| File name: | funny-warez.7z |
| Full analysis: | https://app.any.run/tasks/3f08dfba-c2a4-45b0-8f2d-80dbc1e7b61c |
| Verdict: | Malicious activity |
| Threats: | njRAT is a remote access trojan. It is one of the most widely accessible RATs on the market that features an abundance of educational information. Interested attackers can even find tutorials on YouTube. This allows it to become one of the most popular RATs in the world. |
| Analysis date: | February 10, 2024, 18:56:01 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-7z-compressed |
| File info: | 7-zip archive data, version 0.4 |
| MD5: | 2C3F245A5A389B4E78684C770FD228F6 |
| SHA1: | 9D00A717E2292D8686BE182AD92335C6695D67B2 |
| SHA256: | 97639634FA14825E108461B2991CE7541EDA2542407425FD3F09B8E4B1969CA7 |
| SSDEEP: | 98304:SZhN16dnLYyaN+eO1IqFAzGI6sKAviFZ/BhASClB3xd1drPgAagIZmERh5WGIkLs:k/DCqpZrhjPd6LwABySrcMfA |
| .7z | | | 7-Zip compressed archive (v0.4) (57.1) |
|---|---|---|
| .7z | | | 7-Zip compressed archive (gen) (42.8) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 480 | "C:\Users\admin\Desktop\hack wifi 2014.exe" | C:\Users\admin\Desktop\hack wifi 2014.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: Exit code: 3762504530 Version: 0.0.0.0 Modules
| |||||||||||||||
| 844 | "C:\Users\admin\Desktop\Moderator Hack.exe" | C:\Users\admin\Desktop\Moderator Hack.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221225547 Modules
| |||||||||||||||
| 1192 | "C:\Users\admin\Desktop\Crossfire.exe1_5F5D516183D54369893BD0FB3980553A.exe" | C:\Users\admin\Desktop\Crossfire.exe1_5F5D516183D54369893BD0FB3980553A.exe | — | explorer.exe | |||||||||||
User: admin Company: Macrovision Corporation Integrity Level: MEDIUM Description: InstallShield Exit code: 3221226540 Version: 12.0.49974 Modules
| |||||||||||||||
| 1540 | C:\Windows\system32\cmd.exe /c color a | C:\Windows\System32\cmd.exe | — | Moderator Hack.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1740 | "C:\Users\admin\AppData\Local\Temp\chorme.exe" | C:\Users\admin\AppData\Local\Temp\chorme.exe | fifa 15 Crack.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: chanayder Exit code: 0 Version: 1.0.0.0 Modules
NjRat(PID) Process(1740) chorme.exe C2hackers01.no-ip.biz Ports4070 BotnetHacKed by me Options Auto-run registry keySoftware\Microsoft\Windows\CurrentVersion\Run\d8c39c97b59541a2cd4789c541b75063 Splitter|'|'| Version0.7d | |||||||||||||||
| 1816 | "C:\Users\admin\Desktop\league of legend Hack tool 2014.exe" | C:\Users\admin\Desktop\league of legend Hack tool 2014.exe | explorer.exe | ||||||||||||
User: admin Company: delortelo Integrity Level: MEDIUM Description: league of legend Hack tool 2014 Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 1888 | "C:\Extracted\HACK PAYPAL 2015 by hackers.exe" | C:\Extracted\HACK PAYPAL 2015 by hackers.exe | — | hack paypal 2014.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: HACK PAYPAL 2015 Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 2052 | "C:\Users\admin\Desktop\Hack Facebook Tool.exe" | C:\Users\admin\Desktop\Hack Facebook Tool.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| 2328 | "C:\Users\admin\Desktop\hack paypal 2014.exe" | C:\Users\admin\Desktop\hack paypal 2014.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 2344 | "C:\Users\admin\Desktop\Hack Facebook Tool.exe" | C:\Users\admin\Desktop\Hack Facebook Tool.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| (PID) Process: | (3672) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3672) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3672) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3672) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (3672) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (3672) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
