| File name: | Netflix Gen and Checker 2018.rar |
| Full analysis: | https://app.any.run/tasks/fb441577-c825-403d-a613-9b6884457c1f |
| Verdict: | Malicious activity |
| Threats: | A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection. |
| Analysis date: | September 18, 2018, 16:07:07 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v5 |
| MD5: | 729C99F780B067FA2FDDFFBC8CF75DD5 |
| SHA1: | FDDB814B2C15F3D30353D2479F6F79821E502565 |
| SHA256: | 63069B5D8AA148C289DDF5F6B5046E1FCC1F067FF78C06BB7B6ED4833E300771 |
| SSDEEP: | 768:grOAX4YMTy+3zXIXtjAwGDiF6fuNCT475cZdvo8xiJdBBc7820WMfaQYso0:grkDu6EFhOiF1NCTO5cZ4d8MfTo0 |
| .rar | | | RAR compressed archive (v5.0) (61.5) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1308 | "C:\Users\admin\AppData\Local\Temp\Netflix Checker v0.2.2.exe" | C:\Users\admin\AppData\Local\Temp\Netflix Checker v0.2.2.exe | — | WinUpdate.exe | |||||||||||
User: admin Company: julioverne Integrity Level: HIGH Description: Netflix Checker Exit code: 0 Version: 2.2.0.0 Modules
| |||||||||||||||
| 1996 | "C:\Users\admin\Desktop\Netflix Gen and Checker 2018.EXE" | C:\Users\admin\Desktop\Netflix Gen and Checker 2018.EXE | Netflix Gen and Checker 2018.EXE | ||||||||||||
User: admin Integrity Level: HIGH Description: Netflix Checker and Gen 2018 Exit code: 0 Version: 00.22.00.00 Modules
| |||||||||||||||
| 2044 | "C:\Users\admin\AppData\Local\Temp\Netflix Gen.exe" | C:\Users\admin\AppData\Local\Temp\Netflix Gen.exe | — | WinUpdate.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 3735929054 Modules
| |||||||||||||||
| 2204 | "C:\Users\admin\Desktop\Netflix Gen and Checker 2018.EXE" | C:\Users\admin\Desktop\Netflix Gen and Checker 2018.EXE | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: Netflix Checker and Gen 2018 Exit code: 0 Version: 00.22.00.00 Modules
| |||||||||||||||
| 2348 | "C:\Users\admin\AppData\Local\Temp\WinUpdate.exe" | C:\Users\admin\AppData\Local\Temp\WinUpdate.exe | — | Netflix Gen and Checker 2018.EXE | |||||||||||
User: admin Integrity Level: MEDIUM Description: Exit code: 3221226540 Version: 0.0.0.0 Modules
| |||||||||||||||
| 3180 | "C:\Windows\System32\cmd.exe" /C choice /C Y /N /D Y /T 3 & Del C:\Users\admin\Desktop\Netflix Gen and Checker 2018.EXE | C:\Windows\System32\cmd.exe | — | Netflix Gen and Checker 2018.EXE | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 3332 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Netflix Gen and Checker 2018.rar" | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 3360 | choice /C Y /N /D Y /T 3 | C:\Windows\system32\choice.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Offers the user a choice Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3484 | "C:\Users\admin\AppData\Local\Temp\WinUpdate.exe" | C:\Users\admin\AppData\Local\Temp\WinUpdate.exe | Netflix Gen and Checker 2018.EXE | ||||||||||||
User: admin Integrity Level: HIGH Description: Exit code: 0 Version: 0.0.0.0 Modules
| |||||||||||||||
| (PID) Process: | (3332) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3332) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3332) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3332) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Netflix Gen and Checker 2018.rar | |||
| (PID) Process: | (3332) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3332) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3332) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3332) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (3332) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface |
| Operation: | write | Name: | ShowPassword |
Value: 0 | |||
| (PID) Process: | (3332) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin |
| Operation: | write | Name: | Placement |
Value: 2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3332 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb3332.3812\Netflix Gen and Checker 2018.EXE | — | |
MD5:— | SHA256:— | |||
| 2204 | Netflix Gen and Checker 2018.EXE | C:\Users\admin\AppData\Local\Temp\uTorrent.exe | executable | |
MD5:— | SHA256:— | |||
| 2204 | Netflix Gen and Checker 2018.EXE | C:\Users\admin\AppData\Local\Temp\BmTVMpA | binary | |
MD5:— | SHA256:— | |||
| 2204 | Netflix Gen and Checker 2018.EXE | C:\Users\admin\AppData\Local\Temp\WinUpdate.exe | executable | |
MD5:— | SHA256:— | |||
| 3484 | WinUpdate.exe | C:\Users\admin\AppData\Local\Temp\Netflix Checker v0.2.2.exe | executable | |
MD5:C281AFD76E71557E53A1B90A42A30C0F | SHA256:6FD0CFCB7C15612D415A89901BFFD3187792056C963CEBA586A1359B0AA88971 | |||
| 3484 | WinUpdate.exe | C:\Users\admin\AppData\Local\Temp\Netflix Gen.exe | executable | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2204 | Netflix Gen and Checker 2018.EXE | GET | 200 | 209.90.88.139:80 | http://hans12345.5gbfree.com/ntflx.exe | US | executable | 12.6 Mb | suspicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2204 | Netflix Gen and Checker 2018.EXE | 209.90.88.139:80 | hans12345.5gbfree.com | FIBERNET Corp. | US | suspicious |
Domain | IP | Reputation |
|---|---|---|
hans12345.5gbfree.com |
| suspicious |
PID | Process | Class | Message |
|---|---|---|---|
2204 | Netflix Gen and Checker 2018.EXE | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
2204 | Netflix Gen and Checker 2018.EXE | Potentially Bad Traffic | ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download |