| download: | AG3-master.rar |
| Full analysis: | https://app.any.run/tasks/15f6215a-460b-4a62-9475-8fe87a5a863e |
| Verdict: | Malicious activity |
| Analysis date: | July 15, 2020, 18:56:48 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v5 |
| MD5: | D1705CF1BF40CB05908AC92CA4CF19AF |
| SHA1: | BBFDD0EE2ED8EA609D77ADDE1ED5818E2034AEC5 |
| SHA256: | 8EEE1EDF6359D4A948A6928925565E873E8E3FD27ABC7162F03E45342166B70C |
| SSDEEP: | 12288:/shclmpJhSGCpMBw8K/d7qPxclmpJhSGCpMBw8vRqpmj/VBL:/4coph//S7Yxcoph//vRH |
| .rar | | | RAR compressed archive (v5.0) (61.5) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1000 | "C:\Program Files\Mozilla Firefox\firefox.exe" | C:\Program Files\Mozilla Firefox\firefox.exe | firefox.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 68.0.1 Modules
| |||||||||||||||
| 1744 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1000.3.697903702\1705681375" -childID 1 -isForBrowser -prefsHandle 1740 -prefMapHandle 1736 -prefsLen 1 -prefMapSize 191824 -parentBuildID 20190717172542 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 1000 "\\.\pipe\gecko-crash-server-pipe.1000" 1760 tab | C:\Program Files\Mozilla Firefox\firefox.exe | firefox.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 68.0.1 Modules
| |||||||||||||||
| 2144 | "C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_26_0_0_131.exe" --proxy-stub-channel=Flash2624.66618844.27900 --host-broker-channel=Flash2624.66618844.5061 --host-pid=2624 --host-npapi-version=29 --plugin-path="C:\Windows\system32\Macromed\Flash\NPSWF32_26_0_0_131.dll" | C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_26_0_0_131.exe | — | plugin-container.exe | |||||||||||
User: admin Company: Adobe Systems, Inc. Integrity Level: MEDIUM Description: Adobe Flash Player 26.0 r0 Exit code: 0 Version: 26,0,0,131 Modules
| |||||||||||||||
| 2584 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\AG3-master.rar" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 2624 | "C:\Program Files\Mozilla Firefox\plugin-container.exe" --channel="1000.27.878254267\392438953" "C:\Windows\system32\Macromed\Flash\NPSWF32_26_0_0_131.dll" "C:\Users\admin\AppData\LocalLow\Mozilla\Temp-{340d53f3-8e15-4bee-bf07-fcd13f403727}" "C:\Users\admin\AppData\Roaming\Adobe\\" -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" 308046B0AF4A39CB 1000 "\\.\pipe\gecko-crash-server-pipe.1000" 3048 plugin | C:\Program Files\Mozilla Firefox\plugin-container.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Plugin Container for Firefox Exit code: 0 Version: 68.0.1 Modules
| |||||||||||||||
| 2764 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1000.13.1342600298\1877587453" -childID 2 -isForBrowser -prefsHandle 2628 -prefMapHandle 2516 -prefsLen 5996 -prefMapSize 191824 -parentBuildID 20190717172542 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 1000 "\\.\pipe\gecko-crash-server-pipe.1000" 2840 tab | C:\Program Files\Mozilla Firefox\firefox.exe | firefox.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 68.0.1 Modules
| |||||||||||||||
| 2904 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="1000.0.2028599941\1351329557" -parentBuildID 20190717172542 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 1000 "\\.\pipe\gecko-crash-server-pipe.1000" 1204 gpu | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 68.0.1 Modules
| |||||||||||||||
| 2980 | "C:\Program Files\Opera\opera.exe" | C:\Program Files\Opera\opera.exe | explorer.exe | ||||||||||||
User: admin Company: Opera Software Integrity Level: MEDIUM Description: Opera Internet Browser Exit code: 0 Version: 1748 Modules
| |||||||||||||||
| 3100 | "C:\Program Files\Mozilla Firefox\firefox.exe" | C:\Program Files\Mozilla Firefox\firefox.exe | — | explorer.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 68.0.1 Modules
| |||||||||||||||
| 3116 | "C:\Users\admin\Desktop\AG3-master\AnarchyGrabber3\bin\Debug\Free Nitro\Free Nitro (Exploit).exe" | C:\Users\admin\Desktop\AG3-master\AnarchyGrabber3\bin\Debug\Free Nitro\Free Nitro (Exploit).exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: AG3 Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| (PID) Process: | (2584) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (2584) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (2584) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\132\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2584) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\AG3-master.rar | |||
| (PID) Process: | (2584) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2584) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2584) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2584) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (2584) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop | |||
| (PID) Process: | (3468) SearchProtocolHost.exe | Key: | HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\132\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2584 | WinRAR.exe | C:\Users\admin\Desktop\AG3-master\.vs\AnarchyGrabber3\v16\.suo | binary | |
