| File name: | Roblox Checker v1.0.1.zip |
| Full analysis: | https://app.any.run/tasks/28e9efa4-3af0-4e0f-847c-155aa3a5c4df |
| Verdict: | Malicious activity |
| Analysis date: | November 21, 2020, 16:27:43 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | 9E44C595C4204B417EE1CB25FC899674 |
| SHA1: | E3DC8A55C4EF034A80FE4F4A249A099453994177 |
| SHA256: | 4D6C8FF952D670639B8B748DECA704E529E641AA491943E4836A0C7FE4E00FD1 |
| SSDEEP: | 24576:5GFHozbH5wlOWgzaH05e+oQkhHiXCCgai9OmgEIa4v0EsaWHhtAbxg:5x5fWgzaUQ+5kxingaiKsO0fTEbq |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2018:09:24 04:38:27 |
| ZipCRC: | 0xc6e1cb70 |
| ZipCompressedSize: | 89521 |
| ZipUncompressedSize: | 220160 |
| ZipFileName: | xNet.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2248 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Roblox Checker v1.0.1.zip" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| (PID) Process: | (2248) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (2248) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (2248) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2248) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Roblox Checker v1.0.1.zip | |||
| (PID) Process: | (2248) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2248) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2248) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2248) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (2248) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\shawty | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2248 | WinRAR.exe | C:\Users\admin\Desktop\shawty\SOCKS4-proxies.txt | text | |
MD5:06759093E9731A265A235ADE16AD4C71 | SHA256:DB3B699D57A3358EAA7D3B3318B7CADCEF2FAD1EB4EA947105770BE99B569921 | |||
| 2248 | WinRAR.exe | C:\Users\admin\Desktop\shawty\xNet.dll | executable | |
MD5:E2EC5217EB1D27F70C0BF35FC3EBDDC6 | SHA256:68BDF5411EB2FD94B12E990BA871580FD73C5A9125EC513E3BC29FF6758AF9C2 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 41.160.100.203:1080 | — | Neotel Pty Ltd | ZA | suspicious |
— | — | 113.212.164.140:5678 | — | PT. Cipta Informatika Cemerlang | ID | unknown |
— | — | 36.67.38.25:30632 | — | PT Telekomunikasi Indonesia | ID | suspicious |
— | — | 185.171.54.35:4153 | — | Shahrad Net Company Ltd. | IR | suspicious |
— | — | 36.67.251.229:4153 | — | PT Telekomunikasi Indonesia | ID | unknown |
— | — | 202.51.100.33:5430 | — | PT iForte Global Internet | ID | unknown |
— | — | 103.200.135.230:4145 | — | AGB Communication Co.Ltd | MM | suspicious |
— | — | 170.79.181.82:4153 | — | TECHTRON ARGENTINA S.A. | AR | unknown |
— | — | 93.35.225.23:4153 | — | Fastweb | IT | unknown |
— | — | 185.171.55.162:4153 | — | Shahrad Net Company Ltd. | IR | suspicious |
Domain | IP | Reputation |
|---|---|---|
www.roblox.com |
| whitelisted |
auth.roblox.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
— | — | Potential Corporate Privacy Violation | POLICY [PTsecurity] Socks4 Connection |
— | — | Potential Corporate Privacy Violation | POLICY [PTsecurity] Socks4 Connection |
— | — | Potential Corporate Privacy Violation | POLICY [PTsecurity] Socks4 Connection |
— | — | Potential Corporate Privacy Violation | POLICY [PTsecurity] Socks4 Connection |
— | — | Potential Corporate Privacy Violation | POLICY [PTsecurity] Socks4 Connection |
— | — | Potential Corporate Privacy Violation | POLICY [PTsecurity] Socks4 Connection |
— | — | Potential Corporate Privacy Violation | POLICY [PTsecurity] Socks4 Connection |
— | — | Potential Corporate Privacy Violation | POLICY [PTsecurity] Socks4 Connection |
— | — | Potential Corporate Privacy Violation | POLICY [PTsecurity] Socks4 Connection |
— | — | Potential Corporate Privacy Violation | POLICY [PTsecurity] Socks4 Connection |