analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

TÀI LIỆU HÀNG HÓA 2019.7z

Full analysis: https://app.any.run/tasks/276dc254-785c-4b1b-be5f-74ad3fc11885
Verdict: Malicious activity
Threats:

Netwire is an advanced RAT — it is a malware that takes control of infected PCs and allows its operators to perform various actions. Unlike many RATs, this one can target every major operating system, including Windows, Linux, and MacOS.

Analysis date: May 20, 2019, 11:58:41
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
rat
netwire
trojan
Indicators:
MIME: application/x-7z-compressed
File info: 7-zip archive data, version 0.4
MD5:

BCCA5A81B99B3EBC92BAA80398373248

SHA1:

F786C50D66680DFA9B7383D946E9BB7D56B9BD04

SHA256:

5486657ABBBD562198AA0020AC84FD5D149381CD17BCC99DE5927311B73E3C00

SSDEEP:

3072:qVovasINzD47ym4xJJW3dwDf9TLzi8jT0WLtwg13mqKnB/VCcW:MNQem4xJJPfNLzdjT0yUqqVO

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • TÀI LIỆU HÀNG HÓA 2019.exe (PID: 2416)
      • TÀI LIỆU HÀNG HÓA 2019.exe (PID: 2996)
      • TÀI LIỆU HÀNG HÓA 2019.exe (PID: 3496)
      • TÀI LIỆU HÀNG HÓA 2019.exe (PID: 3848)
    • NETWIRE was detected

      • TÀI LIỆU HÀNG HÓA 2019.exe (PID: 2996)
    • Changes the autorun value in the registry

      • TÀI LIỆU HÀNG HÓA 2019.exe (PID: 2996)
    • Connects to CnC server

      • TÀI LIỆU HÀNG HÓA 2019.exe (PID: 2996)
  • SUSPICIOUS

    • Application launched itself

      • TÀI LIỆU HÀNG HÓA 2019.exe (PID: 3496)
      • TÀI LIỆU HÀNG HÓA 2019.exe (PID: 2416)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2960)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.7z | 7-Zip compressed archive (v0.4) (57.1)
.7z | 7-Zip compressed archive (gen) (42.8)
No data.
screenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
37
Monitored processes
5
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
drop and start drop and start start winrar.exe tài liệu hàng hóa 2019.exe no specs #NETWIRE tài liệu hàng hóa 2019.exe tài liệu hàng hóa 2019.exe no specs tài liệu hàng hóa 2019.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2960"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\TÀI LIỆU HÀNG HÓA 2019.7z"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.60.0
2416"C:\Users\admin\AppData\Local\Temp\Rar$EXa2960.4410\TÀI LIỆU HÀNG HÓA 2019.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2960.4410\TÀI LIỆU HÀNG HÓA 2019.exeWinRAR.exe
User:
admin
Company:
CHESTNUT4
Integrity Level:
MEDIUM
Exit code:
0
Version:
1.01.0005
2996C:\Users\admin\AppData\Local\Temp\Rar$EXa2960.4410\TÀI LIỆU HÀNG HÓA 2019.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2960.4410\TÀI LIỆU HÀNG HÓA 2019.exe
TÀI LIỆU HÀNG HÓA 2019.exe
User:
admin
Company:
CHESTNUT4
Integrity Level:
MEDIUM
Version:
1.01.0005
3496"C:\Users\admin\AppData\Local\Temp\Rar$EXa2960.7647\TÀI LIỆU HÀNG HÓA 2019.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2960.7647\TÀI LIỆU HÀNG HÓA 2019.exeWinRAR.exe
User:
admin
Company:
CHESTNUT4
Integrity Level:
MEDIUM
Exit code:
0
Version:
1.01.0005
3848C:\Users\admin\AppData\Local\Temp\Rar$EXa2960.7647\TÀI LIỆU HÀNG HÓA 2019.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2960.7647\TÀI LIỆU HÀNG HÓA 2019.exeTÀI LIỆU HÀNG HÓA 2019.exe
User:
admin
Company:
CHESTNUT4
Integrity Level:
MEDIUM
Version:
1.01.0005
Total events
442
Read events
428
Write events
14
Delete events
0

Modification events

(PID) Process:(2960) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2960) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2960) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2960) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\TÀI LIỆU HÀNG HÓA 2019.7z
(PID) Process:(2960) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2960) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2960) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2960) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2960) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(2960) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
Executable files
2
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
2960WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2960.4410\TÀI LIỆU HÀNG HÓA 2019.exeexecutable
MD5:95D30E03EE30D9BCB3DB9E0CAAF1D4E6
SHA256:D92A4D000C4571398FE5A2B578C5F9D3CBFB6EDEA1DDD59BE5E418B28CAE9D2D
2960WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2960.7647\TÀI LIỆU HÀNG HÓA 2019.exeexecutable
MD5:95D30E03EE30D9BCB3DB9E0CAAF1D4E6
SHA256:D92A4D000C4571398FE5A2B578C5F9D3CBFB6EDEA1DDD59BE5E418B28CAE9D2D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
3
DNS requests
4
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2996
TÀI LIỆU HÀNG HÓA 2019.exe
185.244.31.116:32144
duc1234.duckdns.org
malicious

DNS requests

Domain
IP
Reputation
duc1234.duckdns.org
  • 185.244.31.116
malicious

Threats

PID
Process
Class
Message
Misc activity
ET INFO DYNAMIC_DNS Query to *.duckdns. Domain
Misc activity
ET INFO DYNAMIC_DNS Query to *.duckdns. Domain
2996
TÀI LIỆU HÀNG HÓA 2019.exe
A Network Trojan was detected
MALWARE [PTsecurity] Netwire.RAT
Misc activity
ET INFO DYNAMIC_DNS Query to *.duckdns. Domain
2996
TÀI LIỆU HÀNG HÓA 2019.exe
A Network Trojan was detected
MALWARE [PTsecurity] Netwire.RAT
2996
TÀI LIỆU HÀNG HÓA 2019.exe
A Network Trojan was detected
ET TROJAN Possible Netwire RAT Client HeartBeat C2
2996
TÀI LIỆU HÀNG HÓA 2019.exe
A Network Trojan was detected
ET TROJAN Possible Netwire RAT Client HeartBeat C2
2996
TÀI LIỆU HÀNG HÓA 2019.exe
Generic Protocol Command Decode
SURICATA STREAM FIN2 FIN with wrong seq
Misc activity
ET INFO DYNAMIC_DNS Query to *.duckdns. Domain
2996
TÀI LIỆU HÀNG HÓA 2019.exe
A Network Trojan was detected
MALWARE [PTsecurity] Netwire.RAT
1 ETPRO signatures available at the full report
No debug info