File name:

AndroidSideloader v2.26.exe

Full analysis: https://app.any.run/tasks/0e69a1ee-6234-4795-8b8c-141dcacffe44
Verdict: Malicious activity
Analysis date: December 08, 2023, 21:26:03
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5:

1158E107E5A5FB9BF3AE7BCC8276F429

SHA1:

EA46F63D51C2C8FB641E9C23C5E206E9CA4FBA6D

SHA256:

6278D167AC356CDAD30CD5A8EA37A7522F823515731AB64F4D1271BF38FB9497

SSDEEP:

98304:CcEQQMDXQmfYGBHkBPUHexnMO93WGY+PF:UY

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • AndroidSideloader v2.26.exe (PID: 1864)
      • 7z.exe (PID: 3964)
  • SUSPICIOUS

    • Reads settings of System Certificates

      • AndroidSideloader v2.26.exe (PID: 1864)
      • AndroidSideloader v2.26.exe (PID: 2988)
    • Reads the Internet Settings

      • Sideloader Launcher.exe (PID: 2364)
      • AndroidSideloader v2.26.exe (PID: 2988)
      • AndroidSideloader v2.26.exe (PID: 1784)
      • AndroidSideloader v2.26.exe (PID: 1864)
    • Application launched itself

      • adb.exe (PID: 4040)
      • AndroidSideloader v2.26.exe (PID: 2988)
    • Drops 7-zip archiver for unpacking

      • AndroidSideloader v2.26.exe (PID: 1864)
  • INFO

    • Checks supported languages

      • AndroidSideloader v2.26.exe (PID: 1864)
      • AndroidSideloader v2.26.exe (PID: 2988)
      • adb.exe (PID: 3588)
      • 7z.exe (PID: 3288)
      • adb.exe (PID: 4040)
      • adb.exe (PID: 3864)
      • rclone.exe (PID: 3584)
      • rclone.exe (PID: 4004)
      • AndroidSideloader v2.26.exe (PID: 1784)
      • Sideloader Launcher.exe (PID: 2364)
      • 7z.exe (PID: 3964)
    • Reads the computer name

      • AndroidSideloader v2.26.exe (PID: 1864)
      • 7z.exe (PID: 3964)
      • Sideloader Launcher.exe (PID: 2364)
      • AndroidSideloader v2.26.exe (PID: 2988)
      • 7z.exe (PID: 3288)
      • adb.exe (PID: 3864)
      • rclone.exe (PID: 4004)
      • rclone.exe (PID: 3584)
      • AndroidSideloader v2.26.exe (PID: 1784)
    • Reads Environment values

      • AndroidSideloader v2.26.exe (PID: 1864)
      • AndroidSideloader v2.26.exe (PID: 2988)
      • AndroidSideloader v2.26.exe (PID: 1784)
    • Reads the machine GUID from the registry

      • AndroidSideloader v2.26.exe (PID: 1864)
      • AndroidSideloader v2.26.exe (PID: 2988)
      • AndroidSideloader v2.26.exe (PID: 1784)
    • Creates files or folders in the user directory

      • AndroidSideloader v2.26.exe (PID: 1864)
      • AndroidSideloader v2.26.exe (PID: 2988)
    • Manual execution by a user

      • explorer.exe (PID: 2820)
      • Sideloader Launcher.exe (PID: 2364)
    • Create files in a temporary directory

