File name:

SWPS4MAX Source Code Fixed.rar

Full analysis: https://app.any.run/tasks/9ffe745f-14ec-42d3-806f-b0529471944f
Verdict: Malicious activity
Analysis date: July 24, 2020, 08:43:25
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v4, os: Win32
MD5:

33DCF16285DDFEC61A81EA16A5DCBFB2

SHA1:

C5EC8A3390DF462CF5E32F9ED7EF241D2A6F3D16

SHA256:

A3A5BF099E16B518D4C3B21A7ED41C4EAEFF9815B6B62EBD3BFFE2E3B55D99B4

SSDEEP:

98304:j37v/c5E2vjZUYLZsKFPvXcW2cAx7FMBOF5sJwZpfE3W95kb1AEc8rvEaoPU3BMJ:jLv/AE2lUY1PvXcmA1p5mc59+b1Ax8zY

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • PS4SaveEditor.exe (PID: 1308)
      • PS4SaveEditor.exe (PID: 2888)
    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 3544)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2324)
  • INFO

    • Dropped object may contain Bitcoin addresses

      • WinRAR.exe (PID: 2324)
    • Manual execution by user

      • PS4SaveEditor.exe (PID: 2888)
      • NOTEPAD.EXE (PID: 2540)
      • PS4SaveEditor.exe (PID: 1308)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

CompressedSize: 404
UncompressedSize: 907
OperatingSystem: Win32
ModifyDate: 2017:07:02 22:57:11
PackingMethod: Normal
ArchivedFileName: SWPS4MAX.sln
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
50
Monitored processes
5
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe searchprotocolhost.exe no specs ps4saveeditor.exe no specs ps4saveeditor.exe no specs notepad.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1308"C:\Users\admin\Desktop\Save Wizard\bin\Debug\PS4SaveEditor.exe" C:\Users\admin\Desktop\Save Wizard\bin\Debug\PS4SaveEditor.exeexplorer.exe
User:
admin
Company:
Cheats Inc
Integrity Level:
MEDIUM
Description:
PS4 Cheats Inc
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\save wizard\bin\debug\ps4saveeditor.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2324"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\SWPS4MAX Source Code Fixed.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2540"C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\New Text Document.txtC:\Windows\system32\NOTEPAD.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2888"C:\Users\admin\Desktop\Save Wizard\bin\Debug\PS4SaveEditor.exe" C:\Users\admin\Desktop\Save Wizard\bin\Debug\PS4SaveEditor.exeexplorer.exe
User:
admin
Company:
Cheats Inc
Integrity Level:
MEDIUM
Description:
PS4 Cheats Inc
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\save wizard\bin\debug\ps4saveeditor.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3544"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe5_ Global\UsGthrCtrlFltPipeMssGthrPipe5 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
1 324
Read events
1 272
Write events
51
Delete events
1

Modification events

(PID) Process:(2324) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2324) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2324) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\132\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2324) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\SWPS4MAX Source Code Fixed.rar
(PID) Process:(2324) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2324) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2324) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2324) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2324) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
(PID) Process:(2324) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\General
Operation:writeName:LastFolder
Value:
C:\Users\admin\AppData\Local\Temp
Executable files
4
Suspicious files
36
Text files
506
Unknown types
6

Dropped files

PID
Process
Filename
Type
2324WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2324.8218\Be\Windows\Forms\DynamicFileByteProvider.cstext
MD5:0F79DCAA8F44D55A436591C7EFAAD94E
SHA256:451C8E7B46801091D85192DADE005D36EA6F31B1625D2C1275F47B4D765637B4
2324WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2324.8218\Be\Windows\Forms\FileDataBlock.cstext
MD5:B84A04D13ABA8C6F93A376171D51C757
SHA256:3D74F48ED73A6FD86CB11A3FE7175B701A8E2F5DB9F912A3BD324991FADA2076
2324WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2324.8218\Be\Windows\Forms\BuiltInContextMenu.cstext
MD5:ACB630A91E9FA85720474F95FACC5D72
SHA256:EC44CB0457EB58D2F28F0D605BF309ED03AF6FC60B3E120D8E23DD79F493B590
2324WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2324.8218\Be\Windows\Forms\ByteCollection.cstext
MD5:AD27F11FCD42DCCF000506B2D6A5DC5A
SHA256:DC0EAF5C4EEAD908045117DB3D2838E6F8E0404F05586C2354B2C9F91C37B92A
2324WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2324.8218\Be\Windows\Forms\EbcdicByteCharProvider.cstext
MD5:65B485FA748D9C1BE5F1A616D26C0E57
SHA256:15603A2703733863F82E544603A947C6D350E166632774C590013D3F50A27776
2324WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2324.8218\Be\Windows\Forms\DataMap.cstext
MD5:61C9B1E1A9A1D3F852630FA3ADBC7699
SHA256:45024F95BA22D606CD4C96AEF6A5F639906A7186250D2E621C7F32A74AF94B8B
2324WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2324.8218\Be\Windows\Forms\HexCasing.cstext
MD5:8844535416744331CC0E2E98C28E8249
SHA256:0BAFEDD32E0B32F66F93166DD8CAAF156CED6D4879ED76D5CFDBBA34EF04C5DF
2324WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2324.8218\Be\Windows\Forms\FileByteProvider.cstext
MD5:1CD8911DB9C95539A5716B470C5D1990
SHA256:5A1EB4B0B92AA106D5AE8A4440DEE7AFA1E4BDEE2ABACCFB6EF8DF4B83049815
2324WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2324.8218\Be\Windows\Forms\DynamicByteProvider.cstext
MD5:0963F8275C85B1AA52158EF5A3FEC2A6
SHA256:FCA356F7F7BA8D09D6A4E03897A5591D67A51CF91495F458FCBAE25C4B05F564
2324WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2324.8218\Be\Windows\Forms\DefaultByteCharConverter.cstext
MD5:3D4266E9A2F54CC5EB2ADDF5642FC804
SHA256:311EC648FD8CB25D6B736BCF32DF7451A5F9083B7A37C682CE68D5DB82D1C824
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info