File name:

武林黑客论坛专版远控 V1.1.rar

Full analysis: https://app.any.run/tasks/777cef48-976a-434b-ba7b-c71b21252ff2
Verdict: Malicious activity
Analysis date: January 22, 2024, 18:33:17
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v4, os: Win32
MD5:

4307F636ABE3DB85CA7580D8393CE34E

SHA1:

026B040B8C37B5B556BFDAC7F1268293CE1973E0

SHA256:

5B7FC29841820275B3A63AFA5DFCB5E9EB13F23D8DF119B653A0657F64358E30

SSDEEP:

49152:roCm8Dadu6aL2ydNVey5RUHMWB19bazEjJZY5OBXxyEaH9oz+YHymBD1gWwcxPfu:roJdu6adHPbaMWB1pqEjJphyj96+yr5m

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 128)
      • 武林黑客论坛专版远控 V1.1.exe (PID: 2000)
      • Server.exe (PID: 2572)
      • 武林黑客论坛专版远控 V1.1.exe (PID: 2504)
      • dfhl;kdflh.exe (PID: 2776)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 128)
      • 武林黑客论坛专版远控 V1.1.exe (PID: 2000)
      • Server.exe (PID: 2572)
      • 武林黑客论坛专版远控 V1.1.exe (PID: 2504)
      • dfhl;kdflh.exe (PID: 2776)
    • Reads the Internet Settings

      • 武林黑客论坛专版远控 V1.1.exe (PID: 2000)
      • 武林黑客论坛专版远控 V1.1.exe (PID: 2504)
      • taskmgr.exe (PID: 552)
    • Executable content was dropped or overwritten

      • 武林黑客论坛专版远控 V1.1.exe (PID: 2000)
      • 武林黑客论坛专版远控 V1.1.exe (PID: 2504)
      • Server.exe (PID: 2572)
      • dfhl;kdflh.exe (PID: 2776)
    • Application launched itself

      • taskmgr.exe (PID: 552)
  • INFO

    • Checks supported languages

      • 武林黑客论坛专版远控 V1.1.exe (PID: 316)
      • 武林黑客论坛专版远控 V1.1.exe (PID: 2000)
      • Server.exe (PID: 2572)
      • 武林黑客论坛专版远控 V1.1.exe (PID: 2504)
      • 武林黑客论坛专版远控 V1.1.exe (PID: 2556)
      • 武林黑客论坛专版远控 V1.1.exe (PID: 3260)
      • dfhl;kdflh.exe (PID: 2776)
    • Reads the computer name

      • 武林黑客论坛专版远控 V1.1.exe (PID: 316)
      • 武林黑客论坛专版远控 V1.1.exe (PID: 2000)
      • Server.exe (PID: 2572)
      • 武林黑客论坛专版远控 V1.1.exe (PID: 2504)
      • 武林黑客论坛专版远控 V1.1.exe (PID: 2556)
      • 武林黑客论坛专版远控 V1.1.exe (PID: 3260)
      • dfhl;kdflh.exe (PID: 2776)
    • Manual execution by a user

      • 武林黑客论坛专版远控 V1.1.exe (PID: 316)
      • 武林黑客论坛专版远控 V1.1.exe (PID: 2000)
      • Server.exe (PID: 2572)
      • taskmgr.exe (PID: 552)
      • 武林黑客论坛专版远控 V1.1.exe (PID: 2504)
      • 武林黑客论坛专版远控 V1.1.exe (PID: 3260)
      • 武林黑客论坛专版远控 V1.1.exe (PID: 2556)
      • dfhl;kdflh.exe (PID: 2776)
    • Reads the machine GUID from the registry

      • 武林黑客论坛专版远控 V1.1.exe (PID: 316)
      • 武林黑客论坛专版远控 V1.1.exe (PID: 2000)
      • 武林黑客论坛专版远控 V1.1.exe (PID: 2504)
      • 武林黑客论坛专版远控 V1.1.exe (PID: 2556)
      • 武林黑客论坛专版远控 V1.1.exe (PID: 3260)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 128)
    • Create files in a temporary directory

