File name:

BTC SCANNER V.3 TRAIL VERSION.rar

Full analysis: https://app.any.run/tasks/92bffc2c-c6e6-429a-95d1-2910b487e4e4
Verdict: Malicious activity
Analysis date: May 30, 2025, 17:21:54
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-doc
python
pyinstaller
qrcode
qr-btc
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

C072E46CB935A9AFCBEAD5EA7ADD91A6

SHA1:

7715E3EB30CDEE6C2338360D4EDB9E02A5DC8EDA

SHA256:

62D6AA921A7A6041E010AE3A79E8AF61C680A85ECB2FA83CD41C0C38961FBAC7

SSDEEP:

98304:I2/mehQj9r2N+rCtA1YEvG7WMt0H/O74c74uLUfw7PEY22QKO5zxbFm+Dk49jiCO:6Rwz0CCTdJF8qO1n

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 5968)
    • Loads Python modules

      • BTC SCANNER V.3 TRAIL VERSION.exe (PID: 1188)
    • Process drops python dynamic module

      • WinRAR.exe (PID: 5968)
    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 5968)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 5968)
    • Manual execution by a user

      • BTC SCANNER V.3 TRAIL VERSION.exe (PID: 1188)
    • Checks supported languages

      • BTC SCANNER V.3 TRAIL VERSION.exe (PID: 1188)
    • PyInstaller has been detected (YARA)

      • BTC SCANNER V.3 TRAIL VERSION.exe (PID: 1188)
    • Reads the software policy settings

      • slui.exe (PID: 7052)
    • Checks proxy server information

      • slui.exe (PID: 7052)
    • The sample compiled with english language support

      • WinRAR.exe (PID: 5968)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)

EXIF

ZIP

FileVersion: RAR v5
CompressedSize: 5042073
UncompressedSize: 5225443
OperatingSystem: Win32
ArchivedFileName: BTC SCANNER V.3 TRAIL VERSION/BTC SCANNER V.3 TRAIL VERSION.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
132
Monitored processes
5
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe btc scanner v.3  trail version.exe no specs conhost.exe no specs rundll32.exe no specs slui.exe

Process information

PID
CMD
Path
Indicators
Parent process
1188"C:\Users\admin\Desktop\BTC SCANNER V.3 TRAIL VERSION.exe" C:\Users\admin\Desktop\BTC SCANNER V.3 TRAIL VERSION.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221225786
Modules
Images
c:\users\admin\desktop\btc scanner v.3 trail version.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
1812\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeBTC SCANNER V.3 TRAIL VERSION.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4200C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
5968"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\BTC SCANNER V.3 TRAIL VERSION.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
7052C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
3 081
Read events
3 063
Write events
18
Delete events
0

Modification events

(PID) Process:(5968) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(5968) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(5968) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(5968) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\BTC SCANNER V.3 TRAIL VERSION.rar
(PID) Process:(5968) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(5968) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(5968) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(5968) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(5968) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:name
Value:
256
(PID) Process:(5968) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:size
Value:
80
Executable files
20
Suspicious files
1
Text files
14
Unknown types
0

