File name:

Valorant Skin Changer.zip

Full analysis: https://app.any.run/tasks/64281854-f235-4bd3-aa32-dfeb4fff6e08
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: February 06, 2022, 17:15:36
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
trojan
rat
redline
loader
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract
MD5:

1ED0DA29D77A4779C8274960D4339B81

SHA1:

81B4335F56BCD5274ECB2E9E395D0991A20AF56D

SHA256:

674A1145E788460D6C627BA0622FA442C6F65D3248D72763D0FECA8FC761559B

SSDEEP:

98304:8fkUNWZHpDiWhPXM9b4jAM45Stjl/qS8k8PnHuLHrk:QYpDZ5cqjAM4YJBacrk

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Valorant SkinChanger.exe (PID: 2544)
      • Valorant SkinChanger.exe (PID: 3976)
      • Valorant SkinChanger.exe (PID: 1984)
      • Valorant SkinChanger.exe (PID: 3576)
      • Valorant SkinChanger.exe (PID: 2184)
      • Valorant SkinChanger.exe (PID: 2324)
    • REDLINE was detected

      • AppLaunch.exe (PID: 3196)
      • AppLaunch.exe (PID: 3216)
    • Actions looks like stealing of personal data

      • AppLaunch.exe (PID: 3196)
      • AppLaunch.exe (PID: 3216)
    • Steals credentials from Web Browsers

      • AppLaunch.exe (PID: 3196)
      • AppLaunch.exe (PID: 3216)
    • Connects to CnC server

      • AppLaunch.exe (PID: 3196)
      • AppLaunch.exe (PID: 3216)
  • SUSPICIOUS

    • Reads the computer name

      • WinRAR.exe (PID: 3436)
      • AppLaunch.exe (PID: 3196)
      • AppLaunch.exe (PID: 3216)
      • AppLaunch.exe (PID: 528)
      • AppLaunch.exe (PID: 2480)
      • AppLaunch.exe (PID: 892)
      • AppLaunch.exe (PID: 2816)
    • Checks supported languages

      • WinRAR.exe (PID: 3436)
      • Valorant SkinChanger.exe (PID: 2544)
      • AppLaunch.exe (PID: 3196)
      • AppLaunch.exe (PID: 3216)
      • Valorant SkinChanger.exe (PID: 3976)
      • Valorant SkinChanger.exe (PID: 1984)
      • AppLaunch.exe (PID: 528)
      • Valorant SkinChanger.exe (PID: 3576)
      • AppLaunch.exe (PID: 892)
      • AppLaunch.exe (PID: 2480)
      • Valorant SkinChanger.exe (PID: 2184)
      • Valorant SkinChanger.exe (PID: 2324)
      • AppLaunch.exe (PID: 2816)
    • Drops a file with a compile date too recent

      • WinRAR.exe (PID: 3436)
      • AppLaunch.exe (PID: 3196)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3436)
      • AppLaunch.exe (PID: 3196)
    • Reads the cookies of Google Chrome

      • AppLaunch.exe (PID: 3196)
      • AppLaunch.exe (PID: 3216)
    • Reads the cookies of Mozilla Firefox

      • AppLaunch.exe (PID: 3196)
      • AppLaunch.exe (PID: 3216)
    • Reads Environment values

      • AppLaunch.exe (PID: 3196)
      • AppLaunch.exe (PID: 3216)
    • Searches for installed software

      • AppLaunch.exe (PID: 3196)
      • AppLaunch.exe (PID: 3216)
  • INFO

    • Manual execution by user

      • Valorant SkinChanger.exe (PID: 2544)
      • Valorant SkinChanger.exe (PID: 3976)
      • Valorant SkinChanger.exe (PID: 1984)
      • Valorant SkinChanger.exe (PID: 3576)
      • Valorant SkinChanger.exe (PID: 2184)
      • Valorant SkinChanger.exe (PID: 2324)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: Valorant Skin Changer/
ZipUncompressedSize: -
ZipCompressedSize: -
ZipCRC: 0x00000000
ZipModifyDate: 2022:02:06 21:43:04
ZipCompression: None
ZipBitFlag: -
ZipRequiredVersion: 10
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
56
Monitored processes
13
Malicious processes
7
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe valorant skinchanger.exe #REDLINE applaunch.exe valorant skinchanger.exe #REDLINE applaunch.exe valorant skinchanger.exe applaunch.exe valorant skinchanger.exe valorant skinchanger.exe applaunch.exe applaunch.exe valorant skinchanger.exe applaunch.exe

