File name:

武林黑客论坛专版远控 V1.1.rar

Full analysis: https://app.any.run/tasks/777cef48-976a-434b-ba7b-c71b21252ff2
Verdict: Malicious activity
Analysis date: January 22, 2024, 18:33:17
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v4, os: Win32
MD5:

4307F636ABE3DB85CA7580D8393CE34E

SHA1:

026B040B8C37B5B556BFDAC7F1268293CE1973E0

SHA256:

5B7FC29841820275B3A63AFA5DFCB5E9EB13F23D8DF119B653A0657F64358E30

SSDEEP:

49152:roCm8Dadu6aL2ydNVey5RUHMWB19bazEjJZY5OBXxyEaH9oz+YHymBD1gWwcxPfu:roJdu6adHPbaMWB1pqEjJphyj96+yr5m

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 128)
      • 武林黑客论坛专版远控 V1.1.exe (PID: 2000)
      • Server.exe (PID: 2572)
      • 武林黑客论坛专版远控 V1.1.exe (PID: 2504)
      • dfhl;kdflh.exe (PID: 2776)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 128)
      • 武林黑客论坛专版远控 V1.1.exe (PID: 2000)
      • Server.exe (PID: 2572)
      • 武林黑客论坛专版远控 V1.1.exe (PID: 2504)
      • dfhl;kdflh.exe (PID: 2776)
    • Reads the Internet Settings

      • 武林黑客论坛专版远控 V1.1.exe (PID: 2000)
      • taskmgr.exe (PID: 552)
      • 武林黑客论坛专版远控 V1.1.exe (PID: 2504)
    • Executable content was dropped or overwritten

      • 武林黑客论坛专版远控 V1.1.exe (PID: 2000)
      • 武林黑客论坛专版远控 V1.1.exe (PID: 2504)
      • Server.exe (PID: 2572)
      • dfhl;kdflh.exe (PID: 2776)
    • Application launched itself

      • taskmgr.exe (PID: 552)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 128)
    • Checks supported languages

      • 武林黑客论坛专版远控 V1.1.exe (PID: 316)
      • 武林黑客论坛专版远控 V1.1.exe (PID: 2000)
      • Server.exe (PID: 2572)
      • 武林黑客论坛专版远控 V1.1.exe (PID: 2504)
      • 武林黑客论坛专版远控 V1.1.exe (PID: 2556)
      • dfhl;kdflh.exe (PID: 2776)
      • 武林黑客论坛专版远控 V1.1.exe (PID: 3260)
    • Reads the computer name

      • 武林黑客论坛专版远控 V1.1.exe (PID: 316)
      • 武林黑客论坛专版远控 V1.1.exe (PID: 2000)
      • Server.exe (PID: 2572)
      • 武林黑客论坛专版远控 V1.1.exe (PID: 2504)
      • 武林黑客论坛专版远控 V1.1.exe (PID: 2556)
      • dfhl;kdflh.exe (PID: 2776)
      • 武林黑客论坛专版远控 V1.1.exe (PID: 3260)
    • Reads the machine GUID from the registry

      • 武林黑客论坛专版远控 V1.1.exe (PID: 316)
      • 武林黑客论坛专版远控 V1.1.exe (PID: 2000)
      • 武林黑客论坛专版远控 V1.1.exe (PID: 2504)
      • 武林黑客论坛专版远控 V1.1.exe (PID: 2556)
      • 武林黑客论坛专版远控 V1.1.exe (PID: 3260)
    • Manual execution by a user

      • 武林黑客论坛专版远控 V1.1.exe (PID: 316)
      • 武林黑客论坛专版远控 V1.1.exe (PID: 2000)
      • Server.exe (PID: 2572)
      • taskmgr.exe (PID: 552)
      • 武林黑客论坛专版远控 V1.1.exe (PID: 2504)
      • 武林黑客论坛专版远控 V1.1.exe (PID: 2556)
      • dfhl;kdflh.exe (PID: 2776)
      • 武林黑客论坛专版远控 V1.1.exe (PID: 3260)
    • Create files in a temporary directory

