analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

BLTools v2.8.3.zip

Full analysis: https://app.any.run/tasks/397a7ab9-7903-4344-9b6e-714ed5629c34
Verdict: Malicious activity
Analysis date: December 17, 2023, 20:22:40
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

26974656CBBD89BF9D6847B23BBD9FE3

SHA1:

455015FDB0A5EC1A7D26C3C595B7A072C8694AB1

SHA256:

4CE39F3AD67CC3CFAF0BC35F088E635945E310067AC8779A909A3BFE78F060B5

SSDEEP:

98304:H6U2PyN1UcbMMutZCG2oLddyTDPI/wiE3CoddOuo4ftYUYb7Vo2JOn+pNew4ex/v:IaDPpOGpBxcqIlb+vp11UF5g40U4fk

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 2184)
    • Reads the BIOS version

      • BLTools.exe (PID: 1836)
    • Reads settings of System Certificates

      • BLTools.exe (PID: 1836)
    • Reads the Internet Settings

      • BLTools.exe (PID: 1836)
  • INFO

    • Checks supported languages

      • BLTools.exe (PID: 1836)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 2184)
    • Manual execution by a user

      • BLTools.exe (PID: 1836)
    • Reads the computer name

      • BLTools.exe (PID: 1836)
    • Create files in a temporary directory

      • BLTools.exe (PID: 1836)
    • Reads the machine GUID from the registry

      • BLTools.exe (PID: 1836)
    • Reads Environment values

      • BLTools.exe (PID: 1836)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: Activator.exe
ZipUncompressedSize: 75806
ZipCompressedSize: 46473
ZipCRC: 0xdeb238e3
ZipModifyDate: 2023:12:17 14:55:48
ZipCompression: Deflated
ZipBitFlag: -
ZipRequiredVersion: 20
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
43
Monitored processes
2
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs bltools.exe

Process information

PID
CMD
Path
Indicators
Parent process
2184"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\BLTools v2.8.3.zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
1836"C:\Users\admin\Desktop\New folder\BLTools.exe" C:\Users\admin\Desktop\New folder\BLTools.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
BLTools Cookies Checker
Version:
2.8.3.0
Modules
Images
c:\users\admin\desktop\new folder\bltools.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
Total events
5 927
Read events
5 892
Write events
35
Delete events
0

Modification events

(PID) Process:(2184) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2184) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(2184) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(2184) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2184) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(2184) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2184) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2184) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2184) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2184) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
Executable files
9
Suspicious files
4
Text files
25
Unknown types
0

Dropped files

PID
Process
Filename
Type
2184WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2184.8440\License.dlltext
MD5:ED247628883C6A3CBDBFAC25D3A9A75A
SHA256:5AABF5D125BE004FBEA47047170505244FDAEA63AA51C0C30FECA595A7CCEF2D
2184WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2184.8440\Projects\capmonster.cloud.projtext
MD5:C4A6593B93DEADE325163A2258668DD4
SHA256:067A5DC77C7EFAC341B2D543F01C6CC6E1D5585B7417EBB93C333BF91774116D
2184WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2184.8440\Projects\finn.no.projhtml
MD5:B8C4F5D353086244CE76FFA07FBB0AF0
SHA256:CD35AD207032BF3937B6DCC05CB58F9602D5ABAD3402A1A5E96F2172F47764FE
2184WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2184.8440\MaterialDesignThemes.Wpf.dllexecutable
MD5:824CBF63999F954AA1747F79586A4D3C
SHA256:344E2CEE979E979932F504DC76BD75E97AE1FF46CAA3FE2795ADFE0A866347F7
2184WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2184.8440\CookiesCreator v1.2.exeexecutable
MD5:30C33F45545B68BD1E0D7EC79A090883
SHA256:4E95226CCE6E17FDC39F3A5F9050720D7848BB34CE2DF72E63C878235C5BE630
2184WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2184.8440\Extreme.Net.dllexecutable
MD5:F79F0E3A0361CAC000E2D3553753CD68
SHA256:8A6518AB7419FBEC3AC9875BAA3AFB410AD1398C7AA622A09CD9084EC6CADFCD
2184WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2184.8440\Projects\Ebay.projtext
MD5:A57E89250A50C010B2B6EDD2EFD0B39F
SHA256:51314174405FE1D723621C67C12C03550426F07A83DDCAB9E36E6D992498D899
2184WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2184.8440\Projects\2dehands.be.projtext
MD5:C83ECFBF6D3A250D9D928DF23D069E0C
SHA256:8F63F6C77EED61B0698665F1FCA117B77C7807384310E50C29194D2A3D822689
2184WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2184.8440\AlphaFS.dllexecutable
MD5:F2F6F6798D306D6D7DF4267434B5C5F9
SHA256:837F2CEAB6BBD9BC4BF076F1CB90B3158191888C3055DD2B78A1E23F1C3AAFDD
2184WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2184.8440\MaterialDesignColors.dllexecutable
MD5:5C108C4DA6D03F0FA2C3B4DC7890CB52
SHA256:B5EC30C93B1D2B4631EE2B178750EC92E302E2E331090EC9783981B9572354F8
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
6
DNS requests
2
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1836
BLTools.exe
GET
200
23.53.40.49:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?517f005e14f6813f
unknown
compressed
65.2 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
1836
BLTools.exe
104.26.0.5:443
keyauth.win
CLOUDFLARENET
US
unknown
1836
BLTools.exe
23.53.40.49:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown

DNS requests

Domain
IP
Reputation
keyauth.win
  • 104.26.0.5
  • 172.67.72.57
  • 104.26.1.5
malicious
ctldl.windowsupdate.com
  • 23.53.40.49
  • 23.53.40.83
  • 23.53.40.56
whitelisted

Threats

No threats detected
No debug info