| File name: | 10.rar |
| Full analysis: | https://app.any.run/tasks/dd1cc3dd-4abe-47e5-af43-b4aeac206060 |
| Verdict: | Malicious activity |
| Threats: | A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection. |
| Analysis date: | April 15, 2019, 08:12:46 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v5 |
| MD5: | EE5913019F84F46ED0C51B6F9A54DAEB |
| SHA1: | 962BF52CBDC623E58A183B072D7587E608B74F99 |
| SHA256: | 8C2884D079A373E60B03C666E117E9F45192AF864F54D019D268C99C34C9DF28 |
| SSDEEP: | 98304:dGVjRLWShF9fKS34MXmExsjH+hbfIhmQbFme1yq77aKk5:dGVUMoMXByOIhbD1yq77a3 |
| .rar | | | RAR compressed archive (v5.0) (61.5) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 296 | "C:\Users\admin\Desktop\Netflix Gift Card Checker by xRisky\NetFlix GC Checker by xRisky.exe" | C:\Users\admin\Desktop\Netflix Gift Card Checker by xRisky\NetFlix GC Checker by xRisky.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 344 | "C:\Users\admin\Desktop\Netflix Gift Card Checker by xRisky\putty.exe" | C:\Users\admin\Desktop\Netflix Gift Card Checker by xRisky\putty.exe | NetFlix GC Checker by xRisky.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 644 | "C:\Windows\system32\rundll32.exe" "C:\Windows\system32\WININET.dll",DispatchAPICall 1 | C:\Windows\system32\rundll32.exe | — | NetFlix GC Checker by xRisky.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 916 | "C:\Users\admin\Desktop\Netflix Gift Card Checker by xRisky\pu.exe" | C:\Users\admin\Desktop\Netflix Gift Card Checker by xRisky\pu.exe | NetFlix GC Checker by xRisky.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 988 | "C:\Windows\System32\svchost.exe" | C:\Windows\System32\svchost.exe | — | putty.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Host Process for Windows Services Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1024 | "C:\Windows\system32\rundll32.exe" "C:\Windows\system32\WININET.dll",DispatchAPICall 1 | C:\Windows\system32\rundll32.exe | — | NetFlix GC Checker by xRisky.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1136 | "C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe" | C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe | puy.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft .NET Assembly Registration Utility Exit code: 0 Version: 2.0.50727.5420 (Win7SP1.050727-5400) Modules
| |||||||||||||||
| 1248 | "C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe" | C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | — | pu.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft .NET Services Installation Utility Exit code: 0 Version: 4.6.1055.0 built by: NETFXREL2 Modules
| |||||||||||||||
| 1540 | "C:\Windows\system32\rundll32.exe" "C:\Windows\system32\WININET.dll",DispatchAPICall 1 | C:\Windows\system32\rundll32.exe | — | NetFlix GC Checker by xRisky.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2044 | "C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe4_ Global\UsGthrCtrlFltPipeMssGthrPipe4 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" | C:\Windows\System32\SearchProtocolHost.exe | — | SearchIndexer.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft Windows Search Protocol Host Exit code: 0 Version: 7.00.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (3640) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3640) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3640) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3640) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\10.rar | |||
| (PID) Process: | (3640) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3640) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3640) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3640) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (2044) SearchProtocolHost.exe | Key: | HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\62\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2044) SearchProtocolHost.exe | Key: | HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\62\52C64B7E |
| Operation: | write | Name: | @C:\Windows\system32\notepad.exe,-469 |
Value: Text Document | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3640 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3640.49935\Netflix Gift Card Checker by xRisky\PRIVATE COMBOLIST.txt | — | |
MD5:— | SHA256:— | |||
| 344 | putty.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\AppReadiness.url | text | |
MD5:— | SHA256:— | |||
| 296 | NetFlix GC Checker by xRisky.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H6QNMHE9\c[1].exe | executable | |
