File name:

Monotone-HWID-Spoofer.zip

Full analysis: https://app.any.run/tasks/e37be01a-6b57-42d8-aa6d-80a81b8a21e7
Verdict: Malicious activity
Analysis date: July 10, 2020, 03:59:54
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

991EB28F2A69E3005B35ED24D66F8412

SHA1:

AD2EE312FFC0D8ACBFAEBA8D7EE416DE1CB05AB4

SHA256:

59DE0781B884DC65532693E485B1AC50178585957CC3F7B673114846119912B0

SSDEEP:

24576:t2Y/OLZgrhGnD6Yr9AbzVBF9+X/GqrsYK0kqGvm6QQvUUAv7quZnozLmMBXLA:t8Z2rrtBF9lbE5GO6JvhW7TZno396

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • GetInput.exe (PID: 3652)
      • batbox.exe (PID: 3360)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2088)
    • Uses TASKLIST.EXE to query information about running processes

      • cmd.exe (PID: 572)
  • INFO

    • Manual execution by user

      • GetInput.exe (PID: 3652)
      • cmd.exe (PID: 1764)
      • cmd.exe (PID: 572)
      • cmd.exe (PID: 236)
      • batbox.exe (PID: 3360)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2020:07:09 23:57:07
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: Monotone-HWID-Spoofer/.git/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
54
Monitored processes
9
Malicious processes
0
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe getinput.exe no specs cmd.exe no specs cmd.exe no specs batbox.exe no specs cmd.exe no specs ping.exe no specs tasklist.exe no specs find.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
236cmd /c ""C:\Users\admin\Desktop\Monotone-HWID-Spoofer\Box.bat" "C:\Windows\system32\cmd.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
572cmd /c ""C:\Users\admin\Desktop\Monotone-HWID-Spoofer\Commands\Hidden\process.bat" "C:\Windows\system32\cmd.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1764cmd /c ""C:\Users\admin\Desktop\Monotone-HWID-Spoofer\Button.bat" "C:\Windows\system32\cmd.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2088"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Monotone-HWID-Spoofer.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2732ping localhost C:\Windows\system32\PING.EXEcmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
TCP/IP Ping Command
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ping.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
3360"C:\Users\admin\Desktop\Monotone-HWID-Spoofer\batbox.exe" C:\Users\admin\Desktop\Monotone-HWID-Spoofer\batbox.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\monotone-hwid-spoofer\batbox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
3652"C:\Users\admin\Desktop\Monotone-HWID-Spoofer\GetInput.exe" C:\Users\admin\Desktop\Monotone-HWID-Spoofer\GetInput.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
97
Modules
Images
c:\users\admin\desktop\monotone-hwid-spoofer\getinput.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
3920tasklist /NH /FI "imagename eq Monotone.exe" C:\Windows\system32\tasklist.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Lists the current running tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\tasklist.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
4016find /i "Monotone.exe"C:\Windows\system32\find.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Find String (grep) Utility
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\find.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
459
Read events
450
Write events
9
Delete events
0

Modification events

(PID) Process:(2088) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2088) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2088) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2088) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12F\52C64B7E
Operation:writeName:@C:\Windows\system32\NetworkExplorer.dll,-1
Value:
Network
(PID) Process:(2088) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Monotone-HWID-Spoofer.zip
(PID) Process:(2088) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2088) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2088) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2088) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
10
Suspicious files
72
Text files
32
Unknown types
0

Dropped files

PID
Process
Filename
Type
2088WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2088.44368\Monotone-HWID-Spoofer\.git\configtext
MD5:6DFBEF200BA6427CDAC49A0DCE907019
SHA256:4EC549013D9E6095E8F70AADDE1026454A10BA8CE70FF19C7623351E671E9278
2088WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2088.44368\Monotone-HWID-Spoofer\.git\logs\HEADtext
MD5:DC3F2B9328FCF11058108F16522E6082
SHA256:83160F741D59E2DCAC636C018327041B3FD2F834EF8C84AF94AE1344FE9E33CA
2088WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2088.44368\Monotone-HWID-Spoofer\.git\indexbinary
MD5:DFC5FE934180F69CB5E1B7284285FD3D
SHA256:57C9ADA30BAEDDCC19A110F696CC3D61C4BAAD22B97B7E1394BF76A223B8A126
2088WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2088.44368\Monotone-HWID-Spoofer\.git\hooks\applypatch-msg.sampletext
MD5:CE562E08D8098926A3862FC6E7905199
SHA256:0223497A0B8B033AA58A3A521B8629869386CF7AB0E2F101963D328AA62193F7
2088WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2088.44368\Monotone-HWID-Spoofer\.git\hooks\update.sampletext
MD5:7BF1FCC5F411E5AD68C59B68661660ED
SHA256:978235AE8B913AB4D0F906A8AF621A0BFE7C314D84B715F4F64EE9B1AA3CCE2D
2088WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2088.44368\Monotone-HWID-Spoofer\.git\hooks\commit-msg.sampletext
MD5:579A3C1E12A1E74A98169175FB913012
SHA256:1F74D5E9292979B573EBD59741D46CB93FF391ACDD083D340B94370753D92437
2088WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2088.44368\Monotone-HWID-Spoofer\.git\descriptiontext
MD5:A0A7C3FFF21F2AEA3CFA1D0316DD816C
SHA256:85AB6C163D43A17EA9CF7788308BCA1466F1B0A8D1CC92E26E9BF63DA4062AEE
2088WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2088.44368\Monotone-HWID-Spoofer\.git\hooks\fsmonitor-watchman.sampletext
MD5:EA587B0FAE70333BCE92257152996E70
SHA256:F3C0228D8E827F1C5260AC59FDD92C3D425C46E54711EF713C5A54AE0A4DB2B4
2088WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2088.44368\Monotone-HWID-Spoofer\.git\hooks\pre-push.sampletext
MD5:3C5989301DD4B949DFA1F43738A22819
SHA256:4B1119E1E13A212571976F4AEE77847CDBD40978546D6273A557E238981A40D1
2088WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2088.44368\Monotone-HWID-Spoofer\.git\hooks\post-update.sampletext
MD5:2B7EA5CEE3C49FF53D41E00785EB974C
SHA256:81765AF2DAEF323061DCBC5E61FC16481CB74B3BAC9AD8A174B186523586F6C5
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info