File name:

REMCOS v1.7 Professional By Viotto.rar

Full analysis: https://app.any.run/tasks/2bc2d12c-aa0d-4e39-9f5e-fe371547ecbe
Verdict: Malicious activity
Analysis date: June 06, 2019, 06:27:49
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v4, os: Win32
MD5:

49A9EDCD68290CBE88023B7830A05F6E

SHA1:

AA5384F1BEE0022D7DA212F2B1F04FC44C9E9E69

SHA256:

7DFF9BE27ECC63A9327CF6E88AFD1D3DFCBA67159183A855F3DDB861F0C1B83F

SSDEEP:

196608:IQA/bUzSO84uxP2fPN7S7fPi+CFcY/gpm+LUF1aFqHYH7q45Kw+V9E+3MpRe3mzg:pA/kSntP2fFOLPi+CiW8pUFs9PEDwR1g

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Remcos Loader.exe (PID: 1448)
    • Runs injected code in another process

      • remcos.exe (PID: 3984)
    • Application was injected by another process

      • explorer.exe (PID: 2044)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2488)
  • INFO

    • Manual execution by user

      • Remcos Loader.exe (PID: 1448)
      • remcos.exe (PID: 3132)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

CompressedSize: 1797132
UncompressedSize: 1839616
OperatingSystem: Win32
ModifyDate: 2017:01:09 14:53:05
PackingMethod: Normal
ArchivedFileName: REMCOS v1.7 Professional\Remcos Loader.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
38
Monitored processes
5
Malicious processes
1
Suspicious processes
2

Behavior graph

Click at the process to see the details
start inject winrar.exe remcos.exe no specs remcos loader.exe no specs remcos.exe explorer.exe

Process information

PID
CMD
Path
Indicators
Parent process
1448"C:\Users\admin\Desktop\REMCOS v1.7 Professional\Remcos Loader.exe" C:\Users\admin\Desktop\REMCOS v1.7 Professional\Remcos Loader.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\remcos v1.7 professional\remcos loader.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\psapi.dll
2044C:\Windows\Explorer.EXEC:\Windows\explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\winanr.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
2488"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\REMCOS v1.7 Professional By Viotto.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3132"C:\Users\admin\Desktop\REMCOS v1.7 Professional\remcos.exe" C:\Users\admin\Desktop\REMCOS v1.7 Professional\remcos.exeexplorer.exe
User:
admin
Company:
Breaking-Security.net
Integrity Level:
MEDIUM
Description:
REMCOS Remote Control & Surveillance
Exit code:
0
Version:
1.7.0.0
Modules
Images
c:\users\admin\desktop\remcos v1.7 professional\remcos.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3984"C:\Users\admin\Desktop\REMCOS v1.7 Professional\remcos.exe"C:\Users\admin\Desktop\REMCOS v1.7 Professional\remcos.exe
Remcos Loader.exe
User:
admin
Company:
Breaking-Security.net
Integrity Level:
MEDIUM
Description:
REMCOS Remote Control & Surveillance
Exit code:
0
Version:
1.7.0.0
Modules
Images
c:\users\admin\desktop\remcos v1.7 professional\remcos.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
Total events
2 504
Read events
2 390
Write events
114
Delete events
0

Modification events

(PID) Process:(2488) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2488) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2488) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2488) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\REMCOS v1.7 Professional By Viotto.rar
(PID) Process:(2488) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2488) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2488) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2488) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2044) explorer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rar\OpenWithList
Operation:writeName:a
Value:
WinRAR.exe
(PID) Process:(2044) explorer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rar\OpenWithList
Operation:writeName:MRUList
Value:
a
Executable files
1
Suspicious files
0
Text files
3
Unknown types
0

Dropped files

PID
Process
Filename
Type
2488WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb2488.219\REMCOS v1.7 Professional\remcos.exe
MD5:
SHA256:
2488WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb2488.219\REMCOS v1.7 Professional\REMCOSAuthHooks.dll
MD5:
SHA256:
2044explorer.exeC:\Users\admin\Desktop\REMCOS v1.7 Professional
MD5:
SHA256:
2488WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb2488.219\REMCOS v1.7 Professional\Remcos Loader.exeexecutable
MD5:75792B5B38EDD028D13EEF62C0D828E6
SHA256:B7F82678830C34DB745A16D5551386F15FF28FDA563F10C6903F6471A58E243E
3984remcos.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H6QNMHE9\gettime[1].htmtext
MD5:D19021C3E24FFF276CE831D27901DB2B
SHA256:A51CE6D2543445BDA96479C74113F63C5FBA8C1DF87B0628D983683CB8970F82
3984remcos.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0488CJO\OnlineCheck_MT[1].htmtext
MD5:442D4F5216CD9DA1FD121655A23E8843
SHA256:0A3706B1424059F3F718B8FBAA2DD145EA0FD1F8D950744CA78C7B32D2DFA4A8
3132remcos.exeC:\Users\admin\Desktop\REMCOS v1.7 Professional\Remcos_Settings.initext
MD5:902927C48D191E30067D84A53158E2BA
SHA256:B408602C7D2107D819B18D47CBC196A307AB6435BBC819173F300E76573E616C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
1
DNS requests
2
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3984
remcos.exe
172.217.21.196:80
www.google.com
Google Inc.
US
whitelisted

DNS requests

Domain
IP
Reputation
breakingsec01.co.nf
unknown
www.google.com
  • 172.217.21.196
malicious

Threats

No threats detected
No debug info