File name:

crypt.7z

Full analysis: https://app.any.run/tasks/5c3f10c6-da86-4f7e-9ac5-537f492ae73d
Verdict: Malicious activity
Analysis date: August 06, 2021, 14:07:11
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-7z-compressed
File info: 7-zip archive data, version 0.4
MD5:

3539E8958EF4132CC675C9E452803452

SHA1:

CF464F1A76F664B07AD4EB8EFE8FF07C872E730F

SHA256:

A61E15127DFCCF7D6BC7DFEE484B5E1952674B5B21B23A57B06E7C1D24D92F77

SSDEEP:

98304:kVP+8+fc5+6Qbi0aSvblOY7pFEBGF4fMteHo7S+xzEDTFKR8:MPR2biXGlzpFETEteI7S+xQDL

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • bcfmgr.exe (PID: 1700)
      • bcfmgr.exe (PID: 1992)
      • bcfmgr.exe (PID: 2768)
      • bcfmgr.exe (PID: 2180)
    • Loads dropped or rewritten executable

      • SearchProtocolHost.exe (PID: 1348)
      • bcfmgr.exe (PID: 1700)
      • bcfmgr.exe (PID: 2768)
      • bcfmgr.exe (PID: 2180)
      • bcfmgr.exe (PID: 1992)
  • SUSPICIOUS

    • Reads the computer name

      • WinRAR.exe (PID: 2076)
      • bcfmgr.exe (PID: 1700)
      • bcfmgr.exe (PID: 2768)
      • bcfmgr.exe (PID: 1992)
      • bcfmgr.exe (PID: 2180)
    • Drops a file that was compiled in debug mode

      • WinRAR.exe (PID: 2076)
    • Reads default file associations for system extensions

      • SearchProtocolHost.exe (PID: 1348)
    • Checks supported languages

      • WinRAR.exe (PID: 2076)
      • cmd.exe (PID: 3348)
      • bcfmgr.exe (PID: 1700)
      • bcfmgr.exe (PID: 2768)
      • bcfmgr.exe (PID: 1992)
      • bcfmgr.exe (PID: 2180)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2076)
    • Executed as Windows Service

      • vds.exe (PID: 460)
      • vds.exe (PID: 3640)
    • Drops a file with too old compile date

      • WinRAR.exe (PID: 2076)
    • Executed via COM

      • vdsldr.exe (PID: 1308)
      • vdsldr.exe (PID: 1996)
    • Creates or modifies windows services

      • bcfmgr.exe (PID: 1700)
      • bcfmgr.exe (PID: 1992)
    • Creates/Modifies COM task schedule object

      • bcfmgr.exe (PID: 1700)
  • INFO

    • Checks supported languages

      • vdsldr.exe (PID: 1308)
      • vds.exe (PID: 460)
      • vds.exe (PID: 3640)
      • vdsldr.exe (PID: 1996)
    • Reads the computer name

      • vds.exe (PID: 460)
      • vdsldr.exe (PID: 1308)
      • vds.exe (PID: 3640)
      • vdsldr.exe (PID: 1996)
    • Manual execution by user

