download:

OpenBullet+1.3.6.rar

Full analysis: https://app.any.run/tasks/4b7c80e1-778b-4d80-a26a-a83c7948e871
Verdict: Malicious activity
Analysis date: August 18, 2019, 17:04:08
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v4, os: Win32
MD5:

99681E868E055972BE32C5263EF7D5AC

SHA1:

B2F305A5E11B6BEF51116A3B548F7E548339ECA8

SHA256:

6D97CDD0A2D17794261FFBE82B10B1931116A21C4C5168A25E9375F0C81E0930

SSDEEP:

393216:5PggzliWNTyvuqoldSPLyTF86m5kUcQ1XC9OHQu7o2inslVeqnA:B5cwTyP0SPL0F86mqNQ2u7luGVnA

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • OpenBullet.exe (PID: 3912)
      • SearchProtocolHost.exe (PID: 772)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3664)
    • Reads Environment values

      • OpenBullet.exe (PID: 3912)
  • INFO

    • Reads settings of System Certificates

      • OpenBullet.exe (PID: 3912)
    • Manual execution by user

      • OpenBullet.exe (PID: 3912)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

CompressedSize: 6431
UncompressedSize: 16896
OperatingSystem: Win32
ModifyDate: 2019:03:06 21:22:26
PackingMethod: Normal
ArchivedFileName: OpenBullet 1.3.6\bin\2Captcha.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
35
Monitored processes
3
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe searchprotocolhost.exe no specs openbullet.exe

Process information

PID
CMD
Path
Indicators
Parent process
772"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3664"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\OpenBullet+1.3.6.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3912"C:\Users\admin\Desktop\OpenBullet 1.3.6\OpenBullet.exe" C:\Users\admin\Desktop\OpenBullet 1.3.6\OpenBullet.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
OpenBullet
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\openbullet 1.3.6\openbullet.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
850
Read events
804
Write events
46
Delete events
0

Modification events

(PID) Process:(3664) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3664) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3664) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3664) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\OpenBullet+1.3.6.rar
(PID) Process:(3664) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3664) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3664) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3664) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3664) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
(PID) Process:(3664) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\General
Operation:writeName:LastFolder
Value:
C:\Users\admin\AppData\Local\Temp
Executable files
37
Suspicious files
0
Text files
8
Unknown types
1

Dropped files

PID
Process
Filename
Type
3664WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3664.43023\OpenBullet 1.3.6\bin\AngleSharp.dllexecutable
MD5:BF331AB2E9BB06D900929DE29C659AE8
SHA256:0B6D37C6113914DECB8AE2142DEE7CF476206036806821AC6DC63D69269F827B
3664WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3664.43023\OpenBullet 1.3.6\bin\Extreme.Net.dllexecutable
MD5:4BD4346716370386491D6EBC4438B69D
SHA256:155E446000555C8EDAC8304CEF99C2CD54E8267981F1482D14A69C66575E6551
3664WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3664.43023\OpenBullet 1.3.6\bin\AntiCaptcha.dllexecutable
MD5:595CB3CD2F929A641391A529219A2F75
SHA256:DFFD4A411F58232D32B1DF1A2B4F2B73B611D01F98FEE8346D3A3211CFEAA3C2
3664WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3664.43023\OpenBullet 1.3.6\bin\RuriLib.dllexecutable
MD5:
SHA256:
3664WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3664.43023\OpenBullet 1.3.6\bin\CloudflareSolver.dllexecutable
MD5:00390D98A549F926124A414948FBF606
SHA256:8DAB176D8DD3B4992CD22FCDEA1A46F7E0A34CDBC9E40925763664323CC42241
3664WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3664.43023\OpenBullet 1.3.6\bin\ProxySocket.dllexecutable
MD5:13F842AC397885C4E647EC35F2AB79E5
SHA256:851E924110BA3FF3DCD8C894D9C264A1AA3715AAED36E5EF4E320A73D3451A16
3664WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3664.43023\OpenBullet 1.3.6\bin\Newtonsoft.Json.dllexecutable
MD5:4DF6C8781E70C3A4912B5BE796E6D337
SHA256:3598CCCAD5B535FEA6F93662107A4183BFD6167BF1D0F80260436093EDC2E3AF
3664WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3664.43023\OpenBullet 1.3.6\bin\IronPython.SQLite.dllexecutable
MD5:B7EFBF654402C78226B8D69AD0011BBB
SHA256:5A6E2EDA86E863E155F67CEBEF095355B7EA7B1DCD97D87E4058F0A5AC60D798
3664WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3664.43023\OpenBullet 1.3.6\bin\Jint.dllexecutable
MD5:734C5CE8F9B104D8AD3C7B494E96F9B9
SHA256:ED618668AE9E7C02C7C2B7332DD09079168CCA96432A051044683C996337001C
3664WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3664.43023\OpenBullet 1.3.6\bin\Microsoft.Dynamic.dllexecutable
MD5:ABA389A299BEB16CC04337EC76C8A965
SHA256:4F7425CB08CC9BCA6FCA4BFC08D22B6D9716C507F306F40AE7134B878D909A21
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
2
DNS requests
2
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3912
OpenBullet.exe
151.101.0.133:443
raw.githubusercontent.com
Fastly
US
malicious
3912
OpenBullet.exe
192.30.253.113:443
github.com
GitHub, Inc.
US
shared

DNS requests

Domain
IP
Reputation
github.com
  • 192.30.253.113
malicious
raw.githubusercontent.com
  • 151.101.0.133
  • 151.101.64.133
  • 151.101.128.133
  • 151.101.192.133
shared

Threats

No threats detected
No debug info