      • Server.exe (PID: 2572)
      • dfhl;kdflh.exe (PID: 2776)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

CompressedSize: 83552
UncompressedSize: 86528
OperatingSystem: Win32
ModifyDate: 2009:09:15 10:29:52
PackingMethod: Normal
ArchivedFileName: ???ֺڿ???̳ר??Զ?? V1.1\SkinH.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
68
Monitored processes
10
Malicious processes
2
Suspicious processes
2

Behavior graph

Click at the process to see the details
start winrar.exe 武林黑客论坛专版远控 v1.1.exe no specs 武林黑客论坛专版远控 v1.1.exe server.exe taskmgr.exe no specs 武林黑客论坛专版远控 v1.1.exe taskmgr.exe 武林黑客论坛专版远控 v1.1.exe 武林黑客论坛专版远控 v1.1.exe no specs dfhl;kdflh.exe

Process information

PID
CMD
Path
Indicators
Parent process
128"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\武林黑客论坛专版远控 V1.1.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
316"C:\Users\admin\Desktop\武林黑客论坛专版远控 V1.1.exe" C:\Users\admin\Desktop\武林黑客论坛专版远控 V1.1.exeexplorer.exe
User:
admin
Company:
武林黑客论坛专版远控 V1.1
Integrity Level:
MEDIUM
Description:
武林黑客论坛专版远控 V1.1 www.50hacker.com
Exit code:
3221225477
Version:
1, 0, 0, 0
Modules
Images
c:\users\admin\desktop\武林黑客论坛专版远控 v1.1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
552"C:\Windows\system32\taskmgr.exe" /4C:\Windows\System32\taskmgr.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Task Manager
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskmgr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2000"C:\Users\admin\Desktop\武林黑客论坛专版远控 V1.1.exe" C:\Users\admin\Desktop\武林黑客论坛专版远控 V1.1.exe
explorer.exe
User:
admin
Company:
武林黑客论坛专版远控 V1.1
Integrity Level:
HIGH
Description:
武林黑客论坛专版远控 V1.1 www.50hacker.com
Exit code:
0
Version:
1, 0, 0, 0
Modules
Images
c:\users\admin\desktop\武林黑客论坛专版远控 v1.1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2504"C:\Users\admin\Desktop\武林黑客论坛专版远控 V1.1.exe" C:\Users\admin\Desktop\武林黑客论坛专版远控 V1.1.exe
explorer.exe
User:
admin
Company:
武林黑客论坛专版远控 V1.1
Integrity Level:
MEDIUM
Description:
武林黑客论坛专版远控 V1.1 www.50hacker.com
Exit code:
3221225547
Version:
1, 0, 0, 0
Modules
Images
c:\users\admin\desktop\武林黑客论坛专版远控 v1.1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2528"C:\Windows\system32\taskmgr.exe" /1C:\Windows\System32\taskmgr.exe
taskmgr.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Task Manager
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskmgr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2556"C:\Users\admin\Desktop\武林黑客论坛专版远控 V1.1.exe" C:\Users\admin\Desktop\武林黑客论坛专版远控 V1.1.exe
explorer.exe
User:
admin
Company:
武林黑客论坛专版远控 V1.1
Integrity Level:
HIGH
Description:
武林黑客论坛专版远控 V1.1 www.50hacker.com
Exit code:
3221225477
Version:
1, 0, 0, 0
Modules
Images
c:\users\admin\desktop\武林黑客论坛专版远控 v1.1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2572"C:\Users\admin\Desktop\Server.exe" C:\Users\admin\Desktop\Server.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Generic Host Process for Win32 Services
Exit code:
0
Version:
5.1.2600.5512 (xpsp.080413-2111)
Modules
Images
c:\users\admin\desktop\server.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2776"C:\Users\admin\Desktop\dfhl;kdflh.exe" C:\Users\admin\Desktop\dfhl;kdflh.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Generic Host Process for Win32 Services
Exit code:
0
Version:
5.1.2600.5512 (xpsp.080413-2111)
Modules
Images
c:\users\admin\desktop\dfhl;kdflh.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3260"C:\Users\admin\Desktop\武林黑客论坛专版远控 V1.1.exe" C:\Users\admin\Desktop\武林黑客论坛专版远控 V1.1.exeexplorer.exe
User:
admin
Company:
武林黑客论坛专版远控 V1.1
Integrity Level:
MEDIUM
Description:
武林黑客论坛专版远控 V1.1 www.50hacker.com
Exit code:
0
Version:
1, 0, 0, 0
Modules
Images
c:\users\admin\desktop\武林黑客论坛专版远控 v1.1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
6 580
Read events
6 503
Write events
73
Delete events
4