      • cmd.exe (PID: 3348)
      • bcfmgr.exe (PID: 2768)
      • bcfmgr.exe (PID: 1992)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.7z | 7-Zip compressed archive (v0.4) (57.1)
.7z | 7-Zip compressed archive (gen) (42.8)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
57
Monitored processes
11
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe searchprotocolhost.exe no specs cmd.exe bcfmgr.exe no specs vdsldr.exe no specs vds.exe no specs bcfmgr.exe no specs bcfmgr.exe vdsldr.exe no specs vds.exe no specs bcfmgr.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
460C:\Windows\System32\vds.exeC:\Windows\System32\vds.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Virtual Disk Service
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\vds.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\atl.dll
1308C:\Windows\System32\vdsldr.exe -EmbeddingC:\Windows\System32\vdsldr.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Virtual Disk Service Loader
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\vdsldr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\atl.dll
1348"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe4_ Global\UsGthrCtrlFltPipeMssGthrPipe4 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\system32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7601.24542 (win7sp1_ldr_escrow.191209-2211)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1700bcfmgr.exeC:\Users\admin\Desktop\crypt\bcfmgr.execmd.exe
User:
admin
Company:
Jetico Inc. Oy
Integrity Level:
HIGH
Description:
BestCrypt Volume Encryption Manager
Exit code:
0
Version:
4.24.2
Modules
Images
c:\users\admin\desktop\crypt\bcfmgr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\version.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\hid.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\secur32.dll
1992"C:\Users\admin\Desktop\crypt\bcfmgr.exe" C:\Users\admin\Desktop\crypt\bcfmgr.exe
Explorer.EXE
User:
admin
Company:
Jetico Inc. Oy
Integrity Level:
HIGH
Description:
BestCrypt Volume Encryption Manager
Exit code:
0
Version:
4.24.2
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\users\admin\desktop\crypt\bcfmgr.exe
c:\windows\system32\msvcrt.dll
c:\windows\system32\secur32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\hid.dll
1996C:\Windows\System32\vdsldr.exe -EmbeddingC:\Windows\System32\vdsldr.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Virtual Disk Service Loader
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\vdsldr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\atl.dll
2076"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\crypt.7z"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2180bcfmgr.exe -CC:\Users\admin\Desktop\crypt\bcfmgr.execmd.exe
User:
admin
Company:
Jetico Inc. Oy
Integrity Level:
HIGH
Description:
BestCrypt Volume Encryption Manager
Exit code:
4
Version:
4.24.2
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\desktop\crypt\bcfmgr.exe
c:\windows\system32\version.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\hid.dll
c:\windows\system32\rpcrt4.dll
2768"C:\Users\admin\Desktop\crypt\bcfmgr.exe" C:\Users\admin\Desktop\crypt\bcfmgr.exeExplorer.EXE
User:
admin
Company:
Jetico Inc. Oy
Integrity Level:
MEDIUM
Description:
BestCrypt Volume Encryption Manager
Exit code:
0
Version:
4.24.2
Modules
Images
c:\users\admin\desktop\crypt\bcfmgr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\hid.dll
3348"C:\Windows\System32\cmd.exe" C:\Windows\System32\cmd.exe
Explorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
2 243
Read events
2 208
Write events
28
Delete events
7

Modification events

(PID) Process:(2076) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2076) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2076) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2076) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(2076) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\crypt.7z
(PID) Process:(2076) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2076) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2076) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2076) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2076) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath
Operation:writeName:0
Value:
C:\Users\admin\Desktop
Executable files
11
Suspicious files
2
Text files
4
Unknown types
0

Dropped files

PID
Process
Filename
Type
2076WinRAR.exeC:\Users\admin\Desktop\crypt\Rescue\rescue.rscbinary
MD5:
SHA256:
2076WinRAR.exeC:\Users\admin\Desktop\crypt\langfile.dllexecutable
MD5:
SHA256:
2076WinRAR.exeC:\Users\admin\Desktop\crypt\license.txttext
MD5:
SHA256:
2076WinRAR.exeC:\Users\admin\Desktop\crypt\x32\bcfnt.sysexecutable
MD5:
SHA256:
2076WinRAR.exeC:\Users\admin\Desktop\crypt\$I30binary
MD5:
SHA256:
2076WinRAR.exeC:\Users\admin\Desktop\crypt\bcfmgr.exeexecutable
MD5:B9337830C32F71A6ECCCEC60BA42DE00
SHA256:7604E9ECEDF298907E537E50B9C74006640561B32265C3EBBA38E587166F67AB
2076WinRAR.exeC:\Users\admin\Desktop\crypt\etoken_3_66.dllexecutable
MD5:17637E2E815F7FE35DCC5D6243BD5353
SHA256:A0F0C56079BA42ABB04C5272A2848DD22171A3E179C8F0F79B2DEFF255E63F2A
2076WinRAR.exeC:\Users\admin\Desktop\crypt\x32_win10\bcfnt.sysexecutable
MD5:B39358A3AA13D11245B2060CB5BC942D
SHA256:619A8626399CCDB122088439E49001A5FA63C3671D7FF451732F1D66B20896C9
2076WinRAR.exeC:\Users\admin\Desktop\crypt\langinfo.txttext
MD5:296B83C4F9BEA1F33578F5FCD0F329A4
SHA256:CC1A434C7561F8C9E8A57DE84E2A138F0B781B986CC21E85336EDCECBABBE8E9
2076WinRAR.exeC:\Users\admin\Desktop\crypt\x32\fsh.sysexecutable
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info