| File name: | Luna-Grabber-1.6.1-alpha.rar |
| Full analysis: | https://app.any.run/tasks/5f51a828-6acb-445b-9d3b-6c7db951364e |
| Verdict: | Malicious activity |
| Threats: | XWorm is a remote access trojan (RAT) sold as a malware-as-a-service. It possesses an extensive hacking toolset and is capable of gathering private information and files from the infected computer, hijacking MetaMask and Telegram accounts, and tracking user activity. XWorm is typically delivered to victims' computers through multi-stage attacks that start with phishing emails. |
| Analysis date: | July 28, 2024, 23:09:55 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v5 |
| MD5: | 646CD3D53C008F1A509B18438AB1E29A |
| SHA1: | 50F15486329D2C863E2D98AE1C5152BBA52289C3 |
| SHA256: | 7F09110CE2ED47609AF0C6B4919C74EC3052F2C23386686C1A66585A9B16C90B |
| SSDEEP: | 98304:H8qKCej2hZlwrAVt68PreDa7VboFiQauARVFmxogmqPxZBQj5uINtt5AmthijWVL:XEg6xi1c8tGwgUi9lETzTL2lE |
| .rar | | | RAR compressed archive (v5.0) (61.5) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 312 | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -ExecutionPolicy Bypass Add-MpPreference -ExclusionPath 'C:\Users\admin\AppData\Local\Temp\Windows driver Fondation.exe' | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | luna.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows PowerShell Exit code: 1 Version: 10.0.14409.1005 (rs1_srvoob.161208-1155) Modules
| |||||||||||||||
| 748 | "C:\Users\admin\Desktop\Luna-Grabber-1.6.1-alpha\Luna-Grabber-1.6.1-alpha\Luna-Grabber-1.6.1-alpha\luna.exe" | C:\Users\admin\Desktop\Luna-Grabber-1.6.1-alpha\Luna-Grabber-1.6.1-alpha\Luna-Grabber-1.6.1-alpha\luna.exe | luna.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft Visual C++ 2008 Redistributable Setup Exit code: 0 Version: 9.0.30729.5677 Modules
| |||||||||||||||
| 972 | "C:\Users\admin\AppData\Local\Temp\Windows driver Fondation.exe" | C:\Users\admin\AppData\Local\Temp\Windows driver Fondation.exe | luna.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft Visual C++ 2008 Redistributable Setup Version: 9.0.30729.5677 Modules
XWorm(PID) Process(972) Windows driver Fondation.exe C2jajaovh.duckdns.org:1605 Keys AES<123456789> Options Splitter<Xwormmm> Sleep time3 USB drop nameXWorm V5.0 MutexXXTdiFRysQHPMYhR | |||||||||||||||
| 1060 | C:\Windows\system32\svchost.exe -k NetworkService | C:\Windows\System32\svchost.exe | services.exe | ||||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1384 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2288.2983\Luna-Grabber-1.6.1-alpha\Luna-Grabber-1.6.1-alpha\Luna-Grabber-1.6.1-alpha.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2288.2983\Luna-Grabber-1.6.1-alpha\Luna-Grabber-1.6.1-alpha\Luna-Grabber-1.6.1-alpha.exe | WinRAR.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 2056 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa2288.2983\Luna-Grabber-1.6.1-alpha\Luna-Grabber-1.6.1-alpha\Crack.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa2288.2983\Luna-Grabber-1.6.1-alpha\Luna-Grabber-1.6.1-alpha\Crack.exe | Crack.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft Visual C++ 2008 Redistributable Setup Exit code: 0 Version: 9.0.30729.5677 Modules
| |||||||||||||||
| 2092 | "C:\Users\admin\Desktop\Luna-Grabber-1.6.1-alpha\Luna-Grabber-1.6.1-alpha\Luna-Grabber-1.6.1-alpha\Crack.exe" | C:\Users\admin\Desktop\Luna-Grabber-1.6.1-alpha\Luna-Grabber-1.6.1-alpha\Luna-Grabber-1.6.1-alpha\Crack.exe | — | Luna-Grabber-1.6.1-alpha.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Visual C++ 2008 Redistributable Setup Exit code: 0 Version: 9.0.30729.5677 Modules
