ANY.RUN Interactive Sandbox
- Full browser-level visibility into phishing
- Huge database of samples and IOCs
- Interactivity in a safe environment
- Actionable Tier 1 reports
Get full visibility into malware and phishing behavior in a safe environment.
| File name: | SilverFox.7z |
| Full analysis: | https://app.any.run/tasks/725e2f75-76c1-455e-9fda-731732010343 |
| Verdict: | Malicious activity |
| Threats: | ValleyRAT is a classic remote access trojan first documented in 2023, targeting mainly Windows systems. It is used by threat actors to gain persistent access to infected devices, steal data, and control compromised machines. ValleyRAT is notable for its relatively advanced evasion techniques and its connections to a prominent Chinese APT group. |
| Analysis date: | December 26, 2024, 14:53:45 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-7z-compressed |
| File info: | 7-zip archive data, version 0.4 |
| MD5: | 54ACF97E27719432C0CDD6714D468AB7 |
| SHA1: | 470A06CC4491311EF43E0D979BBA300AD4DF5F72 |
| SHA256: | 4D08AF0A23E230672FAE7CAB550F7F7D512CC02D4EE5DF04F7EB8E997F90A5A4 |
| SSDEEP: | 98304:Rjuu3XoayYXkVZFvOYLXXTsnelbeDpsHUz2tFCqgWOQA56ffNRkYTZT7Zjcdh3Li:ryhQxEsAhk4fJ |
| .7z | | | 7-Zip compressed archive (v0.4) (57.1) |
|---|---|---|
| .7z | | | 7-Zip compressed archive (gen) (42.8) |
| FileVersion: | 7z v0.04 |
|---|
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 624 | "powershell.exe" -Command "Add-MpPreference -ExclusionPath 'C:\'" | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | 安装助手1.0.2.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows PowerShell Exit code: 1 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2612 | "C:\Users\admin\AppData\Local\Temp\is-PQQOT.tmp\安装助手1.0.2.tmp" /SL5="$702EC,4753116,845824,C:\Users\admin\AppData\Local\Temp\Rar$EXb6056.19294\安装助手1.0.2.exe" /SPAWNWND=$4027A /NOTIFYWND=$7028C | C:\Users\admin\AppData\Local\Temp\is-PQQOT.tmp\安装助手1.0.2.tmp | 安装助手1.0.2.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Setup/Uninstall Exit code: 1 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 2672 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | powershell.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3288 | "C:\Users\admin\AppData\Local\Temp\Rar$EXb6056.19294\安装助手1.0.2.exe" /SPAWNWND=$4027A /NOTIFYWND=$7028C | C:\Users\admin\AppData\Local\Temp\Rar$EXb6056.19294\安装助手1.0.2.exe | 安装助手1.0.2.tmp | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: SSRClient.exe Exit code: 1 Version: 1.3.32.1 Modules
| |||||||||||||||
| 4932 | "C:\Users\admin\AppData\Local\Temp\Rar$EXb6056.19294\安装助手1.0.2.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXb6056.19294\安装助手1.0.2.exe | WinRAR.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: SSRClient.exe Exit code: 1 Version: 1.3.32.1 Modules
| |||||||||||||||
| 5732 | "C:\Users\admin\AppData\Local\Temp\is-AUFJ9.tmp\安装助手1.0.2.tmp" /SL5="$7028C,4753116,845824,C:\Users\admin\AppData\Local\Temp\Rar$EXb6056.19294\安装助手1.0.2.exe" | C:\Users\admin\AppData\Local\Temp\is-AUFJ9.tmp\安装助手1.0.2.tmp | — | 安装助手1.0.2.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 1 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 5876 | "C:\Users\admin\AppData\Local\Temp\Rar$EXb6056.19294\安装助手1.0.2.exe" /VERYSILENT | C:\Users\admin\AppData\Local\Temp\Rar$EXb6056.19294\安装助手1.0.2.exe | 安装助手1.0.2.tmp | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: SSRClient.exe Exit code: 0 Version: 1.3.32.1 Modules
| |||||||||||||||
| 6056 | "C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\Downloads\SilverFox.7z | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Version: 5.91.0 Modules
| |||||||||||||||
| 6268 | "C:\Users\admin\AppData\Local\Temp\is-SJESA.tmp\安装助手1.0.2.tmp" /SL5="$8028C,4753116,845824,C:\Users\admin\AppData\Local\Temp\Rar$EXb6056.19294\安装助手1.0.2.exe" /VERYSILENT | C:\Users\admin\AppData\Local\Temp\is-SJESA.tmp\安装助手1.0.2.tmp | 安装助手1.0.2.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| (PID) Process: | (6056) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (6056) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (6056) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (6056) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (6056) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface |
| Operation: | write | Name: | ShowPassword |
Value: 0 | |||
| (PID) Process: | (6056) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\preferences.zip | |||
| (PID) Process: | (6056) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\chromium_ext.zip | |||
| (PID) Process: | (6056) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\omni_23_10_2024_.zip | |||
| (PID) Process: | (6056) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Downloads\SilverFox.7z | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3288 | 安装助手1.0.2.exe | C:\Users\admin\AppData\Local\Temp\is-PQQOT.tmp\安装助手1.0.2.tmp | executable | |
MD5:9902FA6D39184B87AED7D94A037912D8 | SHA256:43D9F1FA3BDA81C618CC23FBB4E9D8551305AF0090A3D452C4070F938F6BCFAC | |||
| 5876 | 安装助手1.0.2.exe | C:\Users\admin\AppData\Local\Temp\is-SJESA.tmp\安装助手1.0.2.tmp | executable | |
MD5:9902FA6D39184B87AED7D94A037912D8 | SHA256:43D9F1FA3BDA81C618CC23FBB4E9D8551305AF0090A3D452C4070F938F6BCFAC | |||
| 6056 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb6056.19294\安装助手1.0.2.exe | executable | |
MD5:8D24FF51C87BC901CB4C88CB885DC15A | SHA256:52AE54A6103BE491559249ED1ED982B69B06948849A880DB142EB37FF0484A3B | |||
| 4932 | 安装助手1.0.2.exe | C:\Users\admin\AppData\Local\Temp\is-AUFJ9.tmp\安装助手1.0.2.tmp | executable | |
MD5:9902FA6D39184B87AED7D94A037912D8 | SHA256:43D9F1FA3BDA81C618CC23FBB4E9D8551305AF0090A3D452C4070F938F6BCFAC | |||
| 2612 | 安装助手1.0.2.tmp | C:\Users\admin\AppData\Local\Temp\is-30K7C.tmp\update.vac | executable | |
MD5:1D1464C73252978A58AC925ECE57F0FB | SHA256:05184064FB017025E0704D75D199BAE02EBBD30AE4D76FB237DF9596CE6450AA | |||
| 624 | powershell.exe | C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_c0jponte.kly.ps1 | text | |
MD5:D17FE0A3F47BE24A6453E9EF58C94641 | SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 | |||
| 624 | powershell.exe | C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_qqrwducx.x1y.psm1 | text | |
MD5:D17FE0A3F47BE24A6453E9EF58C94641 | SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 | |||
| 6268 | 安装助手1.0.2.tmp | C:\Users\admin\AppData\Local\Temp\is-25QRA.tmp\_isetup\_setup64.tmp | executable | |
MD5:E4211D6D009757C078A9FAC7FF4F03D4 | SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95 | |||
| 6268 | 安装助手1.0.2.tmp | C:\Users\admin\AppData\Local\Temp\is-25QRA.tmp\update.vac | executable | |
MD5:1D1464C73252978A58AC925ECE57F0FB | SHA256:05184064FB017025E0704D75D199BAE02EBBD30AE4D76FB237DF9596CE6450AA | |||
| 624 | powershell.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive | binary | |
MD5:F395A95DE9129C7E2CDC3001D7FE3256 | SHA256:8512F43DDBA1416BFAFD2F59724CFD81554D32A02B11BC751205450BE9D77EE2 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
4712 | MoUsoCoreWorker.exe | GET | 200 | 23.48.23.167:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | DE | binary | 1.01 Kb | whitelisted |
1176 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | US | binary | 471 b | whitelisted |
7076 | SIHClient.exe | GET | 200 | 23.37.237.227:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | DE | binary | 418 b | whitelisted |
7076 | SIHClient.exe | GET | 200 | 23.37.237.227:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | DE | binary | 408 b | whitelisted |
6768 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | US | binary | 471 b | whitelisted |
4712 | MoUsoCoreWorker.exe | GET | 200 | 23.38.73.129:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | DE | binary | 973 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4712 | MoUsoCoreWorker.exe | 23.48.23.167:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
4712 | MoUsoCoreWorker.exe | 23.38.73.129:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
2736 | svchost.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5064 | SearchApp.exe | 2.21.110.146:443 | — | AKAMAI-AS | DE | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1480 | RUXIMICS.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
3976 | svchost.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
1176 | svchost.exe | 40.126.32.76:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |
arc.msn.com |
| whitelisted |