| File name: | SilverFox.7z |
| Full analysis: | https://app.any.run/tasks/725e2f75-76c1-455e-9fda-731732010343 |
| Verdict: | Malicious activity |
| Threats: | ValleyRAT is a classic remote access trojan first documented in 2023, targeting mainly Windows systems. It is used by threat actors to gain persistent access to infected devices, steal data, and control compromised machines. ValleyRAT is notable for its relatively advanced evasion techniques and its connections to a prominent Chinese APT group. |
| Analysis date: | December 26, 2024, 14:53:45 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-7z-compressed |
| File info: | 7-zip archive data, version 0.4 |
| MD5: | 54ACF97E27719432C0CDD6714D468AB7 |
| SHA1: | 470A06CC4491311EF43E0D979BBA300AD4DF5F72 |
| SHA256: | 4D08AF0A23E230672FAE7CAB550F7F7D512CC02D4EE5DF04F7EB8E997F90A5A4 |
| SSDEEP: | 98304:Rjuu3XoayYXkVZFvOYLXXTsnelbeDpsHUz2tFCqgWOQA56ffNRkYTZT7Zjcdh3Li:ryhQxEsAhk4fJ |
| .7z | | | 7-Zip compressed archive (v0.4) (57.1) |
|---|---|---|
| .7z | | | 7-Zip compressed archive (gen) (42.8) |
| FileVersion: | 7z v0.04 |
|---|
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 624 | "powershell.exe" -Command "Add-MpPreference -ExclusionPath 'C:\'" | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | 安装助手1.0.2.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows PowerShell Exit code: 1 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2612 | "C:\Users\admin\AppData\Local\Temp\is-PQQOT.tmp\安装助手1.0.2.tmp" /SL5="$702EC,4753116,845824,C:\Users\admin\AppData\Local\Temp\Rar$EXb6056.19294\安装助手1.0.2.exe" /SPAWNWND=$4027A /NOTIFYWND=$7028C | C:\Users\admin\AppData\Local\Temp\is-PQQOT.tmp\安装助手1.0.2.tmp | 安装助手1.0.2.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Setup/Uninstall Exit code: 1 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 2672 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | powershell.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3288 | "C:\Users\admin\AppData\Local\Temp\Rar$EXb6056.19294\安装助手1.0.2.exe" /SPAWNWND=$4027A /NOTIFYWND=$7028C | C:\Users\admin\AppData\Local\Temp\Rar$EXb6056.19294\安装助手1.0.2.exe | 安装助手1.0.2.tmp | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: SSRClient.exe Exit code: 1 Version: 1.3.32.1 Modules
| |||||||||||||||
| 4932 | "C:\Users\admin\AppData\Local\Temp\Rar$EXb6056.19294\安装助手1.0.2.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXb6056.19294\安装助手1.0.2.exe | WinRAR.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: SSRClient.exe Exit code: 1 Version: 1.3.32.1 Modules
| |||||||||||||||
| 5732 | "C:\Users\admin\AppData\Local\Temp\is-AUFJ9.tmp\安装助手1.0.2.tmp" /SL5="$7028C,4753116,845824,C:\Users\admin\AppData\Local\Temp\Rar$EXb6056.19294\安装助手1.0.2.exe" | C:\Users\admin\AppData\Local\Temp\is-AUFJ9.tmp\安装助手1.0.2.tmp | — | 安装助手1.0.2.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 1 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 5876 | "C:\Users\admin\AppData\Local\Temp\Rar$EXb6056.19294\安装助手1.0.2.exe" /VERYSILENT | C:\Users\admin\AppData\Local\Temp\Rar$EXb6056.19294\安装助手1.0.2.exe | 安装助手1.0.2.tmp | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: SSRClient.exe Exit code: 0 Version: 1.3.32.1 Modules
| |||||||||||||||
| 6056 | "C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\Downloads\SilverFox.7z | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Version: 5.91.0 Modules
| |||||||||||||||
| 6268 | "C:\Users\admin\AppData\Local\Temp\is-SJESA.tmp\安装助手1.0.2.tmp" /SL5="$8028C,4753116,845824,C:\Users\admin\AppData\Local\Temp\Rar$EXb6056.19294\安装助手1.0.2.exe" /VERYSILENT | C:\Users\admin\AppData\Local\Temp\is-SJESA.tmp\安装助手1.0.2.tmp | 安装助手1.0.2.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| (PID) Process: | (6056) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (6056) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (6056) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (6056) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (6056) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface |
