File name:

CG - Multihack Control Panel 1.0.9.rar

Full analysis: https://app.any.run/tasks/4b9c0ef7-3007-4e8a-897d-393598eebc93
Verdict: Malicious activity
Analysis date: May 30, 2021, 17:33:43
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

AB40B22F97119BBB4A1EB9914BF0C53D

SHA1:

24C5A174BA64CF5835F77EDB6876604000905866

SHA256:

A08C8C1B4246D55405310D49DB5FAD872335C3614BC36C96EFD0E3A2EE860107

SSDEEP:

196608:P54+hRYdFr3AYo3WnpUEJB2h8/EhDrZssn1M5Sd7qxCQ8vSsVrG9r/DiIc3ZnG/v:lORLfndjE5vZBn1MQdLDkr/TEmv

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Drops a file with a compile date too recent

      • WinRAR.exe (PID: 1868)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1868)
    • Drops a file that was compiled in debug mode

      • WinRAR.exe (PID: 1868)
    • Drops a file with too old compile date

      • WinRAR.exe (PID: 1868)
  • INFO

    • Manual execution by user

      • explorer.exe (PID: 3700)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
41
Monitored processes
3
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe notepad.exe no specs explorer.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1868"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\CG - Multihack Control Panel 1.0.9.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2360"C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\AppData\Local\Temp\Rar$DIa1868.39289\How to use.txtC:\Windows\system32\NOTEPAD.EXEWinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3700"C:\Windows\explorer.exe" C:\Windows\explorer.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
533
Read events
499
Write events
34
Delete events
0

Modification events

(PID) Process:(1868) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1868) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1868) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1868) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E
Operation:writeName:@C:\Windows\system32\NetworkExplorer.dll,-1
Value:
Network
(PID) Process:(1868) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\CG - Multihack Control Panel 1.0.9.rar
(PID) Process:(1868) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1868) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1868) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1868) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1868) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E
Operation:writeName:@C:\Windows\system32\notepad.exe,-469
Value:
Text Document
Executable files
31
Suspicious files
1
Text files
4
Unknown types
0

Dropped files

PID
Process
Filename
Type
1868WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1868.38678\CG - Multihack Control Panel 1.0.9\Crash Report\RarExt.dllexecutable
MD5:
SHA256:
1868WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1868.38678\CG - Multihack Control Panel 1.0.9\How to use.txttext
MD5:
SHA256:
1868WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1868.38678\CG - Multihack Control Panel 1.0.9\Cheats\GTA5.dllexecutable
MD5:D91BF81CF5178D47D1A588B0DF98EB24
SHA256:F8E3B45FD3E22866006F16A9E73E28B5E357F31F3C275B517692A5F16918B492
1868WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1868.38678\CG - Multihack Control Panel 1.0.9\Cheats\LOL.dllexecutable
MD5:EEFE86B5A3AB256BEED8621A05210DF2
SHA256:1D1C11FC1AD1FEBF9308225C4CCF0431606A4AB08680BA04494D276CB310BF15
1868WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1868.38678\CG - Multihack Control Panel 1.0.9\Cheats\COD.dllexecutable
MD5:8894176AF3EA65A09AE5CF4C0E6FF50F
SHA256:C64B7C6400E9BACC1A4F1BAED6374BFBCE9A3F8CF20C2D03F81EF18262F89C60
1868WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1868.38678\CG - Multihack Control Panel 1.0.9\Cheats\Apex.dllexecutable
MD5:3F224766FE9B090333FDB43D5A22F9EA
SHA256:AE5E73416EB64BC18249ACE99F6847024ECEEA7CE9C343696C84196460F3A357
1868WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1868.38678\CG - Multihack Control Panel 1.0.9\Cheats\Rainbow Six Siege.dllexecutable
MD5:879920C7FA905036856BCB10875121D9
SHA256:7E4CBA620B87189278B5631536CDAD9BFDA6E12ABD8E4EB647CB85369A204FE8
1868WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1868.38678\CG - Multihack Control Panel 1.0.9\Cheats\Fortnite.dllexecutable
MD5:CFE87D58F973DAEDA4EE7D2CF4AE521D
SHA256:4997FDA5D0E90B8A0AB7DA314CB56F25D1450B366701C45C294D8DD3254DE483
1868WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1868.38678\CG - Multihack Control Panel 1.0.9\Cheats\Valorant.dllexecutable
MD5:FF8026DAB5D3DABCA8F72B6FA7D258FA
SHA256:535E9D20F00A2F1A62F843A4A26CFB763138D5DFE358B0126D33996FBA9CA4D1
1868WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1868.38678\CG - Multihack Control Panel 1.0.9\Cheats\PUBG.dllexecutable
MD5:0C48220A4485F36FEED84EF5DD0A5E9C
SHA256:2DD4EBAA12CBBA142B5D61A0EBF84A14D0D1BB8826BA42B63E303FE6721408DF
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info