MD5:— | SHA256:— | |||
| 2584 | WinRAR.exe | C:\Users\admin\Desktop\AG3-master\AnarchyGrabber3\bin\Debug\Free Nitro.rar | compressed | |
MD5:— | SHA256:— | |||
| 2584 | WinRAR.exe | C:\Users\admin\Desktop\AG3-master\AnarchyGrabber3\AnarchyGrabber3.csproj | xml | |
MD5:— | SHA256:— | |||
| 2584 | WinRAR.exe | C:\Users\admin\Desktop\AG3-master\AnarchyGrabber3\obj\Debug\AG3.exe | executable | |
MD5:— | SHA256:— | |||
| 2584 | WinRAR.exe | C:\Users\admin\Desktop\AG3-master\AnarchyGrabber3\DiscordBuild.cs | text | |
MD5:— | SHA256:— | |||
| 2584 | WinRAR.exe | C:\Users\admin\Desktop\AG3-master\AnarchyGrabber3\bin\Debug\AG3.pdb | pdb | |
MD5:— | SHA256:— | |||
| 2584 | WinRAR.exe | C:\Users\admin\Desktop\AG3-master\AnarchyGrabber3\obj\Debug\AnarchyGrabber3.csprojAssemblyReference.cache | pi2 | |
MD5:— | SHA256:— | |||
| 2584 | WinRAR.exe | C:\Users\admin\Desktop\AG3-master\AnarchyGrabber3\obj\Debug\DesignTimeResolveAssemblyReferences.cache | pi2 | |
MD5:— | SHA256:— | |||
| 2584 | WinRAR.exe | C:\Users\admin\Desktop\AG3-master\AnarchyGrabber3\bin\Debug\Free Nitro\Free Nitro (Exploit).pdb | pdb | |
MD5:— | SHA256:— | |||
| 2584 | WinRAR.exe | C:\Users\admin\Desktop\AG3-master\AnarchyGrabber3\bin\Debug\Free Nitro\Free Nitro (Exploit).exe | executable | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2980 | opera.exe | GET | 200 | 93.184.220.29:80 | http://crl4.digicert.com/DigiCertHighAssuranceEVRootCA.crl | US | der | 564 b | whitelisted |
2980 | opera.exe | GET | 403 | 172.217.168.238:80 | http://clients1.google.com/complete/search?q=yourae&client=opera-suggest-omnibox&hl=de | US | html | 1.08 Kb | whitelisted |
2980 | opera.exe | GET | 400 | 185.26.182.106:80 | http://sitecheck2.opera.com/?host=youareanidiot.cc&hdn=gZ4MEQ7kGVVmal8/5A%2B1TA== | unknown | html | 150 b | whitelisted |
2980 | opera.exe | GET | 200 | 185.26.182.110:80 | http://redir.opera.com/favicons/google/favicon.ico | unknown | image | 5.30 Kb | whitelisted |
1000 | firefox.exe | POST | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/ | US | der | 471 b | whitelisted |
1000 | firefox.exe | POST | 200 | 172.217.17.99:80 | http://ocsp.pki.goog/gts1o1core | US | der | 472 b | whitelisted |
1000 | firefox.exe | POST | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/ | US | der | 471 b | whitelisted |
2980 | opera.exe | GET | 403 | 172.217.168.238:80 | http://clients1.google.com/complete/search?q=yourareanidiot&client=opera-suggest-search&hl=de | US | html | 1.08 Kb | whitelisted |
1000 | firefox.exe | GET | 200 | 95.101.78.113:80 | http://detectportal.firefox.com/success.txt | unknown | text | 8 b | whitelisted |
2980 | opera.exe | GET | 301 | 104.28.25.163:80 | http://youareanidiot.cc/ | US | — | — | malicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2980 | opera.exe | 185.26.182.94:443 | certs.opera.com | Opera Software AS | — | whitelisted |
2980 | opera.exe | 172.217.168.238:80 | clients1.google.com | Google Inc. | US | whitelisted |
1000 | firefox.exe | 172.217.168.234:443 | safebrowsing.googleapis.com | Google Inc. | US | whitelisted |
1000 | firefox.exe | 34.214.1.68:443 | push.services.mozilla.com | Amazon.com, Inc. | US | malicious |
1000 | firefox.exe | 93.184.220.29:80 | crl4.digicert.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
1000 | firefox.exe | 172.217.17.99:80 | ocsp.pki.goog | Google Inc. | US | whitelisted |
1000 | firefox.exe | 13.227.223.126:443 | content-signature-2.cdn.mozilla.net | — | US | unknown |
1000 | firefox.exe | 95.101.78.82:443 | shavar.services.mozilla.com | Akamai International B.V. | — | suspicious |
2980 | opera.exe | 185.26.182.106:80 | sitecheck2.opera.com | Opera Software AS | — | suspicious |
1000 | firefox.exe | 52.222.141.94:443 | snippets.cdn.mozilla.net | Amazon.com, Inc. | US | unknown |
Domain | IP | Reputation |
|---|---|---|
certs.opera.com |
| whitelisted |
crl4.digicert.com |
| whitelisted |
dns.msftncsi.com |
| shared |
clients1.google.com |
| whitelisted |
yourareanidiot.cc |
| unknown |
redir.opera.com |
| whitelisted |
youareanidiot.cc |
| malicious |
sitecheck2.opera.com |
| whitelisted |
detectportal.firefox.com |
| whitelisted |
search.services.mozilla.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
1040 | svchost.exe | Potentially Bad Traffic | ET DNS Query for .cc TLD |
1040 | svchost.exe | Potentially Bad Traffic | ET DNS Query for .cc TLD |
2980 | opera.exe | Potentially Bad Traffic | ET INFO TLS Handshake Failure |
2980 | opera.exe | Potentially Bad Traffic | ET INFO TLS Handshake Failure |
2980 | opera.exe | Potentially Bad Traffic | ET INFO TLS Handshake Failure |
2980 | opera.exe | Potentially Bad Traffic | ET INFO TLS Handshake Failure |
2980 | opera.exe | Potentially Bad Traffic | ET INFO TLS Handshake Failure |
2980 | opera.exe | Potentially Bad Traffic | ET INFO TLS Handshake Failure |
2980 | opera.exe | Potentially Bad Traffic | ET INFO TLS Handshake Failure |
2980 | opera.exe | Potentially Bad Traffic | ET INFO TLS Handshake Failure |