File name:

RedLine Stealer Cracked.zip

Full analysis: https://app.any.run/tasks/ac3cf452-13b5-4717-b165-8d15411ae858
Verdict: Malicious activity
Threats:

AsyncRAT is a RAT that can monitor and remotely control infected systems. This malware was introduced on Github as a legitimate open-source remote administration software, but hackers use it for its many powerful malicious functions.

Analysis date: January 17, 2024, 13:39:35
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
rat
asyncrat
remote
xworm
stealer
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

5F8DD9E5A738989E7AEF24E01AA5A7B3

SHA1:

EFDA070ECBC5187DBDFE933424F7B64A9AB6512F

SHA256:

6596D3B749DA46E024CFB916F35AD382E2361599D68237D9DAF8A68EB3E7A74A

SSDEEP:

98304:4GNzU0kk1p//u7stL3qN716LHLvudVvsthLPIuooqbS901/TmcebFzPKfs0cRY2h:BBXoV1cFoF9Od

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Adds path to the Windows Defender exclusion list

      • Build.exe (PID: 2748)
      • Build.exe (PID: 3584)
      • stub.exe (PID: 2300)
    • Drops the executable file immediately after the start

      • builder.exe (PID: 2340)
      • Build.exe (PID: 2748)
      • svchost.exe (PID: 1028)
    • Changes powershell execution policy (Bypass)

      • Build.exe (PID: 2748)
      • Build.exe (PID: 3584)
      • stub.exe (PID: 2300)
    • Bypass execution policy to execute commands

      • powershell.exe (PID: 2844)
      • powershell.exe (PID: 2888)
      • powershell.exe (PID: 4088)
      • powershell.exe (PID: 1976)
      • powershell.exe (PID: 712)
      • powershell.exe (PID: 2304)
    • Uses Task Scheduler to autorun other applications

      • Build.exe (PID: 2748)
      • Build.exe (PID: 3584)
      • stub.exe (PID: 2300)
    • Changes the autorun value in the registry

      • svchost.exe (PID: 1028)
      • cfmon.exe (PID: 3064)
      • Build.exe (PID: 3584)
      • stub.exe (PID: 2300)
    • ASYNCRAT has been detected (SURICATA)

      • svchost.exe (PID: 3180)
    • Create files in the Startup directory

      • cfmon.exe (PID: 3064)
    • XWORM has been detected (SURICATA)

      • cfmon.exe (PID: 3064)
    • Connects to the CnC server

      • cfmon.exe (PID: 3064)
    • Steals credentials

      • cfmon.exe (PID: 3064)
    • Actions looks like stealing of personal data

      • cfmon.exe (PID: 3064)
  • SUSPICIOUS

    • Uses NETSH.EXE to add a firewall rule or allowed programs

      • cmd.exe (PID: 1344)
    • Reads the Internet Settings

      • RedLine.MainPanel-cracked.exe (PID: 1820)
      • Build.exe (PID: 2748)
      • builder.exe (PID: 2340)
      • powershell.exe (PID: 2844)
      • powershell.exe (PID: 2888)
      • svchost.exe (PID: 3180)
      • cfmon.exe (PID: 3064)
      • powershell.exe (PID: 4088)
      • Build.exe (PID: 3584)
      • powershell.exe (PID: 1976)
      • stub.exe (PID: 2300)
      • powershell.exe (PID: 712)
      • powershell.exe (PID: 2304)
    • Script adds exclusion path to Windows Defender

      • Build.exe (PID: 2748)
      • Build.exe (PID: 3584)
      • stub.exe (PID: 2300)
    • Executable content was dropped or overwritten

      • builder.exe (PID: 2340)
      • Build.exe (PID: 2748)
      • svchost.exe (PID: 1028)
    • Using PowerShell to operate with local accounts

      • powershell.exe (PID: 2844)
      • powershell.exe (PID: 2888)
      • powershell.exe (PID: 4088)
      • powershell.exe (PID: 1976)
      • powershell.exe (PID: 712)
      • powershell.exe (PID: 2304)
    • The process creates files with name similar to system file names

