download:

OpenBullet+1.3.6.rar

Full analysis: https://app.any.run/tasks/4b7c80e1-778b-4d80-a26a-a83c7948e871
Verdict: Malicious activity
Analysis date: August 18, 2019, 17:04:08
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v4, os: Win32
MD5:

99681E868E055972BE32C5263EF7D5AC

SHA1:

B2F305A5E11B6BEF51116A3B548F7E548339ECA8

SHA256:

6D97CDD0A2D17794261FFBE82B10B1931116A21C4C5168A25E9375F0C81E0930

SSDEEP:

393216:5PggzliWNTyvuqoldSPLyTF86m5kUcQ1XC9OHQu7o2inslVeqnA:B5cwTyP0SPL0F86mqNQ2u7luGVnA

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 772)
      • OpenBullet.exe (PID: 3912)
  • SUSPICIOUS

    • Reads Environment values

      • OpenBullet.exe (PID: 3912)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3664)
  • INFO

    • Manual execution by user

      • OpenBullet.exe (PID: 3912)
    • Reads settings of System Certificates

      • OpenBullet.exe (PID: 3912)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

CompressedSize: 6431
UncompressedSize: 16896
OperatingSystem: Win32
ModifyDate: 2019:03:06 21:22:26
PackingMethod: Normal
ArchivedFileName: OpenBullet 1.3.6\bin\2Captcha.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
35
Monitored processes
3
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe searchprotocolhost.exe no specs openbullet.exe

Process information

PID
CMD
Path
Indicators
Parent process
772"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3664"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\OpenBullet+1.3.6.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3912"C:\Users\admin\Desktop\OpenBullet 1.3.6\OpenBullet.exe" C:\Users\admin\Desktop\OpenBullet 1.3.6\OpenBullet.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
OpenBullet
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\openbullet 1.3.6\openbullet.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
850
Read events
804
Write events
46
Delete events
0

Modification events

(PID) Process:(3664) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3664) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3664) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3664) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\OpenBullet+1.3.6.rar
(PID) Process:(3664) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3664) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3664) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3664) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3664) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
(PID) Process:(3664) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\General
Operation:writeName:LastFolder
Value:
C:\Users\admin\AppData\Local\Temp
Executable files
37
Suspicious files
0
Text files
8
Unknown types
1

Dropped files

PID
Process
Filename
Type
3664WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3664.43023\OpenBullet 1.3.6\bin\2Captcha.dllexecutable
MD5:007F2210FC5A0CA51516BB5CA77ED01A
SHA256:DE53E27553D738EC82ADC0F48B6F118D9AF93791482CCEAF28E4A5033A413A7B
3664WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3664.43023\OpenBullet 1.3.6\bin\Extreme.Net.dllexecutable
MD5:4BD4346716370386491D6EBC4438B69D
SHA256:155E446000555C8EDAC8304CEF99C2CD54E8267981F1482D14A69C66575E6551
3664WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3664.43023\OpenBullet 1.3.6\bin\RuriLib.dllexecutable
MD5:
SHA256:
3664WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3664.43023\OpenBullet 1.3.6\bin\ICSharpCode.AvalonEdit.dllexecutable
MD5:B4D5D46E50006E87B30E7D514E95173C
SHA256:058F38F33F3F99F904AB9588447A234346C859718404B4E8A523673ED19CDBE7
3664WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3664.43023\OpenBullet 1.3.6\bin\CloudflareSolver.dllexecutable
MD5:00390D98A549F926124A414948FBF606
SHA256:8DAB176D8DD3B4992CD22FCDEA1A46F7E0A34CDBC9E40925763664323CC42241
3664WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3664.43023\OpenBullet 1.3.6\bin\IronPython.Modules.dllexecutable
MD5:621192DB357916F2261989A49FA2C6BD
SHA256:87525121D7826DCFC76963AB8BD7996B9644BF4F148D1296757EB702A43DA51F
3664WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3664.43023\OpenBullet 1.3.6\bin\Microsoft.Dynamic.dllexecutable
MD5:ABA389A299BEB16CC04337EC76C8A965
SHA256:4F7425CB08CC9BCA6FCA4BFC08D22B6D9716C507F306F40AE7134B878D909A21
3664WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3664.43023\OpenBullet 1.3.6\bin\LiteDB.dllexecutable
MD5:25B242D00C6C32E1F437EB2064EA2E29
SHA256:E72ACDDF47586BC0999D598E3BD125A254BB6F4AE151C076993304F6E31FBBED
3664WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3664.43023\OpenBullet 1.3.6\bin\Jint.dllexecutable
MD5:734C5CE8F9B104D8AD3C7B494E96F9B9
SHA256:ED618668AE9E7C02C7C2B7332DD09079168CCA96432A051044683C996337001C
3664WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3664.43023\OpenBullet 1.3.6\bin\Newtonsoft.Json.dllexecutable
MD5:4DF6C8781E70C3A4912B5BE796E6D337
SHA256:3598CCCAD5B535FEA6F93662107A4183BFD6167BF1D0F80260436093EDC2E3AF
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
2
DNS requests
2
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3912
OpenBullet.exe
192.30.253.113:443
github.com
GitHub, Inc.
US
shared
3912
OpenBullet.exe
151.101.0.133:443
raw.githubusercontent.com
Fastly
US
malicious

DNS requests

Domain
IP
Reputation
github.com
  • 192.30.253.113
malicious
raw.githubusercontent.com
  • 151.101.0.133
  • 151.101.64.133
  • 151.101.128.133
  • 151.101.192.133
shared

Threats

No threats detected
No debug info