Dropped files

PID
Process
Filename
Type
5968WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5968.5338\BTC SCANNER V.3 TRAIL VERSION\_internal\charset_normalizer\md.cp312-win_amd64.pydexecutable
MD5:71D96F1DBFCD6F767D81F8254E572751
SHA256:611E1B4B9ED6788640F550771744D83E404432830BB8E3063F0B8EC3B98911AF
5968WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5968.5338\BTC SCANNER V.3 TRAIL VERSION\_internal\charset_normalizer\md__mypyc.cp312-win_amd64.pydexecutable
MD5:D8F690EAE02332A6898E9C8B983C56DD
SHA256:C6BB8CAD80B8D7847C52931F11D73BA64F78615218398B2C058F9B218FF21CA9
5968WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5968.5338\BTC SCANNER V.3 TRAIL VERSION\BTC SCANNER V.3 TRAIL VERSION.exeexecutable
MD5:877B4F67DB98F7FB825112ECBA7DFD3B
SHA256:03AC2778630621A6D582249E19C84409E5F425117A255F295C3AE8BCF0C0929D
5968WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5968.5338\BTC SCANNER V.3 TRAIL VERSION\_internal\base_library.zipcompressed
MD5:68F96A1F0B49D240B392EBB7EA147939
SHA256:29556CC179D145E9F64D287F0455991BD62A8DC4304E20429F83A1A40959FD09
5968WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5968.5338\BTC SCANNER V.3 TRAIL VERSION\_internal\certifi\cacert.pemtext
MD5:52A8319281308DE49CCEF4850A7245BC
SHA256:807897254F383A27F45E44F49656F378ABAB2141EDE43A4AD3C2420A597DD23F
5968WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5968.5338\BTC SCANNER V.3 TRAIL VERSION\_internal\mnemonic\py.typedtext
MD5:48734178084EF7F5C250997C28F8BDEE
SHA256:6D67B0F661E0332F0BA8CBBB46EA905C55CB071876091C747546D2C7EDF0138F
5968WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5968.5338\BTC SCANNER V.3 TRAIL VERSION\_internal\mnemonic\wordlist\english.txttext
MD5:F23506956964FA69C98FA3FB5C8823B5
SHA256:2F5EED53A4727B4BF8880D8F3F199EFC90E58503646D9FF8EFF3A2ED3B24DBDA
5968WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5968.5338\BTC SCANNER V.3 TRAIL VERSION\_internal\libssl-3.dllexecutable
MD5:19A2ABA25456181D5FB572D88AC0E73E
SHA256:2E9FBCD8F7FDC13A5179533239811456554F2B3AA2FB10E1B17BE0DF81C79006
5968WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5968.5338\BTC SCANNER V.3 TRAIL VERSION\_internal\mnemonic\wordlist\chinese_traditional.txttext
MD5:00D0909E346B52006D1E9EF680B5A5FC
SHA256:417B26B3D8500A4AE3D59717D7011952DB6FC2FB84B807F3F94AC734E89C1B5F
5968WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa5968.5338\BTC SCANNER V.3 TRAIL VERSION\_internal\libcrypto-3.dllexecutable
MD5:E547CF6D296A88F5B1C352C116DF7C0C
SHA256:05FE080EAB7FC535C51E10C1BD76A2F3E6217F9C91A25034774588881C3F99DE
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
37
DNS requests
23
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
2924
SearchApp.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
7824
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
7824
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
2924
SearchApp.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
2924
SearchApp.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
8028
RUXIMICS.exe
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5496
MoUsoCoreWorker.exe
23.216.77.6:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
472
svchost.exe
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5496
MoUsoCoreWorker.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
472
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
20.190.160.17:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
crl.microsoft.com
  • 23.216.77.6
  • 23.216.77.28
whitelisted
www.microsoft.com
  • 184.30.21.171
  • 95.101.149.131
whitelisted
google.com
  • 142.250.74.206
whitelisted
settings-win.data.microsoft.com
  • 20.73.194.208
whitelisted
login.live.com
  • 20.190.160.17
  • 40.126.32.68
  • 20.190.160.66
  • 20.190.160.5
  • 20.190.160.4
  • 20.190.160.64
  • 20.190.160.2
  • 20.190.160.67
  • 40.126.31.69
  • 20.190.159.23
  • 40.126.31.131
  • 20.190.159.64
  • 20.190.159.71
  • 20.190.159.4
  • 20.190.159.131
  • 20.190.159.129
whitelisted
ocsp.digicert.com
  • 2.23.77.188
  • 184.30.131.245
whitelisted
client.wns.windows.com
  • 172.211.123.249
  • 172.211.123.248
whitelisted
slscr.update.microsoft.com
  • 20.109.210.53
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 40.69.42.241
whitelisted
activation-v2.sls.microsoft.com
  • 20.83.72.98
whitelisted

Threats

No threats detected
No debug info