      • adb.exe (PID: 3864)
      • AndroidSideloader v2.26.exe (PID: 2988)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic CIL Executable (.NET, Mono, etc.) (63.1)
.exe | Win64 Executable (generic) (23.8)
.dll | Win32 Dynamic Link Library (generic) (5.6)
.exe | Win32 Executable (generic) (3.8)
.exe | Generic Win/DOS Executable (1.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2059:02:11 10:21:06+01:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 48
CodeSize: 3800064
InitializedDataSize: 413184
UninitializedDataSize: -
EntryPoint: 0x3a1ade
OSVersion: 4
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 2.0.0.0
ProductVersionNumber: 2.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: Rookie Sideloader
CompanyName: Rookie.WTF
FileDescription: AndroidSideloader
FileVersion: 2.0.0.0
InternalName: AndroidSideloader.exe
LegalCopyright: Copyright © 2020
LegalTrademarks: -
OriginalFileName: AndroidSideloader.exe
ProductName: AndroidSideloader
ProductVersion: 2.0.0.0
AssemblyVersion: 2.0.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
55
Monitored processes
12
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
start androidsideloader v2.26.exe explorer.exe no specs 7z.exe no specs sideloader launcher.exe no specs androidsideloader v2.26.exe 7z.exe no specs adb.exe no specs adb.exe no specs adb.exe no specs rclone.exe no specs rclone.exe no specs androidsideloader v2.26.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1784"C:\Users\admin\Downloads\AndroidSideloader v2.26.exe" --offlineC:\Users\admin\Downloads\AndroidSideloader v2.26.exeAndroidSideloader v2.26.exe
User:
admin
Company:
Rookie.WTF
Integrity Level:
MEDIUM
Description:
AndroidSideloader
Exit code:
0
Version:
2.0.0.0
Modules
Images
c:\users\admin\downloads\androidsideloader v2.26.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
1864"C:\Users\admin\Downloads\AndroidSideloader v2.26.exe" C:\Users\admin\Downloads\AndroidSideloader v2.26.exe
explorer.exe
User:
admin
Company:
Rookie.WTF
Integrity Level:
MEDIUM
Description:
AndroidSideloader
Exit code:
0
Version:
2.0.0.0
Modules
Images
c:\users\admin\downloads\androidsideloader v2.26.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2364"C:\Users\admin\Downloads\Sideloader Launcher.exe" C:\Users\admin\Downloads\Sideloader Launcher.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Sideloader Launcher
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\downloads\sideloader launcher.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
2820"C:\Windows\explorer.exe" C:\Windows\explorer.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2988"C:\Users\admin\Downloads\AndroidSideloader v2.26.exe" C:\Users\admin\Downloads\AndroidSideloader v2.26.exe
Sideloader Launcher.exe
User:
admin
Company:
Rookie.WTF
Integrity Level:
MEDIUM
Description:
AndroidSideloader
Exit code:
4294967295
Version:
2.0.0.0
Modules
Images
c:\users\admin\downloads\androidsideloader v2.26.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
3288"7z.exe" x "C:\Users\admin\Downloads\rclone.zip" -y -o"C:\Users\admin\Downloads" -bsp1C:\Users\admin\Downloads\7z.exeAndroidSideloader v2.26.exe
User:
admin
Company:
Igor Pavlov
Integrity Level:
MEDIUM
Description:
7-Zip Standalone Console
Exit code:
0
Version:
23.01
Modules
Images
c:\users\admin\downloads\7z.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3584"C:\Users\admin\Downloads\rclone\rclone.exe" cat ":Quest Games/VRP-GameList.txt" --config vrp.download.configC:\Users\admin\Downloads\rclone\rclone.exeAndroidSideloader v2.26.exe
User:
admin
Company:
https://rclone.org
Integrity Level:
MEDIUM
Description:
Rsync for cloud storage
Exit code:
1
Version:
1.62.2
Modules
Images
c:\users\admin\downloads\rclone\rclone.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
3588"C:\RSL\platform-tools\adb.exe" kill-serverC:\RSL\platform-tools\adb.exeAndroidSideloader v2.26.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\rsl\platform-tools\adb.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
3864adb -L tcp:5037 fork-server server --reply-fd 268C:\RSL\platform-tools\adb.exeadb.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\rsl\platform-tools\adb.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
3964"7z.exe" x "C:\Users\admin\Downloads\_adb.7z" -y -o"C:\RSL\platform-tools" -bsp1C:\Users\admin\Downloads\7z.exeAndroidSideloader v2.26.exe
User:
admin
Company:
Igor Pavlov
Integrity Level:
MEDIUM
Description:
7-Zip Standalone Console
Exit code:
0
Version:
23.01
Modules
Images
c:\users\admin\downloads\7z.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
Total events
11 763
Read events
11 707
Write events
56
Delete events
0

Modification events

(PID) Process:(1864) AndroidSideloader v2.26.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(1864) AndroidSideloader v2.26.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(1864) AndroidSideloader v2.26.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(1864) AndroidSideloader v2.26.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(1864) AndroidSideloader v2.26.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\17F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2364) Sideloader Launcher.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2364) Sideloader Launcher.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2364) Sideloader Launcher.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2364) Sideloader Launcher.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2988) AndroidSideloader v2.26.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
15
Suspicious files
56
Text files
1 216
Unknown types
0