      • Build.exe (PID: 2748)
      • svchost.exe (PID: 1028)
    • Starts POWERSHELL.EXE for commands execution

      • Build.exe (PID: 2748)
      • Build.exe (PID: 3584)
      • stub.exe (PID: 2300)
    • Uses TIMEOUT.EXE to delay execution

      • cmd.exe (PID: 3128)
    • Executing commands from a ".bat" file

      • svchost.exe (PID: 1028)
    • Connects to unusual port

      • svchost.exe (PID: 3180)
      • cfmon.exe (PID: 3064)
    • Starts CMD.EXE for commands execution

      • svchost.exe (PID: 1028)
    • The executable file from the user directory is run by the CMD process

      • svchost.exe (PID: 3180)
    • Reads settings of System Certificates

      • svchost.exe (PID: 3180)
    • The process executes via Task Scheduler

      • cfmon.exe (PID: 3512)
      • cfmon.exe (PID: 1544)
    • Reads browser cookies

      • cfmon.exe (PID: 3064)
    • Loads DLL from Mozilla Firefox

      • cfmon.exe (PID: 3064)
  • INFO

    • Manual execution by a user

      • cmd.exe (PID: 1344)
      • notepad.exe (PID: 1264)
      • rundll32.exe (PID: 712)
      • RedLine.MainPanel-cracked.exe (PID: 1820)
      • Build.exe (PID: 2748)
      • cmd.exe (PID: 2584)
      • Build.exe (PID: 3584)
      • stub.exe (PID: 2300)
      • builder.exe (PID: 956)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 128)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 128)
    • Checks supported languages

      • RedLine.MainPanel-cracked.exe (PID: 1820)
      • builder.exe (PID: 2340)
      • Build.exe (PID: 2748)
      • cfmon.exe (PID: 3064)
      • svchost.exe (PID: 1028)
      • svchost.exe (PID: 3180)
      • cfmon.exe (PID: 3512)
      • Build.exe (PID: 3584)
      • svchost.exe (PID: 2032)
      • cfmon.exe (PID: 4052)
      • stub.exe (PID: 2300)
      • cfmon.exe (PID: 1544)
      • builder.exe (PID: 956)
      • cfmon.exe (PID: 2404)
      • svchost.exe (PID: 2916)
    • Reads the machine GUID from the registry

      • RedLine.MainPanel-cracked.exe (PID: 1820)
      • Build.exe (PID: 2748)
      • builder.exe (PID: 2340)
      • cfmon.exe (PID: 3064)
      • svchost.exe (PID: 1028)
      • svchost.exe (PID: 3180)
      • cfmon.exe (PID: 3512)
      • Build.exe (PID: 3584)
      • cfmon.exe (PID: 4052)
      • svchost.exe (PID: 2032)
      • cfmon.exe (PID: 1544)
      • builder.exe (PID: 956)
      • stub.exe (PID: 2300)
      • cfmon.exe (PID: 2404)
      • svchost.exe (PID: 2916)
    • Reads the computer name

      • RedLine.MainPanel-cracked.exe (PID: 1820)
      • Build.exe (PID: 2748)
      • builder.exe (PID: 2340)
      • cfmon.exe (PID: 3064)
      • svchost.exe (PID: 1028)
      • svchost.exe (PID: 3180)
      • Build.exe (PID: 3584)
      • cfmon.exe (PID: 3512)
      • cfmon.exe (PID: 4052)
      • svchost.exe (PID: 2032)
      • stub.exe (PID: 2300)
      • builder.exe (PID: 956)
      • cfmon.exe (PID: 1544)
      • cfmon.exe (PID: 2404)
      • svchost.exe (PID: 2916)
    • Reads Environment values

      • RedLine.MainPanel-cracked.exe (PID: 1820)
      • svchost.exe (PID: 3180)
    • Create files in a temporary directory

