download:

Eziriz%20.NET%20Reactor%206.8.0.rar

Full analysis: https://app.any.run/tasks/cf0f834e-8b20-4ef5-9276-ced298adcadf
Verdict: Malicious activity
Analysis date: May 21, 2022, 07:24:08
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

5A60B830657E94AF29DC192940B07F50

SHA1:

3BE35B1F66DB91F9773ADBB3200A50F04E1EFEA8

SHA256:

A3AE0AD73C9ACF359D76999B5082D33F599BAEB1A39EB69ADCD4EA43BAFE4E94

SSDEEP:

393216:eJYk7hditOx6YYPmCKyUTFXBVR1GR8/bJNrz:eYk7icQ9mCKFBXxbDz

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • dotNET_Reactor.exe (PID: 3540)
    • Drops executable file immediately after starts

      • WinRAR.exe (PID: 3388)
    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 3604)
  • SUSPICIOUS

    • Reads the computer name

      • WinRAR.exe (PID: 3388)
      • dotNET_Reactor.exe (PID: 3540)
    • Checks supported languages

      • WinRAR.exe (PID: 3388)
      • dotNET_Reactor.exe (PID: 3540)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3388)
    • Drops a file with a compile date too recent

      • WinRAR.exe (PID: 3388)
    • Creates files in the user directory

      • dotNET_Reactor.exe (PID: 3540)
  • INFO

    • Manual execution by user

      • dotNET_Reactor.exe (PID: 3540)
    • Reads the computer name

      • WISPTIS.EXE (PID: 3352)
    • Checks supported languages

      • WISPTIS.EXE (PID: 3352)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
40
Monitored processes
5
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe dotnet_reactor.exe no specs searchprotocolhost.exe no specs wisptis.exe no specs wisptis.exe

Process information

PID
CMD
Path
Indicators
Parent process
900"C:\Windows\SYSTEM32\WISPTIS.EXE" /ManualLaunch;C:\Windows\SYSTEM32\WISPTIS.EXEdotNET_Reactor.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Pen and Touch Input Component
Exit code:
3221226540
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\wisptis.exe
c:\windows\system32\ntdll.dll
3352"C:\Windows\SYSTEM32\WISPTIS.EXE" /ManualLaunch;C:\Windows\SYSTEM32\WISPTIS.EXE
dotNET_Reactor.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Pen and Touch Input Component
Exit code:
24
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\wisptis.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
3388"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\666fa86e-d88b-4c56-b35a-6cdb7d15cd30.rar"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3540"C:\Users\admin\Desktop\Eziriz .NET Reactor 6.8.0\dotNET_Reactor.exe" C:\Users\admin\Desktop\Eziriz .NET Reactor 6.8.0\dotNET_Reactor.exeExplorer.EXE
User:
admin
Company:
EZIRIZ
Integrity Level:
MEDIUM
Description:
.NET Reactor
Exit code:
0
Version:
6.8.0.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\desktop\eziriz .net reactor 6.8.0\dotnet_reactor.exe
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3604"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\system32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7601.24542 (win7sp1_ldr_escrow.191209-2211)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
2 793
Read events
2 703
Write events
90
Delete events
0

Modification events

(PID) Process:(3388) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3388) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3388) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3388) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(3388) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3388) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\666fa86e-d88b-4c56-b35a-6cdb7d15cd30.rar
(PID) Process:(3388) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3388) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3388) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3388) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
78
Suspicious files
29
Text files
188
Unknown types
2

Dropped files

PID
Process
Filename
Type
3388WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3388.2565\Eziriz .NET Reactor 6.8.0\dotNET_Reactor.Console.exeexecutable
MD5:
SHA256:
3388WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3388.2565\Eziriz .NET Reactor 6.8.0\.NET Reactor SDK Test Apps\License Examination Windows Forms\VB.NET\SDK_TestApp\bin\Release\LicenseExamination_Secure\LicenseExamination.exeexecutable
MD5:
SHA256:
3388WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3388.2565\Eziriz .NET Reactor 6.8.0\.NET Reactor SDK Test Apps\License Examination Windows Forms\C#\SDK_TestApp\bin\Release\LicenseExamination_Secure\LicenseExamination.exeexecutable
MD5:
SHA256:
3388WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3388.2565\Eziriz .NET Reactor 6.8.0\.NET Reactor SDK Test Apps\License Examination .NET 5.0 Console\C#\LicenseExamination\bin\Release\net5.0\LicenseExamination.exeexecutable
MD5:74143F06EC90F07CC2C55DEC66DFD838
SHA256:D044AD319E6E8041281F7526536C017B39B266E249D88BE4896B3840227317D9
3388WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3388.2565\Eziriz .NET Reactor 6.8.0\dotNET_Reactor.exeexecutable
MD5:44B10B3B38DF861E83D7FE0C06414BCD
SHA256:0133F4878D4441DAD5C153B83B2CB70B510FF089814820CBFB4E88DF31564C8E
3388WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3388.2565\Eziriz .NET Reactor 6.8.0\VSPackage\17\[Content_Types].xmlxml
MD5:6D509405F78992D7B6549E82A58D978A
SHA256:2103094BE12ABA4C2A3E3CC234A1E40A967983636F67CC539D68520A7A4D3742
3388WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3388.2565\Eziriz .NET Reactor 6.8.0\VSPackage\15\[Content_Types].xmlxml
MD5:EB2A6F6183149485432478C6BBFE8D82
SHA256:80E58A3FCE2F285C9B3DB607A4EB57F79FEE2B800E20738E02320ABFBD075245
3388WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3388.2565\Eziriz .NET Reactor 6.8.0\VSPackage\[Content_Types].xmlxml
MD5:B9C3AE0E82195B170FEA8976D2EAFF22
SHA256:14DEC7D1C20FC426AD5463D1B658F87A22F7E576BA4A08905CAF399551813A72
3388WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3388.2565\Eziriz .NET Reactor 6.8.0\.NET Reactor SDK Test Apps\License Examination .NET 5.0 Windows Forms\C#\LicenseExamination\bin\Release\net5.0-windows\LicenseExamination.exeexecutable
MD5:4521532CA48434FB46B8D02A78278E0A
SHA256:E5419FCEF71DB07C1C0A76D27E187F623D33657C2D4B67BA1938B6B5BAB8AC1D
3388WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3388.2565\Eziriz .NET Reactor 6.8.0\.NET Reactor SDK Test Apps\License Examination Windows Forms\VB.NET\SDK_TestApp\bin\Release\LicenseExamination.exeexecutable
MD5:58AC86B2CE7B6C33F47F795B0EDBA8CA
SHA256:7EEFF2D7498313C89254A0B0A804B223B7F0DD94F1724C82404FD3F291057703
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info