analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

Combo Editor Pro v1 by Draghost.rar

Full analysis: https://app.any.run/tasks/a165c619-b949-42e2-bf4d-ad72042b40b5
Verdict: Malicious activity
Analysis date: October 08, 2023, 12:09:32
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

9643DEB9B89BA2DD585256A48E162B10

SHA1:

CA5470346DA49DD03E46B637B9447886B94C0294

SHA256:

8D57195C05BCC5D97872E8F17424BD9E69CF0EC4B3D1C688A2C1E41EBC16B8A5

SSDEEP:

98304:eOkHH0Vqkw/b3QTjZbj3YBoH0KUqP/DcgJx1ZVGP2ElYcNSWkKq3P4/cikgF9x5k:zrmNPibe1YX

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Adds path to the Windows Defender exclusion list

      • Combo Editor Pro.exe (PID: 3632)
      • Combo Editor Pro.exe (PID: 2556)
      • LZMYBCTLTD.exe (PID: 980)
      • Combo Editor Pro.exe (PID: 2808)
      • Combo Editor Pro.exe (PID: 3876)
      • LZMYBCTLTD.exe (PID: 3712)
    • Uses Task Scheduler to run other applications

      • LZMYBCTLTD.exe (PID: 3712)
  • SUSPICIOUS

    • Reads the BIOS version

      • Combo Editor Pro.exe (PID: 3632)
      • Combo Editor Pro.exe (PID: 2272)
      • Combo Editor Pro.exe (PID: 2460)
      • Combo Editor Pro.exe (PID: 2556)
      • LZMYBCTLTD.exe (PID: 980)
      • Combo Editor Pro.exe (PID: 2808)
      • Combo Editor Pro.exe (PID: 3876)
      • LZMYBCTLTD.exe (PID: 3712)
    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 3832)
    • Powershell version downgrade attack

      • powershell.exe (PID: 3448)
      • powershell.exe (PID: 2620)
      • powershell.exe (PID: 2232)
      • powershell.exe (PID: 292)
      • powershell.exe (PID: 2268)
      • powershell.exe (PID: 372)
      • powershell.exe (PID: 3544)
      • powershell.exe (PID: 3524)
      • powershell.exe (PID: 3004)
      • powershell.exe (PID: 3256)
      • powershell.exe (PID: 3612)
      • powershell.exe (PID: 1484)
    • Script adds exclusion path to Windows Defender

      • Combo Editor Pro.exe (PID: 3632)
      • Combo Editor Pro.exe (PID: 2556)
      • LZMYBCTLTD.exe (PID: 980)
      • Combo Editor Pro.exe (PID: 2808)
      • Combo Editor Pro.exe (PID: 3876)
      • LZMYBCTLTD.exe (PID: 3712)
    • Reads the Internet Settings

      • Combo Editor Pro.exe (PID: 2272)
      • Combo Editor Pro.exe (PID: 3632)
      • Combo Editor Pro.exe (PID: 2460)
      • Combo Editor Pro.exe (PID: 2556)
      • LZMYBCTLTD.exe (PID: 980)
      • Combo Editor Pro.exe (PID: 2808)
      • Combo Editor Pro.exe (PID: 3876)
      • LZMYBCTLTD.exe (PID: 3712)
    • Starts POWERSHELL.EXE for commands execution

      • Combo Editor Pro.exe (PID: 3632)
      • Combo Editor Pro.exe (PID: 2556)
      • LZMYBCTLTD.exe (PID: 980)
      • Combo Editor Pro.exe (PID: 2808)
      • Combo Editor Pro.exe (PID: 3876)
      • LZMYBCTLTD.exe (PID: 3712)
    • Application launched itself

      • Combo Editor Pro.exe (PID: 2272)
      • Combo Editor Pro.exe (PID: 2460)
    • Starts CMD.EXE for commands execution

      • Combo Editor Pro.exe (PID: 3632)
      • Combo Editor Pro.exe (PID: 2556)
      • Combo Editor Pro.exe (PID: 2808)
    • Uses TIMEOUT.EXE to delay execution

      • cmd.exe (PID: 1828)
      • cmd.exe (PID: 300)
      • cmd.exe (PID: 3116)
    • Executing commands from a ".bat" file

