File name:

Spotify Checker ChileCracking By XCrisX.rar

Full analysis: https://app.any.run/tasks/3895455d-d264-4d1e-a824-ecd6a3523f13
Verdict: Malicious activity
Analysis date: June 22, 2019, 12:13:13
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

F4C9BAB1FBF76412580E8E26202E83FC

SHA1:

56263B604CCC5421D90E4E8A13C098981AD413D1

SHA256:

A44FAF91CB7F81A80FC7F4CA95274079C7B6BE93D7B98A4B77719CD4F090CEA0

SSDEEP:

12288:CA4aZ6LbYp2QDPZEVQMSN3jyx0aVoRS3pUAXfZciSrWu:CA4tbYppDRk+zy2aqg3p/fZkrWu

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Spotify Checker ChileCracking By XCrisX.exe (PID: 900)
      • ._cache_Spotify Checker ChileCracking By XCrisX.exe (PID: 620)
      • Synaptics.exe (PID: 680)
    • Changes the autorun value in the registry

      • Spotify Checker ChileCracking By XCrisX.exe (PID: 900)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 252)
      • Spotify Checker ChileCracking By XCrisX.exe (PID: 900)
    • Creates files in the program directory

      • Spotify Checker ChileCracking By XCrisX.exe (PID: 900)
  • INFO

    • Manual execution by user

      • Spotify Checker ChileCracking By XCrisX.exe (PID: 900)
    • Application was crashed

      • ._cache_Spotify Checker ChileCracking By XCrisX.exe (PID: 620)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
42
Monitored processes
4
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start drop and start drop and start winrar.exe spotify checker chilecracking by xcrisx.exe ._cache_spotify checker chilecracking by xcrisx.exe synaptics.exe

Process information

PID
CMD
Path
Indicators
Parent process
252"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Spotify Checker ChileCracking By XCrisX.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\windows\system32\comdlg32.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\powrprof.dll
620"C:\Users\admin\Desktop\._cache_Spotify Checker ChileCracking By XCrisX.exe" C:\Users\admin\Desktop\._cache_Spotify Checker ChileCracking By XCrisX.exe
Spotify Checker ChileCracking By XCrisX.exe
User:
admin
Company:
Spotify Checker ChileCracking By XCrisX
Integrity Level:
HIGH
Description:
Spotify Checker ChileCracking By XCrisX
Exit code:
0
Version:
3.0.0.0
Modules
Images
c:\users\admin\desktop\._cache_spotify checker chilecracking by xcrisx.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
680"C:\ProgramData\Synaptics\Synaptics.exe" InjUpdateC:\ProgramData\Synaptics\Synaptics.exe
Spotify Checker ChileCracking By XCrisX.exe
User:
admin
Company:
Synaptics
Integrity Level:
HIGH
Description:
Synaptics Pointing Device Driver
Exit code:
0
Version:
1.0.0.4
Modules
Images
c:\programdata\synaptics\synaptics.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
900"C:\Users\admin\Desktop\Spotify Checker ChileCracking By XCrisX.exe" C:\Users\admin\Desktop\Spotify Checker ChileCracking By XCrisX.exe
explorer.exe
User:
admin
Company:
Synaptics
Integrity Level:
HIGH
Description:
Synaptics Pointing Device Driver
Exit code:
0
Version:
1.0.0.4
Modules
Images
c:\users\admin\desktop\spotify checker chilecracking by xcrisx.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
Total events
753
Read events
615
Write events
138
Delete events
0

Modification events

(PID) Process:(252) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(252) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(252) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(252) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Spotify Checker ChileCracking By XCrisX.rar
(PID) Process:(252) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(252) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(252) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(252) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(900) Spotify Checker ChileCracking By XCrisX.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(900) Spotify Checker ChileCracking By XCrisX.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
Executable files
4
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
900Spotify Checker ChileCracking By XCrisX.exeC:\ProgramData\Synaptics\RCX6B8E.tmp
MD5:
SHA256:
900Spotify Checker ChileCracking By XCrisX.exeC:\Users\admin\Desktop\._cache_Spotify Checker ChileCracking By XCrisX.exeexecutable
MD5:
SHA256:
900Spotify Checker ChileCracking By XCrisX.exeC:\ProgramData\Synaptics\Synaptics.exeexecutable
MD5:
SHA256:
252WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa252.11919\Spotify Checker ChileCracking By XCrisX.exeexecutable
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
1
DNS requests
1
Threats
1

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
104.238.46.220:1199
xred.mooo.com
QuadraNet, Inc
US
unknown

DNS requests

Domain
IP
Reputation
xred.mooo.com
  • 104.238.46.220
suspicious

Threats

PID
Process
Class
Message
1068
svchost.exe
Misc activity
ET INFO DYNAMIC_DNS Query to Abused Domain *.mooo.com
No debug info