      • Server.exe (PID: 2572)
      • dfhl;kdflh.exe (PID: 2776)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

CompressedSize: 83552
UncompressedSize: 86528
OperatingSystem: Win32
ModifyDate: 2009:09:15 10:29:52
PackingMethod: Normal
ArchivedFileName: ???ֺڿ???̳ר??Զ?? V1.1\SkinH.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
68
Monitored processes
10
Malicious processes
2
Suspicious processes
2

Behavior graph

Click at the process to see the details
start winrar.exe 武林黑客论坛专版远控 v1.1.exe no specs 武林黑客论坛专版远控 v1.1.exe server.exe taskmgr.exe no specs 武林黑客论坛专版远控 v1.1.exe taskmgr.exe 武林黑客论坛专版远控 v1.1.exe 武林黑客论坛专版远控 v1.1.exe no specs dfhl;kdflh.exe

Process information

PID
CMD
Path
Indicators
Parent process
128"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\武林黑客论坛专版远控 V1.1.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
316"C:\Users\admin\Desktop\武林黑客论坛专版远控 V1.1.exe" C:\Users\admin\Desktop\武林黑客论坛专版远控 V1.1.exeexplorer.exe
User:
admin
Company:
武林黑客论坛专版远控 V1.1
Integrity Level:
MEDIUM
Description:
武林黑客论坛专版远控 V1.1 www.50hacker.com
Exit code:
3221225477
Version:
1, 0, 0, 0
Modules
Images
c:\users\admin\desktop\武林黑客论坛专版远控 v1.1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
552"C:\Windows\system32\taskmgr.exe" /4C:\Windows\System32\taskmgr.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Task Manager
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskmgr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2000"C:\Users\admin\Desktop\武林黑客论坛专版远控 V1.1.exe" C:\Users\admin\Desktop\武林黑客论坛专版远控 V1.1.exe
explorer.exe
User:
admin
Company:
武林黑客论坛专版远控 V1.1
Integrity Level:
HIGH
Description:
武林黑客论坛专版远控 V1.1 www.50hacker.com
Exit code:
0
Version:
1, 0, 0, 0
Modules
Images
c:\users\admin\desktop\武林黑客论坛专版远控 v1.1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2504"C:\Users\admin\Desktop\武林黑客论坛专版远控 V1.1.exe" C:\Users\admin\Desktop\武林黑客论坛专版远控 V1.1.exe
explorer.exe
User:
admin
Company:
武林黑客论坛专版远控 V1.1
Integrity Level:
MEDIUM
Description:
武林黑客论坛专版远控 V1.1 www.50hacker.com
Exit code:
3221225547
Version:
1, 0, 0, 0
Modules
Images
c:\users\admin\desktop\武林黑客论坛专版远控 v1.1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2528"C:\Windows\system32\taskmgr.exe" /1C:\Windows\System32\taskmgr.exe
taskmgr.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Task Manager
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskmgr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2556"C:\Users\admin\Desktop\武林黑客论坛专版远控 V1.1.exe" C:\Users\admin\Desktop\武林黑客论坛专版远控 V1.1.exe
explorer.exe
User:
admin
Company:
武林黑客论坛专版远控 V1.1
Integrity Level:
HIGH
Description:
武林黑客论坛专版远控 V1.1 www.50hacker.com
Exit code:
3221225477
Version:
1, 0, 0, 0
Modules
Images
c:\users\admin\desktop\武林黑客论坛专版远控 v1.1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2572"C:\Users\admin\Desktop\Server.exe" C:\Users\admin\Desktop\Server.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Generic Host Process for Win32 Services
Exit code:
0
Version:
5.1.2600.5512 (xpsp.080413-2111)
Modules
Images
c:\users\admin\desktop\server.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2776"C:\Users\admin\Desktop\dfhl;kdflh.exe" C:\Users\admin\Desktop\dfhl;kdflh.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Generic Host Process for Win32 Services
Exit code:
0
Version:
5.1.2600.5512 (xpsp.080413-2111)
Modules
Images
c:\users\admin\desktop\dfhl;kdflh.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3260"C:\Users\admin\Desktop\武林黑客论坛专版远控 V1.1.exe" C:\Users\admin\Desktop\武林黑客论坛专版远控 V1.1.exeexplorer.exe
User:
admin
Company:
武林黑客论坛专版远控 V1.1
Integrity Level:
MEDIUM
Description:
武林黑客论坛专版远控 V1.1 www.50hacker.com
Exit code:
0
Version:
1, 0, 0, 0
Modules
Images
c:\users\admin\desktop\武林黑客论坛专版远控 v1.1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
6 580
Read events
6 503
Write events
73
Delete events
4