| Operation: | write | Name: | ShowPassword |
Value: 0 | |||
| (PID) Process: | (6056) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\preferences.zip | |||
| (PID) Process: | (6056) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\chromium_ext.zip | |||
| (PID) Process: | (6056) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\omni_23_10_2024_.zip | |||
| (PID) Process: | (6056) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Downloads\SilverFox.7z | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2612 | 安装助手1.0.2.tmp | C:\Users\admin\AppData\Local\Temp\is-30K7C.tmp\_isetup\_setup64.tmp | executable | |
MD5:E4211D6D009757C078A9FAC7FF4F03D4 | SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95 | |||
| 6056 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb6056.19294\安装助手1.0.2.exe | executable | |
MD5:8D24FF51C87BC901CB4C88CB885DC15A | SHA256:52AE54A6103BE491559249ED1ED982B69B06948849A880DB142EB37FF0484A3B | |||
| 6268 | 安装助手1.0.2.tmp | C:\Program Files (x86)\Windows NT\is-CT1M9.tmp | binary | |
MD5:07861A39CF1633A3AE529B0AE04C40E1 | SHA256:F693C2A4124E1E7A072F6FA826D86BFCB2C2D46C584F57107B993355919EAD65 | |||
| 6268 | 安装助手1.0.2.tmp | C:\Users\admin\AppData\Local\Temp\is-25QRA.tmp\_isetup\_setup64.tmp | executable | |
MD5:E4211D6D009757C078A9FAC7FF4F03D4 | SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95 | |||
| 624 | powershell.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive | binary | |
MD5:F395A95DE9129C7E2CDC3001D7FE3256 | SHA256:8512F43DDBA1416BFAFD2F59724CFD81554D32A02B11BC751205450BE9D77EE2 | |||
| 5876 | 安装助手1.0.2.exe | C:\Users\admin\AppData\Local\Temp\is-SJESA.tmp\安装助手1.0.2.tmp | executable | |
MD5:9902FA6D39184B87AED7D94A037912D8 | SHA256:43D9F1FA3BDA81C618CC23FBB4E9D8551305AF0090A3D452C4070F938F6BCFAC | |||
| 4932 | 安装助手1.0.2.exe | C:\Users\admin\AppData\Local\Temp\is-AUFJ9.tmp\安装助手1.0.2.tmp | executable | |
MD5:9902FA6D39184B87AED7D94A037912D8 | SHA256:43D9F1FA3BDA81C618CC23FBB4E9D8551305AF0090A3D452C4070F938F6BCFAC | |||
| 624 | powershell.exe | C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_c0jponte.kly.ps1 | text | |
MD5:D17FE0A3F47BE24A6453E9EF58C94641 | SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 | |||
| 3288 | 安装助手1.0.2.exe | C:\Users\admin\AppData\Local\Temp\is-PQQOT.tmp\安装助手1.0.2.tmp | executable | |
MD5:9902FA6D39184B87AED7D94A037912D8 | SHA256:43D9F1FA3BDA81C618CC23FBB4E9D8551305AF0090A3D452C4070F938F6BCFAC | |||
| 624 | powershell.exe | C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_qqrwducx.x1y.psm1 | text | |
MD5:D17FE0A3F47BE24A6453E9EF58C94641 | SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
4712 | MoUsoCoreWorker.exe | GET | 200 | 23.48.23.167:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | DE | binary | 1.01 Kb | whitelisted |
4712 | MoUsoCoreWorker.exe | GET | 200 | 23.38.73.129:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | DE | binary | 973 b | whitelisted |
7076 | SIHClient.exe | GET | 200 | 23.37.237.227:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | DE | binary | 418 b | whitelisted |
7076 | SIHClient.exe | GET | 200 | 23.37.237.227:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | DE | binary | 408 b | whitelisted |
6768 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | US | binary | 471 b | whitelisted |
1176 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | US | binary | 471 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4712 | MoUsoCoreWorker.exe | 23.48.23.167:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
4712 | MoUsoCoreWorker.exe | 23.38.73.129:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
2736 | svchost.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5064 | SearchApp.exe | 2.21.110.146:443 | — | AKAMAI-AS | DE | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1480 | RUXIMICS.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
3976 | svchost.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
1176 | svchost.exe | 40.126.32.76:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |
arc.msn.com |
| whitelisted |