File name:

SilverFox.7z

Full analysis: https://app.any.run/tasks/725e2f75-76c1-455e-9fda-731732010343
Verdict: Malicious activity
Threats:

ValleyRAT is a classic remote access trojan first documented in 2023, targeting mainly Windows systems. It is used by threat actors to gain persistent access to infected devices, steal data, and control compromised machines. ValleyRAT is notable for its relatively advanced evasion techniques and its connections to a prominent Chinese APT group.

Analysis date: December 26, 2024, 14:53:45
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
auto
valleyrat
silverfox
Indicators:
MIME: application/x-7z-compressed
File info: 7-zip archive data, version 0.4
MD5:

54ACF97E27719432C0CDD6714D468AB7

SHA1:

470A06CC4491311EF43E0D979BBA300AD4DF5F72

SHA256:

4D08AF0A23E230672FAE7CAB550F7F7D512CC02D4EE5DF04F7EB8E997F90A5A4

SSDEEP:

98304:Rjuu3XoayYXkVZFvOYLXXTsnelbeDpsHUz2tFCqgWOQA56ffNRkYTZT7Zjcdh3Li:ryhQxEsAhk4fJ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • VALLEYRAT has been found (auto)

      • WinRAR.exe (PID: 6056)
    • Adds path to the Windows Defender exclusion list

      • 安装助手1.0.2.tmp (PID: 2612)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • 安装助手1.0.2.exe (PID: 4932)
      • 安装助手1.0.2.tmp (PID: 2612)
      • 安装助手1.0.2.exe (PID: 3288)
      • 安装助手1.0.2.exe (PID: 5876)
      • 安装助手1.0.2.tmp (PID: 6268)
    • Reads the Windows owner or organization settings

      • 安装助手1.0.2.tmp (PID: 2612)
    • Process drops legitimate windows executable

      • 安装助手1.0.2.tmp (PID: 2612)
      • 安装助手1.0.2.tmp (PID: 6268)
    • Script adds exclusion path to Windows Defender

      • 安装助手1.0.2.tmp (PID: 2612)
    • Starts POWERSHELL.EXE for commands execution

      • 安装助手1.0.2.tmp (PID: 2612)
    • Reads security settings of Internet Explorer

      • 安装助手1.0.2.tmp (PID: 2612)
  • INFO

    • The process uses the downloaded file

      • WinRAR.exe (PID: 6056)
      • 安装助手1.0.2.tmp (PID: 2612)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 6056)
    • Checks supported languages

      • 安装助手1.0.2.exe (PID: 4932)
      • 安装助手1.0.2.tmp (PID: 5732)
      • 安装助手1.0.2.tmp (PID: 2612)
      • 安装助手1.0.2.tmp (PID: 6268)
    • Create files in a temporary directory

      • 安装助手1.0.2.exe (PID: 3288)
      • 安装助手1.0.2.tmp (PID: 2612)
      • 安装助手1.0.2.exe (PID: 5876)
      • 安装助手1.0.2.tmp (PID: 6268)
    • Reads the computer name

      • 安装助手1.0.2.tmp (PID: 2612)
      • 安装助手1.0.2.tmp (PID: 6268)
    • Checks if a key exists in the options dictionary (POWERSHELL)

      • powershell.exe (PID: 624)
    • Script raised an exception (POWERSHELL)

      • powershell.exe (PID: 624)
    • Creates files in the program directory

      • 安装助手1.0.2.tmp (PID: 6268)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.7z | 7-Zip compressed archive (v0.4) (57.1)
.7z | 7-Zip compressed archive (gen) (42.8)

EXIF

ZIP

FileVersion: 7z v0.04
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
138
Monitored processes
9
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
624"powershell.exe" -Command "Add-MpPreference -ExclusionPath 'C:\'"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe安装助手1.0.2.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows PowerShell
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
2612"C:\Users\admin\AppData\Local\Temp\is-PQQOT.tmp\安装助手1.0.2.tmp" /SL5="$702EC,4753116,845824,C:\Users\admin\AppData\Local\Temp\Rar$EXb6056.19294\安装助手1.0.2.exe" /SPAWNWND=$4027A /NOTIFYWND=$7028C C:\Users\admin\AppData\Local\Temp\is-PQQOT.tmp\安装助手1.0.2.tmp
安装助手1.0.2.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
1
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-pqqot.tmp\安装助手1.0.2.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
2672\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3288"C:\Users\admin\AppData\Local\Temp\Rar$EXb6056.19294\安装助手1.0.2.exe" /SPAWNWND=$4027A /NOTIFYWND=$7028C C:\Users\admin\AppData\Local\Temp\Rar$EXb6056.19294\安装助手1.0.2.exe
安装助手1.0.2.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
SSRClient.exe
Exit code:
1
Version:
1.3.32.1
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb6056.19294\安装助手1.0.2.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comctl32.dll
4932"C:\Users\admin\AppData\Local\Temp\Rar$EXb6056.19294\安装助手1.0.2.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb6056.19294\安装助手1.0.2.exe
WinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
SSRClient.exe
Exit code:
1
Version:
1.3.32.1
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb6056.19294\安装助手1.0.2.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\comctl32.dll
c:\windows\syswow64\advapi32.dll
5732"C:\Users\admin\AppData\Local\Temp\is-AUFJ9.tmp\安装助手1.0.2.tmp" /SL5="$7028C,4753116,845824,C:\Users\admin\AppData\Local\Temp\Rar$EXb6056.19294\安装助手1.0.2.exe" C:\Users\admin\AppData\Local\Temp\is-AUFJ9.tmp\安装助手1.0.2.tmp安装助手1.0.2.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
1
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-aufj9.tmp\安装助手1.0.2.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\comdlg32.dll
c:\windows\syswow64\msvcrt.dll
5876"C:\Users\admin\AppData\Local\Temp\Rar$EXb6056.19294\安装助手1.0.2.exe" /VERYSILENTC:\Users\admin\AppData\Local\Temp\Rar$EXb6056.19294\安装助手1.0.2.exe
安装助手1.0.2.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
SSRClient.exe
Exit code:
0
Version:
1.3.32.1
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb6056.19294\安装助手1.0.2.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comctl32.dll
6056"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\Downloads\SilverFox.7zC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
6268"C:\Users\admin\AppData\Local\Temp\is-SJESA.tmp\安装助手1.0.2.tmp" /SL5="$8028C,4753116,845824,C:\Users\admin\AppData\Local\Temp\Rar$EXb6056.19294\安装助手1.0.2.exe" /VERYSILENTC:\Users\admin\AppData\Local\Temp\is-SJESA.tmp\安装助手1.0.2.tmp
安装助手1.0.2.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-sjesa.tmp\安装助手1.0.2.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
Total events
7 496
Read events
7 487
Write events
9
Delete events
0