Modification events

(PID) Process:(128) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(128) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(128) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(128) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(128) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(128) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(128) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(128) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(128) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2000) 武林黑客论坛专版远控 V1.1.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
Operation:writeName:NodeSlots
Value:
020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202
Executable files
14
Suspicious files
7
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
2776dfhl;kdflh.exe
MD5:
SHA256:
2000武林黑客论坛专版远控 V1.1.exeC:\Users\admin\Desktop\Server.exeexecutable
MD5:541FA0106619A6995CC48F789EF69451
SHA256:C147B38DCF9121572B4E1B1BDA7C9A73FBDF74BBD5EAD416168FC5FC72342699
2572Server.exeC:\Windows\Svchost.regbinary
MD5:0489B42DC535A67D63105AE10DCA0C89
SHA256:73FEABC32C5F460B7126B059C81434C47E0E63BF8FF6191CB1F32E23716A596B
2504武林黑客论坛专版远控 V1.1.exeC:\Users\admin\Desktop\dfhl;kdflh.exeexecutable
MD5:541FA0106619A6995CC48F789EF69451
SHA256:C147B38DCF9121572B4E1B1BDA7C9A73FBDF74BBD5EAD416168FC5FC72342699
2504武林黑客论坛专版远控 V1.1.exeC:\Users\admin\Desktop\RCX3AB9.tmpexecutable
MD5:2A9FD5A571B529D319799C5B59724116
SHA256:95EC73CE611252A667062AB0D31595EEBB003A94A5B9097D71824D7FC82031F0
2572Server.exeC:\Windows\Svchost.txtbinary
MD5:39F0AAD752C77CE3A8B0E03AD48F8DCC
SHA256:D792E7B2A76FFDEA3D9852D956E742CEB86DF69E7D8F066477ADA2AFD9E7E2D8
2572Server.exeC:\Windows\hfsetemp.initext
MD5:6D76157714001817D3C46A81BD56A0C0
SHA256:C5901E46DE33DC165D20648D8BD4A13FB7A703A079C1778192DD4BF1522DF547
128WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa128.40897\武林黑客论坛专版远控 V1.1\Update\install.datexecutable
MD5:541FA0106619A6995CC48F789EF69451
SHA256:C147B38DCF9121572B4E1B1BDA7C9A73FBDF74BBD5EAD416168FC5FC72342699
2000武林黑客论坛专版远控 V1.1.exeC:\Users\admin\Desktop\RCX9805.tmpexecutable
MD5:2A9FD5A571B529D319799C5B59724116
SHA256:95EC73CE611252A667062AB0D31595EEBB003A94A5B9097D71824D7FC82031F0
128WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa128.40897\武林黑客论坛专版远控 V1.1\skinh.shebinary
MD5:47001D668B67771AB9279A3946E38ACA
SHA256:1D77B110F9B9800CC3A0D3C4B8270E978DEDD693B9570DA019F44AD237EEC803
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
5
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
unknown
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info