| (PID) Process: | (3672) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\funny-warez.7z | |||
| (PID) Process: | (3672) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3672) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3672) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3672 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb3672.37355\clash of clans hack tool 2014.exe | executable | |
MD5:28311B3CAC1CC5CA9358B43E54357CCA | SHA256:F6300D442F5A46BE7AB5C46D3188772AA9984D690186A547902E96F4A282FF07 | |||
| 3672 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb3672.37355\Crossfire.exe1_5F5D516183D54369893BD0FB3980553A.exe | executable | |
MD5:21ABF88390478FBA5011CE283BD84013 | SHA256:3C3EFAA45404B43C4D5C25B7DA7E43780A0C31426421347241804D61E02F7331 | |||
| 3672 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb3672.37355\pass facebook.scr | executable | |
MD5:CE5ADD18348171121BA8CD1C85A03BE1 | SHA256:45E6CEB58EF50E0AA14BF61765600F8413D5E4E8E8ADB8938F58820A247D1078 | |||
| 3672 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb3672.37355\Ak RecoilScriptsMacrosCheatsNoRecoilAimbotWallHAckFlyHack.exe | executable | |
MD5:6CC583A1F3F4500A524B61255F1D2710 | SHA256:1CBAA4D4C817743A7EC88BDC3F8D15200E543A86E0B3374C6D05A15A0762970F | |||
| 3672 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb3672.37355\hack instagram.rar | compressed | |
MD5:B4021E435D09B587BCF708A46D29EFCD | SHA256:1FA6FB1E0BF25B8C7456B4F5D045464E60E2BD9139603691499DBF48E71A0755 | |||
| 3672 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb3672.37355\AIMBOT.exe.bat | text | |
MD5:0DDC187A02EF790D440FC4953952EC2C | SHA256:5AA369AAFE17EE03C848DAC672CCFBEA4FEB9533D708B92FBBB3FF0186E3106C | |||
| 3672 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb3672.37355\Instagram Hack 2016.zip | compressed | |
MD5:F293F9AD2C87931F4851132E34B3A59E | SHA256:E81EF659C78A991D9CE981848662C8175C14B98C82E980FC097EF1291236B64D | |||
| 3672 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb3672.37355\hack facrbook 2015 v0.3.5.Scr | executable | |
MD5:71C7B31F60BC87076EF7C87EB775139F | SHA256:7998555A18CD1D65F928FD85B433E369CAFA3CA7BF61A731888D2BF12A8F49E4 | |||
| 3672 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb3672.37355\hack instagram 100%.rar | compressed | |
MD5:BE4BFAD0EF72C306C6AB52E32472B85D | SHA256:62D0D25DD7FD75EFE2A5B6A986766C76AE9E2EC9F84F272ED8BC5A1019ECC684 | |||
| 3672 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb3672.37355\Hack Accounts FaceBook_exe.Scr | executable | |
MD5:D279D19FFFBE0DD2D91AE790791C09A2 | SHA256:44BFD6A71A4F204734CA195A8D2A600F3A039F35371A49249E57FF361BEFF908 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1740 | chorme.exe | 78.159.135.230:4070 | hackers01.no-ip.biz | — | BG | unknown |
2956 | Trojan.exe | 139.99.66.103:8188 | dykh.linkpc.net | OVH SAS | SG | unknown |
Domain | IP | Reputation |
|---|---|---|
hackers01.no-ip.biz |
| unknown |
dns.msftncsi.com |
| shared |
dykh.linkpc.net |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
1080 | svchost.exe | Potentially Bad Traffic | ET INFO Observed DNS Query to .biz TLD |
1080 | svchost.exe | Misc activity | ET INFO DYNAMIC_DNS Query to a Suspicious no-ip Domain |
1080 | svchost.exe | Potentially Bad Traffic | ET INFO Observed DNS Query to DynDNS Domain (linkpc .net) |
1080 | svchost.exe | Potentially Bad Traffic | ET INFO Observed DNS Query to .biz TLD |
1080 | svchost.exe | Misc activity | ET INFO DYNAMIC_DNS Query to a Suspicious no-ip Domain |