| File name: | Dfgownloads.rar |
| Full analysis: | https://app.any.run/tasks/1e0acd0c-2acd-41c5-9ddb-03c113ed6465 |
| Verdict: | Malicious activity |
| Analysis date: | October 19, 2023, 10:28:23 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v5 |
| MD5: | BB4C399E02EE90EFE868AFAC1A7D4E9B |
| SHA1: | 44B4D1C297EA627AFD566DE84EFF1A9DAAD234EF |
| SHA256: | 7B821449D8A58E32F8607626BC8A7F2DE8F727C76231A42C5F3DE56B771AE620 |
| SSDEEP: | 393216:CalJ6jv61hz03ePtUq01E8dFFZOtVx+G8DOgeyOtcrvJUXmOkp8E:PJ6e1qq09dZOtffBgctAnOU8E |
| .rar | | | RAR compressed archive (v5.0) (61.5) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 368 | taskeng.exe {A138C7FA-105D-4695-A941-2BE80CB32127} | C:\Windows\System32\taskeng.exe | svchost.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Task Scheduler Engine Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 584 | "C:\Users\admin\Desktop\BiFrOsT_Korabika_0.1\Dev-PoinT\Bifrost Korabika.exe" | C:\Users\admin\Desktop\BiFrOsT_Korabika_0.1\Dev-PoinT\Bifrost Korabika.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: BiFrOsT KoRaBiKa 0.1 Exit code: 20 Version: 0, 1 Modules
| |||||||||||||||
| 888 | "C:\Users\admin\Desktop\Bifrost_SAWII\Bifrost_SAWII\مترجم الكيلوجر.exe" | C:\Users\admin\Desktop\Bifrost_SAWII\Bifrost_SAWII\مترجم الكيلوجر.exe | — | explorer.exe | |||||||||||
User: admin Company: alshamrani Integrity Level: MEDIUM Exit code: 0 Version: 1.00 Modules
| |||||||||||||||
| 928 | "C:\Windows\system32\Dwm.exe" | C:\Windows\System32\dwm.exe | svchost.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Desktop Window Manager Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 964 | "C:\Users\admin\Desktop\BiFroSt-MaTreX\BiFroSt-MaTreX\server.exe" | C:\Users\admin\Desktop\BiFroSt-MaTreX\BiFroSt-MaTreX\server.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 1028 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1232 | "C:\Users\admin\Desktop\BiFrOsT-MoJaHeDN1\BiFrOsT-MoJaHeDN1\BiFrOsT-MoJaHeDN\BiFrOsT-MoJaHeD.exe" | C:\Users\admin\Desktop\BiFrOsT-MoJaHeDN1\BiFrOsT-MoJaHeDN1\BiFrOsT-MoJaHeDN\BiFrOsT-MoJaHeD.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: عآشق رسول الله Exit code: 4294967295 Version: 1, 2, 1, 0 Modules
| |||||||||||||||
| 1372 | "C:\Users\admin\Desktop\Bifrost - MiSter Swat\Bifrost - MiSter Swat\Bifrost.exe" | C:\Users\admin\Desktop\Bifrost - MiSter Swat\Bifrost - MiSter Swat\Bifrost.exe | — | explorer.exe | |||||||||||
User: admin Company: http://www.chasenet.org Integrity Level: MEDIUM Description: Bifrost 1.2.1 Exit code: 20 Version: 1, 2, 1, 0 Modules
| |||||||||||||||
| 1396 | "C:\Users\admin\Desktop\Bifrost 2.6 final\Bifrost 2.6 final.exe" | C:\Users\admin\Desktop\Bifrost 2.6 final\Bifrost 2.6 final.exe | — | Bifrost 2.6 final.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 1400 | C:\Windows\Explorer.EXE | C:\Windows\explorer.exe | — | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (1400) explorer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (3708) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3708) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (3708) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (3708) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (3708) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3708) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3708) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3708) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (1400) explorer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs |
| Operation: | write | Name: | MRUListEx |
Value: 020000001E0000001D0000001C0000001B0000001A000000000000001900000003000000180000001600000017000000150000001400000013000000120000000F00000011000000100000000E0000000D0000000C0000000B0000000A00000009000000080000000700000006000000050000000400000001000000FFFFFFFF | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1400 | explorer.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\Dfgownloads.rar.lnk | binary | |
MD5:90E1E451344DFC8DEC3BD6F36C80CA9C | SHA256:886F57A2FA882376312E73E8807631C252DBA61CBB7ECF34D5CFA7B230AE079C | |||
| 3708 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3708.30443\BiFrost Sa$a HACk.rar | compressed | |
MD5:723F735E8EADD6D9F1FA60849FE675FC | SHA256:39D82928FAFA5FD976B3C7AD685726DD4C8CB30BC4A55E3427D1F9B7E7C4742D | |||
| 1400 | explorer.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\1b4dd67f29cb1962.automaticDestinations-ms | binary | |
MD5:4070A52115E2A64D1BEF13DFF479DFC6 | SHA256:DAED6CD08BC1C41D544A75704C7C3F9554A2EA7218C105B5C95ED3F0B57ACA96 | |||
| 1400 | explorer.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\290532160612e071.automaticDestinations-ms | binary | |
MD5:0F32F7BFD1D642F883AB4364F6FEDD3D | SHA256:28B64329C1AED82D898213D2EE32E0F14B3F4C3AEB0E2D3F6F6439C026F6C6B0 | |||
| 3708 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3708.30443\Bifrost Bypass limit 2100 victims bourkane.rar | compressed | |
MD5:427BB60D09A03E3E5DC03D7E1B6DB5EB | SHA256:ADD74373B2F2ADD6A5CBE873FCA05AF0347B4CB6FEE14B9D9E1ED7F85594F79F | |||
| 3708 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3708.30443\Bifrost_dernier_version.rar | compressed | |
MD5:487EF0A92FC705A12299376EC0C80E46 | SHA256:E9D0DA0CD8C1C2D0E4C39079C12DA720ADCA0C267339AF14F41A054A99D0514B | |||
| 3708 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3708.30443\Bifrost_SAWII.rar | compressed | |
MD5:51A2FC71622077455F2511882FF17E07 | SHA256:F0C4E3AC4BDBE0D9E72A4F59FCBC6ADEC2587E87618840E392F05A2DDD9FFFB2 | |||
| 3708 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3708.30443\BiFrOsT_Dr.AdNaN_0.3_ByPaSs_LiMiT.rar | compressed | |
MD5:840B841CAFA3D80938E7416810A1F6DD | SHA256:64C0D187AF4FC6C065B0EB360A19359A827A6C8ED57EE0B15D57F3129A114E6E | |||
| 3708 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3708.30443\BiFrOsT Dr.AdNaN 0.3.rar | compressed | |
MD5:476C297E26C2F7DAD7318F17EA8C9772 | SHA256:933584B9F50FA6F37EFA531F64B75BBABF8B86F0A7DD8B25D7C7450E31E79F71 | |||
| 3708 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3708.30443\Bifrost - MiSter Swat.rar | compressed | |
MD5:61E3078B7A05607E28F4940F128BEB49 | SHA256:738C9C6AFE4F48466F1EB888EE121CDE5A20C847799D0AAB505B0595833D96F5 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
Domain | IP | Reputation |
|---|---|---|
azouz0.no-ip.org |
| unknown |
saidsaid.no-ip.org |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
1088 | svchost.exe | Misc activity | ET INFO DYNAMIC_DNS Query to a Suspicious no-ip Domain |
1088 | svchost.exe | Misc activity | ET INFO DYNAMIC_DNS Query to a Suspicious no-ip Domain |