File name:

RakSAMP Lite.rar

Full analysis: https://app.any.run/tasks/c128d23b-1a35-47d0-8b40-5de3968b03b4
Verdict: Malicious activity
Analysis date: August 23, 2024, 19:09:18
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

811E03C940278C5CE0F499E28FA101B5

SHA1:

59DDA3E1550DB96181B9CF552E45E3BA2CC0425E

SHA256:

7B8358BEF78109E14EDA409CACBF4EE6C2E0204D0DF9340C5BB732331A5357AA

SSDEEP:

98304:FhkkQM+CXmDRPSdvRzDNo7LC+QbL0LtdUF+JijCE1nFdVulf75PfI0yxH2Qc0cLV:WVkxXA

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads the date of Windows installation

      • RakLaunch Lite.exe (PID: 1116)
    • Reads security settings of Internet Explorer

      • RakLaunch Lite.exe (PID: 1116)
    • Potential Corporate Privacy Violation

      • RakSAMP Lite.exe (PID: 6912)
      • RakSAMP Lite.exe (PID: 3812)
      • RakSAMP Lite.exe (PID: 3864)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 6812)
    • Manual execution by a user

      • RakLaunch Lite.exe (PID: 1116)
    • Checks supported languages

      • RakLaunch Lite.exe (PID: 1116)
      • RakSAMP Lite.exe (PID: 3864)
      • RakSAMP Lite.exe (PID: 3812)
      • RakSAMP Lite.exe (PID: 6912)
    • Process checks computer location settings

      • RakLaunch Lite.exe (PID: 1116)
    • Reads the computer name

      • RakSAMP Lite.exe (PID: 3812)
      • RakLaunch Lite.exe (PID: 1116)
      • RakSAMP Lite.exe (PID: 3864)
      • RakSAMP Lite.exe (PID: 6912)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
138
Monitored processes
9
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe rundll32.exe no specs raklaunch lite.exe raksamp lite.exe conhost.exe no specs raksamp lite.exe conhost.exe no specs raksamp lite.exe conhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1116"C:\Users\admin\Desktop\RakSAMP Lite\RakLaunch Lite.exe" C:\Users\admin\Desktop\RakSAMP Lite\RakLaunch Lite.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\users\admin\desktop\raksamp lite\raklaunch lite.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
3256C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
3812"C:\Users\admin\Desktop\RakSAMP Lite\RakSAMP Lite.exe" -h 80.66.82.82 -p 7777 -n nick -z C:\Users\admin\Desktop\RakSAMP Lite\RakSAMP Lite.exe
RakLaunch Lite.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\users\admin\desktop\raksamp lite\raksamp lite.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
3864"C:\Users\admin\Desktop\RakSAMP Lite\RakSAMP Lite.exe" -h 80.66.82.82 -p 7777 -n nick -z C:\Users\admin\Desktop\RakSAMP Lite\RakSAMP Lite.exe
RakLaunch Lite.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\users\admin\desktop\raksamp lite\raksamp lite.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
6304\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeRakSAMP Lite.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6556\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeRakSAMP Lite.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6592\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeRakSAMP Lite.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6812"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\RakSAMP Lite.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
6912"C:\Users\admin\Desktop\RakSAMP Lite\RakSAMP Lite.exe" -h 80.66.82.82 -p 7777 -n nick -z C:\Users\admin\Desktop\RakSAMP Lite\RakSAMP Lite.exe
RakLaunch Lite.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\users\admin\desktop\raksamp lite\raksamp lite.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
Total events
7 165
Read events
7 138
Write events
27
Delete events
0

Modification events

(PID) Process:(6812) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(6812) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(6812) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\GoogleChromeEnterpriseBundle64.zip
(PID) Process:(6812) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\RakSAMP Lite.rar
(PID) Process:(6812) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(6812) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(6812) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(6812) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(6812) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF3D0000002D000000FD03000016020000
(PID) Process:(6812) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\General
Operation:writeName:LastFolder
Value:
C:\Users\admin\AppData\Local\Temp
Executable files
17
Suspicious files
13
Text files
70
Unknown types
0

