File name:

ChessBotX 1.5.7 TRIAL.rar

Full analysis: https://app.any.run/tasks/0ca73ba9-ebe5-405d-b688-416fc4d2afef
Verdict: Malicious activity
Analysis date: July 03, 2021, 19:11:34
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

AA0C99CC30D77BCD453F542B3BB32714

SHA1:

4A6D41A38164A1B8B544486E18A56D18C8491BDA

SHA256:

74849D184BDCE7AA1EE7E0FB194030046E3A9D0D4FD22A3D70396580150C2960

SSDEEP:

98304:oWdAlPAFlOv7qLtWX3x4yzL2k6ZDQmWlTYOYWbJGNluy5xiC7O1OB:BAl4HDKtLneQxlTLYWbJGX5zB

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • ChessBot.exe (PID: 2916)
      • ChessBot.exe (PID: 2400)
      • ChessBot.exe (PID: 3648)
      • njrat8.exe (PID: 2440)
      • Client.exe (PID: 2712)
    • Writes to a start menu file

      • Client.exe (PID: 2712)
  • SUSPICIOUS

    • Reads the computer name

      • WinRAR.exe (PID: 1696)
      • ChessBot.exe (PID: 2916)
      • njrat8.exe (PID: 2440)
      • ChessBot.exe (PID: 3648)
      • Client.exe (PID: 2712)
    • Checks supported languages

      • WinRAR.exe (PID: 1696)
      • ChessBot.exe (PID: 2916)
      • ChessBot.exe (PID: 3648)
      • njrat8.exe (PID: 2440)
      • Client.exe (PID: 2712)
    • Drops a file with too old compile date

      • WinRAR.exe (PID: 1696)
      • ChessBot.exe (PID: 2916)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1696)
      • ChessBot.exe (PID: 2916)
      • njrat8.exe (PID: 2440)
      • Client.exe (PID: 2712)
    • Starts itself from another location

      • njrat8.exe (PID: 2440)
    • Creates files in the user directory

      • Client.exe (PID: 2712)
    • Reads Environment values

      • Client.exe (PID: 2712)
  • INFO

    • Manual execution by user

      • ChessBot.exe (PID: 2400)
      • ChessBot.exe (PID: 2916)
    • Dropped object may contain Bitcoin addresses

      • ChessBot.exe (PID: 2916)
      • njrat8.exe (PID: 2440)
      • Client.exe (PID: 2712)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
43
Monitored processes
6
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
start drop and start drop and start drop and start winrar.exe chessbot.exe no specs chessbot.exe chessbot.exe no specs njrat8.exe client.exe

Process information

PID
CMD
Path
Indicators
Parent process
1696"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\ChessBotX 1.5.7 TRIAL.rar"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2400"C:\Users\admin\Desktop\ChessBotX 1.5.7 TRIAL\ChessBot.exe" C:\Users\admin\Desktop\ChessBotX 1.5.7 TRIAL\ChessBot.exeExplorer.EXE
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\chessbotx 1.5.7 trial\chessbot.exe
c:\windows\system32\ntdll.dll
2440"C:\Users\admin\AppData\Local\Temp\njrat8.exe" C:\Users\admin\AppData\Local\Temp\njrat8.exe
ChessBot.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\njrat8.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\rpcrt4.dll
2712"C:\Users\admin\AppData\Local\Temp\Client.exe" C:\Users\admin\AppData\Local\Temp\Client.exe
njrat8.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\client.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2916"C:\Users\admin\Desktop\ChessBotX 1.5.7 TRIAL\ChessBot.exe" C:\Users\admin\Desktop\ChessBotX 1.5.7 TRIAL\ChessBot.exe
Explorer.EXE
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\chessbotx 1.5.7 trial\chessbot.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
3648"C:\Users\admin\AppData\Local\Temp\ChessBot.exe" C:\Users\admin\AppData\Local\Temp\ChessBot.exeChessBot.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\chessbot.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\sechost.dll
Total events
3 680
Read events
3 651
Write events
29
Delete events
0

Modification events

(PID) Process:(1696) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1696) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1696) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1696) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(1696) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\ChessBotX 1.5.7 TRIAL.rar
(PID) Process:(1696) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1696) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1696) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1696) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2916) ChessBot.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
6
Suspicious files
0
Text files
8
Unknown types
70

Dropped files

PID
Process
Filename
Type
1696WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1696.34432\ChessBotX 1.5.7 TRIAL\Books\GM.book
MD5:
SHA256:
1696WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1696.34432\ChessBotX 1.5.7 TRIAL\System\SystemDelays.cfgtext
MD5:
SHA256:
1696WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1696.34432\ChessBotX 1.5.7 TRIAL\Settings.initext
MD5:
SHA256:
1696WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1696.34432\ChessBotX 1.5.7 TRIAL\ChessBot.exeexecutable
MD5:
SHA256:
1696WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1696.34432\ChessBotX 1.5.7 TRIAL\System\defaults.cfgtext
MD5:
SHA256:
1696WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1696.34432\ChessBotX 1.5.7 TRIAL\Config\Delays for bullet 1+0.cfgtext
MD5:AF2E825EA6E80FB5E10D9DA97A31F39C
SHA256:D6E1A4435C11E493C4AB3F8C9A2E0F0615463E1E04516C2F9009438EE4CFC76A
1696WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1696.34432\ChessBotX 1.5.7 TRIAL\voiceover\a2.mp3mp3
MD5:A000D7EBD6C6549CC66720E8F520470A
SHA256:990A8A68237F5620EBD2ED383B347F33674B89DED2EF04E05A6BACE20FA3D189
1696WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1696.34432\ChessBotX 1.5.7 TRIAL\Engines Settings\stockfish_10_x32.cfgtext
MD5:E2942405D2A4ECBF21C5BB8AA13FEC42
SHA256:21F5A31AAB15A3EE6FA01BA98EF3A2B55A40172AA518AAF0B4957E36ADDE7C58
1696WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1696.34432\ChessBotX 1.5.7 TRIAL\voiceover\a1.mp3mp3
MD5:CED1AA96B588829BB1C912B93B09882F
SHA256:2A256643B2387848EAC75A6AF0B5E9F861EE552255525EDF1CC0455C6870830D
1696WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1696.34432\ChessBotX 1.5.7 TRIAL\voiceover\a7.mp3mp3
MD5:9C89D3E9CBBF3801BEF7A3A9C572D861
SHA256:7CFBD0ECB70AB518F3444195C0CCAFFC0F2058D2F7406507463782FC477E4CE0
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
1
DNS requests
1
Threats
1

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2712
Client.exe
102.44.173.68:6666
medomoshkela.ddns.net
unknown

DNS requests

Domain
IP
Reputation
medomoshkela.ddns.net
  • 102.44.173.68
unknown

Threats

PID
Process
Class
Message
Potentially Bad Traffic
ET POLICY DNS Query to DynDNS Domain *.ddns .net
No debug info