File name:

Free Rainbow Six Siege Cheats.rar

Full analysis: https://app.any.run/tasks/e9dad141-efc8-44fa-9b83-c47bc7addabe
Verdict: Malicious activity
Analysis date: March 18, 2021, 13:33:01
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

503CC8651A3E7537E890062A05E94B7E

SHA1:

B2549B0B221AA79F5495C5451AE889CCE6723E84

SHA256:

924AE3C13D27C31A2055750DB3268487C46702114C2319D264B3C6ED8D44BCCD

SSDEEP:

98304:qDvHNZ8BYmZmjkAbgCnC9069y5q2MfWJMeF0HfomGwxNlr7:qDcBnZmjkAbfc06Yc2Mf6V4fomGWr7

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Disables Windows Defender

      • Defender.exe (PID: 3636)
      • Defender.exe (PID: 1096)
      • Defender.exe (PID: 1504)
      • Defender.exe (PID: 1940)
    • Modifies Windows Defender service settings

      • Defender.exe (PID: 3636)
      • Defender.exe (PID: 1096)
      • Defender.exe (PID: 1940)
      • Defender.exe (PID: 1504)
    • Drops executable file immediately after starts

      • UndetectedClient.exe (PID: 2732)
      • UndetectedClient.exe (PID: 2680)
      • Bypass.exe (PID: 2968)
    • Application was dropped or rewritten from another process

      • UndetectedClient.exe (PID: 2252)
      • UndetectedClient.exe (PID: 2732)
      • Bypass.exe (PID: 2180)
      • Defender.exe (PID: 3636)
      • Defender.exe (PID: 1096)
      • UndetectedClient.exe (PID: 2656)
      • UndetectedClient.exe (PID: 2680)
      • Bypass.exe (PID: 2968)
      • Defender.exe (PID: 1940)
      • Defender.exe (PID: 1504)
    • Writes to a start menu file

      • cmd.exe (PID: 3896)
      • cmd.exe (PID: 996)
  • SUSPICIOUS

    • Drops a file with too old compile date

      • UndetectedClient.exe (PID: 2732)
      • cmd.exe (PID: 3896)
      • UndetectedClient.exe (PID: 2680)
      • cmd.exe (PID: 996)
    • Executable content was dropped or overwritten

      • UndetectedClient.exe (PID: 2732)
      • WinRAR.exe (PID: 3648)
      • Bypass.exe (PID: 2180)
      • cmd.exe (PID: 3896)
      • UndetectedClient.exe (PID: 2680)
      • Bypass.exe (PID: 2968)
      • cmd.exe (PID: 996)
    • Starts CMD.EXE for commands execution

      • UndetectedClient.exe (PID: 2732)
      • UndetectedClient.exe (PID: 2680)
    • Drops a file that was compiled in debug mode

      • UndetectedClient.exe (PID: 2732)
      • cmd.exe (PID: 3896)
      • UndetectedClient.exe (PID: 2680)
      • cmd.exe (PID: 996)
    • Application launched itself

      • Defender.exe (PID: 3636)
      • Defender.exe (PID: 1940)
    • Creates files in the Windows directory

      • Defender.exe (PID: 1096)
      • Defender.exe (PID: 1504)
    • Removes files from Windows directory

      • Defender.exe (PID: 1096)
      • Defender.exe (PID: 1504)
    • Creates files in the user directory

      • cmd.exe (PID: 3896)
  • INFO

    • Manual execution by user

      • taskmgr.exe (PID: 960)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
61
Monitored processes
14
Malicious processes
11
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start drop and start drop and start drop and start start drop and start drop and start drop and start drop and start winrar.exe undetectedclient.exe no specs undetectedclient.exe cmd.exe bypass.exe defender.exe no specs defender.exe taskmgr.exe no specs undetectedclient.exe no specs undetectedclient.exe cmd.exe bypass.exe defender.exe no specs defender.exe

