| download: | Peunion.rar |
| Full analysis: | https://app.any.run/tasks/78464e35-3a12-4789-9937-dc34c8d10752 |
| Verdict: | Malicious activity |
| Threats: | njRAT is a remote access trojan. It is one of the most widely accessible RATs on the market that features an abundance of educational information. Interested attackers can even find tutorials on YouTube. This allows it to become one of the most popular RATs in the world. |
| Analysis date: | March 26, 2020, 15:42:11 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v5 |
| MD5: | 77986B8C8AC371C8CC99CE5D5FCF4CC9 |
| SHA1: | E1F8087D19BDAC6E5E8E54816D7CCF99C0D39655 |
| SHA256: | 9AE8675DD290D6A964947445E1A5C16CBE6DF50D2BC3161ADDB664E93AC78BEE |
| SSDEEP: | 12288:CTf3lBiNg4p8e7u3rAlMlow+lY0JjtpbtwzSP/Bufqm:CD2NnH7ubAelt+RJjWu6qm |
| .rar | | | RAR compressed archive (v5.0) (61.5) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 528 | "C:\Windows\system32\notepad.exe" | C:\Windows\system32\notepad.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Notepad Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 580 | "C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_compiler.exe" | C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_compiler.exe | — | aspnet_compiler.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: aspnet_compiler.exe Exit code: 1 Version: 2.0.50727.4927 (NetFXspW7.050727-4900) Modules
| |||||||||||||||
| 608 | "C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_compiler.exe" | C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_compiler.exe | — | aspnet_compiler.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: aspnet_compiler.exe Exit code: 1 Version: 2.0.50727.4927 (NetFXspW7.050727-4900) Modules
| |||||||||||||||
| 744 | "C:\Windows\system32\taskmgr.exe" | C:\Windows\system32\taskmgr.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Task Manager Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 780 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Peunion.rar" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 816 | "C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_compiler.exe" | C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_compiler.exe | PEUNIUON.EXE | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: aspnet_compiler.exe Exit code: 0 Version: 2.0.50727.4927 (NetFXspW7.050727-4900) Modules
| |||||||||||||||
| 1876 | "C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe" /noconfig @"C:\Users\admin\AppData\Local\Temp\cy7tk2s-.cmdline" | C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe | aspnet_compiler.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Visual Basic Command Line Compiler Exit code: 0 Version: 8.0.50727.5420 Modules
| |||||||||||||||
| 2356 | schtasks /create /sc minute /mo 1 /tn "Client" /tr "C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Client.exe" | C:\Windows\system32\schtasks.exe | — | aspnet_compiler.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2360 | "C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe" /noconfig @"C:\Users\admin\AppData\Local\Temp\ms3s7ahp.cmdline" | C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe | aspnet_compiler.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Visual Basic Command Line Compiler Exit code: 0 Version: 8.0.50727.5420 Modules
| |||||||||||||||
| 2436 | C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\admin\AppData\Local\Temp\RESB153.tmp" "C:\Users\admin\AppData\Local\Temp\vbcB152.tmp" | C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.exe | — | vbc.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft® Resource File To COFF Object Conversion Utility Exit code: 0 Version: 8.00.50727.4940 (Win7SP1.050727-5400) Modules
| |||||||||||||||
| (PID) Process: | (780) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (780) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (780) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (780) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Peunion.rar | |||
| (PID) Process: | (780) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (780) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (780) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (780) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (2580) Peunion.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (2580) Peunion.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3560 | PEUNION.EXE | C:\Users\admin\AppData\Local\Temp\tmp8EEA.tmp | — | |
MD5:— | SHA256:— | |||
| 3452 | cvtres.exe | C:\Users\admin\AppData\Local\Temp\RESA2BC.tmp | — | |
MD5:— | SHA256:— | |||
| 3508 | vbc.exe | C:\Users\admin\AppData\Local\Temp\6lfhydeb.out | — | |
MD5:— | SHA256:— | |||
| 2768 | vbc.exe | C:\Users\admin\AppData\Local\Temp\vbcA54C.tmp | — | |
MD5:— | SHA256:— | |||
| 3044 | cvtres.exe | C:\Users\admin\AppData\Local\Temp\RESA54D.tmp | — | |
MD5:— | SHA256:— | |||
| 3356 | PEUNIUON.EXE | C:\Users\admin\AppData\Local\Temp\XkqFTccA.txt | text | |
MD5:— | SHA256:— | |||
| 2768 | vbc.exe | C:\Users\admin\AppData\Local\Temp\x8qrelb6.out | — | |
MD5:— | SHA256:— | |||
| 2580 | Peunion.exe | C:\Users\admin\AppData\Local\Temp\PEUNION.EXE | executable | |
MD5:— | SHA256:— | |||
| 2724 | aspnet_compiler.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Client.exe | executable | |
MD5:— | SHA256:— | |||
| 2724 | aspnet_compiler.exe | C:\Users\admin\AppData\Local\Temp\6lfhydeb.0.vb | text | |
MD5:— | SHA256:— | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
816 | aspnet_compiler.exe | 185.140.53.19:444 | — | myLoc managed IT AG | DE | malicious |
2724 | aspnet_compiler.exe | 185.140.53.19:444 | — | myLoc managed IT AG | DE | malicious |
PID | Process | Class | Message |
|---|---|---|---|
816 | aspnet_compiler.exe | A Network Trojan was detected | MALWARE [PTsecurity] Revenge/hamza-RAT CnC Checkin |
816 | aspnet_compiler.exe | A Network Trojan was detected | MALWARE [PTsecurity] MSIL/Maadawy-RAT (njRAT) CnC Response |
816 | aspnet_compiler.exe | A Network Trojan was detected | MALWARE [PTsecurity] njRAT |
816 | aspnet_compiler.exe | A Network Trojan was detected | MALWARE [PTsecurity] MSIL/Maadawy-RAT (njRAT) CnC Response |
816 | aspnet_compiler.exe | A Network Trojan was detected | MALWARE [PTsecurity] njRAT |
816 | aspnet_compiler.exe | A Network Trojan was detected | MALWARE [PTsecurity] MSIL/Maadawy-RAT (njRAT) CnC Response |
816 | aspnet_compiler.exe | A Network Trojan was detected | MALWARE [PTsecurity] njRAT |
816 | aspnet_compiler.exe | A Network Trojan was detected | MALWARE [PTsecurity] MSIL/Maadawy-RAT (njRAT) CnC Response |
816 | aspnet_compiler.exe | A Network Trojan was detected | MALWARE [PTsecurity] njRAT |
816 | aspnet_compiler.exe | A Network Trojan was detected | MALWARE [PTsecurity] Revenge/hamza-RAT CnC Checkin |
Process | Message |
|---|---|
Peunion.exe | C:\Users\admin\AppData\Local\Temp\PEUNION.EXE |
Peunion.exe | C:\Users\admin\AppData\Local\Temp\PEUNIUON.EXE |