      • Build.exe (PID: 2748)
      • svchost.exe (PID: 1028)
      • svchost.exe (PID: 3180)
      • cfmon.exe (PID: 3064)
    • Creates files or folders in the user directory

      • Build.exe (PID: 2748)
      • cfmon.exe (PID: 3064)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2023:12:26 05:01:40
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: RedLine Stealer Cracked/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
92
Monitored processes
36
Malicious processes
7
Suspicious processes
6

Behavior graph

Click at the process to see the details
start winrar.exe cmd.exe no specs netsh.exe no specs notepad.exe no specs rundll32.exe no specs redline.mainpanel-cracked.exe no specs builder.exe cmd.exe no specs build.exe powershell.exe no specs schtasks.exe no specs #XWORM cfmon.exe powershell.exe no specs schtasks.exe no specs svchost.exe cmd.exe no specs timeout.exe no specs #ASYNCRAT svchost.exe schtasks.exe no specs cfmon.exe no specs build.exe powershell.exe no specs schtasks.exe no specs cfmon.exe no specs powershell.exe no specs schtasks.exe no specs svchost.exe no specs builder.exe no specs cfmon.exe no specs stub.exe powershell.exe no specs schtasks.exe no specs powershell.exe no specs cfmon.exe no specs schtasks.exe no specs svchost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
128"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\RedLine Stealer Cracked.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
584netsh advfirewall firewall add rule name="RLS" dir=in action=allow protocol=TCP localport=6677C:\Windows\System32\netsh.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Network Command Shell
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\netsh.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\credui.dll
c:\windows\system32\user32.dll
712"C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\Desktop\RedLine Stealer Cracked\RedLine.MainPanel1.exe.configC:\Windows\System32\rundll32.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
712"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -ExecutionPolicy Bypass Add-MpPreference -ExclusionPath 'C:\Users\admin\AppData\Local\Temp\cfmon.exe'C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exestub.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
1
Version:
10.0.14409.1005 (rs1_srvoob.161208-1155)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\atl.dll
c:\windows\system32\user32.dll
956"C:\Users\admin\Desktop\RedLine Stealer Cracked\Libraries\builder.exe" C:\Users\admin\Desktop\RedLine Stealer Cracked\Libraries\builder.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
builder
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\redline stealer cracked\libraries\builder.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1028"C:\Users\admin\AppData\Roaming\svchost.exe" C:\Users\admin\AppData\Roaming\svchost.exe
Build.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Version:
3.6.0.0
Modules
Images
c:\users\admin\appdata\roaming\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1264"C:\Windows\System32\NOTEPAD.EXE" C:\Users\admin\Desktop\RedLine Stealer Cracked\OpenPort.batC:\Windows\System32\notepad.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1344C:\Windows\system32\cmd.exe /c ""C:\Users\admin\Desktop\RedLine Stealer Cracked\OpenPort.bat" "C:\Windows\System32\cmd.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1404"C:\Windows\System32\schtasks.exe" /Create /F /TN "svchost" /SC ONLOGON /TR "C:\Users\admin\AppData\Roaming\svchost.exe" /RL HIGHESTC:\Windows\System32\schtasks.exeBuild.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Manages scheduled tasks
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
1544C:\Users\admin\AppData\Local\Temp\cfmon.exe C:\Users\admin\AppData\Local\Temp\cfmon.exetaskeng.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\cfmon.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
21 701
Read events
21 425
Write events
269
Delete events
7

Modification events

(PID) Process:(128) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(128) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(128) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(128) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(128) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(128) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(128) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(128) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(128) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(128) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
Executable files
18
Suspicious files
35
Text files
7
Unknown types
0

