File name: | RedLine unpacked by Grizzly.rar |
Full analysis: | https://app.any.run/tasks/d9d01ed3-0e9f-4bf8-a4d2-5c0e38925960 |
Verdict: | Malicious activity |
Analysis date: | January 24, 2022, 19:11:28 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/x-rar |
File info: | RAR archive data, v5 |
MD5: | 7DD77B4F4763579B7E4089F84150129B |
SHA1: | 733F9F4418F493EDF8BCB95845A00A039826DC34 |
SHA256: | 9F76F8E662F2AF134584487443D79AD02D668D9EE9F1AAA3143C17E874F00423 |
SSDEEP: | 24576:fD6QtITfzjCBsyRDG7L1xgLRKuXfsGycg3KGRKBOpdHfqxlcSl3z:fD/G/CBsys9+sL56GQOPfSzl3z |
.rar | | | RAR compressed archive (v5.0) (61.5) |
---|---|---|
.rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
3564 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\RedLine unpacked by Grizzly.rar" | C:\Program Files\WinRAR\WinRAR.exe | Explorer.EXE | |
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 | ||||
3604 | "C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" | C:\Windows\system32\SearchProtocolHost.exe | — | SearchIndexer.exe |
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft Windows Search Protocol Host Version: 7.00.7601.24542 (win7sp1_ldr_escrow.191209-2211) | ||||
408 | "C:\Users\admin\Desktop\RedLine.MainPanel_unpack_by_grizzly.exe" | C:\Users\admin\Desktop\RedLine.MainPanel_unpack_by_grizzly.exe | — | Explorer.EXE |
User: admin Integrity Level: MEDIUM Description: RedLinePanel Exit code: 3221226540 Version: 1.0.0.0 | ||||
120 | "C:\Users\admin\Desktop\RedLine.MainPanel_unpack_by_grizzly.exe" | C:\Users\admin\Desktop\RedLine.MainPanel_unpack_by_grizzly.exe | Explorer.EXE | |
User: admin Integrity Level: HIGH Description: RedLinePanel Exit code: 0 Version: 1.0.0.0 | ||||
1260 | "C:\Users\admin\Desktop\RedLine.MainPanel_unpack_by_grizzly.exe" | C:\Users\admin\Desktop\RedLine.MainPanel_unpack_by_grizzly.exe | — | Explorer.EXE |
User: admin Integrity Level: MEDIUM Description: RedLinePanel Exit code: 3221226540 Version: 1.0.0.0 | ||||
3520 | "C:\Users\admin\Desktop\RedLine.MainPanel_unpack_by_grizzly.exe" | C:\Users\admin\Desktop\RedLine.MainPanel_unpack_by_grizzly.exe | Explorer.EXE | |
User: admin Integrity Level: HIGH Description: RedLinePanel Exit code: 0 Version: 1.0.0.0 |
(PID) Process: | (3564) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtBMP |
Value: | |||
(PID) Process: | (3564) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
Operation: | write | Name: | ShellExtIcon |
Value: | |||
(PID) Process: | (3564) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (3564) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
(PID) Process: | (3564) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
(PID) Process: | (3564) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\RedLine unpacked by Grizzly.rar | |||
(PID) Process: | (3564) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | name |
Value: 120 | |||
(PID) Process: | (3564) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | size |
Value: 80 | |||
(PID) Process: | (3564) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | type |
Value: 120 | |||
(PID) Process: | (3564) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
Operation: | write | Name: | mtime |
Value: 100 |
PID | Process | Filename | Type | |
---|---|---|---|---|
3564 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb3564.15447\RedLine.MainPanel_unpack_by_grizzly.exe | executable | |
MD5:B17B6C4102557727A1939DFBBB3F3F53 | SHA256:290F38FB4BF0A44E0AEAF7A4F7FA8ABCF5F599D94F9D01743463ADB90BADF79A | |||
3564 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb3564.15447\RedLine.SharedModels.dll | executable | |
MD5:AE877D9B64C6907D4591463CB52CA9FA | SHA256:E7339D9B25849A1B61D2C186B11D9CDB53352B65C7EE4603A1B6D2A5BB733C0D | |||
3564 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb3564.15447\Pluralsight.Crypto.dll | executable | |
MD5:6D0FAB9DF4408F42C339109D4AD80D5A | SHA256:5018C1B21264B1FA8BE9904647FC2732D2514F01F3F8AF70702931F0234D0D94 | |||
3564 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb3564.15447\RedLine.MainPanel.exe.config | xml | |
MD5:E0B9F161A4F5595C87FF6F2490AC3EF5 | SHA256:9CDEEEC22B816EAE2A98D13FDA178768CA0BCCCB2C2B6A984CCFB3AF95D2C7D6 | |||
3564 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb3564.15447\Telegram.Bot.dll | executable | |
MD5:B2C03E251DE45AD9A8206AC20A5E0E8F | SHA256:6CC510863C1FD54BE384041E928A151501CFFD5AB3881E22ACA2119C82F7EBC7 | |||
3564 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb3564.15447\Newtonsoft.Json.dll | executable | |
MD5:6815034209687816D8CF401877EC8133 | SHA256:7F912B28A07C226E0BE3ACFB2F57F050538ABA0100FA1F0BF2C39F1A1F1DA814 | |||
3564 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb3564.15447\protobuf-net.dll | executable | |
MD5:D16FFFEB71891071C1C5D9096BA03971 | SHA256:141B235AF8EBF25D5841EDEE29E2DCF6297B8292A869B3966C282DA960CBD14D | |||
3564 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb3564.15447\MetroSet UI.dll.config | xml | |
MD5:9A25AE6E4FBE956CC33A232AC97D3B16 | SHA256:A407B110C78C0077B651FCBD05CCE073541B61E3E8B4747608069AC5CE686A8C | |||
3564 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb3564.15447\serviceSettings.json | binary | |
MD5:A2ECA06223DFB21BD7C815EC354FA87D | SHA256:7158D6194A4EB9B47F17B174E180F34835561A230CF37309FD7DDA55B7016EB3 | |||
3564 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRb3564.15447\MetroSet UI.dll | odttf | |
MD5:5AEEA45913EB8475077A9547D7D3F2F3 | SHA256:EF2A67849FBE0F1C99263BF0ACFDDF15A1B3668E49FD9D35868E147D8A4C8C73 |