File name:

Android Bulk SMS Sender.rar

Full analysis: https://app.any.run/tasks/94a2effe-ff94-4046-9e5d-75b7e66fc9f3
Verdict: Malicious activity
Analysis date: November 02, 2019, 18:55:10
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

A13276C2841B654B5788FF0909E28FFC

SHA1:

6B0D21275A959BEB0592C4A284D471411C6A4498

SHA256:

8A73B1EE5C3BB66AB95276FEF907EAD9783EAAA7FAB78239CBEA16DDA714B1E2

SSDEEP:

24576:vgSaaEf5SFRRR+HKOCAXi067mCZ+x528aeRP2tGCVuX+AcC:YaEf5qzRoCY5HaWzCkxcC

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 3488)
      • Android Bulk SMS Sender.exe (PID: 992)
    • Application was dropped or rewritten from another process

      • Android Bulk SMS Sender.exe (PID: 992)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1296)
      • Android Bulk SMS Sender.exe (PID: 992)
    • Reads Environment values

      • Android Bulk SMS Sender.exe (PID: 992)
  • INFO

    • Reads settings of System Certificates

      • Android Bulk SMS Sender.exe (PID: 992)
    • Manual execution by user

      • Android Bulk SMS Sender.exe (PID: 992)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
37
Monitored processes
3
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe searchprotocolhost.exe no specs android bulk sms sender.exe

Process information

PID
CMD
Path
Indicators
Parent process
992"C:\Users\admin\Desktop\Android Bulk SMS Sender\Android Bulk SMS Sender.exe" C:\Users\admin\Desktop\Android Bulk SMS Sender\Android Bulk SMS Sender.exe
explorer.exe
User:
admin
Company:
Technocom
Integrity Level:
MEDIUM
Description:
Android Bulk SMS Sender
Exit code:
0
Version:
6.0.1.17
Modules
Images
c:\users\admin\desktop\android bulk sms sender\android bulk sms sender.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1296"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Android Bulk SMS Sender.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3488"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
1 093
Read events
804
Write events
289
Delete events
0

Modification events

(PID) Process:(1296) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1296) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1296) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1296) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Android Bulk SMS Sender.rar
(PID) Process:(1296) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1296) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1296) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1296) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1296) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
(PID) Process:(1296) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\General
Operation:writeName:LastFolder
Value:
C:\Users\admin\AppData\Local\Temp
Executable files
5
Suspicious files
0
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
1296WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1296.43709\Android Bulk SMS Sender\Gappalytics.dllexecutable
MD5:
SHA256:
1296WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1296.43709\Android Bulk SMS Sender\Android Bulk SMS Sender.exeexecutable
MD5:
SHA256:
1296WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1296.43709\Android Bulk SMS Sender\Excel Import.dllexecutable
MD5:
SHA256:
1296WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1296.43709\Android Bulk SMS Sender\IPAddressControlLib.dllexecutable
MD5:B1DC7821C11C4C8FADE4DB86604BD6A7
SHA256:3F89E4F9FD628A561AB3CA152F9852371C149CB931AB88E33FDFB109EBF4DC60
992Android Bulk SMS Sender.exeC:\Users\admin\AppData\Local\Temp\Protect97b6f7b9.dllexecutable
MD5:97B6F7B91E343DAE3B3D822DF2B8E39A
SHA256:73B04C3DB43DBDF62DA5A740A3945FB5CC7CE89DECA440C05CECFF2C201F2BA1
1296WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1296.43709\Android Bulk SMS Sender\Android Bulk SMS Sender.exe.configxml
MD5:04315AF96531115DE855C729CAA07D15
SHA256:DEEB6FEB77E58A4B2D6DA96B3A3A6A3E6974BF6C012EFB10346D8DFAEF605E8A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
3
DNS requests
3
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
992
Android Bulk SMS Sender.exe
GET
200
172.217.21.238:80
http://www.google-analytics.com/__utm.gif?utmhn=lantechsoft.com&utmcs=UTF-8&utmsr=1280x800&utmvp=1280x800&utmsc=24-bit&utmul=en-us&utmdt=Run%20Setup&utmhid=590683286&utmac=UA-37203880-1&utmn=569913620&utmr=-&utmp=/https://www.technocomsolutions.com/buy-android-bulk-sms-sender.html&utmwv=5.3.5&utmcc=__utma%3D12039849.924808266.1572720939.1572720939.1572720939.1%3B%2B__utmz%3D12039849.1572720939.1.1.utmcsr%3D(direct)%7Cutmccn%3D(direct)%7Cutmcmd%3D(none)%3B
US
image
35 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
172.217.21.238:80
www.google-analytics.com
Google Inc.
US
whitelisted
992
Android Bulk SMS Sender.exe
172.217.21.238:80
www.google-analytics.com
Google Inc.
US
whitelisted
992
Android Bulk SMS Sender.exe
192.254.186.135:443
www.technocomsolutions.com
Unified Layer
US
malicious

DNS requests

Domain
IP
Reputation
www.google-analytics.com
  • 172.217.21.238
whitelisted
www.technocomsolutions.com
  • 192.254.186.135
malicious

Threats

No threats detected
No debug info