File name:

RavelCros_Cro IP Pinger Pack 2.rar

Full analysis: https://app.any.run/tasks/57ed06c0-6c36-4cb1-9dfb-1e643413f0bb
Verdict: Malicious activity
Analysis date: September 24, 2021, 16:45:28
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

0F9B66EC4D49C6D7E65CEC1ED8AD8E5F

SHA1:

D5389140590093ECE81F765A56877B9DFF69942C

SHA256:

94C85340357B2A75BBEDF35606B7872ECDF990EEBA82D613EE495C68E1C2D1DE

SSDEEP:

96:ZSJq14lbolYiv2tWwf4wNBtlHN2gv+HKhOIjQZixZ039aF:X4lbsGWwZj8KhNjQ59Y

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Runs PING.EXE for delay simulation

      • cmd.exe (PID: 2280)
  • SUSPICIOUS

    • Checks supported languages

      • mode.com (PID: 128)
      • WinRAR.exe (PID: 3228)
      • cmd.exe (PID: 1208)
      • cmd.exe (PID: 2280)
      • mode.com (PID: 2412)
      • cmd.exe (PID: 1408)
      • mode.com (PID: 3448)
    • Reads the computer name

      • WinRAR.exe (PID: 3228)
  • INFO

    • Manual execution by user

      • cmd.exe (PID: 1208)
      • cmd.exe (PID: 2280)
      • cmd.exe (PID: 1408)
    • Checks supported languages

      • PING.EXE (PID: 2596)
      • PING.EXE (PID: 3604)
      • PING.EXE (PID: 2968)
      • PING.EXE (PID: 3076)
      • timeout.exe (PID: 3564)
      • PING.EXE (PID: 1536)
      • PING.EXE (PID: 2284)
      • PING.EXE (PID: 3848)
      • PING.EXE (PID: 4028)
      • PING.EXE (PID: 3632)
      • PING.EXE (PID: 1632)
      • PING.EXE (PID: 2272)
      • PING.EXE (PID: 3540)
      • PING.EXE (PID: 2456)
      • PING.EXE (PID: 1036)
    • Reads the computer name

      • PING.EXE (PID: 2596)
      • PING.EXE (PID: 3604)
      • PING.EXE (PID: 2968)
      • PING.EXE (PID: 3540)
      • PING.EXE (PID: 3848)
      • PING.EXE (PID: 4028)
      • PING.EXE (PID: 3632)
      • PING.EXE (PID: 1632)
      • PING.EXE (PID: 3076)
      • PING.EXE (PID: 2272)
      • PING.EXE (PID: 1536)
      • PING.EXE (PID: 2456)
      • PING.EXE (PID: 2284)
      • PING.EXE (PID: 1036)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
59
Monitored processes
22
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs cmd.exe no specs mode.com no specs cmd.exe no specs mode.com no specs ping.exe no specs ping.exe no specs ping.exe no specs ping.exe no specs ping.exe no specs ping.exe no specs timeout.exe no specs ping.exe no specs ping.exe no specs ping.exe no specs ping.exe no specs ping.exe no specs ping.exe no specs ping.exe no specs ping.exe no specs cmd.exe no specs mode.com no specs

Process information

PID
CMD
Path
Indicators
Parent process
128mode con cols=71 lines=25C:\Windows\system32\mode.comcmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
DOS Device MODE Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\mode.com
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ulib.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1036ping localhost -n 1 C:\Windows\system32\PING.EXEcmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
TCP/IP Ping Command
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ping.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
1208C:\Windows\system32\cmd.exe /c ""C:\Users\admin\Desktop\RavelCros_Cro IP Pinger Pack 2\Aqua_v3 IP Pinger.bat" "C:\Windows\system32\cmd.exeExplorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
3221225786
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1408C:\Windows\system32\cmd.exe /c ""C:\Users\admin\Desktop\RavelCros_Cro IP Pinger Pack 2\Crystal pinger.bat" "C:\Windows\system32\cmd.exeExplorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
3221225786
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\cmd.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
1536ping localhost -n 1 C:\Windows\system32\PING.EXEcmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
TCP/IP Ping Command
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ping.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
1632ping localhost -n 1 C:\Windows\system32\PING.EXEcmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
TCP/IP Ping Command
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ping.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\nsi.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\iphlpapi.dll
2272ping localhost -n 1 C:\Windows\system32\PING.EXEcmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
TCP/IP Ping Command
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ping.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\gdi32.dll
2280C:\Windows\system32\cmd.exe /c ""C:\Users\admin\Desktop\RavelCros_Cro IP Pinger Pack 2\Biohazard IP Pinger.bat" "C:\Windows\system32\cmd.exeExplorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
3221225786
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2284ping localhost -n 1 C:\Windows\system32\PING.EXEcmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
TCP/IP Ping Command
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ping.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
2412mode con lines=35 cols=60C:\Windows\system32\mode.comcmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
DOS Device MODE Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\mode.com
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ulib.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
3 399
Read events
3 391
Write events
8
Delete events
0

Modification events

(PID) Process:(3228) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3228) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3228) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\171\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3228) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\RavelCros_Cro IP Pinger Pack 2.rar
(PID) Process:(3228) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3228) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3228) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3228) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
0
Suspicious files
0
Text files
7
Unknown types
0

Dropped files

PID
Process
Filename
Type
3228WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3228.15122\RavelCros_Cro IP Pinger Pack 2\Aqua_v3 IP Pinger.battext
MD5:416E733933100EA2370E280974917A87
SHA256:9481E1F2199EC8EB4CDC6C44D4155B6B09B3D9B6C92FC5E73FDC4AB05BF378B3
3228WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3228.15122\RavelCros_Cro IP Pinger Pack 2\Biohazard IP Pinger.battext
MD5:151F990BF67A846FAFB869FBEA42A557
SHA256:3B3BA5D145A01D7CD0F6C783ACB41D515EBFD1DD275BF8D21A98B16317948DEA
3228WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3228.15122\RavelCros_Cro IP Pinger Pack 2\Pinger_v2.3.battext
MD5:1CB2F1422760214BB29D6359C0FBBC4F
SHA256:C1422DC8D3F3BDFC5617F68048C88C21C03A345A1A180E729E22CE214F8CC111
3228WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3228.15122\RavelCros_Cro IP Pinger Pack 2\Space Pinger by RavelCros_Cro.battext
MD5:3C26E96AC98F1B35DBA18A0A10712695
SHA256:1584446276BBC5D67568E1A2701BD1EB66920A7576435B845786B99D1DC83B19
3228WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3228.15122\RavelCros_Cro IP Pinger Pack 2\Crystal pinger.battext
MD5:E622222DFE2E8A1F98CA7101566382E3
SHA256:F40CDBED7C086E579A3030CB11D25F82EB679F169D5D2DC73B709F1721E7FFCB
3228WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3228.15122\RavelCros_Cro IP Pinger Pack 2\Star Pinger by RavelCros_Cro.battext
MD5:D889CA8D0BDFA93E8D3FDB95E9B6C338
SHA256:B04CBC9355B1B8E25DB4DBACD5C000EC29DD1AFDDC35354D3D8F76BCE1CC76B1
3228WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3228.15122\RavelCros_Cro IP Pinger Pack 2\IP Pinger Toxic.battext
MD5:9F58DC8F5816E3E5D61F645AC6F35640
SHA256:12DB0CBA515F5670A17D3684D82E466C07E914A069DCD80CDC126F1C8921A4C1
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info