File name:

BeingADIK-0.9.1-pc to 0.10.1.lite.txt

Full analysis: https://app.any.run/tasks/2babec95-4ac0-41f3-8c7d-c9d6277f4843
Verdict: Malicious activity
Analysis date: February 01, 2024, 22:26:04
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: text/plain
File info: ASCII text, with no line terminators
MD5:

D343F4AA6E4F030A30523D1DEC19BC0F

SHA1:

305CD4C1CC842E2033DB245587159815C809FB51

SHA256:

7D972C8A04D0B5B2D7515338F4A150C97D1F19EFF5AFCE61F9D00A88F58C49F7

SSDEEP:

3:Yowh/oieVghSz:YhwieVgIz

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Actions looks like stealing of personal data

      • WinRAR.exe (PID: 1288)
      • BeingADIK-32.exe (PID: 3524)
      • BeingADIK-32.exe (PID: 1192)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 1288)
    • Uses WMIC.EXE to obtain data on processes

      • cmd.exe (PID: 3268)
      • cmd.exe (PID: 3432)
    • Starts CMD.EXE for commands execution

      • BeingADIK-32.exe (PID: 1192)
      • BeingADIK-32.exe (PID: 3524)
    • Reads the Internet Settings

      • WMIC.exe (PID: 2952)
      • WMIC.exe (PID: 3592)
    • Start notepad (likely ransomware note)

      • BeingADIK-32.exe (PID: 3524)
      • BeingADIK-32.exe (PID: 1192)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1288)
    • Reads the computer name

      • BeingADIK-32.exe (PID: 3524)
      • BeingADIK-32.exe (PID: 1192)
    • Checks supported languages

      • BeingADIK-32.exe (PID: 3524)
      • BeingADIK-32.exe (PID: 1192)
    • Manual execution by a user

      • WinRAR.exe (PID: 1288)
      • BeingADIK-32.exe (PID: 3524)
      • BeingADIK-32.exe (PID: 1192)
    • Reads the machine GUID from the registry

      • BeingADIK-32.exe (PID: 3524)
      • BeingADIK-32.exe (PID: 1192)
    • Create files in a temporary directory

      • BeingADIK-32.exe (PID: 3524)
      • BeingADIK-32.exe (PID: 1192)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 1288)
    • Creates files or folders in the user directory

      • BeingADIK-32.exe (PID: 3524)
      • BeingADIK-32.exe (PID: 1192)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
54
Monitored processes
10
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start notepad.exe no specs winrar.exe beingadik-32.exe cmd.exe no specs wmic.exe no specs notepad.exe no specs beingadik-32.exe cmd.exe no specs wmic.exe no specs notepad.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1192"C:\Users\admin\Desktop\BeingADIK-0.9.1-pc to 0.10.1.lite\BeingADIK-32.exe" C:\Users\admin\Desktop\BeingADIK-0.9.1-pc to 0.10.1.lite\BeingADIK-32.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1
Modules
Images
c:\users\admin\desktop\beingadik-0.9.1-pc to 0.10.1.lite\beingadik-32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-crt-convert-l1-1-0.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\api-ms-win-core-timezone-l1-1-0.dll
c:\windows\system32\api-ms-win-core-file-l2-1-0.dll
c:\windows\system32\api-ms-win-core-localization-l1-2-0.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
1288"C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Desktop\BeingADIK-0.9.1-pc to 0.10.1.lite.rar" "C:\Users\admin\Desktop\BeingADIK-0.9.1-pc to 0.10.1.lite\"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
1380"C:\Windows\system32\NOTEPAD.EXE" "C:\Users\admin\Desktop\BeingADIK-0.9.1-pc to 0.10.1.lite.txt"C:\Windows\System32\notepad.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2136"C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\BeingADIK-0.9.1-pc to 0.10.1.lite\traceback.txtC:\Windows\System32\notepad.exeBeingADIK-32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2952wmic process get DescriptionC:\Windows\System32\wbem\WMIC.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
WMI Commandline Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\wbem\wmic.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
3268C:\Windows\system32\cmd.exe /c "wmic process get Description"C:\Windows\System32\cmd.exeBeingADIK-32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3432C:\Windows\system32\cmd.exe /c "wmic process get Description"C:\Windows\System32\cmd.exeBeingADIK-32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3524"C:\Users\admin\Desktop\BeingADIK-0.9.1-pc to 0.10.1.lite\BeingADIK-32.exe" C:\Users\admin\Desktop\BeingADIK-0.9.1-pc to 0.10.1.lite\BeingADIK-32.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1
Modules
Images
c:\users\admin\desktop\beingadik-0.9.1-pc to 0.10.1.lite\beingadik-32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-crt-convert-l1-1-0.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\api-ms-win-core-timezone-l1-1-0.dll
c:\windows\system32\api-ms-win-core-file-l2-1-0.dll
c:\windows\system32\api-ms-win-core-localization-l1-2-0.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
3592wmic process get DescriptionC:\Windows\System32\wbem\WMIC.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
WMI Commandline Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\wbem\wmic.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
3660"C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\BeingADIK-0.9.1-pc to 0.10.1.lite\traceback.txtC:\Windows\System32\notepad.exeBeingADIK-32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
1 200
Read events
1 192
Write events
8
Delete events
0

