File name:

XSONICXFV2TRAINER 16.0 2019.rar

Full analysis: https://app.any.run/tasks/9b420295-eaa3-454f-9198-01dfcb0dd493
Verdict: Malicious activity
Analysis date: February 09, 2019, 02:42:25
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

F5A74DCD5F000E1EFA1977EA8DCD0BEE

SHA1:

5996D137526A034543ACDE1769B93075311E8732

SHA256:

54B8917999F6ABD5A9110BE55D6477DE3CD1284E3CD94956E079E97A82EE83A2

SSDEEP:

196608:OuQZAHI1Mimsw47jHSmuk7pouX4XWwl2PuRQRGHtZ67u0MN8ek/ELZDPiXjWqE9R:QOHezdfFVpNxw8PyQR0tZk4cO6Xj1E9R

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • FV2-XSONICX(Windows 32Bits).exe (PID: 3944)
      • FV2-XSONICX(Windows 32Bits).exe (PID: 3884)
      • FV2-XSONICX(Windows 32Bits).exe (PID: 3340)
    • Changes the autorun value in the registry

      • WScript.exe (PID: 3652)
      • wscript.exe (PID: 1472)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2492)
      • FV2-XSONICX(Windows 32Bits).exe (PID: 3944)
    • Creates files in the user directory

      • FV2-XSONICX(Windows 32Bits).exe (PID: 3944)
    • Executes scripts

      • FV2-XSONICX(Windows 32Bits).exe (PID: 3944)
      • WScript.exe (PID: 3652)
    • Application launched itself

      • WScript.exe (PID: 3652)
    • Connects to unusual port

      • wscript.exe (PID: 1472)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
45
Monitored processes
6
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start drop and start winrar.exe fv2-xsonicx(windows 32bits).exe no specs fv2-xsonicx(windows 32bits).exe fv2-xsonicx(windows 32bits).exe no specs wscript.exe wscript.exe

Process information

PID
CMD
Path
Indicators
Parent process
1472"C:\Windows\System32\wscript.exe" //B "C:\Users\admin\AppData\Local\Temp\Farmville 2 XSONICX TRAINER 15.5.2019.vbs"C:\Windows\System32\wscript.exe
WScript.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft ® Windows Based Script Host
Exit code:
0
Version:
5.8.7600.16385
Modules
Images
c:\windows\system32\wscript.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2492"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\XSONICXFV2TRAINER 16.0 2019.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3340"C:\Users\admin\AppData\Roaming\FV2-XSONICX(Windows 32Bits).exe" C:\Users\admin\AppData\Roaming\FV2-XSONICX(Windows 32Bits).exeFV2-XSONICX(Windows 32Bits).exe
User:
admin
Company:
Fv2XsonicXTrainer
Integrity Level:
HIGH
Description:
Fv2XsonicXTrainer
Exit code:
3221225781
Version:
6.6.0.4837
Modules
Images
c:\users\admin\appdata\roaming\fv2-xsonicx(windows 32bits).exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\gdi32.dll
3652"C:\Windows\System32\WScript.exe" "C:\Users\admin\AppData\Roaming\Farmville 2 XSONICX TRAINER 15.5.2019.vbs" C:\Windows\System32\WScript.exe
FV2-XSONICX(Windows 32Bits).exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft ® Windows Based Script Host
Exit code:
0
Version:
5.8.7600.16385
Modules
Images
c:\windows\system32\wscript.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3884"C:\Users\admin\Desktop\XSONICXFV2TRAINER 16.0 2019\XSONICXFV2TRAINER\FV2-XSONICX(Windows 32Bits).exe" C:\Users\admin\Desktop\XSONICXFV2TRAINER 16.0 2019\XSONICXFV2TRAINER\FV2-XSONICX(Windows 32Bits).exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\xsonicxfv2trainer 16.0 2019\xsonicxfv2trainer\fv2-xsonicx(windows 32bits).exe
c:\systemroot\system32\ntdll.dll
3944"C:\Users\admin\Desktop\XSONICXFV2TRAINER 16.0 2019\XSONICXFV2TRAINER\FV2-XSONICX(Windows 32Bits).exe" C:\Users\admin\Desktop\XSONICXFV2TRAINER 16.0 2019\XSONICXFV2TRAINER\FV2-XSONICX(Windows 32Bits).exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\xsonicxfv2trainer 16.0 2019\xsonicxfv2trainer\fv2-xsonicx(windows 32bits).exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
Total events
933
Read events
873
Write events
60
Delete events
0

Modification events

(PID) Process:(2492) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2492) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2492) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2492) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\XSONICXFV2TRAINER 16.0 2019.rar
(PID) Process:(2492) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2492) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2492) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2492) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2492) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
(PID) Process:(2492) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\General
Operation:writeName:LastFolder
Value:
C:\Users\admin\Desktop
Executable files
2
Suspicious files
0
Text files
5
Unknown types
0

Dropped files

PID
Process
Filename
Type
2492WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2492.18642\XSONICXFV2TRAINER 16.0 2019\XSONICXFV2TRAINER\FV2-XSONICX(Windows 64Bits).exe
MD5:
SHA256:
2492WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2492.18642\XSONICXFV2TRAINER 16.0 2019\XSONICXFV2TRAINER\FV2-XSONICX-V14.0.XSONICX
MD5:
SHA256:
2492WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2492.18642\XSONICXFV2TRAINER 16.0 2019\XSONICXFV2TRAINER\FV2-XSONICX.XSONICX
MD5:
SHA256:
2492WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2492.18642\XSONICXFV2TRAINER 16.0 2019\XSONICXFV2TRAINER\lua53-32.dll
MD5:
SHA256:
2492WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2492.18642\XSONICXFV2TRAINER 16.0 2019\XSONICXFV2TRAINER\lua53-64.dll
MD5:
SHA256:
2492WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2492.18642\XSONICXFV2TRAINER 16.0 2019\XSONICXFV2TRAINER\FV2-XSONICX(Windows 32Bits).exeexecutable
MD5:
SHA256:
1472wscript.exeC:\Farmville 2 XSONICX TRAINER 15.5.2019.vbstext
MD5:
SHA256:
3652WScript.exeC:\Users\admin\AppData\Local\Temp\Farmville 2 XSONICX TRAINER 15.5.2019.vbstext
MD5:
SHA256:
3944FV2-XSONICX(Windows 32Bits).exeC:\Users\admin\AppData\Roaming\FV2-XSONICX(Windows 32Bits).exeexecutable
MD5:
SHA256:
3652WScript.exeC:\Farmville 2 XSONICX TRAINER 15.5.2019.vbstext
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
5
DNS requests
3
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1472
wscript.exe
87.19.70.7:1188
musigiallifuck.ddns.net
Telecom Italia
IT
malicious

DNS requests

Domain
IP
Reputation
musigiallifuck.ddns.net
  • 87.19.70.7
malicious
dns.msftncsi.com
  • 131.107.255.255
shared

Threats

No threats detected
No debug info