Process information

PID
CMD
Path
Indicators
Parent process
528"C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe"C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe
Valorant SkinChanger.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft .NET ClickOnce Launch Utility
Exit code:
0
Version:
4.0.30319.34209 built by: FX452RTMGDR
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\applaunch.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
892"C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe"C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe
Valorant SkinChanger.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft .NET ClickOnce Launch Utility
Exit code:
0
Version:
4.0.30319.34209 built by: FX452RTMGDR
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\microsoft.net\framework\v4.0.30319\applaunch.exe
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
1984"C:\Users\admin\Desktop\Valorant Skin Changer\Valorant SkinChanger.exe" C:\Users\admin\Desktop\Valorant Skin Changer\Valorant SkinChanger.exe
Explorer.EXE
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221225477
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\desktop\valorant skin changer\valorant skinchanger.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\oleaut32.dll
2184"C:\Users\admin\Desktop\Valorant Skin Changer\Valorant SkinChanger.exe" C:\Users\admin\Desktop\Valorant Skin Changer\Valorant SkinChanger.exe
Explorer.EXE
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221225477
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\usp10.dll
2324"C:\Users\admin\Desktop\Valorant Skin Changer\Valorant SkinChanger.exe" C:\Users\admin\Desktop\Valorant Skin Changer\Valorant SkinChanger.exe
Explorer.EXE
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221225477
Modules
Images
c:\users\admin\desktop\valorant skin changer\valorant skinchanger.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2480"C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe"C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe
Valorant SkinChanger.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft .NET ClickOnce Launch Utility
Exit code:
0
Version:
4.0.30319.34209 built by: FX452RTMGDR
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\applaunch.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
2544"C:\Users\admin\Desktop\Valorant Skin Changer\Valorant SkinChanger.exe" C:\Users\admin\Desktop\Valorant Skin Changer\Valorant SkinChanger.exe
Explorer.EXE
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221225477
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\desktop\valorant skin changer\valorant skinchanger.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
2816"C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe"C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe
Valorant SkinChanger.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft .NET ClickOnce Launch Utility
Exit code:
0
Version:
4.0.30319.34209 built by: FX452RTMGDR
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\applaunch.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
3196"C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe"C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe
Valorant SkinChanger.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft .NET ClickOnce Launch Utility
Exit code:
0
Version:
4.0.30319.34209 built by: FX452RTMGDR
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\applaunch.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
3216"C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe"C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe
Valorant SkinChanger.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft .NET ClickOnce Launch Utility
Exit code:
0
Version:
4.0.30319.34209 built by: FX452RTMGDR
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\applaunch.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
5 866
Read events
5 824
Write events
42
Delete events
0

Modification events

(PID) Process:(3436) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3436) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3436) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3436) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(3436) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3436) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Valorant Skin Changer.zip
(PID) Process:(3436) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3436) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3436) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3436) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
2
Suspicious files
2
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
3436WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3436.40106\Valorant Skin Changer\config.jsonbinary
MD5:
SHA256:
3436WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3436.40106\Valorant Skin Changer\package-lock.jsonbinary
MD5:
SHA256:
3436WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3436.40106\Valorant Skin Changer\protect.dlltext
MD5:
SHA256:
3436WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3436.40106\Valorant Skin Changer\changer.dlltext
MD5:
SHA256:
3436WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3436.40106\Valorant Skin Changer\Valorant SkinChanger.exeexecutable
MD5:
SHA256:
3196AppLaunch.exeC:\Users\admin\AppData\Local\Temp\sys32.exeexecutable
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
7
DNS requests
1
Threats
57

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3196
AppLaunch.exe
GET
200
146.185.239.127:80
http://coin-coin-file-9.com/files/2158_1643992374_7458.exe
RU
executable
7.27 Mb
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3196
AppLaunch.exe
91.243.32.8:20856
Petersburg Internet Network ltd.
RU
malicious
3216
AppLaunch.exe
91.243.32.8:20856
Petersburg Internet Network ltd.
RU
malicious
3196
AppLaunch.exe
146.185.239.127:80
coin-coin-file-9.com
root SA
RU
malicious
528
AppLaunch.exe
91.243.32.8:20856
Petersburg Internet Network ltd.
RU
malicious
892
AppLaunch.exe
91.243.32.8:20856
Petersburg Internet Network ltd.
RU
malicious
2480
AppLaunch.exe
91.243.32.8:20856
Petersburg Internet Network ltd.
RU
malicious
2816
AppLaunch.exe
91.243.32.8:20856
Petersburg Internet Network ltd.
RU
malicious

DNS requests

Domain
IP
Reputation
coin-coin-file-9.com
  • 146.185.239.127
malicious

Threats

PID
Process
Class
Message
3196
AppLaunch.exe
Potential Corporate Privacy Violation
AV POLICY HTTP request for .exe file with no User-Agent
3196
AppLaunch.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
3196
AppLaunch.exe
Potentially Bad Traffic
ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download
54 ETPRO signatures available at the full report
No debug info