| |||||||||||||||
| 2252 | "C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\AppData\Local\Temp\luna.py | C:\Windows\System32\rundll32.exe | — | luna.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows host process (Rundll32) Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2288 | "C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\Desktop\Luna-Grabber-1.6.1-alpha.rar | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 2484 | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -ExecutionPolicy Bypass Add-MpPreference -ExclusionPath 'C:\Users\admin\AppData\Local\Temp\Windows driver Fondation.exe' | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | Crack.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows PowerShell Exit code: 1 Version: 10.0.14409.1005 (rs1_srvoob.161208-1155) Modules
| |||||||||||||||
| (PID) Process: | (2288) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (2288) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (2288) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2288) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (2288) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (2288) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
| (PID) Process: | (2288) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\Luna-Grabber-1.6.1-alpha.rar | |||
| (PID) Process: | (2288) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2288) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2288) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1060 | svchost.exe | C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Temp\Tar1F8A.tmp | binary | |
MD5:78785956AB4E54D6116D673C3491EDFF | SHA256:C514DBDBB13632CBB378C59086C1EBB0BC9B25FFB0A349F2B052B065C0D913E6 | |||
| 1060 | svchost.exe | C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Temp\Cab1F89.tmp | compressed | |
MD5:1BFE591A4FE3D91B03CDF26EAACD8F89 | SHA256:9CF94355051BF0F4A45724CA20D1CC02F76371B963AB7D1E38BD8997737B13D8 | |||
| 2288 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2288.2983\Luna-Grabber-1.6.1-alpha\Luna-Grabber-1.6.1-alpha\Luna-Grabber-1.6.1-alpha.exe | executable | |
MD5:BA4E961972B6A98A53973F4C4C0CD789 | SHA256:F195C9427EB1EE586060E1B662C9AC83E55601D7D93A3DF934E3122A41BA2937 | |||
| 1060 | svchost.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506 | binary | |
MD5:D64DD3463B1CF800C43F5E4E922EFD34 | SHA256:394715ED3122797DCFD33F0B346B5AEE36B4C2C93A76D5315B7FD51347F546E4 | |||
| 1384 | Luna-Grabber-1.6.1-alpha.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2288.2983\Luna-Grabber-1.6.1-alpha\Luna-Grabber-1.6.1-alpha\tools\update.py | text | |
MD5:986C41243FA69B8B7D641C5C0AE40839 | SHA256:4C68B08EE9CE02E3AB1DF65F135FAC36712EB8A4F8970988CA12A86AD12AEE99 | |||
| 2288 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2288.2983\Luna-Grabber-1.6.1-alpha\Luna-Grabber-1.6.1-alpha\password les bg.txt | text | |
MD5:C45B6223B7E72E70DBF38291414374E1 | SHA256:AB4BCD99FCD634E96869D257FEAE564967BBB7E4F5433DEC56DDBC218593BBF1 | |||
| 1384 | Luna-Grabber-1.6.1-alpha.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2288.2983\Luna-Grabber-1.6.1-alpha\Luna-Grabber-1.6.1-alpha\.github\ISSUE_TEMPLATE\feature_request.md | text | |
MD5:CC5C8C854A08D96E7DC387AE16B00B0B | SHA256:F721940DA862B87B42613D6B8C33D4E4700AD56BB3EE0B6A9F8F636CBDBA6198 | |||
| 1384 | Luna-Grabber-1.6.1-alpha.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2288.2983\Luna-Grabber-1.6.1-alpha\Luna-Grabber-1.6.1-alpha\gui_images\clipboard.png | image | |