Dropped files

PID
Process
Filename
Type
6812WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6812.48166\RakSAMP Lite\RakLaunch Lite.exeexecutable
MD5:7D53985DBCDBED7E32F22934EC1F7B94
SHA256:7AE2A1E9F328110BAE84CD82158041DE56DD5FCC0A8F5BB3E9378419A3BBEFCB
6812WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6812.48166\RakSAMP Lite\scripts\aim_fix.luabinary
MD5:DE2C0E4F9ACECD6BD2C1819B0874EC6C
SHA256:9C61CC4F3F87C92696989450230C5046DACCE96FB3CDA16B33F70BCC3B220362
6812WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6812.48166\RakSAMP Lite\scripts\libs\addon.luatext
MD5:0A08857B250D7A30646C46BC5D26F910
SHA256:22297CF758E7FA6C93E663DA2EAC22DA0D3746987F27BBD5FB86296C4BB3DB15
6812WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6812.48166\RakSAMP Lite\scripts\libs\autobus.luabinary
MD5:EB9032303580667E2D4ACD66F32FE313
SHA256:D7EB520D3D500C3C6EC2BC4606F11A95B3341C92276BAFC8558CACFD3B3FFE6C
6812WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6812.48166\RakSAMP Lite\scripts\clitorfix.luabinary
MD5:622D759107C9DB4BF2E91A5988E9AA32
SHA256:623AE83AF7572FCEAA303106B445B1D2CD8D055E62994C7C384BB54E5B33D882
6812WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6812.48166\RakSAMP Lite\scripts\AutoRegistrationBySURVERS.luabinary
MD5:8FF494DD25EA9C55ACA13FA80DF21D40
SHA256:371FE963EC7D01BF8A23839B345D84017CF7F700C57B83AC6BF949BA9A070E7C
6812WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6812.48166\RakSAMP Lite\scripts\libs\base64.dllexecutable
MD5:A7B7CE324277FF19D9BA081C4DFDCB1D
SHA256:4E19BAC2A3E0A3E854143ED9259B82A4F405409B0D2928E10A27DB672BF346BE
6812WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6812.48166\RakSAMP Lite\RakSAMP Lite.logtext
MD5:F2E9A882F05E60B40158C85A20E843BA
SHA256:8BD603593BC0E090092E04ACA45BAF1704C3E9D627A361B830D24B9BCB1322A6
6812WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6812.48166\RakSAMP Lite\lua51.dllexecutable
MD5:3DFF7448B43FCFB4DC65E0040B0FFB88
SHA256:FF976F6E965E3793E278FA9BF5E80B9B226A0B3932B9DA764BFFC8E41E6CDB60
6812WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6812.48166\RakSAMP Lite\RakSAMP Lite.exeexecutable
MD5:9802AC594BD6245E31C5E640A23F1652
SHA256:0C1AEEAB9ADCF23318A04837CCB1D4EA1210DA2943AC1AF4A9D94A450F733D87
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
41
DNS requests
13
Threats
6

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2584
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
2584
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
2584
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
7116
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
7060
SIHClient.exe
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3412
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
1344
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3888
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:137
whitelisted
3260
svchost.exe
40.115.3.253:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2584
svchost.exe
40.126.32.138:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2584
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
7116
backgroundTaskHost.exe
20.223.35.26:443
arc.msn.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
whitelisted
google.com
  • 216.58.212.142
whitelisted
client.wns.windows.com
  • 40.115.3.253
whitelisted
login.live.com
  • 40.126.32.138
  • 40.126.32.76
  • 40.126.32.68
  • 40.126.32.134
  • 40.126.32.133
  • 20.190.160.14
  • 20.190.160.22
  • 20.190.160.17
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
arc.msn.com
  • 20.223.35.26
whitelisted
slscr.update.microsoft.com
  • 20.12.23.50
whitelisted
www.microsoft.com
  • 23.52.120.96
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.85.23.206
whitelisted
nexusrules.officeapps.live.com
  • 52.111.243.31
whitelisted

Threats

PID
Process
Class
Message
6912
RakSAMP Lite.exe
Potential Corporate Privacy Violation
ET P2P Edonkey Publicize File ACK
6912
RakSAMP Lite.exe
Potential Corporate Privacy Violation
ET P2P Edonkey Publicize File ACK
3864
RakSAMP Lite.exe
Potential Corporate Privacy Violation
ET P2P Edonkey Publicize File ACK
3864
RakSAMP Lite.exe
Potential Corporate Privacy Violation
ET P2P Edonkey Publicize File ACK
3812
RakSAMP Lite.exe
Potential Corporate Privacy Violation
ET P2P Edonkey Publicize File ACK
3864
RakSAMP Lite.exe
Potential Corporate Privacy Violation
ET P2P Edonkey Publicize File ACK
No debug info