MD5:— | SHA256:— | |||
| 344 | putty.exe | C:\Users\admin\AppData\Local\Temp\MaxxAudioMeters64\AppReadiness.vbs | text | |
MD5:— | SHA256:— | |||
| 296 | NetFlix GC Checker by xRisky.exe | C:\Users\admin\Desktop\Netflix Gift Card Checker by xRisky\putty.exe | executable | |
MD5:— | SHA256:— | |||
| 3640 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3640.49935\Netflix Gift Card Checker by xRisky\Leaf.xNet.dll | executable | |
MD5:42CF916DF4EA1D300201EC9559B7BEF3 | SHA256:939C8980BCB9BD9A2279714F6086714229E7AF194EC4E32677C5A4ED96DB5EDD | |||
| 296 | NetFlix GC Checker by xRisky.exe | C:\Users\admin\Desktop\Netflix Gift Card Checker by xRisky\puy.exe | executable | |
MD5:— | SHA256:— | |||
| 1024 | rundll32.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\H7SPBY9W\desktop.ini | ini | |
MD5:4A3DEB274BB5F0212C2419D3D8D08612 | SHA256:2842973D15A14323E08598BE1DFB87E54BF88A76BE8C7BC94C56B079446EDF38 | |||
| 1024 | rundll32.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IS4SVBAK\desktop.ini | ini | |
MD5:4A3DEB274BB5F0212C2419D3D8D08612 | SHA256:2842973D15A14323E08598BE1DFB87E54BF88A76BE8C7BC94C56B079446EDF38 | |||
| 296 | NetFlix GC Checker by xRisky.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0488CJO\l[1].exe | executable | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
296 | NetFlix GC Checker by xRisky.exe | GET | — | 88.13.146.179:80 | http://Chrome.theworkpc.com/i.exe | ES | — | — | malicious |
296 | NetFlix GC Checker by xRisky.exe | GET | 200 | 88.13.146.179:80 | http://Chrome.theworkpc.com/l4.exe | ES | executable | 926 Kb | malicious |
296 | NetFlix GC Checker by xRisky.exe | GET | 200 | 88.13.146.179:80 | http://Chrome.theworkpc.com/l.exe | ES | executable | 926 Kb | malicious |
296 | NetFlix GC Checker by xRisky.exe | GET | 200 | 88.13.146.179:80 | http://Chrome.theworkpc.com/r.exe | ES | executable | 908 Kb | malicious |
296 | NetFlix GC Checker by xRisky.exe | GET | 200 | 88.13.146.179:80 | http://Chrome.theworkpc.com/c.exe | ES | executable | 1.40 Mb | malicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
296 | NetFlix GC Checker by xRisky.exe | 88.13.146.179:80 | chrome.theworkpc.com | Telefonica De Espana | ES | malicious |
2668 | RegAsm.exe | 88.13.146.179:9898 | chrome.theworkpc.com | Telefonica De Espana | ES | malicious |
3132 | svchost.exe | 88.13.146.179:1552 | chrome.theworkpc.com | Telefonica De Espana | ES | malicious |
1136 | RegAsm.exe | 88.13.146.179:3344 | chrome.theworkpc.com | Telefonica De Espana | ES | malicious |
2668 | RegAsm.exe | 104.20.209.21:443 | pastebin.com | Cloudflare Inc | US | shared |
3636 | RegAsm.exe | 88.13.146.179:5553 | chrome.theworkpc.com | Telefonica De Espana | ES | malicious |
— | — | 88.13.146.179:3344 | chrome.theworkpc.com | Telefonica De Espana | ES | malicious |
Domain | IP | Reputation |
|---|---|---|
chrome.theworkpc.com |
| malicious |
redlan.hopto.org |
| malicious |
pastebin.com |
| malicious |
PID | Process | Class | Message |
|---|---|---|---|
296 | NetFlix GC Checker by xRisky.exe | Potential Corporate Privacy Violation | ET POLICY Autoit Windows Automation tool User-Agent in HTTP Request - Possibly Hostile |
296 | NetFlix GC Checker by xRisky.exe | A Network Trojan was detected | ET TROJAN Single char EXE direct download likely trojan (multiple families) |
296 | NetFlix GC Checker by xRisky.exe | A Network Trojan was detected | ET INFO AutoIt User Agent Downloading EXE |
296 | NetFlix GC Checker by xRisky.exe | Potentially Bad Traffic | ET CURRENT_EVENTS Terse alphanumeric executable downloader high likelihood of being hostile |
296 | NetFlix GC Checker by xRisky.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
296 | NetFlix GC Checker by xRisky.exe | Potential Corporate Privacy Violation | ET POLICY Autoit Windows Automation tool User-Agent in HTTP Request - Possibly Hostile |
296 | NetFlix GC Checker by xRisky.exe | A Network Trojan was detected | ET TROJAN Single char EXE direct download likely trojan (multiple families) |
296 | NetFlix GC Checker by xRisky.exe | A Network Trojan was detected | ET INFO AutoIt User Agent Downloading EXE |
296 | NetFlix GC Checker by xRisky.exe | Potentially Bad Traffic | ET CURRENT_EVENTS Terse alphanumeric executable downloader high likelihood of being hostile |
296 | NetFlix GC Checker by xRisky.exe | Potential Corporate Privacy Violation | ET POLICY Autoit Windows Automation tool User-Agent in HTTP Request - Possibly Hostile |