MD5:5928442BF2B7571FF23692278C7D3419 | SHA256:73176DFD2ADDD67C8EEC7750F603DCB607D3F3E76458AEB95C0E07CADD5503A8 | |||
| 1384 | Luna-Grabber-1.6.1-alpha.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2288.2983\Luna-Grabber-1.6.1-alpha\Luna-Grabber-1.6.1-alpha\tools\upx.py | text | |
MD5:76EFB2A3AE61D0E41F069272FB783CC9 | SHA256:3100E615D0A1BB235E18B30FC2F0974E7FA02D8C9BEAF6D0550E35805E2D3EDB | |||
| 1384 | Luna-Grabber-1.6.1-alpha.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa2288.2983\Luna-Grabber-1.6.1-alpha\Luna-Grabber-1.6.1-alpha\.gitignore | text | |
MD5:2B2AC73441C2DBC21C9BA60D1D262A8F | SHA256:9251A258D8EF1C62B7ECDA2DC139C5D976BFF284B76B5936E711A54F90A8F38C | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1372 | svchost.exe | GET | 304 | 41.63.96.0:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?33775f6043c93e33 | unknown | — | — | whitelisted |
1372 | svchost.exe | GET | 200 | 23.48.23.156:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
1372 | svchost.exe | GET | 200 | 2.19.217.218:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
1060 | svchost.exe | GET | 304 | 41.63.96.0:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?8f69642324cc87bd | unknown | — | — | whitelisted |
3452 | Windows driver Fondation.exe | GET | 200 | 208.95.112.1:80 | http://ip-api.com/line/?fields=hosting | unknown | — | — | shared |
972 | Windows driver Fondation.exe | GET | 200 | 208.95.112.1:80 | http://ip-api.com/line/?fields=hosting | unknown | — | — | shared |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1372 | svchost.exe | 20.73.194.208:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | whitelisted |
1060 | svchost.exe | 224.0.0.252:5355 | — | — | — | whitelisted |
1372 | svchost.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
1372 | svchost.exe | 41.63.96.0:80 | ctldl.windowsupdate.com | LLNW | ZA | unknown |
1372 | svchost.exe | 23.48.23.156:80 | crl.microsoft.com | Akamai International B.V. | DE | unknown |
1372 | svchost.exe | 2.19.217.218:80 | www.microsoft.com | Akamai International B.V. | NL | unknown |
3452 | Windows driver Fondation.exe | 208.95.112.1:80 | ip-api.com | TUT-AS | US | unknown |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
dns.msftncsi.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
ip-api.com |
| shared |
PID | Process | Class | Message |
|---|---|---|---|
1060 | svchost.exe | Device Retrieving External IP Address Detected | INFO [ANY.RUN] External IP Check (ip-api .com) |
1060 | svchost.exe | Device Retrieving External IP Address Detected | ET INFO External IP Lookup Domain in DNS Lookup (ip-api .com) |
3452 | Windows driver Fondation.exe | Device Retrieving External IP Address Detected | ET POLICY External IP Lookup ip-api.com |
3452 | Windows driver Fondation.exe | Device Retrieving External IP Address Detected | POLICY [ANY.RUN] External Hosting Lookup by ip-api |
1060 | svchost.exe | Device Retrieving External IP Address Detected | ET INFO External IP Lookup Domain in DNS Lookup (ip-api .com) |
972 | Windows driver Fondation.exe | Device Retrieving External IP Address Detected | ET POLICY External IP Lookup ip-api.com |
972 | Windows driver Fondation.exe | Device Retrieving External IP Address Detected | POLICY [ANY.RUN] External Hosting Lookup by ip-api |
Process | Message |
|---|---|
Windows driver Fondation.exe | CLR: Managed code called FailFast without specifying a reason.
|
Windows driver Fondation.exe | CLR: Managed code called FailFast without specifying a reason.
|