File name:

Mega NZ Account checker.zip

Full analysis: https://app.any.run/tasks/b4325ca8-6ce4-4d98-a680-a6b04100924e
Verdict: Malicious activity
Threats:

njRAT is a remote access trojan. It is one of the most widely accessible RATs on the market that features an abundance of educational information. Interested attackers can even find tutorials on YouTube. This allows it to become one of the most popular RATs in the world.

Analysis date: May 16, 2019, 15:53:13
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
rat
njrat
bladabindi
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

5A469549C2F3753C3E98DBFF8BF416EC

SHA1:

F3273451BDE601F4BE201B35EC4D8DED89AF404D

SHA256:

6331C8998038C9BC83B0A44E752C42C444DD2D7FD9358D5ADFD89478FDD30E41

SSDEEP:

24576:EWt2lF4KFFT+CDxmI8qElyA6rxyfZL4o2n/2ClECHHvB:rt2lFfqCX8DyB+Ltg/NEYH5

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • MegaChecker[byJayP].exe (PID: 1660)
      • MegaChecker[byJayP].exe (PID: 2680)
      • MegaChecker[byJayP].exe (PID: 1000)
    • Loads the Task Scheduler COM API

      • schtasks.exe (PID: 3064)
    • Known privilege escalation attack

      • MegaChecker[byJayP].exe (PID: 1000)
    • Uses Task Scheduler to run other applications

      • MegaChecker[byJayP].exe (PID: 2680)
    • NJRAT was detected

      • RegAsm.exe (PID: 2832)
  • SUSPICIOUS

    • Uses NETSH.EXE for network configuration

      • RegAsm.exe (PID: 2832)
    • Creates files in the user directory

      • MegaChecker[byJayP].exe (PID: 2680)
    • Modifies the open verb of a shell class

      • MegaChecker[byJayP].exe (PID: 1000)
    • Executable content was dropped or overwritten

      • MegaChecker[byJayP].exe (PID: 2680)
      • WinRAR.exe (PID: 3932)
  • INFO

    • Application was crashed

      • MegaChecker[byJayP].exe (PID: 1660)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2017:12:20 19:13:10
ZipCRC: 0x3effd8d3
ZipCompressedSize: 59309
ZipUncompressedSize: 135510
ZipFileName: Mega NZ Account checker/input.txt
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
49
Monitored processes
9
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start drop and start winrar.exe megachecker[byjayp].exe no specs eventvwr.exe no specs eventvwr.exe megachecker[byjayp].exe megachecker[byjayp].exe #NJRAT regasm.exe netsh.exe no specs schtasks.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1000"C:\Users\admin\AppData\Local\Temp\Rar$EXa3932.1853\Mega NZ Account checker\MegaChecker[byJayP].exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3932.1853\Mega NZ Account checker\MegaChecker[byJayP].exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3932.1853\mega nz account checker\megachecker[byjayp].exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\version.dll
1660"C:\Users\admin\AppData\Roaming\MegaChecker[byJayP].exe" C:\Users\admin\AppData\Roaming\MegaChecker[byJayP].exe
MegaChecker[byJayP].exe
User:
admin
Integrity Level:
HIGH
Description:
MegaCrack
Exit code:
3762504530
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\roaming\megachecker[byjayp].exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2056"C:\Windows\System32\eventvwr.exe" C:\Windows\System32\eventvwr.exeMegaChecker[byJayP].exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Event Viewer Snapin Launcher
Exit code:
3221226540
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\eventvwr.exe
c:\systemroot\system32\ntdll.dll
2680"C:\Users\admin\AppData\Local\Temp\Rar$EXa3932.1853\Mega NZ Account checker\MegaChecker[byJayP].exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3932.1853\Mega NZ Account checker\MegaChecker[byJayP].exe
eventvwr.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3932.1853\mega nz account checker\megachecker[byjayp].exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\version.dll
2832"C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe"C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe
MegaChecker[byJayP].exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft .NET Assembly Registration Utility
Exit code:
0
Version:
2.0.50727.5420 (Win7SP1.050727-5400)
Modules
Images
c:\windows\microsoft.net\framework\v2.0.50727\regasm.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
3064"C:\Windows\System32\schtasks.exe" /create /tn Locator /tr "C:\Users\admin\LocationNotificationWindows\Windows update notification.exe" /sc minute /mo 1 /FC:\Windows\System32\schtasks.exeMegaChecker[byJayP].exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Manages scheduled tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
3420netsh firewall add allowedprogram "C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe" "RegAsm.exe" ENABLEC:\Windows\system32\netsh.exeRegAsm.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Network Command Shell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\netsh.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\credui.dll
c:\windows\system32\user32.dll
3724"C:\Windows\System32\eventvwr.exe" C:\Windows\System32\eventvwr.exe
MegaChecker[byJayP].exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Event Viewer Snapin Launcher
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\eventvwr.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
3932"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Mega NZ Account checker.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
1 060
Read events
961
Write events
99
Delete events
0

Modification events

(PID) Process:(3932) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3932) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3932) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3932) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Mega NZ Account checker.zip
(PID) Process:(3932) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3932) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3932) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3932) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3932) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(3932) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
Executable files
5
Suspicious files
0
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
3932WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3932.1853\Mega NZ Account checker\MegaChecker[byJayP].exeexecutable
MD5:
SHA256:
2680MegaChecker[byJayP].exeC:\Users\admin\LocationNotificationWindows\Windows update notification.exeexecutable
MD5:
SHA256:
3932WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3932.1853\Mega NZ Account checker\input.txttext
MD5:126557026E85CE990610345466C94F44
SHA256:EB23036497279E56442225AB04AB19AA05136BD17AA1CA3FCDE75187DB38D282
2680MegaChecker[byJayP].exeC:\Users\admin\AppData\Roaming\MegaChecker[byJayP].exeexecutable
MD5:159D853382F949B5A6134810634FE63B
SHA256:D5E236C100AB938745324532925F0F6CBE02B0F5EA72FB2B31EDDFF45411406A
3932WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3932.1853\Mega NZ Account checker\MegaApiClient.dllexecutable
MD5:1F640DADFCADB98DE27096A5C45C8C4B
SHA256:15DA28AA30A6E25C0A612A18909AAED5B52D329338F3F4FF3E7C75FD7889252C
3932WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3932.1853\Mega NZ Account checker\Newtonsoft.Json.dllexecutable
MD5:C53737821B861D454D5248034C3C097C
SHA256:575E30F98E4EA42C9E516EDC8BBB29AD8B50B173A3E6B36B5BA39E133CCE9406
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
2
DNS requests
3
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2832
RegAsm.exe
172.111.154.46:5559
pur3vpn.ddns.net
AltusHost B.V.
GB
malicious
172.111.154.46:5559
pur3vpn.ddns.net
AltusHost B.V.
GB
malicious

DNS requests

Domain
IP
Reputation
pur3vpn.ddns.net
  • 172.111.154.46
malicious
dns.msftncsi.com
  • 131.107.255.255
shared

Threats

No threats detected
No debug info