      • Combo Editor Pro.exe (PID: 3632)
      • Combo Editor Pro.exe (PID: 2556)
      • Combo Editor Pro.exe (PID: 2808)
  • INFO

    • Reads the computer name

      • Combo Editor Pro.exe (PID: 3632)
      • Combo Editor Pro.exe (PID: 2272)
      • Combo Editor Pro.exe (PID: 2460)
      • Combo Editor Pro.exe (PID: 2556)
      • LZMYBCTLTD.exe (PID: 980)
      • Combo Editor Pro.exe (PID: 2808)
      • Combo Editor Pro.exe (PID: 3876)
      • LZMYBCTLTD.exe (PID: 3712)
    • Process checks are UAC notifies on

      • Combo Editor Pro.exe (PID: 3632)
      • Combo Editor Pro.exe (PID: 2556)
      • LZMYBCTLTD.exe (PID: 980)
      • Combo Editor Pro.exe (PID: 2808)
      • Combo Editor Pro.exe (PID: 3876)
      • LZMYBCTLTD.exe (PID: 3712)
    • Checks supported languages

      • Combo Editor Pro.exe (PID: 3632)
      • Combo Editor Pro.exe (PID: 2272)
      • Combo Editor Pro.exe (PID: 2460)
      • LZMYBCTLTD.exe (PID: 980)
      • Combo Editor Pro.exe (PID: 2556)
      • Combo Editor Pro.exe (PID: 2808)
      • Combo Editor Pro.exe (PID: 3876)
      • LZMYBCTLTD.exe (PID: 3712)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 3832)
    • Creates files in the program directory

      • Combo Editor Pro.exe (PID: 3632)
      • Combo Editor Pro.exe (PID: 2808)
    • Manual execution by a user

      • Combo Editor Pro.exe (PID: 2272)
      • Combo Editor Pro.exe (PID: 2460)
      • Combo Editor Pro.exe (PID: 2808)
      • Combo Editor Pro.exe (PID: 3876)
    • Create files in a temporary directory

      • Combo Editor Pro.exe (PID: 3632)
      • Combo Editor Pro.exe (PID: 2556)
      • Combo Editor Pro.exe (PID: 2808)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
88
Monitored processes
29
Malicious processes
22
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe no specs searchprotocolhost.exe no specs combo editor pro.exe no specs combo editor pro.exe powershell.exe no specs powershell.exe no specs cmd.exe no specs timeout.exe no specs combo editor pro.exe no specs combo editor pro.exe lzmybctltd.exe no specs powershell.exe no specs powershell.exe no specs powershell.exe no specs powershell.exe no specs cmd.exe no specs timeout.exe no specs combo editor pro.exe powershell.exe no specs powershell.exe no specs combo editor pro.exe powershell.exe no specs powershell.exe no specs cmd.exe no specs timeout.exe no specs lzmybctltd.exe no specs powershell.exe no specs powershell.exe no specs schtasks.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3832"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Combo Editor Pro v1 by Draghost.rar"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
3920"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe4_ Global\UsGthrCtrlFltPipeMssGthrPipe4 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Version:
7.00.7601.24542 (win7sp1_ldr_escrow.191209-2211)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2272"C:\Users\admin\Desktop\Combo Editor Pro v1 by Draghost\Combo Editor Pro.exe" C:\Users\admin\Desktop\Combo Editor Pro v1 by Draghost\Combo Editor Pro.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Logon Application
Exit code:
1
Version:
10.0.17134.1
Modules
Images
c:\users\admin\desktop\combo editor pro v1 by draghost\combo editor pro.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3632"C:\Users\admin\Desktop\Combo Editor Pro v1 by Draghost\Combo Editor Pro.exe" C:\Users\admin\Desktop\Combo Editor Pro v1 by Draghost\Combo Editor Pro.exe
Combo Editor Pro.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Logon Application
Exit code:
0
Version:
10.0.17134.1
Modules
Images
c:\users\admin\desktop\combo editor pro v1 by draghost\combo editor pro.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\sechost.dll
c:\windows\system32\advapi32.dll
3448"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath 'C:\ProgramData'C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeCombo Editor Pro.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows PowerShell
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2620"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath 'C:\Users\admin\AppData\Roaming'C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeCombo Editor Pro.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows PowerShell
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\atl.dll
c:\windows\system32\user32.dll
1828C:\Windows\system32\cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\s2sw.0.bat" "C:\Windows\System32\cmd.exeCombo Editor Pro.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\winbrand.dll
3688timeout 3 C:\Windows\System32\timeout.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
timeout - pauses command processing
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\timeout.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
2460"C:\Users\admin\Desktop\Combo Editor Pro v1 by Draghost\Combo Editor Pro.exe" C:\Users\admin\Desktop\Combo Editor Pro v1 by Draghost\Combo Editor Pro.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Logon Application
Exit code:
1
Version:
10.0.17134.1
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2556"C:\Users\admin\Desktop\Combo Editor Pro v1 by Draghost\Combo Editor Pro.exe" C:\Users\admin\Desktop\Combo Editor Pro v1 by Draghost\Combo Editor Pro.exe
Combo Editor Pro.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Logon Application
Exit code:
0
Version:
10.0.17134.1
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\users\admin\desktop\combo editor pro v1 by draghost\combo editor pro.exe
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
Total events
19 604
Read events
18 793
Write events
811
Delete events
0