Dropped files

PID
Process
Filename
Type
128WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb128.27253\RedLine Stealer Cracked\Libraries\Mono.Cecil.dllexecutable
MD5:7546ACEBC5A5213DEE2A5ED18D7EBC6C
SHA256:7744C9C84C28033BC3606F4DFCE2ADCD6F632E2BE7827893C3E2257100F1CF9E
128WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb128.27253\RedLine Stealer Cracked\Libraries\Mono.Cecil.Mdb.pdbbinary
MD5:0BA762B6B5FBDA000E51D66722A3BB2C
SHA256:D18EB89421D50F079291B78783408CEE4BAB6810E4C5A4B191849265BDD5BA7C
128WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb128.27253\RedLine Stealer Cracked\Libraries\links.txttext
MD5:7E0B0F449C419BC5DCE0A9AE1920C00C
SHA256:2CA989920E2CD5C250BE6FB5E0EF82EE45A77F2147E91D736562C110B5EC372E
128WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb128.27253\RedLine Stealer Cracked\Libraries\MetroSet UI.dllbinary
MD5:F13DC3CFFEF729D26C4DA102674561CF
SHA256:D490C04E6E89462FD46099D3454985F319F57032176C67403B3B92C86CA58BCB
128WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb128.27253\RedLine Stealer Cracked\Libraries\builder.pdbbinary
MD5:418DC008EF956465E179EC29D3C3C245
SHA256:8C7E21B37540211D56C5FDBB7E731655A96945AA83F2988E33D5ADB8AA7C8DF1
128WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb128.27253\RedLine Stealer Cracked\Libraries\builder.exeexecutable
MD5:2D6AC27235E545727F1C543CBCB4C606
SHA256:615AA9B90FB40C052EEA89F0B273ED0BC5A4AB218783D30F00ECD72D56B08A25
128WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb128.27253\RedLine Stealer Cracked\Libraries\GuiLib.dllexecutable
MD5:EAF9C55793CD26F133708714ED3A5397
SHA256:87CFC70BEC2D2A37BCD5D46F9E6F0051F82E015FF96E8F2BC2D81B85F2632F15
128WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb128.27253\RedLine Stealer Cracked\Libraries\Bunifu_UI_v1.52.dllexecutable
MD5:5ECA94D909F1BA4C5F3E35AC65A49076
SHA256:DE0E530D46C803D85B8AEB6D18816F1B09CB3DAFEFB5E19FDFA15C9F41E0F474
128WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb128.27253\RedLine Stealer Cracked\Libraries\Mono.Cecil.pdbbinary
MD5:C0A69F1B0C50D4F133CD0B278AC2A531
SHA256:A4F79C99D8923BD6C30EFAFA39363C18BABE95F6609BBAD242BCA44342CCC7BB
128WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb128.27253\RedLine Stealer Cracked\Libraries\Mono.Cecil.Rocks.dllexecutable
MD5:C8F36848CE8F13084B355C934FC91746
SHA256:A08C040912DF2A3C823ADE85D62239D56ABAA8F788A2684FB9D33961922687C7
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
14
DNS requests
1
Threats
20

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3180
svchost.exe
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?7b8bf25e79379a08
GB
compressed
65.2 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
3180
svchost.exe
85.217.170.160:3232
Belcloud LTD
BG
unknown
3180
svchost.exe
93.184.221.240:80
ctldl.windowsupdate.com
EDGECAST
GB
whitelisted
3064
cfmon.exe
206.123.140.95:7000
M247 Ltd
DE
malicious
3064
cfmon.exe
206.123.140.137:7000
M247 Ltd
DE
unknown
3180
svchost.exe
206.123.140.137:3232
M247 Ltd
DE
unknown
3064
cfmon.exe
85.217.170.160:7000
Belcloud LTD
BG
unknown

DNS requests

Domain
IP
Reputation
ctldl.windowsupdate.com
  • 93.184.221.240
whitelisted

Threats

PID
Process
Class
Message
3180
svchost.exe
Domain Observed Used for C2 Detected
REMOTE [ANY.RUN] AsyncRAT SSL certificate
3180
svchost.exe
Malware Command and Control Activity Detected
REMOTE [ANY.RUN] AsyncRAT Successful Connection
3064
cfmon.exe
Malware Command and Control Activity Detected
REMOTE [ANY.RUN] Xworm Network Packet
17 ETPRO signatures available at the full report
No debug info