File name:

Project Eternity.rar

Full analysis: https://app.any.run/tasks/c28c1d3d-0373-4b04-bde9-4ef816c8a445
Verdict: Malicious activity
Analysis date: January 14, 2022, 16:33:35
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

493F5A6A9C6B13D9C2799F4CF77966F5

SHA1:

CE594BA5BAB08D40742A37395A0C6C5F1B438726

SHA256:

A2462017C5BCA6DF5C3E297C2A1AE88A67EE45B2BBD8DFEB16A31FE229339857

SSDEEP:

12288:SrR+nDszCMQnhLTOPqnyqREybXXj8KI3uAvw:AR+nD8GnhPv114Ks0

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Project Eternity.exe (PID: 2512)
      • dcd.exe (PID: 3168)
      • Project Eternity.exe (PID: 3692)
      • dcd.exe (PID: 3340)
    • Drops executable file immediately after starts

      • Project Eternity.exe (PID: 2512)
      • Project Eternity.exe (PID: 3692)
    • Writes to a start menu file

      • Project Eternity.exe (PID: 2512)
  • SUSPICIOUS

    • Checks supported languages

      • Project Eternity.exe (PID: 2512)
      • WinRAR.exe (PID: 2188)
      • dcd.exe (PID: 3340)
      • dcd.exe (PID: 3168)
      • Project Eternity.exe (PID: 3692)
    • Reads the computer name

      • WinRAR.exe (PID: 2188)
      • Project Eternity.exe (PID: 2512)
      • Project Eternity.exe (PID: 3692)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2188)
      • Project Eternity.exe (PID: 2512)
      • Project Eternity.exe (PID: 3692)
    • Reads Environment values

      • Project Eternity.exe (PID: 2512)
      • Project Eternity.exe (PID: 3692)
    • Creates files in the user directory

      • Project Eternity.exe (PID: 2512)
  • INFO

    • Manual execution by user

      • Project Eternity.exe (PID: 2512)
      • Project Eternity.exe (PID: 3692)
    • Reads settings of System Certificates

      • Project Eternity.exe (PID: 2512)
      • Project Eternity.exe (PID: 3692)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
42
Monitored processes
5
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start drop and start drop and start winrar.exe project eternity.exe dcd.exe no specs project eternity.exe dcd.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2188"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Project Eternity.rar"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2512"C:\Users\admin\Desktop\Project Eternity.exe" C:\Users\admin\Desktop\Project Eternity.exe
Explorer.EXE
User:
admin
Integrity Level:
MEDIUM
Description:
Exit code:
3762504530
Version:
0.0.0.0
Modules
Images
c:\users\admin\desktop\project eternity.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3168"C:\Users\admin\AppData\Local\Temp\dcd.exe" -path=""C:\Users\admin\AppData\Local\Temp\dcd.exeProject Eternity.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\dcd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
3340"C:\Users\admin\AppData\Local\Temp\dcd.exe" -path=""C:\Users\admin\AppData\Local\Temp\dcd.exeProject Eternity.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\dcd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
3692"C:\Users\admin\Desktop\Project Eternity.exe" C:\Users\admin\Desktop\Project Eternity.exe
Explorer.EXE
User:
admin
Integrity Level:
MEDIUM
Description:
Exit code:
0
Version:
0.0.0.0
Modules
Images
c:\users\admin\desktop\project eternity.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
8 963
Read events
8 902
Write events
61
Delete events
0

Modification events

(PID) Process:(2188) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2188) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2188) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2188) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(2188) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2188) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Project Eternity.rar
(PID) Process:(2188) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2188) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2188) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2188) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
4
Suspicious files
3
Text files
0
Unknown types
1

Dropped files

PID
Process
Filename
Type
2188WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2188.18317\Project Eternity.exeexecutable
MD5:
SHA256:
2512Project Eternity.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506binary
MD5:
SHA256:
2512Project Eternity.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506compressed
MD5:ACAEDA60C79C6BCAC925EEB3653F45E0
SHA256:6B0CECCF0103AFD89844761417C1D23ACC41F8AEBF3B7230765209B61EEE5658
2512Project Eternity.exeC:\Users\admin\AppData\Local\Temp\dcd.exeexecutable
MD5:B5AC46E446CEAD89892628F30A253A06
SHA256:DEF7AFCB65126C4B04A7CBF08C693F357A707AA99858CAC09A8D5E65F3177669
2512Project Eternity.exeC:\Users\admin\AppData\Local\Temp\Cab5EE4.tmpcompressed
MD5:ACAEDA60C79C6BCAC925EEB3653F45E0
SHA256:6B0CECCF0103AFD89844761417C1D23ACC41F8AEBF3B7230765209B61EEE5658
2512Project Eternity.exeC:\Users\admin\AppData\Local\Temp\Tar5EE5.tmpcat
MD5:D99661D0893A52A0700B8AE68457351A
SHA256:BDD5111162A6FA25682E18FA74E37E676D49CAFCB5B7207E98E5256D1EF0D003
2512Project Eternity.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Project Eternity.exeexecutable
MD5:
SHA256:
3692Project Eternity.exeC:\Users\admin\AppData\Local\Temp\dcd.exeexecutable
MD5:B5AC46E446CEAD89892628F30A253A06
SHA256:DEF7AFCB65126C4B04A7CBF08C693F357A707AA99858CAC09A8D5E65F3177669
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
6
DNS requests
4
Threats
3

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2512
Project Eternity.exe
GET
204
142.250.186.78:80
http://google.com/generate_204
US
malicious
3692
Project Eternity.exe
GET
204
142.250.186.78:80
http://google.com/generate_204
US
malicious
2512
Project Eternity.exe
GET
200
178.79.242.128:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?8692b4abe97b95b9
DE
compressed
59.9 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2512
Project Eternity.exe
46.229.170.2:443
api.imgbb.com
DataWeb Global Group B.V.
US
suspicious
2512
Project Eternity.exe
178.79.242.128:80
ctldl.windowsupdate.com
Limelight Networks, Inc.
DE
malicious
3692
Project Eternity.exe
142.250.186.78:80
google.com
Google Inc.
US
whitelisted
3692
Project Eternity.exe
46.229.170.2:443
api.imgbb.com
DataWeb Global Group B.V.
US
suspicious
2512
Project Eternity.exe
172.67.199.29:443
eternitypr.net
US
malicious
2512
Project Eternity.exe
142.250.186.78:80
google.com
Google Inc.
US
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.186.78
malicious
api.imgbb.com
  • 46.229.170.2
malicious
ctldl.windowsupdate.com
  • 178.79.242.128
whitelisted
eternitypr.net
  • 172.67.199.29
  • 104.21.21.142
malicious

Threats

Found threats are available for the paid subscriptions
3 ETPRO signatures available at the full report
No debug info