File name:

N00bs Account Generator.zip

Full analysis: https://app.any.run/tasks/c2ce7eb1-5d3d-489e-86ad-d2025e5fac0a
Verdict: Malicious activity
Analysis date: March 06, 2019, 15:12:45
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

F22BB93F1A9B501B74BE2E0C09FC46BA

SHA1:

9AE79EFCC3F8DF07CA0D6BC79AAB11D754C163DF

SHA256:

9C82BD01D2E0D9D925A9D5A0131E5F115FA1490D54119D345E02543E50AC9F6F

SSDEEP:

1536:JyBwDP7AEvM7e46dMpe9uJ2RmoqjWlkGlN:wByEEU/WeeJR4jW7lN

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • N00bAccountGen.exe (PID: 2648)
      • N00bAccountGen.exe (PID: 3252)
    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 1920)
      • N00bAccountGen.exe (PID: 2648)
      • N00bAccountGen.exe (PID: 3252)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2936)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2018:10:27 18:32:07
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: N00bs Account Generator/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
35
Monitored processes
4
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
drop and start start winrar.exe n00baccountgen.exe searchprotocolhost.exe no specs n00baccountgen.exe

Process information

PID
CMD
Path
Indicators
Parent process
1920"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe6_ Global\UsGthrCtrlFltPipeMssGthrPipe6 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2648"C:\Users\admin\AppData\Local\Temp\Rar$EXa2936.19026\N00bs Account Generator\N00bAccountGen.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2936.19026\N00bs Account Generator\N00bAccountGen.exe
WinRAR.exe
User:
admin
Company:
Hewlett-Packard Company
Integrity Level:
MEDIUM
Description:
N00bAccountGen
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2936.19026\n00bs account generator\n00baccountgen.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2936"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\N00bs Account Generator.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3252"C:\Users\admin\Desktop\N00bAccountGen.exe" C:\Users\admin\Desktop\N00bAccountGen.exe
explorer.exe
User:
admin
Company:
Hewlett-Packard Company
Integrity Level:
MEDIUM
Description:
N00bAccountGen
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\n00baccountgen.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
524
Read events
479
Write events
45
Delete events
0

Modification events

(PID) Process:(2936) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2936) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2936) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2936) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\N00bs Account Generator.zip
(PID) Process:(2936) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2936) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2936) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2936) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2936) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(2936) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
Executable files
2
Suspicious files
0
Text files
1
Unknown types
1

Dropped files

PID
Process
Filename
Type
2936WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2936.20608\N00bs Account Generator\MetroFramework.dll
MD5:
SHA256:
2936WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2936.20608\N00bs Account Generator\N00bAccountGen.exe
MD5:
SHA256:
2936WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2936.20608\N00bs Account Generator\N00bAccountGen.exe.config
MD5:
SHA256:
2936WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2936.20608\N00bs Account Generator\N00bAccountGen.pdb
MD5:
SHA256:
2936WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2936.19026\N00bs Account Generator\MetroFramework.dllexecutable
MD5:A3A380676711EAC89F67E0043C21B5D6
SHA256:C23CDACB0DE78C5C6E8A1DDE085CCA1BF8261D3B90DAC39379A4AC4518D212D1
2936WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2936.19026\N00bs Account Generator\N00bAccountGen.pdbpdb
MD5:3972344AB1A071F083745285F4B6F199
SHA256:6095AA967E2EA65FE0A72A30378380CC2BDAA9590166635F6B62101385FF3187
2936WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2936.19026\N00bs Account Generator\N00bAccountGen.exeexecutable
MD5:F6DA01BF90FA70802582829E872772EF
SHA256:91CE8EEBD837BE4CFB13FAC9FB570CA03B3E449033586A392804093824F050B7
2936WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2936.19026\N00bs Account Generator\N00bAccountGen.exe.configxml
MD5:EF0181DE18EF3951806C0AD63B897BA4
SHA256:E8DECC96235B5494880083EB79C22C84C6D9EF312828BAF9490BEE7782C350EC
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2648
N00bAccountGen.exe
104.20.209.21:443
pastebin.com
Cloudflare Inc
US
shared
3252
N00bAccountGen.exe
104.20.209.21:443
pastebin.com
Cloudflare Inc
US
shared
2648
N00bAccountGen.exe
104.20.208.21:443
pastebin.com
Cloudflare Inc
US
shared

DNS requests

Domain
IP
Reputation
pastebin.com
  • 104.20.209.21
  • 104.20.208.21
malicious

Threats

No threats detected
No debug info