Modification events

(PID) Process:(128) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(128) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(128) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(128) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(128) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(128) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(128) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(128) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(128) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2000) 武林黑客论坛专版远控 V1.1.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
Operation:writeName:NodeSlots
Value:
020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202
Executable files
14
Suspicious files
7
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
2776dfhl;kdflh.exe
MD5:
SHA256:
128WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa128.40897\武林黑客论坛专版远控 V1.1\Update\MAINDLL.DLLexecutable
MD5:3324C9D2D2F084B6708298EC1FDD9B26
SHA256:C8901FEA93B7891B6C64D2C47636821035FF779ED07E55748F3104E7CD80CE69
2000武林黑客论坛专版远控 V1.1.exeC:\Users\admin\Desktop\RCX9805.tmpexecutable
MD5:2A9FD5A571B529D319799C5B59724116
SHA256:95EC73CE611252A667062AB0D31595EEBB003A94A5B9097D71824D7FC82031F0
128WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa128.40897\武林黑客论坛专版远控 V1.1\Update\install.datexecutable
MD5:541FA0106619A6995CC48F789EF69451
SHA256:C147B38DCF9121572B4E1B1BDA7C9A73FBDF74BBD5EAD416168FC5FC72342699
2000武林黑客论坛专版远控 V1.1.exeC:\Users\admin\Desktop\Server.exeexecutable
MD5:541FA0106619A6995CC48F789EF69451
SHA256:C147B38DCF9121572B4E1B1BDA7C9A73FBDF74BBD5EAD416168FC5FC72342699
2504武林黑客论坛专版远控 V1.1.exeC:\Users\admin\Desktop\dfhl;kdflh.exeexecutable
MD5:541FA0106619A6995CC48F789EF69451
SHA256:C147B38DCF9121572B4E1B1BDA7C9A73FBDF74BBD5EAD416168FC5FC72342699
2504武林黑客论坛专版远控 V1.1.exeC:\Users\admin\Desktop\RCX3AB9.tmpexecutable
MD5:2A9FD5A571B529D319799C5B59724116
SHA256:95EC73CE611252A667062AB0D31595EEBB003A94A5B9097D71824D7FC82031F0
2572Server.exeC:\Windows\hfsetemp.initext
MD5:6D76157714001817D3C46A81BD56A0C0
SHA256:C5901E46DE33DC165D20648D8BD4A13FB7A703A079C1778192DD4BF1522DF547
2776dfhl;kdflh.exeC:\Users\admin\AppData\Local\Temp\1090265_tem.infoexecutable
MD5:56EE2F358D9A6509AA866DC150D115E9
SHA256:3EE4D306F21B4C66DCD013C6C207D7E9B04207D03D808E1CB6D65B784D909639
2776dfhl;kdflh.exeC:\Windows\Svchost.txtbinary
MD5:26FCA272AAE44EE5580576D5DE751E26
SHA256:49BB57F4D907F7BA2C513A0F7D5F50116CA4642CA6554E357E890FF499941DA0
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
5
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
unknown
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info