Dropped files

PID
Process
Filename
Type
1864AndroidSideloader v2.26.exeC:\Users\admin\Downloads\Sideloader Launcher.exeexecutable
MD5:A53A5E70248EB3DA58DEFA74B0554704
SHA256:98BC8CF1C6A59EF70D6431E1E92887984E5B21C8FBC85B4AD23CCC70589C4B1F
1864AndroidSideloader v2.26.exeC:\Users\admin\AppData\Local\Rookie.WTF\AndroidSideloader_v2.26.e_Url_gcjmotvko2u1iiz02vp1mi3vursd4ozl\2.0.0.0\lngusv5w.newcfgxml
MD5:B091BCB2968A1DDEE3C7640D3280519E
SHA256:F675FF215969B2AC83697896E8476F48EF12658A76EF0CEEE4245C974E5DCB55
39647z.exeC:\RSL\platform-tools\AdbWinApi.dllexecutable
MD5:ED5A809DC0024D83CBAB4FB9933D598D
SHA256:D60103A5E99BC9888F786EE916F5D6E45493C3247972CB053833803DE7E95CF9
39647z.exeC:\RSL\platform-tools\make_f2fs.exeexecutable
MD5:20FCDC6407E29B85B99780EC39979465
SHA256:950D13846129D3653F37FEDE77995510F77EBAAD0E8233090A51891A2A20D6D2
1864AndroidSideloader v2.26.exeC:\Users\admin\Downloads\Rookie Offline.cmdtext
MD5:513248E44025E42FD2B8F9280501A8BB
SHA256:7DD245A6267A6D9500EE6B13A29FBDD80CEF9A020162C0E24A228558C58FA092
39647z.exeC:\RSL\platform-tools\etc1tool.exeexecutable
MD5:29A86ACF93731FA26C2B3AFA6A155B4C
SHA256:4C82EA5A7C50EC482B401AF272FE437AB5861816F10EC8A2584875A853690767
39647z.exeC:\RSL\platform-tools\libwinpthread-1.dllexecutable
MD5:95DECA9CA898F8DAEB3288A06F4A020A
SHA256:6CD4726956F3487453F151B847AFFAD442A81ACFCC4CB816B9BCB5AD5E7B6F7C
1864AndroidSideloader v2.26.exeC:\Users\admin\Downloads\7z.dllexecutable
MD5:AE7DE9A0278F37331D2E9F8D5C0281F0
SHA256:A3FC74468477BA54517157EFA5021EAA6FF72F8F5C31E53D89F07D59071C0AE7
39647z.exeC:\RSL\platform-tools\make_f2fs_casefold.exeexecutable
MD5:E1086A2A0F5E3BDCCFCB2F183598D9C0
SHA256:CD334AD72EE383E5F39722E2304CD2C7576B86A8134A33284E1AF7DEB8968337
39647z.exeC:\RSL\platform-tools\mke2fs.conftext
MD5:699098CA95F87BA48BB94A3E848549B3
SHA256:AD58A58DCDD24D85055814CA9CAC67DB89D4E67C434E96774BDCE0D0A007D067
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
9
DNS requests
6
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2988
AndroidSideloader v2.26.exe
GET
200
184.24.77.186:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?4eca5b14b2c3e3a3
unknown
compressed
65.2 Kb
unknown
2988
AndroidSideloader v2.26.exe
GET
200
172.64.149.23:80
http://zerossl.crt.sectigo.com/ZeroSSLECCDomainSecureSiteCA.crt
unknown
binary
905 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1864
AndroidSideloader v2.26.exe
140.82.121.4:443
github.com
GITHUB
US
unknown
1864
AndroidSideloader v2.26.exe
185.199.110.133:443
raw.githubusercontent.com
FASTLY
US
unknown
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
2988
AndroidSideloader v2.26.exe
95.217.6.16:443
downloads.rclone.org
Hetzner Online GmbH
FI
unknown
2988
AndroidSideloader v2.26.exe
184.24.77.186:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
2988
AndroidSideloader v2.26.exe
185.199.110.133:443
raw.githubusercontent.com
FASTLY
US
unknown
2988
AndroidSideloader v2.26.exe
185.247.224.87:443
vrpirates.wiki
Flokinet Ltd
SC
unknown
2988
AndroidSideloader v2.26.exe
172.64.149.23:80
zerossl.crt.sectigo.com
CLOUDFLARENET
US
unknown

DNS requests

Domain
IP
Reputation
github.com
  • 140.82.121.4
shared
raw.githubusercontent.com
  • 185.199.110.133
  • 185.199.109.133
  • 185.199.111.133
  • 185.199.108.133
shared
downloads.rclone.org
  • 95.217.6.16
unknown
ctldl.windowsupdate.com
  • 184.24.77.186
  • 184.24.77.207
  • 184.24.77.205
  • 184.24.77.173
  • 184.24.77.188
  • 184.24.77.183
  • 184.24.77.194
  • 184.24.77.191
  • 184.24.77.174
whitelisted
vrpirates.wiki
  • 185.247.224.87
unknown
zerossl.crt.sectigo.com
  • 172.64.149.23
  • 104.18.38.233
whitelisted

Threats

PID
Process
Class
Message
2988
AndroidSideloader v2.26.exe
Misc activity
ET INFO Observed ZeroSSL SSL/TLS Certificate
No debug info