V1.2 Cracked by JC0der-FireEye\logs\17-03-2019\failed.txttext
MD5:5BF69041628016D0810F1B1F654A6FF7
SHA256:3E044122033B8C7F4B6F75144891203924880FED76891BC2198E71944FA1E816
3336WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3336.49852\Heart-Sender-V1.2 Cracked by JC0der-FireEye\logs\17-03-2019\logs.txttext
MD5:5BF69041628016D0810F1B1F654A6FF7
SHA256:3E044122033B8C7F4B6F75144891203924880FED76891BC2198E71944FA1E816
3336WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3336.49852\Heart-Sender-V1.2 Cracked by JC0der-FireEye\logs\17-03-2019\success.txttext
MD5:5BF69041628016D0810F1B1F654A6FF7
SHA256:3E044122033B8C7F4B6F75144891203924880FED76891BC2198E71944FA1E816
3336WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3336.49852\Heart-Sender-V1.2 Cracked by JC0der-FireEye\Heart-Sender-V1.2 Cracked by JC0der-FireEye.exeexecutable
MD5:9C7691FF597E9EFD7F796B31ACCB78E8
SHA256:1624AF752C9F85FD117FAFB28FEB42A079F283DC133CDCC5799810072A95A6CB
3336WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3336.49852\Heart-Sender-V1.2 Cracked by JC0der-FireEye\logs\18-03-2019\failed.txttext
MD5:C6C938699FEC5A0B48649FDD1162F5F3
SHA256:82EC2730A87D39A0209F890C790739257D819419E2B43DAA6AA4A32CF0B2E2C7
3336WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3336.49852\Heart-Sender-V1.2 Cracked by JC0der-FireEye\logs\18-03-2019\logs.txttext
MD5:C6C938699FEC5A0B48649FDD1162F5F3
SHA256:82EC2730A87D39A0209F890C790739257D819419E2B43DAA6AA4A32CF0B2E2C7
3336WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3336.49852\Heart-Sender-V1.2 Cracked by JC0der-FireEye\license.txttext
MD5:B28BA1C42E3F7AC4A232F995DB96F8E6
SHA256:F9598EBA595AAB0895F5804807EAD4546E9C1770F10028D0FA843707A11F2897
3336WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3336.49852\Heart-Sender-V1.2 Cracked by JC0der-FireEye\logs\18-03-2019\success.txttext
MD5:C6C938699FEC5A0B48649FDD1162F5F3
SHA256:82EC2730A87D39A0209F890C790739257D819419E2B43DAA6AA4A32CF0B2E2C7
3336WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3336.49852\Heart-Sender-V1.2 Cracked by JC0der-FireEye\Settings.initext
MD5:B48B1B05E298D45EFA4C56C34A2EA642
SHA256:B9AE3242DAC9AFE4D8C2A4F889D633A3BC10217E2C4E374158D9753E8AB02A6E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info