Modification events

(PID) Process:(3832) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3832) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(3832) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3832) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3832) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3832) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3832) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3832) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3832) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
(PID) Process:(3832) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\General
Operation:writeName:LastFolder
Value:
C:\Users\admin\Desktop
Executable files
5
Suspicious files
37
Text files
4
Unknown types
0

Dropped files

PID
Process
Filename
Type
3832WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3832.46789\Combo Editor Pro v1 by Draghost\Combo Editor Pro.exe
MD5:
SHA256:
3632Combo Editor Pro.exeC:\ProgramData\active\LZMYBCTLTD.exe
MD5:
SHA256:
292powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms~RF159247.TMPbinary
MD5:B2A14C47DF15CD98C7FC022417BAC08B
SHA256:6EF2E6B9227BAE870B2046C9E6D0CB669B61545444F3E2116C30DDA8ED58AF3F
2620powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\RQ1PP5EBKBYNCDQSNGL9.tempbinary
MD5:B2A14C47DF15CD98C7FC022417BAC08B
SHA256:6EF2E6B9227BAE870B2046C9E6D0CB669B61545444F3E2116C30DDA8ED58AF3F
3832WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3832.46789\Combo Editor Pro v1 by Draghost\updater.inibinary
MD5:BDB71E725923415AD118571A96A58F9C
SHA256:CDFD1E0DB31EF98BE246AC26C14CBD47B24A11F85DD255FE55F93F8FB9FCAB11
3448powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms~RF15584b.TMPbinary
MD5:CAEA3B1F09925DA2A47C2B8B890AB890
SHA256:66F29B00CBB7B1DED878F96AAC6F52907C088DE194A1FD0CD6E1FF1916047549
2620powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-msbinary
MD5:B2A14C47DF15CD98C7FC022417BAC08B
SHA256:6EF2E6B9227BAE870B2046C9E6D0CB669B61545444F3E2116C30DDA8ED58AF3F
3832WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3832.46789\Combo Editor Pro v1 by Draghost\System.ServiceModel.Internals.dllexecutable
MD5:BC3DBD339745E51C60DBD0A095EB50D5
SHA256:0BE5890DEE0DC8CCD1444781287DFEED46BBFBDBF4EE289E564EA98EA94E006D
2620powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms~RF15584b.TMPbinary
MD5:B2A14C47DF15CD98C7FC022417BAC08B
SHA256:6EF2E6B9227BAE870B2046C9E6D0CB669B61545444F3E2116C30DDA8ED58AF3F
292powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\TRFBIF1C9NE4MUIKVEOK.tempbinary
MD5:B2A14C47DF15CD98C7FC022417BAC08B
SHA256:6EF2E6B9227BAE870B2046C9E6D0CB669B61545444F3E2116C30DDA8ED58AF3F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
3
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2656
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted

DNS requests

No data

Threats

No threats detected
No debug info