Modification events

(PID) Process:(1380) notepad.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Notepad
Operation:writeName:iWindowPosX
Value:
76
(PID) Process:(1380) notepad.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Notepad
Operation:writeName:iWindowPosY
Value:
189
(PID) Process:(1380) notepad.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Notepad
Operation:writeName:iWindowPosDX
Value:
960
(PID) Process:(1380) notepad.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Notepad
Operation:writeName:iWindowPosDY
Value:
501
(PID) Process:(1288) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1288) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1288) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1288) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
28
Suspicious files
115
Text files
938
Unknown types
0

Dropped files

PID
Process
Filename
Type
1288WinRAR.exeC:\Users\admin\Desktop\BeingADIK-0.9.1-pc to 0.10.1.lite\renpy\angle\gldraw.pyxtext
MD5:CCF8BB0719362E30AF88F8D9BE3537F0
SHA256:FDDF8BFB7EE5A400BB3D840D9B4BBFD76978F881E17EAEB574B06E4C39D33C97
1288WinRAR.exeC:\Users\admin\Desktop\BeingADIK-0.9.1-pc to 0.10.1.lite\renpy\angle\glblacklist.pyotext
MD5:8D32C19F29458F431732DD9612DD7619
SHA256:9AF145072D6B451CDCD2EB96261E09B0A3B1D80C2E0381A38D60C555E638A734
1288WinRAR.exeC:\Users\admin\Desktop\BeingADIK-0.9.1-pc to 0.10.1.lite\renpy\angle\gldraw.pxdtext
MD5:1649AA0BF1E494B96C180C9F6A3CD661
SHA256:7A08EC6EB5C69F103910068A77BAE6131942E4C450AD964492525833338DD949
1288WinRAR.exeC:\Users\admin\Desktop\BeingADIK-0.9.1-pc to 0.10.1.lite\renpy\add_from.pytext
MD5:A77AD70548881449462CB60BD1614096
SHA256:FF0E12234DAC7B6B932A7E57CAD2BC094481CBA9CB368560FF143E61B860B30D
1288WinRAR.exeC:\Users\admin\Desktop\BeingADIK-0.9.1-pc to 0.10.1.lite\renpy\angle\gl.pyxtext
MD5:98F42CB65CDB06C22FBC14FBBE7DE5EB
SHA256:B4E90256E45AE0BF2127D9FC58ED453E424FC6B7ECC5729C5112FA241E7FCE00
1288WinRAR.exeC:\Users\admin\Desktop\BeingADIK-0.9.1-pc to 0.10.1.lite\renpy\angle\gl.pxdtext
MD5:87B56F61222E57C0341D8BCF38622CA5
SHA256:E5A4C7699C6E8FB332E6D1088A9CFAC40A9468C91A61B929FE25D2406EE99DA1
1288WinRAR.exeC:\Users\admin\Desktop\BeingADIK-0.9.1-pc to 0.10.1.lite\renpy\add_from.pyotext
MD5:ABF463E0DF091164438EBC04E3BB5642
SHA256:CDC96B9AF2E67B5C35FCEB11028D66C2B403A0B18D1302CA74E65614A6924335
1288WinRAR.exeC:\Users\admin\Desktop\BeingADIK-0.9.1-pc to 0.10.1.lite\renpy\angle\glblacklist.pytext
MD5:5AF76F747DE98D645CECB06F155EA0E9
SHA256:07579F48CB2A7266C7CD4762CE0CA906BE3802B71788952B5F93FA87BFAD94B4
1288WinRAR.exeC:\Users\admin\Desktop\BeingADIK-0.9.1-pc to 0.10.1.lite\renpy\angle\gltexture.pyxtext
MD5:0C83182CF33BC9E74CE5B9D51CD102C4
SHA256:C28B1DEF7D53C837FCD89C6B78107F818A8D4955464973BDAE081D1646CD5561
1288WinRAR.exeC:\Users\admin\Desktop\BeingADIK-0.9.1-pc to 0.10.1.lite\renpy\angle\glrtt_fbo.pyxtext
MD5:C7AC2FEA1275448105653361D7A31ADE
SHA256:40C610D7B4E655E478E55B37DCBFC7A17B42AF7926BA4F030AC9496AD2C01968
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
Process
Message
BeingADIK-32.exe
[S_API] SteamAPI_Init(): SteamAPI_IsSteamRunning() did not locate a running instance of Steam.
BeingADIK-32.exe
[S_API] SteamAPI_Init(): Sys_LoadModule failed to load: C:\Program Files\Steam\steamclient.dll
BeingADIK-32.exe
[S_API] SteamAPI_Init(): SteamAPI_IsSteamRunning() did not locate a running instance of Steam.
BeingADIK-32.exe
[S_API] SteamAPI_Init(): Sys_LoadModule failed to load: C:\Program Files\Steam\steamclient.dll