File name:

ChessBotX 1.5.7 TRIAL.rar

Full analysis: https://app.any.run/tasks/0ca73ba9-ebe5-405d-b688-416fc4d2afef
Verdict: Malicious activity
Analysis date: July 03, 2021, 19:11:34
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

AA0C99CC30D77BCD453F542B3BB32714

SHA1:

4A6D41A38164A1B8B544486E18A56D18C8491BDA

SHA256:

74849D184BDCE7AA1EE7E0FB194030046E3A9D0D4FD22A3D70396580150C2960

SSDEEP:

98304:oWdAlPAFlOv7qLtWX3x4yzL2k6ZDQmWlTYOYWbJGNluy5xiC7O1OB:BAl4HDKtLneQxlTLYWbJGX5zB

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • ChessBot.exe (PID: 2400)
      • ChessBot.exe (PID: 2916)
      • njrat8.exe (PID: 2440)
      • ChessBot.exe (PID: 3648)
      • Client.exe (PID: 2712)
    • Writes to a start menu file

      • Client.exe (PID: 2712)
  • SUSPICIOUS

    • Reads the computer name

      • WinRAR.exe (PID: 1696)
      • ChessBot.exe (PID: 2916)
      • ChessBot.exe (PID: 3648)
      • njrat8.exe (PID: 2440)
      • Client.exe (PID: 2712)
    • Checks supported languages

      • WinRAR.exe (PID: 1696)
      • ChessBot.exe (PID: 2916)
      • ChessBot.exe (PID: 3648)
      • njrat8.exe (PID: 2440)
      • Client.exe (PID: 2712)
    • Drops a file with too old compile date

      • WinRAR.exe (PID: 1696)
      • ChessBot.exe (PID: 2916)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1696)
      • ChessBot.exe (PID: 2916)
      • njrat8.exe (PID: 2440)
      • Client.exe (PID: 2712)
    • Starts itself from another location

      • njrat8.exe (PID: 2440)
    • Creates files in the user directory

      • Client.exe (PID: 2712)
    • Reads Environment values

      • Client.exe (PID: 2712)
  • INFO

    • Manual execution by user

      • ChessBot.exe (PID: 2400)
      • ChessBot.exe (PID: 2916)
    • Dropped object may contain Bitcoin addresses

      • ChessBot.exe (PID: 2916)
      • Client.exe (PID: 2712)
      • njrat8.exe (PID: 2440)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
43
Monitored processes
6
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
start drop and start drop and start drop and start winrar.exe chessbot.exe no specs chessbot.exe chessbot.exe no specs njrat8.exe client.exe

Process information

PID
CMD
Path
Indicators
Parent process
1696"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\ChessBotX 1.5.7 TRIAL.rar"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2400"C:\Users\admin\Desktop\ChessBotX 1.5.7 TRIAL\ChessBot.exe" C:\Users\admin\Desktop\ChessBotX 1.5.7 TRIAL\ChessBot.exeExplorer.EXE
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\chessbotx 1.5.7 trial\chessbot.exe
c:\windows\system32\ntdll.dll
2440"C:\Users\admin\AppData\Local\Temp\njrat8.exe" C:\Users\admin\AppData\Local\Temp\njrat8.exe
ChessBot.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\njrat8.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\rpcrt4.dll
2712"C:\Users\admin\AppData\Local\Temp\Client.exe" C:\Users\admin\AppData\Local\Temp\Client.exe
njrat8.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\client.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2916"C:\Users\admin\Desktop\ChessBotX 1.5.7 TRIAL\ChessBot.exe" C:\Users\admin\Desktop\ChessBotX 1.5.7 TRIAL\ChessBot.exe
Explorer.EXE
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\chessbotx 1.5.7 trial\chessbot.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
3648"C:\Users\admin\AppData\Local\Temp\ChessBot.exe" C:\Users\admin\AppData\Local\Temp\ChessBot.exeChessBot.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\chessbot.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\sechost.dll
Total events
3 680
Read events
3 651
Write events
29
Delete events
0

Modification events

(PID) Process:(1696) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1696) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1696) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1696) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(1696) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\ChessBotX 1.5.7 TRIAL.rar
(PID) Process:(1696) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1696) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1696) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1696) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2916) ChessBot.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
6
Suspicious files
0
Text files
8
Unknown types
70

Dropped files

PID
Process
Filename
Type
1696WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1696.34432\ChessBotX 1.5.7 TRIAL\Books\GM.book
MD5:
SHA256:
1696WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1696.34432\ChessBotX 1.5.7 TRIAL\Settings.initext
MD5:
SHA256:
1696WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1696.34432\ChessBotX 1.5.7 TRIAL\System\SystemDelays.cfgtext
MD5:
SHA256:
1696WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1696.34432\ChessBotX 1.5.7 TRIAL\System\defaults.cfgtext
MD5:
SHA256:
1696WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1696.34432\ChessBotX 1.5.7 TRIAL\Config\Delays for bullet 1+0.cfgtext
MD5:AF2E825EA6E80FB5E10D9DA97A31F39C
SHA256:D6E1A4435C11E493C4AB3F8C9A2E0F0615463E1E04516C2F9009438EE4CFC76A
1696WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1696.34432\ChessBotX 1.5.7 TRIAL\ChessBot.exeexecutable
MD5:
SHA256:
1696WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1696.34432\ChessBotX 1.5.7 TRIAL\voiceover\a1.mp3mp3
MD5:CED1AA96B588829BB1C912B93B09882F
SHA256:2A256643B2387848EAC75A6AF0B5E9F861EE552255525EDF1CC0455C6870830D
1696WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1696.34432\ChessBotX 1.5.7 TRIAL\Config\Instant (without delay).cfgtext
MD5:F010618E4182AF042A52A43842133D63
SHA256:BDF694978E13BEBE3E4987D888A119CA76AC36F8ECB5033DD2D6ECE5C42687AE
1696WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1696.34432\ChessBotX 1.5.7 TRIAL\voiceover\a3.mp3mp3
MD5:EA3613566864C05AB1D10BE0ADC2880A
SHA256:6D1FC4061FEC1B45A6628CD8E05ECEEBD0BEF00F3C3A5C3F88437D8E85B4104B
1696WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1696.34432\ChessBotX 1.5.7 TRIAL\voiceover\a6.mp3mp3
MD5:54C69A2E4BECF27CEF9068F4F656C062
SHA256:5C0665238AB5A256E5994B5971973F9D94452C280C80CCD20B18C2CB73C83676
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
1
DNS requests
1
Threats
1

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2712
Client.exe
102.44.173.68:6666
medomoshkela.ddns.net
unknown

DNS requests

Domain
IP
Reputation
medomoshkela.ddns.net
  • 102.44.173.68
unknown

Threats

PID
Process
Class
Message
Potentially Bad Traffic
ET POLICY DNS Query to DynDNS Domain *.ddns .net
No debug info