File name:

Ladon7.0.rar.7z

Full analysis: https://app.any.run/tasks/f12d1346-8661-415a-9869-24591fab258d
Verdict: Malicious activity
Analysis date: November 24, 2020, 07:41:48
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-7z-compressed
File info: 7-zip archive data, version 0.3
MD5:

34ED4E75C61D1B762016848566F8F049

SHA1:

E23C1F1F61F48DC57FBDC7144F45AA98D85BC726

SHA256:

4ACC82CFE890F43CF0B4613C83C50FCB4DD1B3E0C2369E1DB96A503BBDE3F38A

SSDEEP:

98304:k+RZwgVMC0dTi793zIjyBzU8MEfpYb7uVuWo9SfM:PRTVMCwTi7B8bXGpQguWnk

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Ladon.exe (PID: 2604)
      • LadonGUI.exe (PID: 1496)
      • LadonExp.exe (PID: 3672)
      • LadonExp.exe (PID: 5072)
      • Ladon.exe (PID: 5996)
      • Ladon.exe (PID: 2092)
      • LadonGUI40.exe (PID: 5652)
    • Runs app for hidden code execution

      • LadonGUI.exe (PID: 1496)
  • SUSPICIOUS

    • Drops a file with a compile date too recent

      • WinRAR.exe (PID: 2408)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2408)
    • Drops a file that was compiled in debug mode

      • WinRAR.exe (PID: 2408)
    • Reads internet explorer settings

      • LadonGUI.exe (PID: 1496)
      • LadonGUI40.exe (PID: 5652)
    • Creates files in the user directory

      • LadonGUI.exe (PID: 1496)
      • LadonGUI40.exe (PID: 5652)
    • Starts CMD.EXE for commands execution

      • LadonGUI.exe (PID: 1496)
  • INFO

    • Manual execution by user

      • WinRAR.exe (PID: 2408)
      • NOTEPAD.EXE (PID: 3636)
      • LadonExp.exe (PID: 3672)
      • Ladon.exe (PID: 2604)
      • NOTEPAD.EXE (PID: 2160)
      • NOTEPAD.EXE (PID: 3992)
      • NOTEPAD.EXE (PID: 1232)
      • LadonGUI.exe (PID: 1496)
      • NOTEPAD.EXE (PID: 1936)
      • LadonGUI40.exe (PID: 5652)
      • Ladon.exe (PID: 5996)
      • LadonExp.exe (PID: 5072)
    • Reads settings of System Certificates

      • LadonGUI.exe (PID: 1496)
      • LadonGUI40.exe (PID: 5652)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.7z | 7-Zip compressed archive (gen) (100)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
63
Monitored processes
15
Malicious processes
6
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe no specs winrar.exe notepad.exe no specs ladon.exe no specs ladonexp.exe no specs notepad.exe no specs notepad.exe no specs notepad.exe no specs notepad.exe no specs ladongui.exe cmd.exe no specs ladon.exe no specs ladonexp.exe no specs ladon.exe no specs ladongui40.exe

Process information

PID
CMD
Path
Indicators
Parent process
1232"C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\Ladon7.0\Ladon7.0\update.txtC:\Windows\system32\NOTEPAD.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1496"C:\Users\admin\Desktop\Ladon7.0\Ladon7.0\LadonGUI.exe" C:\Users\admin\Desktop\Ladon7.0\Ladon7.0\LadonGUI.exe
explorer.exe
User:
admin
Company:
K8gege
Integrity Level:
MEDIUM
Description:
Ladon
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\ladon7.0\ladon7.0\ladongui.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1800"cmd.exe"C:\Windows\system32\cmd.exeLadonGUI.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1936"C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\Ladon7.0\Ladon7.0\tmpnote.txtC:\Windows\system32\NOTEPAD.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2092Ladon OnlinePCC:\Users\admin\Desktop\Ladon7.0\Ladon7.0\Ladon.execmd.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Version:
7.0.0.0
Modules
Images
c:\users\admin\desktop\ladon7.0\ladon7.0\ladon.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2160"C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\Ladon7.0\Ladon7.0\update.txtC:\Windows\system32\NOTEPAD.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2408"C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Desktop\Ladon7.0.rar" "?\"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2604"C:\Users\admin\Desktop\Ladon7.0\Ladon7.0\Ladon.exe" C:\Users\admin\Desktop\Ladon7.0\Ladon7.0\Ladon.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Version:
7.0.0.0
Modules
Images
c:\users\admin\desktop\ladon7.0\ladon7.0\ladon.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2740"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Ladon7.0.rar.7z"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3636"C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\Ladon7.0\Ladon7.0\tmpnote.txtC:\Windows\system32\NOTEPAD.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
1 095
Read events
1 006
Write events
89
Delete events
0

Modification events

(PID) Process:(2740) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2740) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2740) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2740) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Ladon7.0.rar.7z
(PID) Process:(2740) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2740) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2740) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2740) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2740) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath
Operation:writeName:0
Value:
C:\Users\admin\Desktop
(PID) Process:(2740) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
Executable files
6
Suspicious files
13
Text files
28
Unknown types
7