Modification events

(PID) Process:(6056) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(6056) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(6056) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(6056) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(6056) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
(PID) Process:(6056) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(6056) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(6056) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(6056) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Downloads\SilverFox.7z
Executable files
11
Suspicious files
3
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
2612安装助手1.0.2.tmpC:\Users\admin\AppData\Local\Temp\is-30K7C.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
6056WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb6056.19294\安装助手1.0.2.exeexecutable
MD5:8D24FF51C87BC901CB4C88CB885DC15A
SHA256:52AE54A6103BE491559249ED1ED982B69B06948849A880DB142EB37FF0484A3B
6268安装助手1.0.2.tmpC:\Program Files (x86)\Windows NT\is-CT1M9.tmpbinary
MD5:07861A39CF1633A3AE529B0AE04C40E1
SHA256:F693C2A4124E1E7A072F6FA826D86BFCB2C2D46C584F57107B993355919EAD65
6268安装助手1.0.2.tmpC:\Users\admin\AppData\Local\Temp\is-25QRA.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
624powershell.exeC:\Users\admin\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractivebinary
MD5:F395A95DE9129C7E2CDC3001D7FE3256
SHA256:8512F43DDBA1416BFAFD2F59724CFD81554D32A02B11BC751205450BE9D77EE2
5876安装助手1.0.2.exeC:\Users\admin\AppData\Local\Temp\is-SJESA.tmp\安装助手1.0.2.tmpexecutable
MD5:9902FA6D39184B87AED7D94A037912D8
SHA256:43D9F1FA3BDA81C618CC23FBB4E9D8551305AF0090A3D452C4070F938F6BCFAC
4932安装助手1.0.2.exeC:\Users\admin\AppData\Local\Temp\is-AUFJ9.tmp\安装助手1.0.2.tmpexecutable
MD5:9902FA6D39184B87AED7D94A037912D8
SHA256:43D9F1FA3BDA81C618CC23FBB4E9D8551305AF0090A3D452C4070F938F6BCFAC
624powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_c0jponte.kly.ps1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
3288安装助手1.0.2.exeC:\Users\admin\AppData\Local\Temp\is-PQQOT.tmp\安装助手1.0.2.tmpexecutable
MD5:9902FA6D39184B87AED7D94A037912D8
SHA256:43D9F1FA3BDA81C618CC23FBB4E9D8551305AF0090A3D452C4070F938F6BCFAC
624powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_qqrwducx.x1y.psm1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
30
DNS requests
16
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4712
MoUsoCoreWorker.exe
GET
200
23.48.23.167:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
DE
binary
1.01 Kb
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
23.38.73.129:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
DE
binary
973 b
whitelisted
7076
SIHClient.exe
GET
200
23.37.237.227:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
DE
binary
418 b
whitelisted
7076
SIHClient.exe
GET
200
23.37.237.227:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
DE
binary
408 b
whitelisted
6768
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
US
binary
471 b
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
binary
471 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4712
MoUsoCoreWorker.exe
23.48.23.167:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4712
MoUsoCoreWorker.exe
23.38.73.129:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
2736
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5064
SearchApp.exe
2.21.110.146:443
AKAMAI-AS
DE
unknown
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1480
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3976
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1176
svchost.exe
40.126.32.76:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.206
whitelisted
crl.microsoft.com
  • 23.48.23.167
  • 23.48.23.156
  • 23.48.23.164
  • 23.48.23.143
  • 23.48.23.159
  • 23.48.23.166
  • 23.48.23.194
whitelisted
www.microsoft.com
  • 23.38.73.129
  • 23.37.237.227
whitelisted
settings-win.data.microsoft.com
  • 4.231.128.59
whitelisted
login.live.com
  • 40.126.32.76
  • 40.126.32.138
  • 20.190.160.14
  • 20.190.160.22
  • 40.126.32.68
  • 40.126.32.133
  • 20.190.160.20
  • 20.190.160.17
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
go.microsoft.com
  • 23.35.238.131
whitelisted
slscr.update.microsoft.com
  • 52.149.20.212
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.242.39.171
whitelisted
arc.msn.com
  • 20.31.169.57
whitelisted

Threats

No threats detected
No debug info