| File name: | Netflix Checker Proxyless V1.82.rar |
| Full analysis: | https://app.any.run/tasks/c555fda9-910b-47aa-a678-38dda19bf1fb |
| Verdict: | Malicious activity |
| Analysis date: | June 04, 2019, 14:25:14 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v5 |
| MD5: | 92F334A13215EAEFE9647116DF47878C |
| SHA1: | A75154D55C26DCC091DBCEDDE0D37C769B6D2625 |
| SHA256: | 5913227C5C9404F86B7069F1DA6638DA1DD48F459A3C409B7515A4F35494D67E |
| SSDEEP: | 3072:XShHvtjiZUOmTO1cd+NdV+OZCPqPZriYrIDQ3pS9t1:ihPYUCcMNqOZBBrpI6e1 |
| .rar | | | RAR compressed archive (v5.0) (61.5) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1320 | cmd /c ""C:\Users\admin\Desktop\uninstall.bat" " | C:\Windows\system32\cmd.exe | — | Netflix Checker.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 1 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2340 | "C:\Users\admin\AppData\Local\Temp\Netflix Checker.exe" | C:\Users\admin\AppData\Local\Temp\Netflix Checker.exe | Netflix Checker Proxyless V1.82.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Exit code: 0 Version: 0.0.0.0 Modules
| |||||||||||||||
| 2592 | reg add HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\Run /V "" /t REG_SZ /d "C:\Users\admin\AppData\Roaming\Netflix Checker | C:\Windows\system32\reg.exe | cmd.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Registry Console Tool Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2636 | icacls "C:\Users\admin\AppData\Roaming" /grant Everyone:(OI)(CI)F /T | C:\Windows\system32\icacls.exe | cmd.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2800 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Netflix Checker Proxyless V1.82.rar" | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 3392 | "C:\Program Files\Windows NT\Accessories\WORDPAD.EXE" "C:\Users\admin\AppData\Roaming\Netflix Checker" | C:\Program Files\Windows NT\Accessories\WORDPAD.EXE | — | rundll32.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Wordpad Application Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3488 | "C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\AppData\Roaming\Netflix Checker | C:\Windows\system32\rundll32.exe | — | Netflix Checker.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3884 | "C:\Users\admin\AppData\Local\Temp\Netflix Checker v0.2.2.exe" | C:\Users\admin\AppData\Local\Temp\Netflix Checker v0.2.2.exe | — | Netflix Checker Proxyless V1.82.exe | |||||||||||
User: admin Company: julioverne Integrity Level: HIGH Description: Netflix Checker Exit code: 0 Version: 2.2.0.0 Modules
| |||||||||||||||
| 4000 | "C:\Users\admin\Desktop\Netflix Checker Proxyless V1.82.exe" | C:\Users\admin\Desktop\Netflix Checker Proxyless V1.82.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Exit code: 0 Version: 0.0.0.0 Modules
| |||||||||||||||
| (PID) Process: | (2800) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (2800) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (2800) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2800) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Netflix Checker Proxyless V1.82.rar | |||
| (PID) Process: | (2800) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2800) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2800) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2800) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (2800) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin |
| Operation: | write | Name: | Placement |
Value: 2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000 | |||
| (PID) Process: | (2800) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\General |
| Operation: | write | Name: | LastFolder |
Value: C:\Users\admin\AppData\Local\Temp | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2800 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa2800.34143\Netflix Checker Proxyless V1.82.exe | — | |
MD5:— | SHA256:— | |||
| 4000 | Netflix Checker Proxyless V1.82.exe | C:\Users\admin\AppData\Local\Temp\Netflix Checker.exe | executable | |
MD5:D1F6EBAF6F4E6C5A0856E2724CFC4FBD | SHA256:D74CBC64DBC76FB89E9C82DF3EF0BED2EA023B415F7C8341A8D07265F6DC4499 | |||
| 2340 | Netflix Checker.exe | C:\Users\admin\AppData\Roaming\Netflix Checker | executable | |
MD5:D1F6EBAF6F4E6C5A0856E2724CFC4FBD | SHA256:D74CBC64DBC76FB89E9C82DF3EF0BED2EA023B415F7C8341A8D07265F6DC4499 | |||
| 2340 | Netflix Checker.exe | C:\Users\admin\Desktop\uninstall.bat | text | |
MD5:E6B1838BED335DD052D15E2A47FDCAAB | SHA256:968D37F4B63F66B2454C429BD39112803B2CA3A753D7436954639B48FEBC2EEB | |||
| 4000 | Netflix Checker Proxyless V1.82.exe | C:\Users\admin\AppData\Local\Temp\Netflix Checker v0.2.2.exe | executable | |
MD5:C281AFD76E71557E53A1B90A42A30C0F | SHA256:6FD0CFCB7C15612D415A89901BFFD3187792056C963CEBA586A1359B0AA88971 | |||