analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

arh.rar

Full analysis: https://app.any.run/tasks/8409c3f1-1aa2-4278-90ec-779535f98a96
Verdict: Malicious activity
Threats:

Trojans are a group of malicious programs distinguished by their ability to masquerade as benign software. Depending on their type, trojans possess a variety of capabilities, ranging from maintaining full remote control over the victim’s machine to stealing data and files, as well as dropping other malware. At the same time, the main functionality of each trojan family can differ significantly depending on its type. The most common trojan infection chain starts with a phishing email.

Analysis date: November 14, 2018, 13:41:55
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
trojan
redaman
Indicators:
MIME: application/x-rar
File info: RAR archive data, flags: EncryptedBlockHeader
MD5:

A1BA4B9DD09EA418B4A632FBA19FB37C

SHA1:

0EDAF06463E92E97DDAB87427797BB65C31BEFAF

SHA256:

8BA8BD70E629A4EF26F146126E42CD5B6F12FBDD13EB306C2707740CB3EC785C

SSDEEP:

6144:Wwhr7rOQw7SN80YYYo+2SSvV2pZVzsVWAvM30Rjg:WwhN9NZqBE2pZVwVW8k

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Док-ты ноябрь.exe (PID: 780)
    • Loads dropped or rewritten executable

      • Док-ты ноябрь.exe (PID: 780)
      • rundll32.exe (PID: 3396)
      • explorer.exe (PID: 1604)
      • WinRAR.exe (PID: 3284)
      • WinRAR.exe (PID: 2760)
    • Loads the Task Scheduler COM API

      • Док-ты ноябрь.exe (PID: 780)
    • REDAMAN was detected

      • rundll32.exe (PID: 3396)
    • Connects to CnC server

      • rundll32.exe (PID: 3396)
  • SUSPICIOUS

    • Application launched itself

      • WinRAR.exe (PID: 920)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2760)
      • Док-ты ноябрь.exe (PID: 780)
    • Creates files in the program directory

      • Док-ты ноябрь.exe (PID: 780)
    • Connects to server without host name

      • rundll32.exe (PID: 3396)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
36
Monitored processes
6
Malicious processes
1
Suspicious processes
3

Behavior graph

Click at the process to see the details
start drop and start winrar.exe no specs winrar.exe winrar.exe no specs док-ты ноябрь.exe #REDAMAN rundll32.exe explorer.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
920"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\arh.rar"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.60.0
2760"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Rar$DIb920.48738\Док-ты ноябрь.rar"C:\Program Files\WinRAR\WinRAR.exe
WinRAR.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.60.0
3284"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Rar$DIb920.49193\Док-ты ноябрь.rar"C:\Program Files\WinRAR\WinRAR.exeWinRAR.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.60.0
780"C:\Users\admin\AppData\Local\Temp\Rar$EXa2760.49715\Док-ты ноябрь.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2760.49715\Док-ты ноябрь.exe
WinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
3396rundll32.exe "C:\ProgramData\lpkcgioc\igfhkcnl.hod",DllGetClassObject hostC:\Windows\system32\rundll32.exe
taskeng.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
1604C:\Windows\Explorer.EXEC:\Windows\explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Total events
1 335
Read events
1 272
Write events
0
Delete events
0

Modification events

No data
Executable files
3
Suspicious files
4
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
3396rundll32.exeC:\Users\admin\AppData\Local\Temp\76AD.tmp
MD5:
SHA256:
3396rundll32.exeC:\Users\admin\AppData\Local\Temp\nhodmmahoehdclhp
MD5:
SHA256:
3396rundll32.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2760.49715\Док-ты ноябрь.exe
MD5:
SHA256:
3396rundll32.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2760.49715\enngfemphajmbnii
MD5:
SHA256:
3396rundll32.exeC:\ProgramData\lpkcgioc\11348a5509a5
MD5:
SHA256:
3396rundll32.exe\Device\HarddiskVolume2\ProgramData\lpkcgioc\akhphnpffmdaeiaj
MD5:
SHA256:
920WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DIb920.49193\Док-ты ноябрь.rarcompressed
MD5:B9FDCA00C6ACC9CA2067AAF243047F80
SHA256:ED84D90A6DF957607DB2528E29EF052DC3980717B13CF01D3B44639FD9A81378
920WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DIb920.48738\Док-ты ноябрь.rarcompressed
MD5:B9FDCA00C6ACC9CA2067AAF243047F80
SHA256:ED84D90A6DF957607DB2528E29EF052DC3980717B13CF01D3B44639FD9A81378
780Док-ты ноябрь.exeC:\Users\admin\AppData\Local\Temp\76AD.tmpexecutable
MD5:ACF5B11B92AA8C99A2807B62C68E3CC7
SHA256:14D33B02A497E46F470D30180A09A1057C6802C1F37B0EFBF82CBDC47A8AE7FF
780Док-ты ноябрь.exeC:\ProgramData\lpkcgioc\igfhkcnl.hodexecutable
MD5:ACF5B11B92AA8C99A2807B62C68E3CC7
SHA256:14D33B02A497E46F470D30180A09A1057C6802C1F37B0EFBF82CBDC47A8AE7FF
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
4
DNS requests
1
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3396
rundll32.exe
POST
200
185.141.61.246:80
http://185.141.61.246/index.php
unknown
binary
9 b
malicious
3396
rundll32.exe
POST
200
185.141.61.246:80
http://185.141.61.246/index.php
unknown
binary
9 b
malicious
3396
rundll32.exe
POST
185.141.61.246:80
http://185.141.61.246/index.php
unknown
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3396
rundll32.exe
104.28.16.33:443
namecha.in
Cloudflare Inc
US
shared
3396
rundll32.exe
185.141.61.246:80
malicious

DNS requests

Domain
IP
Reputation
namecha.in
  • 104.28.16.33
  • 104.28.17.33
unknown

Threats

PID
Process
Class
Message
3396
rundll32.exe
A Network Trojan was detected
MALWARE [PTsecurity] Win32/Spy.RTM.N
1 ETPRO signatures available at the full report
No debug info