File name:

ChessBotX 1.5.7 TRIAL.rar

Full analysis: https://app.any.run/tasks/0ca73ba9-ebe5-405d-b688-416fc4d2afef
Verdict: Malicious activity
Analysis date: July 03, 2021, 19:11:34
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

AA0C99CC30D77BCD453F542B3BB32714

SHA1:

4A6D41A38164A1B8B544486E18A56D18C8491BDA

SHA256:

74849D184BDCE7AA1EE7E0FB194030046E3A9D0D4FD22A3D70396580150C2960

SSDEEP:

98304:oWdAlPAFlOv7qLtWX3x4yzL2k6ZDQmWlTYOYWbJGNluy5xiC7O1OB:BAl4HDKtLneQxlTLYWbJGX5zB

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • ChessBot.exe (PID: 2916)
      • ChessBot.exe (PID: 2400)
      • Client.exe (PID: 2712)
      • ChessBot.exe (PID: 3648)
      • njrat8.exe (PID: 2440)
    • Writes to a start menu file

      • Client.exe (PID: 2712)
  • SUSPICIOUS

    • Checks supported languages

      • WinRAR.exe (PID: 1696)
      • ChessBot.exe (PID: 2916)
      • ChessBot.exe (PID: 3648)
      • njrat8.exe (PID: 2440)
      • Client.exe (PID: 2712)
    • Drops a file with too old compile date

      • WinRAR.exe (PID: 1696)
      • ChessBot.exe (PID: 2916)
    • Reads the computer name

      • WinRAR.exe (PID: 1696)
      • ChessBot.exe (PID: 2916)
      • ChessBot.exe (PID: 3648)
      • Client.exe (PID: 2712)
      • njrat8.exe (PID: 2440)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1696)
      • ChessBot.exe (PID: 2916)
      • Client.exe (PID: 2712)
      • njrat8.exe (PID: 2440)
    • Starts itself from another location

      • njrat8.exe (PID: 2440)
    • Creates files in the user directory

      • Client.exe (PID: 2712)
    • Reads Environment values

      • Client.exe (PID: 2712)
  • INFO

    • Manual execution by user

      • ChessBot.exe (PID: 2400)
      • ChessBot.exe (PID: 2916)
    • Dropped object may contain Bitcoin addresses

      • ChessBot.exe (PID: 2916)
      • njrat8.exe (PID: 2440)
      • Client.exe (PID: 2712)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
43
Monitored processes
6
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
start drop and start drop and start drop and start winrar.exe chessbot.exe no specs chessbot.exe chessbot.exe no specs njrat8.exe client.exe

Process information

PID
CMD
Path
Indicators
Parent process
1696"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\ChessBotX 1.5.7 TRIAL.rar"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2400"C:\Users\admin\Desktop\ChessBotX 1.5.7 TRIAL\ChessBot.exe" C:\Users\admin\Desktop\ChessBotX 1.5.7 TRIAL\ChessBot.exeExplorer.EXE
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\chessbotx 1.5.7 trial\chessbot.exe
c:\windows\system32\ntdll.dll
2440"C:\Users\admin\AppData\Local\Temp\njrat8.exe" C:\Users\admin\AppData\Local\Temp\njrat8.exe
ChessBot.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\njrat8.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\rpcrt4.dll
2712"C:\Users\admin\AppData\Local\Temp\Client.exe" C:\Users\admin\AppData\Local\Temp\Client.exe
njrat8.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\client.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2916"C:\Users\admin\Desktop\ChessBotX 1.5.7 TRIAL\ChessBot.exe" C:\Users\admin\Desktop\ChessBotX 1.5.7 TRIAL\ChessBot.exe
Explorer.EXE
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\chessbotx 1.5.7 trial\chessbot.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
3648"C:\Users\admin\AppData\Local\Temp\ChessBot.exe" C:\Users\admin\AppData\Local\Temp\ChessBot.exeChessBot.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\chessbot.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\sechost.dll
Total events
3 680
Read events
3 651
Write events
29
Delete events
0

Modification events

(PID) Process:(1696) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1696) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1696) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1696) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(1696) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\ChessBotX 1.5.7 TRIAL.rar
(PID) Process:(1696) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1696) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1696) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1696) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2916) ChessBot.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
6
Suspicious files
0
Text files
8
Unknown types
70

Dropped files

PID
Process
Filename
Type
1696WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1696.34432\ChessBotX 1.5.7 TRIAL\Books\GM.book
MD5:
SHA256:
1696WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1696.34432\ChessBotX 1.5.7 TRIAL\Settings.initext
MD5:
SHA256:
1696WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1696.34432\ChessBotX 1.5.7 TRIAL\System\defaults.cfgtext
MD5:
SHA256:
1696WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1696.34432\ChessBotX 1.5.7 TRIAL\voiceover\a4.mp3mp3
MD5:36A23F7B9F166261D0AC4BA54E52D380
SHA256:E5F0B8A6A0601644CDFA2DCAFDE32A248CDAC6B46BE53268D9A594175B3E806A
1696WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1696.34432\ChessBotX 1.5.7 TRIAL\voiceover\a1.mp3mp3
MD5:CED1AA96B588829BB1C912B93B09882F
SHA256:2A256643B2387848EAC75A6AF0B5E9F861EE552255525EDF1CC0455C6870830D
1696WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1696.34432\ChessBotX 1.5.7 TRIAL\Books\Basic.booktext
MD5:A1C8E87C5852D13D050D4DBE08B43A94
SHA256:6097925BA0DC7280303A1BBAD83F31912E6084F2BADBA859632C6ED2F5EBFA8B
1696WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1696.34432\ChessBotX 1.5.7 TRIAL\Config\Delays for bullet 1+0.cfgtext
MD5:AF2E825EA6E80FB5E10D9DA97A31F39C
SHA256:D6E1A4435C11E493C4AB3F8C9A2E0F0615463E1E04516C2F9009438EE4CFC76A
1696WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1696.34432\ChessBotX 1.5.7 TRIAL\voiceover\a6.mp3mp3
MD5:54C69A2E4BECF27CEF9068F4F656C062
SHA256:5C0665238AB5A256E5994B5971973F9D94452C280C80CCD20B18C2CB73C83676
1696WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1696.34432\ChessBotX 1.5.7 TRIAL\System\stockfish_10_x32.exeexecutable
MD5:34406AA7CF824AFD1C99EDBC8DED5A73
SHA256:A1A2A352CA9647106E743FB2C1E8551BA6CC1B714DEDA49596B33AF7B11FAC97
1696WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1696.34432\ChessBotX 1.5.7 TRIAL\voiceover\a2.mp3mp3
MD5:A000D7EBD6C6549CC66720E8F520470A
SHA256:990A8A68237F5620EBD2ED383B347F33674B89DED2EF04E05A6BACE20FA3D189
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
1
DNS requests
1
Threats
1

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2712
Client.exe
102.44.173.68:6666
medomoshkela.ddns.net
unknown

DNS requests

Domain
IP
Reputation
medomoshkela.ddns.net
  • 102.44.173.68
unknown

Threats

PID
Process
Class
Message
Potentially Bad Traffic
ET POLICY DNS Query to DynDNS Domain *.ddns .net
No debug info