Dropped files

PID
Process
Filename
Type
2408WinRAR.exeC:\Users\admin\Desktop\Ladon7.0\Ladon7.0\LadonGUI.exeexecutable
MD5:
SHA256:
2408WinRAR.exeC:\Users\admin\Desktop\Ladon7.0\Ladon7.0\CS\Ladon.cnatext
MD5:
SHA256:
2408WinRAR.exeC:\Users\admin\Desktop\Ladon7.0\Ladon7.0\update.txttext
MD5:
SHA256:
2408WinRAR.exeC:\Users\admin\Desktop\Ladon7.0\Ladon7.0\tmpnote.txttext
MD5:
SHA256:
2408WinRAR.exeC:\Users\admin\Desktop\Ladon7.0\Ladon7.0\Ladon.exeexecutable
MD5:
SHA256:
2408WinRAR.exeC:\Users\admin\Desktop\Ladon7.0\Ladon7.0\Ladon40.exeexecutable
MD5:
SHA256:
1496LadonGUI.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\Ladon[1].htmhtml
MD5:
SHA256:
2740WinRAR.exeC:\Users\admin\Desktop\Ladon7.0.rarcompressed
MD5:
SHA256:
2408WinRAR.exeC:\Users\admin\Desktop\Ladon7.0\Ladon7.0\LadonGUI40.exeexecutable
MD5:
SHA256:
1496LadonGUI.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\style[1].csstext
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
25
TCP/UDP connections
16
DNS requests
267
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1496
LadonGUI.exe
GET
200
185.199.109.153:80
http://k8gege.org/Ladon/?gui
NL
html
8.72 Kb
malicious
1496
LadonGUI.exe
GET
200
185.199.109.153:80
http://k8gege.org/css/style.css?rev=@@hash.css
NL
text
6.52 Kb
malicious
1496
LadonGUI.exe
GET
200
185.199.109.153:80
http://k8gege.org/Ladon/latest
NL
html
24.4 Kb
malicious
1496
LadonGUI.exe
GET
200
104.18.20.226:80
http://ocsp.globalsign.com/rootr1/MEwwSjBIMEYwRDAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCCwQAAAAAAURO8EJH
US
der
1.49 Kb
whitelisted
1496
LadonGUI.exe
GET
200
97.64.23.206:80
http://busuanzi.ibruce.info/busuanzi?jsonpCallback=BusuanziCallback_21054897779
US
text
111 b
unknown
1496
LadonGUI.exe
GET
200
104.18.21.226:80
http://ocsp2.globalsign.com/gsorganizationvalsha2g2/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBQMnk2cPe3vhNiR6XLHz4QGvBl7BwQUlt5h8b0cFilTHMDMfTuDAEDmGnwCDBhyuElvTh7HbtMMiw%3D%3D
US
der
1.54 Kb
whitelisted
1496
LadonGUI.exe
GET
200
104.18.21.226:80
http://ocsp2.globalsign.com/gsalphasha2g2/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBSE1Wv4CYvTB7dm2OHrrWWWqmtnYQQU9c3VPAhQ%2BWpPOreX2laD5mnSaPcCDGSqYntfYLNu9dpoIw%3D%3D
US
der
1.49 Kb
whitelisted
1496
LadonGUI.exe
GET
200
104.18.20.226:80
http://ocsp.globalsign.com/rootr1/MEwwSjBIMEYwRDAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCCwQAAAAAAURO8DYx
US
der
1.49 Kb
whitelisted
1496
LadonGUI.exe
GET
200
185.199.109.153:80
http://k8gege.org/css/bootstrap.min.css?rev=3.3.7.css
NL
text
19.6 Kb
malicious
1496
LadonGUI.exe
GET
200
185.199.109.153:80
http://k8gege.org/assets/tagcanvas.min.js?rev=2.9.js
NL
text
15.1 Kb
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1496
LadonGUI.exe
185.199.109.153:80
k8gege.org
GitHub, Inc.
NL
shared
1496
LadonGUI.exe
182.61.62.50:80
libs.baidu.com
Beijing Baidu Netcom Science and Technology Co., Ltd.
CN
unknown
1496
LadonGUI.exe
97.64.23.206:80
busuanzi.ibruce.info
IT7 Networks Inc
US
unknown
1496
LadonGUI.exe
118.31.180.41:443
www.cnblogs.com
Hangzhou Alibaba Advertising Co.,Ltd.
CN
suspicious
1496
LadonGUI.exe
103.235.46.191:443
hm.baidu.com
Beijing Baidu Netcom Science and Technology Co., Ltd.
HK
suspicious
1496
LadonGUI.exe
171.107.85.49:80
apps.bdimg.com
No.31,Jin-rong Street
CN
unknown
5652
LadonGUI40.exe
104.243.17.131:80
busuanzi.ibruce.info
Black Fox Limited
US
unknown
5652
LadonGUI40.exe
185.199.109.153:80
k8gege.org
GitHub, Inc.
NL
shared
1496
LadonGUI.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
1496
LadonGUI.exe
163.172.6.164:443
s2.ax1x.com
Online S.a.s.
FR
unknown

DNS requests

Domain
IP
Reputation
k8gege.org
  • 185.199.109.153
malicious
libs.baidu.com
  • 182.61.62.50
whitelisted
apps.bdimg.com
  • 171.107.85.49
  • 125.74.42.49
  • 125.74.1.49
  • 203.56.69.49
  • 218.93.204.49
  • 219.153.113.49
  • 106.38.179.49
  • 110.157.248.49
  • 111.177.8.49
  • 113.62.122.49
whitelisted
busuanzi.ibruce.info
  • 97.64.23.206
  • 104.243.17.131
unknown
hm.baidu.com
  • 103.235.46.191
whitelisted
www.cnblogs.com
  • 118.31.180.41
whitelisted
s2.ax1x.com
  • 163.172.6.164
suspicious
ocsp.globalsign.com
  • 104.18.20.226
  • 104.18.21.226
whitelisted
ocsp2.globalsign.com
  • 104.18.21.226
  • 104.18.20.226
whitelisted
ocsp.digicert.com
  • 93.184.220.29
whitelisted

Threats

No threats detected
No debug info