Process information

PID
CMD
Path
Indicators
Parent process
960"C:\Windows\system32\taskmgr.exe" /4C:\Windows\system32\taskmgr.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Task Manager
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskmgr.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
996"C:\Windows\system32\cmd.exe" /c "C:\Users\admin\AppData\Local\Temp\ECA5.tmp\ECA6.tmp\ECA7.bat "C:\Users\admin\AppData\Local\Temp\Rar$EXa3648.27676\Free Rainbow Six Siege Cheats\UndetectedClient.exe""C:\Windows\system32\cmd.exe
UndetectedClient.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1096"C:\Users\admin\AppData\Local\Temp\Defender.exe" /SYS 1C:\Users\admin\AppData\Local\Temp\Defender.exe
Defender.exe
User:
SYSTEM
Company:
www.sordum.org
Integrity Level:
SYSTEM
Description:
Windows Defender Control
Exit code:
1
Version:
1.5.0.0
Modules
Images
c:\users\admin\appdata\local\temp\defender.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\version.dll
1504"C:\Users\admin\AppData\Local\Temp\Defender.exe" /SYS 1C:\Users\admin\AppData\Local\Temp\Defender.exe
Defender.exe
User:
SYSTEM
Company:
www.sordum.org
Integrity Level:
SYSTEM
Description:
Windows Defender Control
Exit code:
1
Version:
1.5.0.0
Modules
Images
c:\users\admin\appdata\local\temp\defender.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\version.dll
1940"C:\Users\admin\AppData\Local\Temp\Defender.exe" /DC:\Users\admin\AppData\Local\Temp\Defender.exeBypass.exe
User:
admin
Company:
www.sordum.org
Integrity Level:
HIGH
Description:
Windows Defender Control
Exit code:
0
Version:
1.5.0.0
Modules
Images
c:\users\admin\appdata\local\temp\defender.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\version.dll
2180Bypass.exeC:\Users\admin\AppData\Local\Temp\5C0E.tmp\Bypass.exe
cmd.exe
User:
admin
Integrity Level:
HIGH
Description:
WindowsDefenderDisabled
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\5c0e.tmp\bypass.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2252"C:\Users\admin\AppData\Local\Temp\Rar$EXa3648.23971\Free Rainbow Six Siege Cheats\UndetectedClient.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3648.23971\Free Rainbow Six Siege Cheats\UndetectedClient.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3648.23971\free rainbow six siege cheats\undetectedclient.exe
c:\systemroot\system32\ntdll.dll
2656"C:\Users\admin\AppData\Local\Temp\Rar$EXa3648.27676\Free Rainbow Six Siege Cheats\UndetectedClient.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3648.27676\Free Rainbow Six Siege Cheats\UndetectedClient.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3648.27676\free rainbow six siege cheats\undetectedclient.exe
c:\systemroot\system32\ntdll.dll
2680"C:\Users\admin\AppData\Local\Temp\Rar$EXa3648.27676\Free Rainbow Six Siege Cheats\UndetectedClient.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3648.27676\Free Rainbow Six Siege Cheats\UndetectedClient.exe
WinRAR.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3648.27676\free rainbow six siege cheats\undetectedclient.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
2732"C:\Users\admin\AppData\Local\Temp\Rar$EXa3648.23971\Free Rainbow Six Siege Cheats\UndetectedClient.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3648.23971\Free Rainbow Six Siege Cheats\UndetectedClient.exe
WinRAR.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3648.23971\free rainbow six siege cheats\undetectedclient.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
Total events
596
Read events
555
Write events
41
Delete events
0

Modification events

(PID) Process:(3648) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3648) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3648) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3648) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E
Operation:writeName:@C:\Windows\system32\NetworkExplorer.dll,-1
Value:
Network
(PID) Process:(3648) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Free Rainbow Six Siege Cheats.rar
(PID) Process:(3648) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3648) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3648) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3648) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3648) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E
Operation:writeName:@C:\Windows\system32\notepad.exe,-469
Value:
Text Document
Executable files
16
Suspicious files
2
Text files
5
Unknown types
0

Dropped files

PID
Process
Filename
Type
3636Defender.exeC:\Users\admin\AppData\Local\Temp\aut5E40.tmp
MD5:
SHA256:
3636Defender.exeC:\Users\admin\AppData\Local\Temp\zwtcncp
MD5:
SHA256:
1096Defender.exeC:\Windows\TEMP\aut6034.tmp
MD5:
SHA256:
1096Defender.exeC:\Windows\TEMP\sdpitbc
MD5:
SHA256:
1940Defender.exeC:\Users\admin\AppData\Local\Temp\autEED8.tmp
MD5:
SHA256:
1940Defender.exeC:\Users\admin\AppData\Local\Temp\yaixvqz
MD5:
SHA256:
3648WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3648.23971\Free Rainbow Six Siege Cheats\readme.txttext
MD5:
SHA256:
1504Defender.exeC:\Windows\TEMP\autF02F.tmp
MD5:
SHA256:
1504Defender.exeC:\Windows\TEMP\jjfrmeb
MD5:
SHA256:
2732UndetectedClient.exeC:\Users\admin\AppData\Local\Temp\5C0E.tmp\Microsoft Edge.exeexecutable
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info